Privacy Policy
Last updated: August 15, 2026
HeadStrong ("HeadStrong", "we", "us", or "our") is a mental health app. You can book licensed therapists and meet them by video, talk to trained peer supporters, take validated screening questionnaires, journal, and use an AI guide. Every one of those produces sensitive information about you, and this policy explains exactly what we do with it.
1. Who this policy covers
This policy covers the HeadStrong mobile and web apps and the getheadstrong.xyz website. Section 2.3 covers the extra information we collect from therapists and other providers who list on HeadStrong; if you are a client, that section does not apply to you.
2. What we collect
2.1 Information you give us
- Account: email address and display name. Your password is handled by Firebase Authentication and we never see it. If you sign in with Apple or Google, we receive only what that sign-in returns to us.
- What you log: mood check-ins, journal entries, and the assessments you complete in the app.
- Clinical screening results: your answers to and scores on the PHQ-9 (depression), GAD-7 (anxiety), PCL-5 (post-traumatic stress), and EPDS (perinatal depression). These are stored as a history so you can see your trend over time.
- Conversations: messages you send to our AI guides (Liam and Ariel) or to Sol, the AI companion used in peer matching, and messages you exchange in peer support chats.
- Preferences you set: including whether you have told us you work a high-stress job, or that you are a new parent. The new-parent setting is information about pregnancy or childbirth, and we treat it as sensitive.
- Booking details: the sessions you book, with whom, and when.
- Photos, only if you choose to upload one: the app asks for photo or camera access only for provider license verification. It is not used anywhere else.
- Waitlist and quiz: if you give us your email on our website for the Mental Health Score quiz or the waitlist, we store it to send you what you asked for and occasional product updates.
2.2 Information collected automatically
- Device and app: device type, operating system version, app version, and language.
- Usage: which features you use and how often, if you have turned analytics on. Analytics is off unless you turn it on.
- Crash and performance data: stack traces and performance timings, through Sentry and Firebase Performance. Before anything leaves your device we strip your email, username, and IP address; an anonymous account identifier is kept so we can tell whether one person hit the same bug twice.
- Push token: if you allow notifications, so we can send session reminders and messages.
- Website: minimal cookies and browser local storage to remember quiz progress and preferences.
2.3 If you are a provider
Therapists and other providers give us additional professional information so we can verify them and pay them: legal name, NPI number, license type, number, and state, and in some cases a photo of the license. We check that information against the national provider registry (NPPES) and screen it against the federal exclusion list (OIG LEIE). Payout and tax details are collected directly by Stripe during onboarding — we never see your bank account or tax identification numbers. Providers who connect a calendar grant us read access to free/busy times through Google Calendar or a subscribed iCal feed; we read availability, not event contents where the feed allows that distinction.
2.4 What we do not collect
- No location. The apps do not request or use device location, precise or coarse. When you pick a state to find a therapist licensed there, that is a choice you type, not a reading from your phone.
- No advertising or tracking SDKs. There is no ad network, no attribution SDK, and no access to the iOS advertising identifier anywhere in our apps. We do not track you across other companies' apps or websites, which is why iOS never shows you a tracking permission prompt for HeadStrong.
- No contacts, no microphone or camera outside the features that need them (video sessions and license verification).
- No card numbers. Payments are handled by Apple, Google, or Stripe. We see that a payment succeeded, not the instrument.
- No data purchased from brokers.
3. How we use your information
- Run the product: your account, bookings, sessions, messages, screenings, and progress.
- Show you your own history and trends, and personalize what the app suggests — only if you have turned personalization on.
- Let the AI guides respond usefully and remember the thread of a conversation.
- Detect signs of crisis and surface safety resources (section 6).
- Verify provider licenses and keep excluded providers off the platform.
- Send transactional email: verification, password reset, booking confirmations and reminders.
- Keep the service working and secure, and debug it when it breaks.
- Meet legal obligations and enforce our Terms of Service.
4. Your conversations with our AI
Liam, Ariel, and Sol are AI, not people and not therapists, and they say so. To generate a reply, your message and the minimum context needed are sent to OpenRouter, which routes the request to a large language model provider. We do not use your conversations to train any model of our own, and we do not sell or share them with advertisers or partners. Your conversation history is stored in our database, tied to your account, so the guide can remember what you have talked about — and you can delete it from the app at any time.
AI conversations are scanned for signs of crisis (section 6). When a Sol conversation triggers that review, the record we create deliberately contains no message text — only the risk level and the type of signal — so reviewing a safety event never means reading your conversation.
5. Video sessions
Video and audio for sessions run through Daily.co. The media itself is real-time.
One-to-one therapy sessions are not recorded. Not by us, not by default, and not by your therapist through the app. If we ever offer session recording, it will require your explicit consent first, shown to you before anything starts, and you will be able to decline and still have your session.
Group webinars are different: a webinar host runs a recorded broadcast, and you are told that before you join. If you do not want to be recorded, do not join the webinar.
6. Crisis detection and when a human gets involved
Messages in the app are automatically screened for indications that someone may be in danger. Most of the time nothing happens beyond the app surfacing crisis resources to you. When the signal is strong, a safety event is created for review by a trained person on our team.
The same applies to two specific screening questions: PHQ-9 question 9 and EPDS question 10 both ask directly about thoughts of harming yourself. Answering either above zero surfaces support immediately and creates a safety event for human review. We would rather over-respond than miss someone.
This is not a monitoring service and it is not a substitute for emergency care. Where there is a credible risk to someone's life, we may contact emergency services, as permitted by law.
7. What your therapist can see
Nothing, until you decide otherwise. Booking a session shares what the booking requires — your name and the appointment. Your journal, check-ins, and screening results are shared with a provider only when you explicitly turn sharing on, you can see exactly what is covered before you do, and you can turn it off again. Turning it off stops future access.
8. Payments
Subscriptions bought inside the app are processed by Apple or Google and tracked for us by RevenueCat, which tells us your subscription status. Session fees and provider payouts run through Stripe. Card and bank details go directly to those processors; we receive confirmation and status, not the numbers. If you use a superbill for insurance reimbursement, the document contains the clinical and billing codes your insurer requires, and it is generated for you to submit — we do not send it to an insurer on your behalf without you asking.
9. Your privacy controls
In the app, under Settings, you can independently turn each of these on or off:
- Analytics — off unless you turn it on.
- Crash reporting — on by default so the app can be kept stable; you can turn it off.
- Personalization — off unless you turn it on. With it off, the AI guide does not receive your assessment history.
- Research data — off unless you turn it on. This covers use of de-identified data to study what helps.
You can also export everything we hold (Settings → Export My Data) and delete your account and its data (Settings → Delete Account). If you have already uninstalled the app, use our data deletion request page.
10. How we share information
We do not sell your personal information, and we do not share it for advertising. We share it only in these cases:
- Service providers who run parts of the product under contract and may use the data only to provide those services to us:
- Google Firebase / Google Cloud — authentication, database, storage, notifications
- OpenRouter — routing AI guide messages to a language model provider
- Daily.co — live video and audio for sessions and webinars
- Stripe — payments and provider payouts
- RevenueCat — subscription status
- Sentry — crash diagnostics
- MailerSend — transactional email
- Your therapist, and only what you have chosen to share (section 7).
- Safety: where there is a credible risk to life, as described in section 6.
- Legal: where required by law or valid legal process, or to protect the rights, property, or safety of HeadStrong, our users, or others.
- Business transfers: if HeadStrong is involved in a merger, acquisition, or asset sale, information may transfer as part of that transaction. We will tell you before your information becomes subject to a different policy.
- With your consent, for anything else.
11. Security
We encrypt data in transit (TLS 1.2+) and at rest, encrypt particularly sensitive fields at the application layer on top of that, restrict access with per-user authorization rules enforced on the server, log access to sensitive records, and apply safeguards informed by the HIPAA Security Rule. The app can also lock itself behind your device biometrics after it has been in the background — that check happens on your device and your biometric data never reaches us. No system is perfectly secure. If we become aware of a breach affecting your information, we will notify you as required by law.
12. How long we keep things
We keep your account and its data while your account is active. You can delete individual content — journal entries, chat history, check-ins — at any time. When you delete your account we delete your personal information within 30 days, except where we must retain something to meet a legal obligation, resolve a dispute, or enforce our agreements. Some records that regulation requires us to keep, such as security audit logs, are retained on their own schedule and are not tied to your profile.
13. Your rights
Depending on where you live, you may have the right to access a copy of your information, correct it, delete it, receive it in a portable format, object to or restrict certain processing, withdraw consent you previously gave, and complain to a data protection authority. Use the in-app export and delete controls, or email privacy@getheadstrong.xyz. We respond within 30 days.
California residents (CCPA / CPRA)
California residents have the right to know what personal information is collected, to delete it, to correct it, and to opt out of its sale or sharing. We do not sell or share personal information as those terms are defined.
European and UK residents (GDPR)
Our legal bases are: performance of our contract with you (running the service), your consent (analytics, personalization, research data, marketing email), our legitimate interests (security, crash diagnostics, preventing abuse), compliance with legal obligations, and — for the crisis pathway — protection of the vital interests of you or another person.
14. Children
HeadStrong is for adults. It is not directed to children, and we do not knowingly collect information from anyone under 18. If you believe a minor has created an account, contact us and we will remove it.
15. International transfers
HeadStrong is operated from the United States, and information is stored and processed there. If you use the service from elsewhere, your information is transferred to the United States.
16. TikTok integration (creator tools only)
This section applies only to HeadStrong's own content and marketing tooling, which is not part of the HeadStrong mental health app and is not available to clients or providers. Where an authorized team member connects a TikTok account, we access that account's profile information (display name, avatar, open ID) and public video list through TikTok's API and can publish videos to that profile on the account holder's behalf. We do not store TikTok credentials, and TikTok data is used only to operate those posting features. Access can be revoked at any time in TikTok account settings. No client data is ever sent to TikTok.
17. Third-party links
Our site and app link to third-party services, including our own social accounts. This policy does not cover them.
18. Changes to this policy
We may update this policy. If the change is material we will notify you by email or with a prominent notice in the app or on the website before it takes effect.
19. Contact
- Privacy: privacy@getheadstrong.xyz
- Support: support@getheadstrong.xyz
- Safety concerns: safety@getheadstrong.xyz
- Web: getheadstrong.xyz