Legal
Privacy Policy & HIPAA Notice
Last updated May 31, 2026
This Privacy Policy explains what information Mentalys, Inc. (“Mentalys,” “we,” “us”) collects when you use our clinical software, how we use it, and the choices you have. It also includes our HIPAA Notice of Privacy Practices, which describes how protected health information (PHI) may be used and disclosed.
Mentalys is built for licensed psychiatric practitioners. When we handle PHI, we do so as a Business Associate of your practice under a Business Associate Agreement (BAA). Your practice remains the Covered Entity and the owner of patient records.
01Information we collect
We collect only what we need to deliver the service.
Account & practice information
- Your name and email address.
- Practice information — organization name, role, specialty, and the number of providers in your practice.
- Authentication credentials and session metadata.
Clinical content (PHI)
- Session audio you record for transcription.
- Patient records you create or import — demographics, visit notes, clinical history, and related documentation.
- Generated artifacts such as transcripts, clinical notes, and summaries.
We do not collect tracking, analytics, or advertising data. See our Cookie Policy for details.
02How we use your information
- To provide, maintain, and secure the Mentalys service.
- To transcribe session audio and generate draft clinical notes at your direction.
- To authenticate you and protect your account from misuse.
- To communicate with you about your account, security, and service changes.
- To meet our legal, regulatory, and HIPAA obligations.
We do not sell your data, and we do not use PHI to train AI models. PHI is processed solely to perform the service you request.
03How PHI is handled under HIPAA
Our role
Mentalys acts as a Business Associate. We use and disclose PHI only as permitted by our BAA with your practice and as required by law. Your practice — the Covered Entity — controls patient consent, access, and disclosure decisions.
PHI is encrypted in transit and at rest, segregated by practice, and accessible only to authenticated users in your organization. Every access to PHI is recorded in an audit log. See our Security page for the technical safeguards.
04Third-party processors (subprocessors)
We rely on a small set of vetted vendors to operate the service. Each processes data on our behalf under contractual confidentiality and security obligations, and each that handles PHI does so under a signed BAA.
- OpenAI (Whisper) — speech-to-text transcription of session audio.
- Anthropic (Claude) — generation of draft clinical notes and summaries.
- Supabase — encrypted database and authentication.
- Vercel — application hosting and delivery.
All subprocessors operate within the United States. We do not permit these vendors to use your PHI for their own purposes, including model training.
05Data retention
We retain PHI and associated records for a minimum of seven (7) years, consistent with HIPAA recordkeeping requirements and applicable state law. Account information is retained for as long as your account is active and as needed to meet our legal obligations.
On cancellation, you may export your data; see our Terms of Service for the export window. After the applicable retention period, data is securely deleted.
06Your rights
Because your practice is the Covered Entity, patient rights of access, amendment, and accounting of disclosures are exercised through your practice. For your own account information, you may:
- Access and correct your account and practice details.
- Request export of the data associated with your account.
- Request deletion, subject to our legal retention obligations.
- Ask questions about how your information is handled.
07Breach notification
In the event of a breach
If we discover a breach of unsecured PHI, we will notify the affected practice without unreasonable delay and in any event no later than 60 days after discovery, consistent with the HIPAA Breach Notification Rule. Our notice will describe what happened, the information involved, and the steps being taken.
08HIPAA Notice of Privacy Practices
This notice describes how medical information about a patient may be used and disclosed and how a patient can get access to this information. Please review it carefully. Mentalys handles PHI as a Business Associate of your practice. This notice supplements — and does not replace — the Notice of Privacy Practices that your practice provides to its patients.
Permitted uses and disclosures of PHI
- Treatment, payment, and operations — to perform the documentation and decision-support functions your practice directs.
- As required by law — when disclosure is mandated by federal, state, or local law.
- To our subprocessors — only as needed to deliver the service and only under BAAs, as described above.
Uses and disclosures that require authorization
We will not use or disclose PHI for marketing, sale of PHI, or any purpose not described in this notice or permitted by the BAA without the authorization obtained by your practice.
Our safeguards
We maintain administrative, physical, and technical safeguards — including AES-256 encryption at rest, TLS 1.3 in transit, access controls, and audit logging — to protect PHI as required by the HIPAA Security Rule.
Patient rights
Patients may exercise their HIPAA rights — including access, amendment, an accounting of disclosures, and restrictions — through the practice that maintains their record. We support practices in fulfilling these requests.
Changes to this notice
We may update this notice to reflect changes in our practices or the law. The current version is always available on this page with its effective date.
09Contact us
For privacy requests or questions about this policy or our HIPAA practices, contact our Privacy Officer at judah@mentalys.ai. To request or review a Business Associate Agreement, the same address will route your request appropriately.