PsyBird.AI is operated by Any Percent LLC, a Washington limited liability company (“PsyBird,” “we,” “our,” or “us”). PsyBird provides an AI-supported platform that helps licensed mental-health professionals extend therapist-directed support to their patients between sessions. PsyBird is not a healthcare provider, therapist, crisis service, or a replacement for professional treatment.
This Privacy Policy explains how we handle personal information. Because different rules apply to different data, please note which framework governs what:
| Type of data | Governing framework | Where it is described |
|---|---|---|
| Protected health information (PHI) we handle for a Practice under a BAA | HIPAA and the Business Associate Agreement | The Practice’s HIPAA Notice of Privacy Practices, and the BAA between PsyBird and the Practice |
| Consumer health data of Washington residents that is not HIPAA PHI | Washington My Health My Data Act (MHMDA) | Our separate Consumer Health Data Privacy Policy (see section 12) |
| Other personal data (e.g. website visitors, therapist accounts, technical data) | This Privacy Policy and applicable state privacy laws | This document |
When we handle PHI on behalf of a Practice, we act as that Practice’s HIPAA business associate, and the Practice (the covered entity) remains responsible for its own HIPAA obligations. For personal data that is not PHI (such as data from website visitors, prospective users, and therapist account and technical data) we act as a controller (or, under some state laws, a processor) and this Policy applies. The same underlying data can shift between these regimes, so we apply the protections appropriate to each.
Patient information. Depending on how a Practice configures the Service, we may process: name; email address; account information; therapist-assigned plans and exercises; therapist-entered notes; conversation content with the AI companion; direct messages between the patient and their Practice; appointment and calendar data; mood, theme, and engagement data; exercise and activity data; voice-mode audio that is converted to text to power voice conversations; and reports or exports generated through the platform.
Video and voice calls. Where a Practice enables calling, calls connect directly between the participants and are encrypted in transit. We store scheduling and connection metadata (for example, who called whom and when) needed to operate the feature; we do not store call audio or video unless the Practice conducts a recorded session, which requires in-call consent before recording begins. Recorded sessions and their transcripts become part of the Practice’s record of care.
Therapist and Practice information. Name; email address; professional and practice information; licensing information when provided; billing and subscription information (payment card details are collected and processed by our payment processor, Stripe; we do not store card numbers); and account and usage information.
Information collected automatically. When you use the Service or visit our website, we and our service providers may automatically collect technical data such as IP address, device and browser information, log data, and usage information, including through cookies and similar technologies (section 6). In the context of a mental-health service, some technical data may be linked to health information and treated accordingly.
We collect information directly from you (for example, when you create an account or use the Service); from the Practice or Therapist that invites and manages a Patient; and automatically through your use of the Service and website.
We use information to: provide AI-supported supportive interactions; deliver therapist-assigned exercises; maintain accounts; enable therapists to review engagement and act on flags; support communication between patients and therapists (including secure messaging, scheduling, and video/voice calling); generate reports and exports; support clinical-documentation and Remote Therapeutic Monitoring workflows where applicable; and maintain and improve the security and reliability of the Service.
Consent for sensitive data. Mental-health information is “sensitive” or “consumer health” data under many laws, which require opt-in consent to collect, use, or share it. Where consent is required, we (and the Practice, as applicable) obtain it before processing, and you may withdraw consent as described in sections 12–13. We do not use sensitive data for purposes incompatible with providing the Service.
We use cookies and similar technologies to operate the Service, keep you signed in, remember preferences, and understand usage so we can improve reliability and security.
No advertising trackers on health data. We do not place third-party advertising or cross-site tracking technologies (such as advertising pixels) on pages or flows that handle patient health information, and we do not use such data for targeted advertising. We honor recognized opt-out preference signals, including Global Privacy Control (GPC), where required.
The Service uses AI to generate supportive interactions and summaries. AI may encourage reflection, offer emotional support, reinforce therapist-assigned exercises, and support continuity between sessions. The AI does not diagnose, make treatment decisions, replace a licensed professional, or provide emergency services, and its output can be inaccurate. Discuss important concerns or treatment decisions with your therapist.
Where AI processing happens. All AI processing runs on Google Cloud’s Vertex AI platform, inside the same HIPAA-covered Google Cloud environment that stores platform data and under PsyBird’s Business Associate Agreement with Google. Patient content is not sent to any separate AI vendor.
No training of public AI models on patient content. We do not use patient conversation content to train public or third-party AI models, consistent with our provider agreements. The AI does not make decisions that produce legal or similarly significant effects about you without a Therapist in the loop.
To provide continuity, the AI companion uses a limited window of recent conversation as context. That AI-context window is distinct from what the platform stores as the record of care: your Practice’s account retains conversation records, summaries, letters, and related data as needed to provide the Service and support your care, subject to the retention practices in section 14 and to your Practice’s own policies. Therapists may access patient conversations when authorized for treatment purposes.
We do not sell your data. We do not sell personal information or consumer health data, and we do not share it for targeted advertising. Any “sale” of consumer health data would require your separate signed authorization, which we do not seek.
We share information only as follows:
We rely on providers to operate the Service, which currently include: Google Cloud (database, authentication, serverless functions, file storage, and AI processing, via Firestore, Identity Platform, Cloud Run/Functions, Cloud Storage, and Vertex AI, which serves the platform’s AI models, together with related Google Cloud services such as text-to-speech and speech-to-text, logging, and monitoring), all under a single Business Associate Agreement with Google; Cloudflare (network services: DNS for our domains and, for video/voice calls that cannot connect directly, a fallback relay that carries only encrypted call media it cannot read and does not store); Stripe (payment processing for Practice subscriptions; Stripe receives billing and payment information from Practices, not patient health information); Google Workspace (operational and notification email; notification messages are designed not to contain health information); and Apple and Google push-notification services (which carry only the minimal content needed to display a notification). Providers that handle PHI do so under a BAA and are limited to using data as needed to provide services to us. We maintain a vendor inventory and confirm appropriate agreements are in place before any provider handles health data.
Where we provide services to a Practice that is a HIPAA covered entity or business associate, and PHI is involved, we act as a business associate under a BAA and maintain administrative, technical, and physical safeguards designed to protect PHI, including authentication, access controls, encryption in transit and at rest, logging, and incident-response procedures. Our infrastructure and AI processing run on Google Cloud under an executed Business Associate Agreement with Google. For PHI, your rights under HIPAA (such as access and amendment) are generally exercised through your healthcare provider, whose HIPAA Notice of Privacy Practices describes them.
If you are a Washington resident, or your consumer health data is collected in Washington, the Washington My Health My Data Act may give you additional rights regarding health data that is not covered by HIPAA. These include the right to confirm whether we collect, share, or sell your consumer health data; to access it; to have it deleted; to withdraw consent; and to obtain a list of the third parties and affiliates with whom it has been shared. We do not sell consumer health data, and we do not operate geofences around healthcare facilities to identify, track, or message individuals.
Separate policy. These rights, and the categories, sources, purposes, and recipients of consumer health data, are described in our separate Consumer Health Data Privacy Policy, linked distinctly from our homepage as required by MHMDA. To exercise MHMDA rights, use the contact method there, or contact us below.
Depending on where you live, you may have rights under state privacy laws (for example, California’s CCPA/CPRA and the Virginia-model laws now in effect in roughly twenty states). Whether a given law applies depends on the law’s thresholds and your residence. These rights may include:
| Right | What it means |
|---|---|
| Access / know | Confirm whether we process your data and request a copy and details about our processing. |
| Delete | Request deletion of your personal data, subject to legal exceptions (MHMDA’s deletion right is broader). |
| Correct | Request correction of inaccurate data. |
| Portability | Receive certain data in a portable, commonly used format. |
| Opt out of sale, sharing, or targeted advertising | We do not sell or share personal data for these purposes; we honor Global Privacy Control where required. |
| Limit or withdraw consent for sensitive data | Limit use of sensitive personal information or withdraw previously given consent. |
| Non-discrimination & appeal | We will not discriminate against you for exercising your rights, and (where the law provides) you may appeal a denied request. |
How to exercise your rights. Contact us using the button at the end of this Policy. We will verify your request as required, allow use of an authorized agent where permitted, and respond within the timeframe the applicable law requires (generally within 45 days). For PHI, please contact your healthcare provider, as HIPAA rights are exercised through them.
We retain personal information only as long as needed to provide the Service, support care and documentation workflows, comply with legal obligations, resolve disputes, and maintain security. Retention of PHI is governed by the BAA and the Practice’s instructions; patient records are generally retained for the duration of the care relationship and then handled as the Practice directs. When a Practice ends its use of the Service, we make patient records available for export and delete our copies within 30 days, with backups purged on our rolling cycle (daily backups retained 14 days, plus a point-in-time recovery window). Operational logs are retained for approximately 12 months, security audit logs for 6 years, and billing records for 7 years. You may contact us for information about applicable retention periods.
We use administrative, technical, and organizational safeguards designed to protect information, including authentication, permission-based and restricted access, encryption, secure infrastructure providers, and monitoring and incident-response procedures. No method of electronic storage or transmission is completely secure.
Breach notification. If a breach affecting your information occurs, we will provide notifications as required by applicable law, which may include HIPAA’s Breach Notification Rule (via the affected Practice), the FTC’s Health Breach Notification Rule, and state breach-notification laws.
The Service is intended for use under the direction of a licensed professional. Accounts are not available to children under 13, and we do not knowingly collect personal information from children under 13. A patient aged 13 to 17 may use the Service only where permitted by law and with the documented consent of a parent or legal guardian, obtained and verified by the supervising Practice consistent with applicable minor-consent laws.
The Service is intended for use in the United States, and information is processed and stored in the United States (our primary data storage is in a U.S. Google Cloud region). If you access the Service from outside the United States, you do so on your own initiative and are responsible for compliance with local law.
We may update this Policy from time to time. We will post the updated Policy with a new effective date and, for material changes, provide reasonable notice (for example, by email or in-app notice). For new categories of health data or new purposes, we will obtain any consent required by law before the change takes effect.
Questions? Ask away.