Privacy Policy
Effective Date: November 29, 2025
Last Updated: November 29, 2025
Introduction
MySensoryBook ("we," "our," or "us") is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered sensory journal platform.
This policy applies to occupational therapists, clinic administrators, parents, and any other users of MySensoryBook.
HIPAA Compliance: As a platform used in healthcare settings, MySensoryBook is designed to comply with the Health Insurance Portability and Accountability Act (HIPAA). We handle Protected Health Information (PHI) with the highest standards of security and confidentiality.
Information We Collect
1. Information You Provide Directly
Account Information:
- Name and professional credentials
- Email address
- Organization/clinic name
- Password (encrypted)
- Billing information (processed securely through our payment provider)
Patient Information (Protected Health Information):
- Patient names (first name, last name, or pseudonyms)
- Date of birth
- Sensory experience descriptions
- Visual journals and associated metadata
- Parent/guardian contact information
- Session notes and clinical observations
Communication Information:
- Support requests and correspondence
- Feedback and survey responses
- Email interactions
2. Information Collected Automatically
Usage Data:
- Login times and frequency
- Features used
- Journals created and accessed
- Browser type and version
- Device information
- IP address
- Session duration
Analytics Data:
- Aggregate usage patterns
- Feature adoption rates
- System performance metrics
- Error logs and diagnostic data
3. Information from Third Parties
Payment Processing:
- Transaction data from Polar.sh (our payment processor)
- Payment method information (we do not store full credit card numbers)
AI Processing:
- When you use our AI features, we send sensory descriptions to our AI provider (OpenAI/Anthropic) with anonymized identifiers only
How We Use Your Information
Primary Uses
To Provide Our Service:
- Create and manage user accounts
- Generate AI-powered sensory journals
- Store and organize patient records
- Enable parent portal access
- Process payments and manage subscriptions
- Provide customer support
To Improve Our Service:
- Analyze usage patterns to enhance features
- Identify and fix technical issues
- Develop new features based on user needs
- Optimize AI journal generation quality
- Conduct research on platform effectiveness
To Communicate With You:
- Send service-related notifications
- Provide customer support responses
- Share product updates and new features
- Send billing and account information
- Request feedback (you can opt out)
For Security and Compliance:
- Prevent fraud and abuse
- Enforce our Terms of Service
- Comply with legal obligations
- Protect user safety and privacy
- Maintain HIPAA compliance
Uses We Will NOT Engage In
We will NEVER:
- Sell your personal information or patient data
- Share patient information for marketing purposes
- Use patient data to train AI models (without explicit consent)
- Share identifiable patient information with third parties (except as required by law or with your permission)
- Send spam or unsolicited marketing to parents
How We Share Your Information
Service Providers
We share information with trusted third-party service providers who help us operate our platform:
AI Processing:
- OpenAI or Anthropic (for journal generation)
- Data sent: Anonymized sensory descriptions only
- Data NOT sent: Patient names, birthdates, or other identifying information
Payment Processing:
- Polar.sh (payment gateway)
- Data shared: Billing information, transaction amounts
- We do not store full credit card numbers
Cloud Infrastructure:
- Amazon Web Services (AWS) or similar
- Purpose: Secure hosting and data storage
- Security: Encrypted at rest and in transit
Analytics:
- Usage analytics tools (anonymized data only)
- Purpose: Improve platform performance and user experience
Email Services:
- Resend or similar email delivery service
- Purpose: Transactional emails and notifications
All service providers:
- Sign Business Associate Agreements (BAAs) when handling PHI
- Are contractually obligated to protect your data
- Use data only for specified purposes
Legal Requirements
We may disclose information when required by law:
- In response to subpoenas or court orders
- To comply with legal processes
- To protect our rights, property, or safety
- To protect the rights, property, or safety of our users or the public
- In connection with fraud prevention or investigation
Business Transfers
If MySensoryBook is acquired, merged, or undergoes a business transition:
- User data may be transferred to the new entity
- You will be notified of any such change
- The new entity will be bound by this Privacy Policy (or you'll be notified of changes)
With Your Consent
We may share information in other circumstances with your explicit consent.
Data Security
Technical Safeguards
Encryption:
- All data encrypted in transit (TLS/SSL)
- All data encrypted at rest (AES-256 or equivalent)
- Database encryption enabled
Access Controls:
- Multi-factor authentication available
- Role-based access permissions
- Regular access audits
- Secure password requirements
Infrastructure Security:
- Regular security assessments
- Intrusion detection systems
- Automated backups (encrypted)
- Disaster recovery procedures
Application Security:
- Regular security updates
- Vulnerability scanning
- Secure coding practices
- Security testing before releases
Organizational Safeguards
Staff Training:
- HIPAA compliance training for all employees
- Privacy and security awareness programs
- Incident response procedures
Policies and Procedures:
- Data handling policies
- Breach notification procedures
- Vendor management protocols
- Regular policy reviews
Monitoring:
- 24/7 system monitoring
- Audit logging of access to PHI
- Regular security reviews
- Penetration testing (periodic)
Limitations
While we implement strong security measures, no system is 100% secure. We cannot guarantee absolute security but maintain industry best practices to protect your data.
Data Retention
Active Accounts
Patient Records:
- Retained as long as your account is active
- You control patient data and can delete it anytime
- Deleted patient data is removed from our systems within 30 days (excluding backups)
Account Information:
- Retained as long as your account is active
- You can request account deletion at any time
Closed Accounts
After Account Closure:
- Patient data deleted within 30 days of account closure
- Billing records retained for 7 years (legal requirement)
- Anonymized usage data may be retained for analytics
- Backup systems purged on regular schedule (90 days)
Legal Holds
Data subject to legal holds, investigations, or disputes will be retained as legally required.
Your Rights and Choices
Access and Correction
You have the right to:
- Access your account information
- View all patient records you've created
- Correct inaccurate information
- Export your data (patient records, journals)
How to exercise: Contact us at privacy@mysensorybook.com or use in-app settings
Data Deletion
You can:
- Delete individual patient records anytime
- Delete your entire account (irreversible)
- Request deletion of specific information
How to exercise: Use in-app deletion or contact support
Note: Some data may be retained as required by law (e.g., billing records)
Opt-Out Rights
Email Communications:
- Opt out of marketing emails (click unsubscribe)
- You will still receive essential service emails (billing, security)
Analytics:
- We use anonymized analytics only
- Contact us to discuss specific concerns
Parent Rights
Parents whose children are patients have the right to:
- Access their child's sensory journals via parent portal
- Request corrections to their child's information
- Request deletion of their child's records
- Revoke portal access at any time
How to exercise: Contact the therapist who created the records
Children's Privacy
MySensoryBook is not intended for direct use by children under 13. Our platform is designed for occupational therapists to use in their professional practice.
Patient Data:
- Patient information is entered by licensed therapists
- Parents access information through secure portals
- We do not knowingly collect information directly from children
If we become aware that we've collected information from a child under 13 without proper parental consent, we will delete it promptly.
International Users
MySensoryBook is based in the United States. If you access our service from outside the U.S., please be aware that:
Data Transfer:
- Your information will be transferred to and stored in the United States
- U.S. privacy laws may differ from your country
- We comply with applicable data protection regulations
GDPR Compliance (EU Users):
- Legal basis for processing: Contract performance, legitimate interests, consent
- Data Protection Officer contact: privacy@mysensorybook.com
- Right to lodge a complaint with your supervisory authority
- Additional rights under GDPR (see "Your Rights" section)
Cookies and Tracking Technologies
What We Use
Essential Cookies:
- Session management
- Authentication
- Security features
- Required for platform to function
Analytics Cookies:
- Usage statistics (anonymized)
- Feature adoption tracking
- Performance monitoring
Preferences:
- Language settings
- Display preferences
Your Choices
Browser Settings:
- You can control cookies through browser settings
- Blocking essential cookies may impair functionality
Do Not Track:
- We honor Do Not Track signals where applicable
- Analytics are anonymized regardless
Third-Party Links
Our platform may contain links to third-party websites or services (e.g., educational resources, professional organizations). We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.
Changes to This Privacy Policy
Updates:
- We may update this Privacy Policy periodically
- Material changes will be communicated via email or in-app notification
- Continued use after changes constitutes acceptance
Version History:
- Current version effective date noted at top
- Previous versions available upon request
HIPAA and Healthcare Compliance
Business Associate Agreement (BAA)
For healthcare providers using MySensoryBook:
- We sign BAAs with all clinic customers
- BAA available upon request or during signup
- Outlines our responsibilities under HIPAA
- Contact privacy@mysensorybook.com for BAA questions
HIPAA Rights
As a patient's representative (parent/guardian), you have rights under HIPAA:
- Right to access medical records
- Right to request corrections
- Right to request restrictions on use
- Right to receive confidential communications
- Right to file a complaint
To exercise HIPAA rights: Contact the healthcare provider (therapist/clinic) who created the records
Breach Notification
In the event of a data breach involving PHI:
- We will notify affected users within 60 days
- Notification will include nature of breach, data affected, steps taken
- We will report to HHS as required by law
- We will assist you in notifying patients if required
Contact Information
Privacy Questions or Concerns
Email: privacy@mysensorybook.com
Support: support@mysensorybook.com
Response Time
- Privacy inquiries: Within 5 business days
- Data access requests: Within 30 days
- GDPR requests: Within 30 days (may extend to 60 if complex)
Complaints
If you have a complaint about our privacy practices:
- Contact us using the information above
- We will investigate and respond within 30 days
- If unresolved, you may contact:
- U.S. Department of Health and Human Services (for HIPAA complaints)
- Your local data protection authority (for GDPR complaints)
- Federal Trade Commission (for general privacy complaints)
State-Specific Rights
California Residents (CCPA/CPRA)
Additional Rights:
- Right to know what personal information is collected
- Right to know if personal information is sold or shared
- Right to opt out of sale/sharing (we do not sell data)
- Right to delete personal information
- Right to non-discrimination for exercising rights
California Privacy Notice:
- Categories of information collected: See "Information We Collect"
- Purposes for collection: See "How We Use Your Information"
- Categories of third parties: See "How We Share Your Information"
- We do not sell personal information
How to exercise: Email privacy@mysensorybook.com with "California Privacy Rights" in subject
Other States
If your state has enacted privacy legislation (e.g., Virginia, Colorado, Connecticut):
- You may have additional rights similar to CCPA
- Contact us to exercise state-specific rights
- We will comply with applicable state laws
Data Processing Addendum (For Clinic Customers)
Clinic customers may require a Data Processing Addendum (DPA) outlining:
- Sub-processors we use
- Data processing instructions
- Security measures
- Audit rights
- Liability and indemnification
To request a DPA: Contact sales@mysensorybook.com
Consent and Acknowledgment
By using MySensoryBook, you acknowledge that:
- You have read and understood this Privacy Policy
- You consent to the collection, use, and sharing of information as described
- If you are a healthcare provider, you are responsible for obtaining necessary consents from patients/parents
- You will use the platform in compliance with HIPAA and other applicable laws
Questions or concerns about this Privacy Policy?
Contact us at privacy@mysensorybook.com
