Privacy Policy

Effective Date: November 29, 2025
Last Updated: November 29, 2025


Introduction

MySensoryBook ("we," "our," or "us") is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered sensory journal platform.

This policy applies to occupational therapists, clinic administrators, parents, and any other users of MySensoryBook.

HIPAA Compliance: As a platform used in healthcare settings, MySensoryBook is designed to comply with the Health Insurance Portability and Accountability Act (HIPAA). We handle Protected Health Information (PHI) with the highest standards of security and confidentiality.


Information We Collect

1. Information You Provide Directly

Account Information:

  • Name and professional credentials
  • Email address
  • Organization/clinic name
  • Password (encrypted)
  • Billing information (processed securely through our payment provider)

Patient Information (Protected Health Information):

  • Patient names (first name, last name, or pseudonyms)
  • Date of birth
  • Sensory experience descriptions
  • Visual journals and associated metadata
  • Parent/guardian contact information
  • Session notes and clinical observations

Communication Information:

  • Support requests and correspondence
  • Feedback and survey responses
  • Email interactions

2. Information Collected Automatically

Usage Data:

  • Login times and frequency
  • Features used
  • Journals created and accessed
  • Browser type and version
  • Device information
  • IP address
  • Session duration

Analytics Data:

  • Aggregate usage patterns
  • Feature adoption rates
  • System performance metrics
  • Error logs and diagnostic data

3. Information from Third Parties

Payment Processing:

  • Transaction data from Polar.sh (our payment processor)
  • Payment method information (we do not store full credit card numbers)

AI Processing:

  • When you use our AI features, we send sensory descriptions to our AI provider (OpenAI/Anthropic) with anonymized identifiers only

How We Use Your Information

Primary Uses

To Provide Our Service:

  • Create and manage user accounts
  • Generate AI-powered sensory journals
  • Store and organize patient records
  • Enable parent portal access
  • Process payments and manage subscriptions
  • Provide customer support

To Improve Our Service:

  • Analyze usage patterns to enhance features
  • Identify and fix technical issues
  • Develop new features based on user needs
  • Optimize AI journal generation quality
  • Conduct research on platform effectiveness

To Communicate With You:

  • Send service-related notifications
  • Provide customer support responses
  • Share product updates and new features
  • Send billing and account information
  • Request feedback (you can opt out)

For Security and Compliance:

  • Prevent fraud and abuse
  • Enforce our Terms of Service
  • Comply with legal obligations
  • Protect user safety and privacy
  • Maintain HIPAA compliance

Uses We Will NOT Engage In

We will NEVER:

  • Sell your personal information or patient data
  • Share patient information for marketing purposes
  • Use patient data to train AI models (without explicit consent)
  • Share identifiable patient information with third parties (except as required by law or with your permission)
  • Send spam or unsolicited marketing to parents

How We Share Your Information

Service Providers

We share information with trusted third-party service providers who help us operate our platform:

AI Processing:

  • OpenAI or Anthropic (for journal generation)
  • Data sent: Anonymized sensory descriptions only
  • Data NOT sent: Patient names, birthdates, or other identifying information

Payment Processing:

  • Polar.sh (payment gateway)
  • Data shared: Billing information, transaction amounts
  • We do not store full credit card numbers

Cloud Infrastructure:

  • Amazon Web Services (AWS) or similar
  • Purpose: Secure hosting and data storage
  • Security: Encrypted at rest and in transit

Analytics:

  • Usage analytics tools (anonymized data only)
  • Purpose: Improve platform performance and user experience

Email Services:

  • Resend or similar email delivery service
  • Purpose: Transactional emails and notifications

All service providers:

  • Sign Business Associate Agreements (BAAs) when handling PHI
  • Are contractually obligated to protect your data
  • Use data only for specified purposes

Legal Requirements

We may disclose information when required by law:

  • In response to subpoenas or court orders
  • To comply with legal processes
  • To protect our rights, property, or safety
  • To protect the rights, property, or safety of our users or the public
  • In connection with fraud prevention or investigation

Business Transfers

If MySensoryBook is acquired, merged, or undergoes a business transition:

  • User data may be transferred to the new entity
  • You will be notified of any such change
  • The new entity will be bound by this Privacy Policy (or you'll be notified of changes)

With Your Consent

We may share information in other circumstances with your explicit consent.


Data Security

Technical Safeguards

Encryption:

  • All data encrypted in transit (TLS/SSL)
  • All data encrypted at rest (AES-256 or equivalent)
  • Database encryption enabled

Access Controls:

  • Multi-factor authentication available
  • Role-based access permissions
  • Regular access audits
  • Secure password requirements

Infrastructure Security:

  • Regular security assessments
  • Intrusion detection systems
  • Automated backups (encrypted)
  • Disaster recovery procedures

Application Security:

  • Regular security updates
  • Vulnerability scanning
  • Secure coding practices
  • Security testing before releases

Organizational Safeguards

Staff Training:

  • HIPAA compliance training for all employees
  • Privacy and security awareness programs
  • Incident response procedures

Policies and Procedures:

  • Data handling policies
  • Breach notification procedures
  • Vendor management protocols
  • Regular policy reviews

Monitoring:

  • 24/7 system monitoring
  • Audit logging of access to PHI
  • Regular security reviews
  • Penetration testing (periodic)

Limitations

While we implement strong security measures, no system is 100% secure. We cannot guarantee absolute security but maintain industry best practices to protect your data.


Data Retention

Active Accounts

Patient Records:

  • Retained as long as your account is active
  • You control patient data and can delete it anytime
  • Deleted patient data is removed from our systems within 30 days (excluding backups)

Account Information:

  • Retained as long as your account is active
  • You can request account deletion at any time

Closed Accounts

After Account Closure:

  • Patient data deleted within 30 days of account closure
  • Billing records retained for 7 years (legal requirement)
  • Anonymized usage data may be retained for analytics
  • Backup systems purged on regular schedule (90 days)

Legal Holds

Data subject to legal holds, investigations, or disputes will be retained as legally required.


Your Rights and Choices

Access and Correction

You have the right to:

  • Access your account information
  • View all patient records you've created
  • Correct inaccurate information
  • Export your data (patient records, journals)

How to exercise: Contact us at privacy@mysensorybook.com or use in-app settings

Data Deletion

You can:

  • Delete individual patient records anytime
  • Delete your entire account (irreversible)
  • Request deletion of specific information

How to exercise: Use in-app deletion or contact support

Note: Some data may be retained as required by law (e.g., billing records)

Opt-Out Rights

Email Communications:

  • Opt out of marketing emails (click unsubscribe)
  • You will still receive essential service emails (billing, security)

Analytics:

  • We use anonymized analytics only
  • Contact us to discuss specific concerns

Parent Rights

Parents whose children are patients have the right to:

  • Access their child's sensory journals via parent portal
  • Request corrections to their child's information
  • Request deletion of their child's records
  • Revoke portal access at any time

How to exercise: Contact the therapist who created the records


Children's Privacy

MySensoryBook is not intended for direct use by children under 13. Our platform is designed for occupational therapists to use in their professional practice.

Patient Data:

  • Patient information is entered by licensed therapists
  • Parents access information through secure portals
  • We do not knowingly collect information directly from children

If we become aware that we've collected information from a child under 13 without proper parental consent, we will delete it promptly.


International Users

MySensoryBook is based in the United States. If you access our service from outside the U.S., please be aware that:

Data Transfer:

  • Your information will be transferred to and stored in the United States
  • U.S. privacy laws may differ from your country
  • We comply with applicable data protection regulations

GDPR Compliance (EU Users):

  • Legal basis for processing: Contract performance, legitimate interests, consent
  • Data Protection Officer contact: privacy@mysensorybook.com
  • Right to lodge a complaint with your supervisory authority
  • Additional rights under GDPR (see "Your Rights" section)

Cookies and Tracking Technologies

What We Use

Essential Cookies:

  • Session management
  • Authentication
  • Security features
  • Required for platform to function

Analytics Cookies:

  • Usage statistics (anonymized)
  • Feature adoption tracking
  • Performance monitoring

Preferences:

  • Language settings
  • Display preferences

Your Choices

Browser Settings:

  • You can control cookies through browser settings
  • Blocking essential cookies may impair functionality

Do Not Track:

  • We honor Do Not Track signals where applicable
  • Analytics are anonymized regardless

Third-Party Links

Our platform may contain links to third-party websites or services (e.g., educational resources, professional organizations). We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.


Changes to This Privacy Policy

Updates:

  • We may update this Privacy Policy periodically
  • Material changes will be communicated via email or in-app notification
  • Continued use after changes constitutes acceptance

Version History:

  • Current version effective date noted at top
  • Previous versions available upon request

HIPAA and Healthcare Compliance

Business Associate Agreement (BAA)

For healthcare providers using MySensoryBook:

  • We sign BAAs with all clinic customers
  • BAA available upon request or during signup
  • Outlines our responsibilities under HIPAA
  • Contact privacy@mysensorybook.com for BAA questions

HIPAA Rights

As a patient's representative (parent/guardian), you have rights under HIPAA:

  • Right to access medical records
  • Right to request corrections
  • Right to request restrictions on use
  • Right to receive confidential communications
  • Right to file a complaint

To exercise HIPAA rights: Contact the healthcare provider (therapist/clinic) who created the records

Breach Notification

In the event of a data breach involving PHI:

  • We will notify affected users within 60 days
  • Notification will include nature of breach, data affected, steps taken
  • We will report to HHS as required by law
  • We will assist you in notifying patients if required

Contact Information

Privacy Questions or Concerns

Email: privacy@mysensorybook.com
Support: support@mysensorybook.com

Response Time

  • Privacy inquiries: Within 5 business days
  • Data access requests: Within 30 days
  • GDPR requests: Within 30 days (may extend to 60 if complex)

Complaints

If you have a complaint about our privacy practices:

  1. Contact us using the information above
  2. We will investigate and respond within 30 days
  3. If unresolved, you may contact:
    • U.S. Department of Health and Human Services (for HIPAA complaints)
    • Your local data protection authority (for GDPR complaints)
    • Federal Trade Commission (for general privacy complaints)

State-Specific Rights

California Residents (CCPA/CPRA)

Additional Rights:

  • Right to know what personal information is collected
  • Right to know if personal information is sold or shared
  • Right to opt out of sale/sharing (we do not sell data)
  • Right to delete personal information
  • Right to non-discrimination for exercising rights

California Privacy Notice:

  • Categories of information collected: See "Information We Collect"
  • Purposes for collection: See "How We Use Your Information"
  • Categories of third parties: See "How We Share Your Information"
  • We do not sell personal information

How to exercise: Email privacy@mysensorybook.com with "California Privacy Rights" in subject

Other States

If your state has enacted privacy legislation (e.g., Virginia, Colorado, Connecticut):

  • You may have additional rights similar to CCPA
  • Contact us to exercise state-specific rights
  • We will comply with applicable state laws

Data Processing Addendum (For Clinic Customers)

Clinic customers may require a Data Processing Addendum (DPA) outlining:

  • Sub-processors we use
  • Data processing instructions
  • Security measures
  • Audit rights
  • Liability and indemnification

To request a DPA: Contact sales@mysensorybook.com


Consent and Acknowledgment

By using MySensoryBook, you acknowledge that:

  • You have read and understood this Privacy Policy
  • You consent to the collection, use, and sharing of information as described
  • If you are a healthcare provider, you are responsible for obtaining necessary consents from patients/parents
  • You will use the platform in compliance with HIPAA and other applicable laws

Questions or concerns about this Privacy Policy?
Contact us at privacy@mysensorybook.com