P Privity
Home Privacy & HIPAA Request access
Legal

Privacy Policy

Bespoke Therapist Software Utah LLC — Privity
Last Updated: August 17, 2026
Section 1

Who we are

Privity is a documentation-assistance tool for licensed mental and behavioral health professionals, operated by Bespoke Therapist Software Utah LLC ("Bespoke," "we," "us," or "our"). This Privacy Policy explains what information we collect, how we use it, and the choices available to you.

This policy covers the Privity application and the Privity marketing website. It does not cover third-party services you reach through links or integrations, which have their own policies.

Section 2

The short version

  • We do not sell your personal information.
  • We do not use your information, or any patient information processed through the Services, to train any artificial intelligence model.
  • We do not persistently store session-note images, audio, transcriptions, or generated notes. They are processed in memory for a single request and then deleted.
  • Our marketing website uses no cookies, analytics, advertising pixels, or trackers. Requesting access uses a short form that asks only for professional contact details.
  • The personal information we retain is the operational and billing information needed to run accounts and credits, plus your contact details so we can reach you about your account and about Privity itself.
  • We send product and feature updates by email, and you can opt out of them at any time.
Section 3

Information we collect

3.1 Marketing website and access requests

Our public marketing website uses no cookies, no analytics, no advertising or tracking pixels, and no trackers, and its own pages collect no personal information.

To request access to Privity, we ask you to complete a short access-request form, hosted by Google Forms and linked from our website. It collects the professional information we need to evaluate and set up access: your name, your work email address, the practice you work with (if any), the kind of account you are requesting, and the state where you practice. We do not ask about your own health, and you should never submit patient information through this form. Responses are stored in Google Workspace and reviewed by us.

You can also simply email us at the address we publish, in which case we have whatever information you choose to include.

3.2 The application (operational and billing data)

When a clinician is granted access to the application, we maintain a limited set of operational data needed to run the Services. This is stored in our cloud database (Google Firestore) and does not include the content of session notes or generated documents. It includes:

  • clinician email address;
  • professional license type, license number, and state of licensure;
  • practice membership and role;
  • credit balance and credit/usage events (for example, the type of action taken, the number of inputs, and a timestamp);
  • authentication and access records; and
  • records of your acceptance of our Terms of Service and of any Business Associate Agreement you sign — including the date and time of acceptance, the version of the document accepted, and the identifying information you provided at signing.

3.3 Protected Health Information / clinical content (transient only)

When a clinician uses the Services, the clinician may submit a photograph of handwritten notes, an optional voice memo, and free-text context, and the Services return a generated draft. This content may include Protected Health Information ("PHI"). This content is processed transiently and is never persistently stored. It exists in memory (and, briefly, in a temporary file in volatile memory) only for the duration of a single request, after which it is deleted. We do not retain it, reuse it, or use it to train any model. Our handling of PHI is governed by HIPAA and by the Business Associate Agreement between your practice and Bespoke.

3.4 Audit logs

For security and compliance, we keep audit logs of events such as logins and generation actions. These logs record identifiers such as email, IP address, action type, and timestamp. They do not contain the content of notes or generated documents.

Section 4

How we use information, and our service providers

We use access-request information solely to evaluate your request, to set up your access if it is granted, and — if you asked us to when you submitted it — to send you product updates. We use operational and billing data to provide, secure, and administer the Services (authenticate access, track and reserve credits, prevent abuse, and meet our legal and compliance obligations). We may use your license number to verify with the issuing licensing authority that your professional license is active and in good standing. We reserve the right to do so at any time while your account is open; we do not represent that we verify every license or that we verify on any particular schedule. We use transiently-processed clinical content solely to generate the draft you requested, and for no other purpose.

We also use your email address to contact you. That includes service messages about your account — billing, security, and availability notices — which are part of providing the Services and cannot be opted out of while your account is open. It also includes product and feature updates about Privity: new capabilities, changes to the Services, and similar product news. You may opt out of product and feature updates at any time, using the unsubscribe instructions in any such message or by emailing us at the address below; we act on opt-out requests promptly. We do not sell or rent your contact information, and we do not send you marketing on behalf of anyone else.

We rely on the following third-party service providers ("subprocessors"):

  • Google — cloud hosting (Cloud Run), database (Firestore), and the AI model that generates drafts (Gemini, on the Gemini Enterprise Agent Platform — the service Google renamed from "Vertex AI" in April 2026), all under a signed Business Associate Agreement with Bespoke, with clinical content processed on a United States multi-region endpoint. We also use Google Workspace for our business email and to host the access-request form described in § 3.1. No clinical content or patient information is placed in Google Workspace.
  • Stripe — payment processing for credit purchases, handled on a separate, physically isolated service. Stripe receives only billing identity and transaction data; it never receives PHI or clinical content.

We do not sell personal information, and we do not share it for cross-context behavioral advertising.

Section 5

Data retention

  • Clinical content / PHI: not retained — deleted after each request.
  • Operational and billing data: retained for as long as your account is active and as needed for legitimate business and legal purposes.
  • Access requests: retained while we evaluate the request and as needed for legitimate business purposes. If access is granted, the relevant details become part of your account record.
  • Contact details used for product updates: retained while your account is active. If you opt out of product and feature updates, we keep the minimum record needed to honor that choice.
  • License and signature records: retained for as long as your account is active and for six years after any agreement you signed terminates, consistent with 45 CFR § 164.530(j).
  • Signed agreements: we retain the information used to generate your signed agreement — your identity, license details, the timestamp of acceptance, and the version of the document accepted — rather than a stored copy of the PDF itself. The PDF is generated and delivered to you at signing and can be reproduced from that record.
  • Audit logs: retained for at least seven years, which meets both the six-year minimum under HIPAA (45 CFR § 164.316(b)(2)(i)) and Utah's longer recordkeeping expectations. Audit records are written to storage under a locked retention policy: entries cannot be altered or deleted before the retention period expires, and the policy itself cannot be shortened or removed once locked. Audit records describe who accessed the Services and what action was taken; they never contain the content of a session note or a generated draft.
Section 6

Security

We use administrative, technical, and physical safeguards designed to protect information, including encryption in transit, authenticated and access-controlled entry to the application, and an architecture that avoids persistent storage of PHI. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.

Section 7

Your choices and rights

Because the application is used by clinicians within their practices, much of the information we hold is operational. If you are a clinician or practice and wish to access, correct, or delete operational or billing data we hold about you, contact us at the address below.

Product email. You can opt out of product and feature announcements at any time — follow the unsubscribe instructions in any such message, or email us. Opting out does not stop essential service messages about your account, such as billing, security, and availability notices.

Section 8

Children

The Services are intended for use by licensed professionals and are not directed to children. We do not knowingly collect personal information directly from children through the Services.

Section 9

Changes to this policy

We may update this policy from time to time. We will post the updated policy and update the "Last Updated" date.

Section 10

Contact

Bespoke Therapist Software Utah LLC
Email: Justin@bespoke-therapist-software.com
P Privity
Justin@bespoke-therapist-software.com
Bespoke Therapist Software Utah LLC
© 2026 · All rights reserved
Privacy Policy Terms of Service