Back to Home

Trust & Safety Center

Our commitment to transparency, clinical integrity, and data security is backed by real engineering safeguards.

Data Privacy & Encryption

All PII/PHI is encrypted in transit using TLS 1.2+ and at rest using AES-256 via Google-managed KMS. The database has zero public internet exposure, running entirely inside a secure private VPC network.

View Privacy Policy →

HIPAA & SOC2 Alignment

We design with HIPAA and SOC2 compliance controls from day one. This includes append-only log tables, cryptographic sanitization of child profiles before processing, and fully auditable access tracking.

View Compliance Spec →

Verified Sub-processors

PartnerPurposeLocation
Google Cloud PlatformSecure application hosting & regional databaseCanada (Montreal)
Google GeminiAI strategy translation (with child names cryptographically redacted before processing)United States
StripeCompliant subscription processingUnited States
ResendTransaction & authentication emailsUnited States
New RelicApplication performance monitoring & structured logsUnited States

Need a SOC2 Report or DPA?

We sign Data Processing Agreements (DPAs) for clinic accounts; Business Associate Agreements (BAAs) are available on request after review. For custom enterprise requests, please reach out to our team.

Contact Support & Trust Lead