Last updated: 27 July 2026
HIPAA and clinical data
If you are a therapist, your practice may have HIPAA duties that Closer Couples cannot satisfy with product design alone. This page is the honest version of where things stand today: what the architecture already does, what remains yours to do, and what is not finished yet. For the product walkthrough, start with For Therapists.
Where we actually are
Closer Couples includes technical safeguards designed for privacy conscious clinical workflows. We are deliberately not saying "HIPAA compliant", because compliance is a property of an arrangement between you, us, and our infrastructure providers. One part of that arrangement is not in place yet:
- Signed business associate agreements are not yet available. Until they are, the safeguards below are real and implemented, but the paperwork that makes them a compliance arrangement is not. If that matters for your practice, and it should, wait for it.
- The safeguards described on this page are implemented today and can be verified in the product: your workspace locks itself, your records are encrypted with a passphrase we never receive, and the access log is in the app under Profile & security.
We would rather lose a signup than have a clinician discover this after putting a client's material into the tool.
Why we can't read your clients' content
This is the part that does most of the work, and it is structural rather than a policy we promise to follow. A couple's answers and messages are encrypted on their own devices with a key derived on those devices. Our servers relay ciphertext. There is no administrator view, no support tool, and no database query that returns a couple's words. Not because we choose not to look, but because the data we hold does not decrypt without a key we never receive.
When a couple shares something with you, it is sealed to your console's device keys specifically. It opens on your device and nowhere else. See how we protect your data for the full model.
The safeguards, in plain terms
- Encryption at rest. Everything your console keeps (the couples you work with, the answers they shared, your own notes) is encrypted with a key derived from your passphrase, held only in memory, and discarded when the workspace locks.
- Automatic logoff. The workspace locks itself after a period of inactivity (you choose 5, 15, or 30 minutes). It never locks in the middle of a live session with a couple.
- An access log. Your device records when the vault was opened, when a passphrase attempt failed, and what kind of action was taken: times and event types only, never the contents. It answers "was this opened while I was away?".
- Consent-scoped access. A couple approves which topics you may ask about, and that agreement is cryptographically signed by all three of you. Nothing outside the approved scope reaches your console.
- Minimum necessary by construction. You receive what a couple chose to send you. Their chat, their media, and their recovery material are never available to you, to us, or to anyone else.
- Export and deletion. You can export everything held about one couple as readable text, which is useful when a client asks what records exist, and delete it just as easily.
- Encrypted backup, if you want it. Off unless you turn it on. Your workspace is sealed on your device with your passphrase and stored with us as bytes we cannot open, so a new computer can restore your couples, your notes, and your verified identity. If you forget the passphrase, the backup cannot be opened: not by you, and not by us.
- Notifications carry nothing. Push messages contain no names, no content, and no identifiers that describe what anyone is talking about. Nothing clinical appears on a lock screen.
What stays your responsibility
A tool cannot be compliant on your behalf, and one that implies otherwise is doing you harm. These remain yours:
- The device you use. Disk encryption, a screen lock, and who else can use that computer. Your vault protects your records; it cannot protect the machine.
- Your passphrase. There is no reset and no recovery; we hold nothing that could restore it. That is what makes the encryption meaningful, and it means losing the passphrase means losing the records.
- Retention schedules and records requests under your own professional obligations.
- Anything you export. Once it is a file on your computer, it is outside these protections and inside your own.
Questions we expect
Do you have a signed BAA? Not yet. See above; it is the main thing standing between this page and a plain compliance claim.
Can Closer Couples staff read a session? No. Not with a warrant, not with a support escalation, not by accident. The content leaves the couple's devices already encrypted.
What happens if I lose my laptop? Whoever has it faces your vault passphrase, with repeated attempts slowed deliberately, and nothing readable without it. Your couples' devices are unaffected.
Getting back to work depends on one thing: whether backup was on. With it, you sign in on a new computer, enter the same passphrase, and your workspace returns: couples, notes, and your verified identity. Without it, the records existed only on that machine and are gone; that is the trade the encryption makes, and it is why the backup switch is worth finding before you need it. Either way you are not locked out of practising: a new computer can be verified again from inside the console, checked by an admin as it was the first time, and your existing verification keeps working until they approve.
Is my clients' data used for anything else? No. It is not used to train anything, not sold, and not shared. Usage analytics are off unless a user turns them on, and carry no identifier for a person or a couple even then.
See also: Why Closer Couples · Security · Privacy Policy · Support