Privacy Policy & Data Security Statement

How we handle
your data.

Last updated: August 2, 2026  ·  Version 2.1  ·  Rewire App LLC

Overview

Our commitment to data protection

Rewire is operated by Rewire App LLC ("Rewire", "we", "us"). We provide a practitioner-assigned between-session support tool for use in conjunction with qualified mental health therapy. Because our platform is used in a clinical context, we treat data protection as a clinical governance obligation.

This policy applies to all users of the Rewire platform: licensed practitioners ("Providers") and their clients ("End Users") who access Rewire under a practitioner's assignment.

For clinical governance review: Rewire is not a HIPAA Covered Entity under 45 CFR §160.103. However, we are actively building our security controls toward HIPAA's Technical Safeguard requirements (45 CFR §164.312) — including access controls, audit logging, and encryption in transit — and can discuss a Business Associate Agreement (BAA) with US-based healthcare providers upon request. We are committed to full GDPR compliance for all European users under Regulation (EU) 2016/679. Our primary data processor, Supabase, maintains SOC 2 Type II certification and operates GDPR-compliant infrastructure. Data transfers to the US are governed by Standard Contractual Clauses (SCCs).

01 — Data Controller

Who is responsible for your data

Data Controller: Rewire App LLC

For all data protection enquiries, data subject rights requests, and Business Associate Agreement requests:
Email: privacy@rewire-emdr.com
Subject line: "Data Privacy Request"

We will acknowledge all requests within 72 hours and respond in full within 30 days.

02 — Data We Collect

What we collect and why

Practitioner (Provider) accounts

Data typePurposeLegal basis (GDPR)
Email addressAccount authentication and platform communicationsContract performance — Art. 6(1)(b)
Practice nameDisplayed within the provider dashboard; identifies the practice to their assigned clientsContract performance — Art. 6(1)(b)
Subscription and billing dataPayment processing via Stripe. Card details are not stored by Rewire. Stripe is PCI DSS Level 1 compliant.Contract performance — Art. 6(1)(b)
Client roster and account detailsClient account identifiers, email addresses, optional first names, practitioner and facility links, and access or invitation codes used to provide and administer care access.Contract performance — Art. 6(1)(b)

End User (client) data

Data typePurposeLegal basis (GDPR)
Email addressAuthentication and service communications. Shared with service providers such as Supabase, Resend, and Stripe only as needed to operate the service; not sold or shared for advertising.Contract performance — Art. 6(1)(b)
Session completion dataRecords which exercises have been completed. Visible to assigning practitioner.Legitimate interests — Art. 6(1)(f) (clinical care continuity)
Nervous system state ratingsPre/post exercise ratings (0–10 scale) entered by the user. Shared with assigning practitioner for clinical review.Consent — Art. 6(1)(a)
Journal entriesOptional written reflections entered during exercises. Shared with the assigning practitioner only if the user explicitly enables sharing. Constitutes potentially special category data.Explicit consent — Art. 9(2)(a)
AI conversation transcriptsUsed in real time to generate personalised session content only. Not stored permanently. Not used for AI model training.Consent — Art. 6(1)(a)

Data we do not collect

03 — Data Storage & Security

How we protect your data

Infrastructure

User data is stored primarily in Supabase, a managed PostgreSQL-based platform. Data is stored on managed infrastructure that provides encryption at rest. Application traffic to Rewire's service providers is encrypted in transit using HTTPS/TLS. Security certifications and infrastructure controls are maintained by the relevant service providers.

Access controls and row-level security

Rewire implements row-level security (RLS) at the database layer. Each practitioner can access only the session data for clients they have directly assigned using their own practitioner access code. No practitioner can access data belonging to clients of a different practitioner. No Rewire employee accesses user session data or journal entries in the ordinary course of operations.

AI processing safeguards

AI-generated content is routed through a Cloudflare Worker to a secure, HIPAA-covered third-party AI provider. Rewire does not intentionally add account names or email addresses to AI requests, but user-provided text may contain identifying or sensitive information. Rewire does not use AI conversation content to train models and does not intentionally retain AI conversation logs server-side beyond the active request; downstream processing is governed by the applicable provider terms and its Business Associate Agreement.

HIPAA-aligned controls (US practitioners)

For practitioners operating in the US healthcare system, Rewire implements the following controls aligned with the HIPAA Security Rule:

US-based healthcare providers requiring a Business Associate Agreement (BAA) may request one at privacy@rewire-emdr.com.

Data retention

04 — Sub-Processors

Third-party processors we use

ProcessorPurposeJurisdictionCertification
SupabaseDatabase, authentication, file storageUS / EU (configurable)SOC 2 Type II
AI provider (HIPAA-covered, under BAA)Models used for AI session content generationUS (API processing)Business Associate Agreement and provider terms apply
CloudflareWorker proxy for AI requests; DDoS and edge securityGlobal edge networkSOC 2 Type II, ISO 27001
ResendTransactional and service email deliveryUSProvider terms and controls apply
StripePayment processingUS / EUPCI DSS Level 1
ContentsquareAnalytics on the public marketing website only; not loaded in the clinical application or authenticated portalsGlobalProvider terms and controls apply

We review all sub-processor agreements for GDPR adequacy before engagement. Data transfers to the US are covered by Standard Contractual Clauses (SCCs) under GDPR Art. 46(2)(c). We will notify account holders of any material change to our sub-processor list at least 30 days in advance.

05 — AI-Powered Features

AI-Powered Features

Rewire uses third-party artificial intelligence service providers to power certain features, such as generating supportive responses, reflections, and summaries. When you use these features, the content you submit may be processed by these providers solely to deliver the feature to you. These providers act as our service providers under contract and are not permitted to use your content to train their models or for any purpose other than providing the service to us. Where this content includes health-related information, we are working to bring our AI processing under appropriate data protection terms, and we do not intentionally include your name or email in AI requests.

06 — Your Rights (GDPR)

Data subject rights

Users in the EEA, UK, Switzerland, and equivalent jurisdictions have the following rights under GDPR (or applicable equivalent legislation):

To exercise any of these rights: email privacy@rewire-emdr.com with the subject line "Data Subject Rights Request". We will respond within 30 days. You also have the right to lodge a complaint with your national supervisory authority (e.g. ICO in the UK, CNIL in France, or the relevant DPA in your country).

07 — Special Category Data

Sensitive data and mental health information

Journal entries entered by users during sessions may constitute special category data under GDPR Art. 9, specifically data concerning health and mental wellbeing. We treat all journal entry data as special category data by default and apply the following additional protections:

08 — Cookies & Analytics

Cookies and tracking

The clinical application and authenticated portals use browser storage and session technologies needed for authentication and application functionality. They do not load advertising trackers, behavioural analytics, or device-fingerprinting technology.

The public marketing website uses Contentsquare to understand website usage and improve the site. This marketing-site analytics service may use cookies or similar technologies under Contentsquare's privacy controls. Rewire does not use marketing analytics data for clinical decision-making.

09 — Changes to This Policy

Policy updates

We will notify all active account holders by email of material changes to this policy at least 14 days before they take effect. The current version is always available at rewire-emdr.com/privacy. Continued use of the platform after the effective date of a revised policy constitutes acceptance of the updated terms.

For questions about this policy: privacy@rewire-emdr.com