Our commitment to data protection
Rewire Clinical is operated by Rewire App LLC ("Rewire", "we", "us"). We provide a modality-agnostic clinical documentation and between-session support platform for licensed mental health professionals and their clients. Because our platform is used in a clinical context, we treat data protection as a clinical governance obligation.
This policy applies to all users of the Rewire Clinical platform: licensed clinicians ("Clinicians") and their clients ("End Users") who access Rewire Clinical under a clinician's assignment.
For clinical governance review: Rewire's infrastructure is built toward the HIPAA Security Rule's Technical Safeguard requirements (45 CFR §164.312) — including access controls, audit logging, and encryption in transit and at rest. For organizations that are HIPAA Covered Entities (hospitals, treatment facilities, EAPs), a direct Business Associate Agreement (BAA) is available at the facility tier. We are committed to GDPR compliance for all European users under Regulation (EU) 2016/679. Our primary data processor, Supabase, maintains SOC 2 Type II certification and operates under a Business Associate Agreement. Data transfers to the US are governed by Standard Contractual Clauses (SCCs).
Who is responsible for your data
Data Controller: Rewire App LLC
For all data protection enquiries, data subject rights requests, and Business Associate Agreement requests:
Email: privacy@rewire-emdr.com
Subject line: "Data Privacy Request — Rewire Clinical"
We will acknowledge all requests within 72 hours and respond in full within 30 days.
What we collect and why
Clinician accounts
| Data type | Purpose | Legal basis (GDPR) |
|---|---|---|
| Email address | Account authentication and platform communications | Contract performance — Art. 6(1)(b) |
| Practice / facility name | Displayed within the clinician dashboard; identifies the practice to assigned clients | Contract performance — Art. 6(1)(b) |
| Subscription and billing data | Payment processing via Stripe. Card details are not stored by Rewire. Stripe is PCI DSS Level 1 compliant. | Contract performance — Art. 6(1)(b) |
| Client roster and account details | Client account identifiers, email addresses, optional first names, clinician and facility links, and access or invitation codes used to provide and administer care access. | Contract performance — Art. 6(1)(b) |
End User (client) data
| Data type | Purpose | Legal basis (GDPR) |
|---|---|---|
| Email address | Authentication and service communications. Shared with service providers such as Supabase, Paubox/Resend, and Stripe only as needed to operate the service; not sold or shared for advertising. | Contract performance — Art. 6(1)(b) |
| Session & progress data | Records which exercises and assignments have been completed. Visible to the assigning clinician for care continuity. | Legitimate interests — Art. 6(1)(f) (clinical care continuity) |
| Distress / state ratings | Pre/post exercise ratings entered by the user. Shared with the assigning clinician for clinical review. | Consent — Art. 6(1)(a) |
| Journal & reflection entries | Optional written reflections. Shared with the assigning clinician only if the user explicitly enables sharing. Constitutes potentially special category data. | Explicit consent — Art. 9(2)(a) |
| AI conversation content | Used in real time to generate personalised session content only. Not stored permanently. Not used for AI model training. | Consent — Art. 6(1)(a) |
Data we do not collect
- Rewire Clinical does not require a full legal name for an individual client account, but may collect an optional first name, and clinician or facility rosters may include identifying account details
- User data is not sold, licensed, or shared with third parties for commercial purposes
- No user data — including AI conversations — is used to train AI models
- The clinical application and authenticated portals do not use advertising trackers or behavioural profiling
How we protect your data
Infrastructure
User data is stored primarily in Supabase, a managed PostgreSQL-based platform operating under a Business Associate Agreement with Rewire. Data is stored on managed infrastructure that provides encryption at rest. Application traffic to Rewire's service providers is encrypted in transit using HTTPS/TLS.
Access controls and row-level security
Rewire Clinical implements row-level security (RLS) at the database layer. Each clinician can access only the data for clients they have directly assigned. No clinician can access data belonging to clients of a different clinician. No Rewire employee accesses user session data or journal entries in the ordinary course of operations.
Clinical free-text encryption
Clinical free-text — including journal entries and narrative notes — is protected with client-side end-to-end encryption (AES-256-GCM with X25519 key wrapping). This content is encrypted on the user's device before storage, so neither Rewire nor its database provider can read it.
AI processing safeguards
AI-generated content is routed through a Cloudflare Worker to a secure, HIPAA-covered third-party AI provider under a Business Associate Agreement. Rewire does not intentionally add account names or email addresses to AI requests, does not use AI conversation content to train models, and does not intentionally retain AI conversation logs server-side beyond the active request.
HIPAA-aligned controls
- Unique user identification and strong authentication for all accounts
- Automatic session timeout after inactivity
- Role-based access controls preventing cross-clinician data access
- Managed infrastructure providing encryption at rest and HTTPS/TLS in transit
- End-to-end encryption of clinical free-text, unreadable by Rewire and its subprocessors
- PHI-access audit logging with a 6-year retention window
Organizations that are HIPAA Covered Entities may request a facility-level Business Associate Agreement at privacy@rewire-emdr.com.
Data retention
- Active account data is retained for as long as the account remains active
- Clinician account data is deleted within 30 days of account closure
- End user session data and journal entries are scheduled for deletion within 30 days of the end user's account closure; removal from a clinician's roster does not itself delete the end user's account or history
- Billing records are retained for 7 years in accordance with applicable financial regulations
- Anonymised, aggregated analytics data (no personal identifiers) may be retained indefinitely for product improvement
Third-party processors we use
| Processor | Purpose | Jurisdiction | Certification |
|---|---|---|---|
| Supabase | Database, authentication, file storage | US / EU (configurable) | SOC 2 Type II · BAA |
| AI provider (HIPAA-covered, under BAA) | Models used for AI session content generation | US (API processing) | Business Associate Agreement and provider terms apply |
| Cloudflare | Worker proxy for AI requests; DDoS and edge security | Global edge network | SOC 2 Type II, ISO 27001 |
| Paubox | HIPAA-compliant transactional email (BAA) | US | Business Associate Agreement |
| Stripe | Payment processing | US / EU | PCI DSS Level 1 |
We review all sub-processor agreements for GDPR adequacy before engagement. Data transfers to the US are covered by Standard Contractual Clauses (SCCs) under GDPR Art. 46(2)(c). We will notify account holders of any material change to our sub-processor list at least 30 days in advance.
Data subject rights
Users in the EEA, UK, Switzerland, and equivalent jurisdictions have the following rights under GDPR (or applicable equivalent legislation):
- Right of access (Art. 15): Request a copy of all personal data we hold about you.
- Right to rectification (Art. 16): Request correction of inaccurate or incomplete personal data.
- Right to erasure (Art. 17): Request permanent deletion of your personal data. Note: billing records may be retained for the statutory minimum period.
- Right to data portability (Art. 20): Request your personal data in a structured, machine-readable format (JSON or CSV).
- Right to restrict processing (Art. 18): Request that we restrict processing while a dispute is resolved.
- Right to object (Art. 21): Object to processing based on legitimate interests, including any direct marketing.
- Right to withdraw consent: Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights: email privacy@rewire-emdr.com with the subject line "Data Subject Rights Request". We will respond within 30 days. You also have the right to lodge a complaint with your national supervisory authority.
Sensitive data and mental health information
Journal entries and clinical narrative entered by users may constitute special category data under GDPR Art. 9, specifically data concerning health and mental wellbeing. We treat all such content as special category data by default and apply the following additional protections:
- Clinical free-text is protected with client-side end-to-end encryption (AES-256-GCM with X25519 key wrapping): encrypted on the user device before storage, so neither Rewire nor its database provider can read it
- Journal entries are never shared with the assigning clinician without explicit, in-app consent from the end user
- Journal entries are never used for AI model training, analytics, or any purpose other than direct service provision to the user
- Clinicians are contractually bound by our Terms of Service to obtain appropriate informed consent from clients before assigning Rewire Clinical
Cookies and tracking
The clinical application and authenticated portals use browser storage and session technologies needed for authentication and application functionality. They do not load advertising trackers, behavioural analytics, or device-fingerprinting technology.
Policy updates
We will notify all active account holders by email of material changes to this policy at least 14 days before they take effect. The current version is always available at rewireclinical.com/privacy. Continued use of the platform after the effective date of a revised policy constitutes acceptance of the updated terms.
For questions about this policy: privacy@rewire-emdr.com