Privacy Policy
Last updated: 23 July 2026
UnifiedSelf is a practice-management platform for therapists, operated by KodeSquadra ("we", "us"), Karnataka, India — GSTIN 29ABZPV9607N1Z5. You can reach us any time at hello@unifiedself.in. This policy explains what data we handle, why, and the rights you have over it, in line with India's Digital Personal Data Protection Act, 2023 (DPDP Act).
Two kinds of people use UnifiedSelf
This distinction matters, because different rules apply:
- Therapists are our customers. For a therapist's own account data (name, email, state, practice and billing details), we decide how it is processed — we act as the data fiduciary.
- Clients are invited onto the platform by their therapist. Their information — including anything clinical — is entered and controlled by the therapist as part of the therapeutic relationship. For that data, the therapist is the fiduciary and we process it only on the therapist's behalf and instructions, to provide the service. We never use client data for our own purposes.
What we collect
- Therapist account data: name, email, password (stored only as a hash), the state where you practice (used for the GST breakup on our invoice to you), public profile details you choose to publish, and billing settings (legal name, address, GSTIN, UPI ID).
- Client data: name and contact details, appointments, invoices and payment records, and — where the therapist uses those features — intake responses, session notes, secure chat messages, and mood entries.
- Technical data: essential sign-in cookies and standard server logs. We run no advertising trackers and no third-party analytics.
Clinical data is walled off
Session notes, chat messages, intake responses, and mood data are visible only to the treating therapist and, where the therapist explicitly shares an item, to that client. Our own platform administrators cannot see clinical content: the admin console is architecturally limited to aggregate numbers (how many practices, how many sessions — never what was said in them), and this separation is enforced by automated tests that fail our build if it is ever breached. Administrator access itself requires two-factor authentication.
AI note drafting (optional)
Therapists on plans that include it can ask for an AI draft of a session note. This happens only when the therapist explicitly clicks "Draft with AI" — nothing is ever sent automatically, and the feature is entirely under the therapist's control: a client who prefers that AI never touch their notes can say so, and their therapist simply doesn't use it for them. Before any text leaves our server, the client's registered name is removed from it. Drafting is processed by Anthropic, a third-party AI provider, under commercial API terms: the submitted text is not used to train AI models, and Anthropic retains it only for a limited period for abuse monitoring before deletion. The therapist always reviews and edits the draft before anything is saved.
WhatsApp reminders
Appointment reminders, booking updates, and invoice notices can arrive over WhatsApp. This is opt-in for each client — via their therapist or the toggle in their own portal — and a client who does not opt in keeps receiving email and in-app messages instead. WhatsApp messages are delivered through Meta's WhatsApp Business Platform, which means the client's phone number and the message content are processed by Meta for delivery. Replies to the WhatsApp number are not read by anyone and are never stored; an automatic reply says so and points the client to their portal.
Sub-processors
We share data with a small number of service providers, only to the extent needed to run UnifiedSelf:
| Provider | Purpose |
|---|---|
| Anthropic | AI note drafting (per-click only, client names removed, not used for training, retained briefly then deleted) |
| Meta (WhatsApp Business Platform) | WhatsApp reminder delivery — per-client opt-in |
| MailBaby | Transactional email (booking confirmations, reminders, invoices) |
| Bunny.net | File and media delivery |
| Razorpay | Subscription payments — when paid billing launches |
We do not sell personal data to anyone, ever.
Retention, export, and deletion — no lock-in
- Export: therapists can export their practice data (CSV) at any time, on every plan including the free one. Data access is never behind a paywall.
- Deletion: ask us to delete your account and we will erase your personal data within 30 days. Encrypted backups rotate out within 14 days after that.
- What we must keep: invoice and tax records are retained for the period required by law, even after account deletion.
- A client can ask their therapist — or us — for a copy or deletion of their data; where the therapist is the fiduciary, we support the therapist in honouring the request.
Your rights under the DPDP Act, 2023
We process personal data on the basis of consent and for the legitimate purposes of providing the service you signed up for. You have the right to access and obtain a copy of your personal data, to correct or update it, to have it erased, to nominate someone to exercise your rights on your behalf, and to have grievances heard. Write to hello@unifiedself.in — this address reaches our grievance contact — and we will respond within a reasonable time. If you are not satisfied, you may complain to the Data Protection Board of India.
Security
All traffic is encrypted in transit (HTTPS). Every practice's data is isolated by tenant at the database layer, access is role-based, passwords are stored only as salted hashes, and administrator accounts require two-factor authentication. If a data breach affecting you ever occurs, we will notify you and the Data Protection Board as the law requires.
Changes
If we make material changes to this policy, we will announce them on this page and, for significant changes, by email. The "last updated" date above always reflects the current version.
Contact
KodeSquadra · Karnataka, India · GSTIN 29ABZPV9607N1Z5
hello@unifiedself.in