CopeSwipe Privacy Policy

    Effective: 06/06/2026 · Last updated: 06/19/2026

    Operated by TherAptAI Corporation.

    1. Introduction

    TherAptAI Corporation ("we," "us," or "our") operates CopeSwipe (copeswipe.com), a digital platform that enables licensed mental health clinicians to assign and manage between-session coping skill exercises for their clients. This Privacy Policy describes how we collect, use, disclose, and protect information in connection with our services.

    CopeSwipe operates as a Business Associate (as defined under the Health Insurance Portability and Accountability Act of 1996, "HIPAA") of the licensed clinicians and therapy practices ("Covered Entities") who use our platform. We are not ourselves a Covered Entity. Our clinician subscribers are responsible for their own HIPAA compliance with respect to their clients.

    2. Information We Collect

    2.1 Information from Clinicians

    When a licensed clinician registers on CopeSwipe, we collect:

    • Full name, professional credentials, and license number
    • Email address and account password (hashed)
    • Practice name, address, and contact information
    • Profile photo (optional)
    • License expiration date and state of licensure
    • Billing and subscription information

    2.2 Information from Clients

    When a clinician adds a client to CopeSwipe, we collect information provided by the clinician, which may include:

    • Client first and last name
    • Client email address
    • Assignment of coping tools and therapy exercises
    • Client interaction data with assigned exercises (completion, ratings, progress)
    • Exposure and response prevention (ERP) session data, including hierarchy items and SUDS ratings

    2.3 Automatically Collected Information

    When you use CopeSwipe, we automatically collect:

    • Device type, browser type, and operating system
    • IP address and approximate location (city/region level)
    • Pages visited, features used, and time spent on the platform
    • Log data, including access timestamps and error reports

    3. How We Use Your Information

    3.1 To Provide and Improve the Service

    • Delivering the CopeSwipe platform and its features to clinicians and their clients
    • Enabling clinicians to assign, track, and review client progress on coping exercises
    • Sending account-related emails (onboarding, password reset, license expiration reminders)
    • Diagnosing technical issues and improving platform performance

    3.2 Permitted Uses and Disclosures of PHI

    As a Business Associate, we use and disclose PHI only as permitted by our Business Associate Agreements with clinician subscribers and applicable law, including:

    • Performing our contractual obligations to the clinician (providing the platform)
    • Ensuring the proper functioning of data processing and storage
    • As required by law, including responding to lawful subpoenas or regulatory requests
    • Reporting violations of law to the appropriate authorities as required

    4. How We Share Information

    4.1 With Service Providers (Subprocessors)

    We share information with vendors who help us operate the platform, each subject to appropriate data processing agreements or Business Associate Agreements where required:

    • Supabase, Inc. — database hosting and authentication
    • Vercel, Inc. — application hosting and content delivery
    • Cloudflare, Inc. — network security and content delivery
    • Twilio SendGrid — transactional email delivery
    • Google LLC — analytics (Google Analytics 4, public pages only)

    4.2 With the Clinician

    Client interaction data, exercise completion records, and ERP session data are accessible to the assigned clinician within the CopeSwipe platform. This is the core purpose of the service.

    4.3 Legal Requirements

    We may disclose information if required to do so by law, regulation, court order, or governmental authority, or if we believe in good faith that disclosure is necessary to protect the rights or safety of any person.

    4.4 Business Transfers

    In the event of a merger, acquisition, or sale of assets, user information may be transferred to the successor entity, subject to equivalent privacy protections. We will notify affected users via email or a prominent notice on the platform.

    5. Your Rights Under HIPAA

    If you are a client whose PHI is processed through CopeSwipe, you have the following rights under HIPAA. To exercise these rights, contact your clinician directly or reach us at the contact information below.

    5.1 Right to Access

    You have the right to inspect and receive a copy of your PHI held in our systems, subject to limited exceptions provided by law.

    5.2 Right to Amendment

    You have the right to request amendment of your PHI if you believe it is inaccurate or incomplete. We may deny the request under certain circumstances and will provide a written explanation.

    5.3 Right to an Accounting of Disclosures

    You have the right to request a list of certain disclosures of your PHI made by us in the prior six years.

    5.4 Right to Request Restrictions

    You have the right to request restrictions on certain uses and disclosures of your PHI. We are not required to agree to all requested restrictions, but we will inform you of our decision.

    5.5 Right to Confidential Communications

    You have the right to request that we communicate with you about your PHI by alternative means or at an alternative location if the normal means of communication could endanger you.

    5.6 Right to Complain

    If you believe your privacy rights have been violated, you may file a complaint with us at hello@copeswipe.com or with the U.S. Department of Health and Human Services Office for Civil Rights at hhs.gov/ocr. We will not retaliate against you for filing a complaint.

    6. Data Security

    We implement technical, administrative, and physical safeguards designed to protect your information, including:

    • Encryption of all data in transit using TLS 1.2 or higher
    • Encryption of data at rest using AES-256 on all database volumes
    • Role-based access controls and Row Level Security policies on all PHI tables
    • Multi-factor authentication (TOTP) is required for all clinician accounts
    • Automatic session timeout after 20 minutes of inactivity
    • Audit logging of all access to and modifications of PHI
    • HTTP security headers, including HSTS, CSP, and X-Frame-Options
    • Regular security reviews and vulnerability assessments

    7. Data Retention

    We retain PHI for as long as necessary to fulfill the purposes described in this policy and as required by applicable law. Clinicians may delete client records from the platform at any time. Upon termination of a clinician's account, PHI associated with that account will be retained for a minimum period required by applicable law and then securely deleted or de-identified.

    Requests for data deletion by clients should be directed to the clinician of record or to us at the contact information below.

    8. Cookies and Analytics

    CopeSwipe uses Google Analytics 4 on public-facing pages (such as our marketing site and clinician directory) to understand how visitors interact with our platform. Google Analytics uses cookies to collect anonymous usage data. We do not send PHI or authenticated session data to Google Analytics.

    You may opt out of Google Analytics tracking by installing the Google Analytics Opt-out Browser Add-on available at tools.google.com/dlpage/gaoptout.

    We do not use advertising cookies or sell data to advertising networks.

    9. Children's Privacy

    CopeSwipe is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13 without verifiable parental consent. If you believe we have inadvertently collected information from a child under 13, please contact us immediately at hello@copeswipe.com.

    10. Changes to This Policy

    We may update this Privacy Policy from time to time. We will notify clinician subscribers of material changes via email to the address on file, and will post the updated policy at copeswipe.com/privacy with a revised effective date. Your continued use of CopeSwipe after a change becomes effective constitutes your acceptance of the updated policy.

    11. Contact Us

    Joy Natwick, Privacy Officer

    TherAptAI Corporation

    Email: hello@copeswipe.com

    Website: copeswipe.com

    Bucks County, Pennsylvania

    Contact us

    CopeSwipe

    Email: hello@copeswipe.com

    Website: copeswipe.com