Privacy Policy
Last updated: 22 July 2026
Sensitive & Connected is software that therapists use to run their practice and that their clients use to stay connected between sessions. This policy explains what personal information we collect, why we hold it, who we share it with and what you can ask us to do with it.
Some of what we hold is information about your health, including notes your therapist writes about your care. We treat that as the most sensitive information on the platform and this policy sets out the extra protections that apply to it.
Who is responsible for your information
Sensitive & Connected is operated by Anastasiya Yunchyts, an individual based at Wiślańska 21, 32-070 Wołowice, Poland. You can reach us at privacy@sensitiveco.com.
The service is in private testing and is not yet open to the public. Before it opens we will move it to a registered company or foundation, which will then be responsible for your information in place of the person named above. We will update this policy and tell you before that happens.
Your therapist decides what to record about your care and how long your clinical record should be kept. They are the data controller for your clinical information. We provide and run the software that stores it on their behalf, which makes us their data processor. For account information such as your email address and sign-in details, we act as the controller.
In practice this means questions about what is in your clinical record are best raised with your therapist, and questions about the app or your account can come to us. You can always contact us and we will help you reach the right person.
Information we collect about clients
Information you or your therapist provide
- Your name, email address, phone number and country
- Your password, stored only as a scrambled value we cannot reverse
- Answers you give in intake forms and questionnaires, including clinical questionnaires such as PHQ-9 and GAD-7
- Messages you exchange with your therapist
- The consents you have given or declined, and when
Information your therapist records about your care
- Session notes, including the plan for your next session
- A working clinical profile your therapist maintains about your care
- A risk level and its history, where your therapist records one
- Appointment dates, times and formats, and any changes to them
- The therapeutic pathway your therapist sets out for you
Information we collect automatically
- Your IP address when you sign in or attempt to sign in, which we use to stop people guessing passwords
- A notification token for your device if you turn on notifications, so we can send them
- Records of significant actions taken in your account, kept as an audit trail
We do not use analytics, advertising or tracking software of any kind. The app contains no advertising identifiers, no crash reporting and no third party trackers. We do not profile you and we do not make automated decisions about you.
Information we collect about therapists
- Your name, email address and password
- Your professional details, including licence number, licensing body and where you practise
- Your Google account identifier and email if you choose to sign in with Google
- Your calendar settings, working hours and any time you block out, including the reason you give
- Your subscription and billing status
- Your IP address when you sign in or attempt to sign in
Why we are allowed to hold this information
We are based in Poland, so the General Data Protection Regulation and Polish data protection law apply. We rely on the following grounds.
- To provide the service. We need your account and appointment information to run the platform you have signed up to use.
- Health and care. Information about your health is held so your therapist can provide care and keep the clinical records their profession requires them to keep.
- Your consent. Some features, such as notifications, only operate if you turn them on. You can withdraw consent at any time.
- Our legitimate interests. We keep sign-in records and audit trails to keep accounts secure.
- Legal obligations. Some records must be kept because the law or a professional body requires it.
Who we share information with
We do not sell your information and we never share it for advertising. We use a small number of service providers to run the platform.
| Provider | What it does | What it receives |
|---|---|---|
| Render | Hosts the application and database in Frankfurt, Germany | All platform data, stored in the EU |
| Resend | Sends emails such as invitations and sign-in links | Your email address, your name, and for appointment changes the therapist name and appointment times |
| Expo | Delivers notifications to your device | Your device notification token and the text of the notification |
| Zoom | Carries video and audio for online sessions | Your video and audio during a session, identified only by an internal reference that does not contain your name or email |
| Optional sign-in for therapists only | Sign-in confirmation and email address |
Online sessions are not recorded. Video and audio pass through Zoom in order to reach the other person and are not stored by us.
We may also share information where the law requires it, or where there is a serious risk to someone's safety. Your therapist is bound by their own professional duties about when they must break confidentiality, and they will normally have explained these to you.
Where your information is stored
The platform and its database run in Frankfurt, Germany, and your clinical information stays in the European Union. Some of our service providers are based outside the EU and the UK. Where information reaches them, it is protected by the standard contractual clauses approved for international transfers.
How long we keep it
Your therapist decides how long your clinical record is kept, in line with the rules of their profession. This is often several years after your care ends, and for some professions longer.
Clinical records on this platform are designed so they cannot quietly be altered or erased after the fact. Changes to notes, changes to a recorded risk level and records of consent are kept as a permanent history. This protects both you and your therapist, because it means the record of your care is trustworthy. It also means that some of your information cannot simply be deleted on request, and the section below explains what that means for your rights.
Account information is kept while your account is open. Records of failed sign-in attempts are kept so we can detect attacks on accounts.
While the service is in private testing we keep information only for as long as the testing needs it. You can ask us to remove your information at any time by emailing privacy@sensitiveco.com, and we will do so unless your therapist is required to keep the clinical record.
Your rights
You have the right to:
- Ask what information we hold about you and get a copy
- Ask us to correct information that is wrong
- Ask us to delete information, though this is limited for clinical records your therapist is required to keep
- Ask us to restrict or object to how information is used
- Withdraw consent for anything you agreed to, without affecting what happened before you withdrew it
- Complain to a data protection regulator. Ours is the Polish authority, the Urząd Ochrony Danych Osobowych (UODO), at uodo.gov.pl. You can also complain to the authority in the country where you live.
To exercise any of these, email us at privacy@sensitiveco.com. We handle these requests by hand rather than through a button in the app, and we will respond within one month. If your request concerns your clinical record we will need to involve your therapist, because the decision about that record is theirs.
How we protect your information
- All traffic between your device and the platform is encrypted
- Passwords are stored scrambled using a slow hashing method, so they cannot be read even by us
- Sign-in tokens are stored only as a scrambled value
- On your phone, your sign-in token is held in the device's secure storage, protected by the iOS Keychain or Android Keystore
- The database sits on a private network and is not exposed to the internet
- Repeated failed sign-in attempts are blocked
- Your therapist can only see their own clients
No system is perfectly secure. If a breach affects your information and puts you at risk, we will tell you and the relevant regulator as the law requires.
Age
This service is for adults. You must be 18 or over to have an account, whether as a therapist or as a client.
We do not knowingly collect information about anyone under 18. If you believe a person under 18 has an account, email us at privacy@sensitiveco.com and we will look into it and remove their information.
Therapists using this platform are responsible for confirming that a client they invite is 18 or over. The platform is not currently built to support treating young people, because it does not record a date of birth and has no way to capture consent from a parent or guardian.
Changes to this policy
If we make a significant change we will tell you in the app or by email before it takes effect. The date at the top shows when this policy was last updated.
Contact us
Email privacy@sensitiveco.com with any question about this policy or about your information. We are a small team and your message reaches us directly.
We have not appointed a data protection officer. We are not required to have one, because we do not process personal information on the scale that triggers that duty. If that changes we will appoint one and say so here.