Privacy Policy
Last updated: August 2026
What TherapyCoach is
TherapyCoach is a clinical skills training simulator. All client characters are fictional. No real client data is used, collected, or stored at any point. You should never enter real client information, identifiable personal data, or content relating to actual clinical cases into the application.
Who we are, and the law this policy is written against
TherapyCoach is operated from Queensland, Australia by Georgia Murphy. Contact details are at the end of this policy.
This policy is written to meet the Australian Privacy Principles (APPs) in Schedule 1 of the Privacy Act 1988 (Cth). We handle personal information in accordance with the APPs whether or not the small business exemption in section 6D of that Act applies to us, because the organisations our users work for are themselves bound by those obligations and those obligations flow through to the tools they use.
If you use TherapyCoach as an employee of a health or community service, your employer remains responsible for its own privacy obligations to its clients. Nothing in this policy changes that, and TherapyCoach is not intended to hold, and must not be used to hold, any information about a real client.
What we collect
When you use TherapyCoach, we collect the following data linked to your account:
Account information: your email address and encrypted password, used for authentication.
Session data: your modality, clinical field, engagement type, cultural context, and skill level selections for each practice session.
Conversation transcripts: the full text of your practice conversations with simulated clients, including coaching feedback received during sessions. These are stored so you can review past sessions and track your development over time.
Progress and learning data: session completion counts, competency ratings from assessment mode, learning pathway progress, drill attempts, and lesson completion records.
Subscription and billing data: if you hold a paid subscription, we store your subscription status and billing period. Payment processing is handled by Stripe — we do not store your credit card details.
Usage data: token usage associated with AI processing of your sessions, used for service management and cost monitoring.
AI model and how conversations are processed
TherapyCoach uses OpenAI's gpt-4o-mini model for text and gpt-realtime-mini for spoken sessions to generate simulated client responses and coaching feedback. Your practice conversations are sent to OpenAI's API for processing. Under OpenAI's API data usage policy, conversations sent via the API are not used to train OpenAI's models.
We do not use your conversation content to train our own AI models. The AI generates responses in real time based on the clinical frameworks and coaching logic built into the platform. For more detail on how we use AI responsibly and the regulatory frameworks that inform our approach, see our AI & Compliance page.
Sending information overseas
This is the most important thing in this policy, so it has its own section.
Your practice conversations leave Australia. Text you type or speak during a session, together with the session's clinical parameters, is transmitted to OpenAI, L.L.C. and processed on infrastructure located in the United States of America. Coaching feedback and assessment scores are generated there and returned to you. This is a disclosure of personal information to an overseas recipient for the purposes of APP 8.
Before making that disclosure we have taken the following steps:
Contractual protection. Use of the OpenAI API is governed by OpenAI's API terms and data usage policy, under which API inputs and outputs are not used to train OpenAI's models and are retained only for a limited abuse-monitoring period before deletion.
Minimisation. We do not send your email address, account identifier, subscription details or payment information to OpenAI. What is sent is the conversation content and the session's clinical parameters.
Design. The product is built and repeatedly signposted so that the content of a session is a fictional roleplay, not a record of a real person. The single largest privacy protection here is that there should be no real client information in the conversation to begin with.
You should understand two consequences. First, information held in the United States may be accessible to United States authorities under that country's laws. Second, while we take the steps above, we cannot guarantee that an overseas recipient will handle information in a way that meets every requirement of the Australian Privacy Principles, and Australian privacy law may not be enforceable against them. If you are not comfortable with that, do not use TherapyCoach.
Account, authentication, session and progress data that is not sent to OpenAI is stored in a Supabase-hosted PostgreSQL database. Database hosting region: ap-south-1 (Mumbai, India). Payment processing is handled by Stripe, which also processes information outside Australia.
AI safety and guardrails
TherapyCoach includes safety measures designed to maintain appropriate boundaries for a training tool. These include: crisis language detection that provides immediate safety messaging and helpline information if distress-related content is identified; content filtering to keep conversations within the bounds of clinical training; clear disclaimers that all interactions are simulated and do not constitute clinical advice; and rate limiting to prevent misuse. These guardrails are built into the application layer and operate independently of the AI model's own safety systems.
Authentication and data storage
TherapyCoach uses email and password authentication powered by Supabase. Your account credentials are stored securely using industry-standard encryption. We do not use social login providers or access any third-party accounts on your behalf. All user data — including session transcripts, progress records, and account information — is stored in a Supabase-hosted PostgreSQL database with row-level security, meaning each user can only access their own data.
How we use engagement data to improve the product
We use aggregated, de-identified engagement data to understand how the platform is being used and to improve the product. This includes patterns such as which modalities and clinical fields are most used, average session lengths, feature adoption rates, and where users encounter difficulties. This data is used internally only — we do not share it with any third party, and it cannot be used to identify individual users.
Cookies and local storage
We use essential cookies to maintain your login session and local storage to save your preferences (such as skill level, preferred modality, and theme settings). We do not use tracking cookies, advertising cookies, or third-party analytics.
Who else receives your information
We do not sell your personal information, and we do not disclose it for any purpose other than running the service. We do not run advertising and do not share data with advertisers, data brokers or analytics providers.
Three service providers necessarily receive some of your information in order for TherapyCoach to work:
OpenAI — conversation content and session parameters, for generating client responses and coaching. Processed in the United States. See Sending information overseas above.
Supabase — account credentials, session transcripts, progress records. This is where your data is stored.
Stripe — subscription and billing information, if you hold a paid subscription. We never see or store your card details.
We may also disclose personal information where we are required or authorised to do so by Australian law.
Data retention and deletion
Account information and session data are retained while your account is active, to support your learning pathways and allow you to review past sessions. If your account is inactive for more than 12 months, we may contact you before deleting your data. You can request deletion of your account and all associated data at any time by emailing support@therapycoach.app. On receipt of a verified deletion request, we will remove your account, all session transcripts, progress data, and any other personal information within 30 days.
Security
All data is transmitted over HTTPS. Authentication tokens are handled securely. The application uses security headers, input sanitisation, and rate limiting to protect against common web vulnerabilities. Row-level security ensures users can only access their own data. We follow reasonable security practices for a training application, but TherapyCoach is not designed to handle sensitive personal health information.
If something goes wrong: data breaches
If we become aware of unauthorised access to, unauthorised disclosure of, or loss of personal information we hold, we will assess it promptly. Where the incident is likely to result in serious harm to any individual, we will notify the affected individuals and the Office of the Australian Information Commissioner (OAIC) in line with the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth).
We will tell you what happened, what information was involved, and what you can do about it — in plain terms, and without waiting to have a complete picture first.
Your rights, and how to complain
Access. You can ask for a copy of the personal information we hold about you. We will respond within 30 days. There is no charge.
Correction. You can ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading.
Deletion. You can ask us to delete your account and everything associated with it, at any time, for any reason. See Data retention and deletion above.
Anonymity. TherapyCoach requires an email address to hold your progress across sessions, so it cannot be used anonymously. If that is a problem for you, tell us and we will talk about it.
To exercise any of these, email support@therapycoach.app.
If you are unhappy with how we have handled your personal information, complain to us first at support@therapycoach.app. We will acknowledge your complaint within 5 business days and give you a substantive response within 30 days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
If you are located in the European Union or the United Kingdom, you may additionally have rights under the GDPR, including data portability and the right to restrict processing. Contact us to exercise them.
Changes to this policy
We may update this policy from time to time. Material changes will be communicated through the application. We encourage you to review this policy periodically.
Questions about privacy? Get in touch.