← Back to HeadStrong

Privacy Policy

Last updated: August 15, 2026

HeadStrong ("HeadStrong", "we", "us", or "our") is a mental health app. You can book licensed therapists and meet them by video, talk to trained peer supporters, take validated screening questionnaires, journal, and use an AI guide. Every one of those produces sensitive information about you, and this policy explains exactly what we do with it.

The short version: We collect what the product needs and not more. We never sell your data and there are no advertising or tracking SDKs in our apps. Your journal, check-ins, screening results, and conversations are yours — a therapist sees them only when you choose to share them. Your 1:1 therapy sessions are not recorded. You can export or delete everything at any time.

1. Who this policy covers

This policy covers the HeadStrong mobile and web apps and the getheadstrong.xyz website. Section 2.3 covers the extra information we collect from therapists and other providers who list on HeadStrong; if you are a client, that section does not apply to you.

2. What we collect

2.1 Information you give us

2.2 Information collected automatically

2.3 If you are a provider

Therapists and other providers give us additional professional information so we can verify them and pay them: legal name, NPI number, license type, number, and state, and in some cases a photo of the license. We check that information against the national provider registry (NPPES) and screen it against the federal exclusion list (OIG LEIE). Payout and tax details are collected directly by Stripe during onboarding — we never see your bank account or tax identification numbers. Providers who connect a calendar grant us read access to free/busy times through Google Calendar or a subscribed iCal feed; we read availability, not event contents where the feed allows that distinction.

2.4 What we do not collect

3. How we use your information

4. Your conversations with our AI

Liam, Ariel, and Sol are AI, not people and not therapists, and they say so. To generate a reply, your message and the minimum context needed are sent to OpenRouter, which routes the request to a large language model provider. We do not use your conversations to train any model of our own, and we do not sell or share them with advertisers or partners. Your conversation history is stored in our database, tied to your account, so the guide can remember what you have talked about — and you can delete it from the app at any time.

AI conversations are scanned for signs of crisis (section 6). When a Sol conversation triggers that review, the record we create deliberately contains no message text — only the risk level and the type of signal — so reviewing a safety event never means reading your conversation.

5. Video sessions

Video and audio for sessions run through Daily.co. The media itself is real-time.

One-to-one therapy sessions are not recorded. Not by us, not by default, and not by your therapist through the app. If we ever offer session recording, it will require your explicit consent first, shown to you before anything starts, and you will be able to decline and still have your session.

Group webinars are different: a webinar host runs a recorded broadcast, and you are told that before you join. If you do not want to be recorded, do not join the webinar.

6. Crisis detection and when a human gets involved

Messages in the app are automatically screened for indications that someone may be in danger. Most of the time nothing happens beyond the app surfacing crisis resources to you. When the signal is strong, a safety event is created for review by a trained person on our team.

The same applies to two specific screening questions: PHQ-9 question 9 and EPDS question 10 both ask directly about thoughts of harming yourself. Answering either above zero surfaces support immediately and creates a safety event for human review. We would rather over-respond than miss someone.

This is not a monitoring service and it is not a substitute for emergency care. Where there is a credible risk to someone's life, we may contact emergency services, as permitted by law.

7. What your therapist can see

Nothing, until you decide otherwise. Booking a session shares what the booking requires — your name and the appointment. Your journal, check-ins, and screening results are shared with a provider only when you explicitly turn sharing on, you can see exactly what is covered before you do, and you can turn it off again. Turning it off stops future access.

8. Payments

Subscriptions bought inside the app are processed by Apple or Google and tracked for us by RevenueCat, which tells us your subscription status. Session fees and provider payouts run through Stripe. Card and bank details go directly to those processors; we receive confirmation and status, not the numbers. If you use a superbill for insurance reimbursement, the document contains the clinical and billing codes your insurer requires, and it is generated for you to submit — we do not send it to an insurer on your behalf without you asking.

9. Your privacy controls

In the app, under Settings, you can independently turn each of these on or off:

You can also export everything we hold (Settings → Export My Data) and delete your account and its data (Settings → Delete Account). If you have already uninstalled the app, use our data deletion request page.

10. How we share information

We do not sell your personal information, and we do not share it for advertising. We share it only in these cases:

11. Security

We encrypt data in transit (TLS 1.2+) and at rest, encrypt particularly sensitive fields at the application layer on top of that, restrict access with per-user authorization rules enforced on the server, log access to sensitive records, and apply safeguards informed by the HIPAA Security Rule. The app can also lock itself behind your device biometrics after it has been in the background — that check happens on your device and your biometric data never reaches us. No system is perfectly secure. If we become aware of a breach affecting your information, we will notify you as required by law.

12. How long we keep things

We keep your account and its data while your account is active. You can delete individual content — journal entries, chat history, check-ins — at any time. When you delete your account we delete your personal information within 30 days, except where we must retain something to meet a legal obligation, resolve a dispute, or enforce our agreements. Some records that regulation requires us to keep, such as security audit logs, are retained on their own schedule and are not tied to your profile.

13. Your rights

Depending on where you live, you may have the right to access a copy of your information, correct it, delete it, receive it in a portable format, object to or restrict certain processing, withdraw consent you previously gave, and complain to a data protection authority. Use the in-app export and delete controls, or email privacy@getheadstrong.xyz. We respond within 30 days.

California residents (CCPA / CPRA)

California residents have the right to know what personal information is collected, to delete it, to correct it, and to opt out of its sale or sharing. We do not sell or share personal information as those terms are defined.

European and UK residents (GDPR)

Our legal bases are: performance of our contract with you (running the service), your consent (analytics, personalization, research data, marketing email), our legitimate interests (security, crash diagnostics, preventing abuse), compliance with legal obligations, and — for the crisis pathway — protection of the vital interests of you or another person.

14. Children

HeadStrong is for adults. It is not directed to children, and we do not knowingly collect information from anyone under 18. If you believe a minor has created an account, contact us and we will remove it.

15. International transfers

HeadStrong is operated from the United States, and information is stored and processed there. If you use the service from elsewhere, your information is transferred to the United States.

16. TikTok integration (creator tools only)

This section applies only to HeadStrong's own content and marketing tooling, which is not part of the HeadStrong mental health app and is not available to clients or providers. Where an authorized team member connects a TikTok account, we access that account's profile information (display name, avatar, open ID) and public video list through TikTok's API and can publish videos to that profile on the account holder's behalf. We do not store TikTok credentials, and TikTok data is used only to operate those posting features. Access can be revoked at any time in TikTok account settings. No client data is ever sent to TikTok.

17. Third-party links

Our site and app link to third-party services, including our own social accounts. This policy does not cover them.

18. Changes to this policy

We may update this policy. If the change is material we will notify you by email or with a prominent notice in the app or on the website before it takes effect.

19. Contact

A note on crises: HeadStrong is a wellness and care-access tool, not a medical device and not a replacement for emergency care. If you are in danger right now, call 911, or call or text 988 (Suicide & Crisis Lifeline). New and expecting parents can reach the National Maternal Mental Health Hotline at 1-833-852-6262, free, 24/7, English and Spanish.