Privacy Policy
Last updated August 15, 2026
This Privacy Policy explains what information Relationship Theory collects, how we use and protect it, and the choices you have. Please read it alongside our Terms of Service and, where you handle client health information, our Business Associate Agreement.
1. Who this policy covers
Relationship Theory is a practice platform for professionals and their clients. Two kinds of people use it, and this policy covers both:
- Professionals: the coaches, therapists, and other practitioners who hold an account with us and use the portal to run their practice.
- Clients: the people a Professional invites into their practice to work through trainings, reps, reflections, and sessions.
For information a Professional collects about their own Clients (client notes, reflections, session history, and any health information), the Professional is the party who decides how that information is used. We handle that information on the Professional’s behalf under our Terms of Service and, where it is protected health information, our Business Associate Agreement. If you are a Client with a question about your own records, the best first contact is your Professional, who manages that relationship.
For information about the Professionals themselves (their account, subscription, and use of the platform), Relationship Theory decides how it is used and this policy applies directly.
2. Information we collect
Account information. Name, email address, and the password you set (stored only as a secure, one-way hash, so we never see your actual password).
Client content. Journal notes, reps, reflections, trainings assigned and completed, session details, and any information a Professional or Client enters into the portal. Depending on the Professional’s practice, this can include health information about a Client. We treat all client content as the most protected data on the platform, and where it is protected health information we handle it as a Business Associate under HIPAA.
Scheduling and calendar information. Session times, availability, and, only if a Professional connects it, read/write access to their Google Calendar to sync sessions. You can disconnect this at any time.
Payment information. When money changes hands, card details are collected and processed directly by our payment provider (Stripe). We do not store full card numbers on our systems; we keep only limited billing records (amounts, dates, the last four digits, and a token that lets us reference a charge).
Community access. If a plan includes access to the Relationship Theory Community, we share the information needed to grant and manage that membership with our community provider.
Usage and device information. Basic technical data such as IP address and browser type, used to keep the service secure, prevent abuse, and diagnose problems.
3. How we use information
We use the information above to:
- Provide and operate the portal: accounts, client content, scheduling, trainings, and community access.
- Process payments, subscriptions, and payouts to Professionals.
- Send necessary service messages: invitations, session reminders, billing notices, and security notices.
- Keep the platform secure: authentication, fraud and abuse prevention, and rate limiting.
- Improve and support the service and respond to your requests.
- Meet legal, tax, and accounting obligations.
We do not sell your personal information, and we do not use client content to advertise to you or to anyone else.
We do not use your information to make decisions about you by automated means alone that produce legal or similarly significant effects.
4. Our legal bases (for EEA/UK users)
If you are in the European Economic Area or the United Kingdom, we process personal information on these legal bases:
- To perform our contract with you: providing the portal, your account, and the features you use.
- For our legitimate interests: securing the service, preventing abuse, and improving what we offer, balanced against your rights.
- To comply with legal obligations: such as tax and accounting requirements.
- With your consent: for anything that requires it, such as connecting an optional integration; you can withdraw consent at any time.
Where a Professional inputs their Clients’ information, the Professional is responsible for having a lawful basis and any consents required for that information.
5. Health information and HIPAA
The platform is built to hold sensitive client information, including health information. Where a Professional is a covered entity under HIPAA and uses the Service to create, receive, maintain, or transmit protected health information (PHI), Relationship Theory acts as the Professional’s Business Associate and handles that PHI under our Business Associate Agreement and HIPAA’s Privacy and Security Rules. The Professional remains responsible for the lawfulness of the information they collect and for the consents and notices their clients require.
6. How we share information
We share information only with the service providers we need to run the platform, and only what each needs to do its job. Each provider that handles protected health information does so under a HIPAA business associate agreement. Our current providers are:
- Neon (a Databricks company): our database and authentication.
- Amazon Web Services: secure file storage (S3) and transactional email (SES).
- Stripe: payment processing and payouts to Professionals.
- Google: optional calendar syncing, only for Professionals who connect it.
- Circle: community membership, only for plans that include it.
- Vercel: hosting and delivery of the website.
Each provider is bound to protect the information and use it only to provide their service to us. We may also disclose information if required by law, to protect our rights or the safety of others, or in connection with a business transfer (such as a merger or acquisition), in which case we will continue to protect it under this policy.
A Professional’s Client information is not shared with other Professionals. Each practice is walled off from every other.
7. Where your data lives and how we protect it
We protect information with layered safeguards, including encryption in transit, strict database-level access rules that isolate each Professional’s data from every other, private file storage served only through short-lived signed links, hashed passwords, breach-password screening, optional two-factor authentication, an append-only audit trail, and rate limiting on sensitive actions.
No system is perfectly secure, but we design for the sensitivity of client health information and review our security regularly. If we ever learn of a breach affecting your information, we will notify you and the appropriate authorities as required by law, and we will notify a Professional of a breach affecting their Clients’ information as described in our Business Associate Agreement.
8. How long we keep information
We keep account and client information for as long as the account is active and as needed to provide the service.
When a Professional deletes a Client, that Client’s personal client content (notes, reps, trainings, progress, and intake forms) is permanently erased, and the Client’s identity is removed. Records we are required to keep for accounting and legal reasons (such as payment history) are retained in a de-identified form, and signed agreements are retained as a legal record for the Professional.
When a Professional closes their account, we remove or de-identify their data after a short retention window, except where we must keep certain records to meet legal, tax, or accounting obligations, and we return or destroy protected health information as described in our Business Associate Agreement.
9. Your choices and rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain uses, and to withdraw consent. These rights apply to residents of the European Economic Area and the United Kingdom (under GDPR) and to California residents (under the CCPA/CPRA), among others.
Because a Professional controls their Clients’ information, a Client should usually direct these requests to their Professional, who can act on them directly in the portal. For information we control (your Professional account), contact us using the details below and we will respond as the law requires.
We will not discriminate against you for exercising any of these rights. We aim to respond to requests within the time the applicable law requires (for example, within 45 days under the CCPA). We may need to verify your identity before acting on a request.
If you are in the EEA or the UK and believe we have not handled your information properly, you also have the right to lodge a complaint with your local data protection supervisory authority.
10. Cookies and tracking signals
We use only the cookies necessary to run the service, chiefly to keep you signed in and to protect your session. We do not use advertising or third-party tracking cookies. Because these cookies are essential to the service, the portal will not work correctly without them.
Because we do not track you across other sites or serve advertising, we do not sell or “share” your information for cross-context behavioral advertising. We honor recognized browser opt-out signals, such as Global Privacy Control (GPC), to the extent the law requires; since we do not sell or share personal information, there is nothing to opt out of, but such a signal is treated as a valid request.
11. Children
The portal is intended for adults (18 and older). It is not directed to children, and we do not knowingly collect information from anyone under 18 for our own account holders. Where a Professional is authorized to provide services to a minor, the Professional is responsible for obtaining any consent the law requires before entering that minor’s information. If you believe a child has provided us information directly, contact us and we will delete it.
12. International users
We operate from the United States, and information we handle is processed there and in the regions our providers operate. If you use the portal from outside the United States, you understand that your information will be transferred to and processed in the United States, where privacy laws may differ from those in your country. Where required, we rely on appropriate safeguards for these transfers.
13. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you. Your continued use of the portal after a change means you accept the updated policy.
14. How to contact us
For privacy questions or to exercise your rights, email us at support@relationshiptheory.com. If you are a Client asking about your own records, please also contact your Professional, who manages that information.