Legal
Privacy Policy
Effective and last updated
This policy explains how Congruent handles information about the people who visit this website, the clinicians and practices who use our software, and the clients whose care is documented in it. It is written to be read. Where it uses a defined term from HIPAA, it means what HIPAA means.
1. Who we are and what this policy covers
"Congruent", "we", and "us" mean the company that operates the website at congruent.care and the Congruent application. This policy covers both. It applies to:
- Visitors to this website, including anyone who requests access or contacts us.
- Account holders and authorised users of the Congruent application: the clinicians, supervisors, and practice staff a practice lets in.
- Clients of a practice, in a limited way. Information about a client inside the application is protected health information that we hold on the practice's behalf. Section 3 explains what that means, and section 10 explains where a client's rights are exercised.
2. Information we collect
On this website. The site is static and can be read without telling us anything. When you request access, we collect your name, work email address, and, if you provide them, your practice name, how many clinicians work there, the software you use today, and anything you write in the notes field. We also record the page you submit the form from and, when available, the page where your visit began, a recognized referring site or general source category, and a recognized campaign tag from the link you used. For these three attribution fields, we retain only values from lists we maintain. Unrecognized values are replaced with general labels such as ‘other’ or omitted. These fields do not retain your search terms or full referring web addresses. When you use the contact form or email us, we receive what you send and keep the correspondence so the next person who helps you has the history.
Web analytics. We use a cookieless analytics service that reports aggregate page views, referrers, country, and device type. It sets no cookies, assigns no identifier that persists across sites or days, and is not connected to any advertising network. Our hosting provider also keeps short-lived server logs, which include IP address, browser type, and timestamps, for security and operations.
In the application. We collect four kinds of information, and they are worth keeping apart.
- Account information. Your name, work email address, practice name, professional credentials and license type, time zone, and the billing contact for the subscription. Prescribers who enable e-prescribing also complete the identity proofing that federal rules require for controlled substances.
- Practice content. Everything a practice puts into the product: schedules, client records, progress notes, treatment plans, assessments, messages, uploaded documents, intake and consent forms, claims, and session recordings or dictation where the practice has enabled them. Charts we migrate from a previous system are practice content from the moment we receive them. Most of this is protected health information and is covered by section 3.
- Payment information. Subscription and invoice records. Card details are collected and stored by our payment processor; we do not store full card numbers on our systems.
- Technical and audit data. IP address, browser and device characteristics, timestamps, feature usage, error reports, and the access log entries that HIPAA requires us to keep.
3. Protected health information and HIPAA
When a practice uses Congruent to document care, the practice is a covered entity and we are its business associate. The protected health information placed in the product is governed by HIPAA and by the business associate agreement between us and the practice, not by this policy. Where the two documents disagree, the business associate agreement controls.
A business associate agreement is included on every plan, including the free trial, at no charge, and it is executed before any protected health information enters the product. Under it we use and disclose protected health information only to provide the service, only as the agreement and HIPAA permit, and we require the same of every subprocessor that touches it.
Clients exercise their HIPAA rights, such as access, amendment, and an accounting of disclosures, through their treating clinician, because the practice holds the designated record set. We support the practice in responding to those requests; we do not respond to them directly.
4. How we use information
- To operate, maintain, secure, and improve the software.
- To authenticate users and keep the audit trail HIPAA requires.
- To bill subscriptions and send transactional notices about an account.
- To respond to a request for access, answer questions, and provide support. If you request access, we will email you about that request; tell us to stop and we will.
- To produce aggregate operational metrics, such as error rates, latency, and feature adoption, that do not identify a client or reveal clinical content.
- To comply with law, respond to lawful requests, and enforce our terms.
We do not use personal information for advertising, we do not sell it, we do not share it for cross-context behavioural advertising, and we do not give it to data brokers. There is no advertising business here to feed.
5. AI processing
Session recordings, dictation, and the text a clinician writes are processed to produce the drafts the clinician asked for: progress notes, treatment plans, summaries, and the compliance check that compares a note against the diagnosis and plan already in the chart. That processing is the purpose, and it is the only purpose.
- Client data is never used to train AI models. Not ours, not a vendor's, not on raw data, not on de-identified extracts, and not on aggregates derived from clinical content.
- Every AI provider in the processing path operates under a business associate agreement with us and under terms that prohibit training on the data we send and that limit how long it may be retained.
- Session audio exists only long enough to produce the note draft and is then deleted. A practice can shorten that window or never record at all and dictate instead.
- Nothing is signed automatically. Every AI-drafted document waits for a clinician to review, edit, and sign it.
6. Service providers and subprocessors
This website runs on a small number of vendors: a hosting and analytics provider (Vercel), a database that stores access requests (Supabase), and business email (Google Workspace). Each receives only the information needed to do its job for us.
The application relies on cloud infrastructure and storage in United States regions, AI model providers, telehealth video, a payment processor, appointment reminders and transactional email, and, where a practice uses them, a claims clearinghouse and the Surescripts e-prescribing network. Every subprocessor with access to protected health information operates under a business associate agreement and contractual security obligations no weaker than our own.
The current list of application subprocessors is provided with the business associate agreement and is available to any account holder on request. We give account holders notice before adding a subprocessor that materially changes how protected health information is handled.
7. Security
Data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256, backups included. Access to production systems is limited to the people who need it, requires multi-factor authentication, is granted on a least-privilege basis, and is logged. Every view, edit, and export of a chart is recorded in an audit trail the practice can pull itself. We run an incident response process and will notify affected practices of a breach of unsecured protected health information within the timelines HIPAA requires.
We do not currently hold a third-party attestation such as SOC 2 or HITRUST, and our security page says so. No system is perfectly secure. What we commit to is a defensible architecture, honest disclosure, and no quiet incidents.
8. Retention and deletion
Website submissions. We keep an access request or contact message for as long as we are in conversation with you about it. If you open an account, it becomes part of your account record. Otherwise, tell us and we will delete it.
Practice content. We retain it for as long as the account is active. A practice can export charts, signed notes, treatment plans, assessment scores, and its client list in standard formats at any time, at no charge, without filing a request.
After a subscription ends, practice content stays available for export for 90 days. We then delete it from active systems within 30 days, and it ages out of encrypted backups on our normal rotation, no later than 90 days after that, except where the business associate agreement or the law requires us to keep it longer. A practice's own record-retention obligations under state law and its licensing board remain its own: export before closing the account.
9. Cookies and tracking
This website sets no cookies. To understand how visitors find us, we store the three attribution fields described above in your tab’s browser session storage. This record contains no unique tracking identifier. Session storage normally clears when the tab’s session ends, but may be restored if your browser restores the session. If you submit a request for access, these fields are sent with it and retained with the request. The application uses strictly necessary cookies for authentication and session management, and nothing else. We run no advertising pixels, build no cross-site behavioural profiles, and do not sell or share personal information for cross-context behavioural advertising as those terms are defined under state privacy law. Because we do neither, a Global Privacy Control or Do Not Track signal asks us to stop something we never started; we treat it as an opt-out all the same.
10. Your privacy rights
Depending on where you live, you may have the right to access, correct, delete, or obtain a portable copy of the personal information we hold about you, to opt out of certain uses, and to appeal a decision we make about such a request. Write to us and we will handle it. We may need to verify that you are who you say you are. We will not charge you, and we will not treat you differently for asking.
These rights apply to information about you as a visitor or account holder. Requests about clinical records, including a client's request to see or amend their own chart, go through the treating clinician, as described in section 3.
Congruent is offered to practices in the United States, and data is stored in the United States. If you visit from elsewhere, the information you send us is transferred to and handled in the United States.
11. Children
Congruent is a professional tool. Accounts are for adults, this website is not directed at children, and we do not knowingly collect personal information from a child under thirteen as a visitor. Minors are, of course, clients in many practices. Information about a minor client is protected health information, handled under HIPAA, the business associate agreement, and the state law that governs the clinician's consent and confidentiality obligations.
12. Links to other sites
This website links to other companies' sites, including on our comparison pages. Their privacy practices are their own, and this policy does not cover them.
13. Changes to this policy
We will update this page when our practices change and will update the date at the top when we do. For changes that materially affect how information is handled, we will notify account holders directly rather than relying on anyone to re-read the page.
14. Contact
Questions about this policy, a privacy request, or a security questionnaire all go to the same place: support@congruent.care. Please do not include protected health information in an email to us.
See also our Terms of Service and our security overview.