Effective June 10, 2026
This Notice of Privacy Practices explains how Relvema receives, uses, and protects protected health information (PHI) that flows through the Relvema platform. It is intended for therapists who use Relvema and their patients who interact with Relvema’s systems through the patient mobile app or the therapist portal.
Relvema operates as a Business Associate under HIPAA — not a covered entity. The therapist or practice using Relvema is the covered entity responsible for issuing their own Notice of Privacy Practices to patients. This notice describes Relvema’s role in that data flow and what patients can expect when their data is processed through Relvema’s infrastructure.
1. What health information Relvema receives
Relvema receives PHI only to the extent necessary to provide the Services. Depending on how a therapist uses the platform, this may include:
- Patient identity: first and last name, email address. These are used to establish and maintain the therapist–patient connection within the platform.
- Session audio recordings: recordings made during in-platform video sessions or uploaded from an in-person session through the patient app. Audio is stored encrypted in Google Cloud Storage and processed solely to generate transcripts and AI-assisted clinical notes.
- Session transcripts and AI notes: text generated from session audio by Relvema’s AI pipeline (running on Google Vertex AI). Transcripts and SOAP/DAP/BIRP clinical notes are stored in Firestore and are accessible only to the connected therapist.
- Session summaries and clinical insights: AI-generated summaries of themes, progress indicators, and session highlights, stored alongside the transcript.
- Patient app data: if the patient uses the Relvema mobile app, Relvema may also receive mood check-in scores, journaling entries, homework assignment progress (across six categories: CBT exercises, journaling, mindfulness, behavioral activation, communication skills, and reflections), and push notification engagement.
- Scheduling data: appointment dates, times, modality (telehealth or in-person), and session notes associated with scheduled appointments.
2. How Relvema uses health information
Relvema uses PHI only for the following purposes:
- To provide the Services: generating AI transcripts and clinical notes, delivering homework and mood-tracking features in the patient app, surfacing session insights in the therapist dashboard, and facilitating video sessions.
- To display information to the treating therapist: session history, patient progress, homework completion, and AI-generated notes are made available in the therapist’s portal view, scoped strictly to their connected patients.
- To fulfill legal obligations: if a court order, subpoena, or regulatory requirement compels disclosure, Relvema will disclose only what is legally required and will notify the therapist to the extent permitted by law.
3. What Relvema never does with health information
- Relvema will never sell PHI to any third party.
- Relvema will never use PHI to train any AI or machine-learning model — including Relvema’s own AI systems or any Google AI service. All AI processing uses PHI only to generate the immediate output (transcript or note) and does not incorporate that data into model training.
- Relvema will never use PHI for advertising, marketing, or profiling purposes.
- Relvema will never share PHI with employers, insurance companies, or any entity not directly involved in providing the Services, except as required by law.
- Relvema will never transmit PHI to any third-party AI service outside the Google Cloud platform. All AI processing is performed exclusively on Google Vertex AI within Relvema’s Google Cloud project.
4. Who can access health information
Access to PHI within Relvema is governed by strict technical controls:
- Therapists can access session data, transcripts, notes, and patient app data only for patients who have accepted their connection invitation. Firestore security rules prevent any cross-therapist data access at the database level.
- Patients on the Relvema mobile app can access their own journal entries, homework, mood logs, and scheduled sessions. They cannot access the AI-generated clinical notes prepared by their therapist.
- Relvema engineers access production data only when required to investigate a security incident or support issue, subject to role-based IAM controls and audit logging.
- Google Cloud provides the infrastructure on which all PHI is stored. Google operates under a signed Business Associate Agreement with Relvema and does not access customer data for any purpose other than infrastructure operation.
5. Retention and deletion
PHI is retained as long as the therapist–patient connection is active and the therapist’s account is in good standing. Therapists can disconnect a patient at any time, which removes that patient’s data from the therapist’s view.
When a therapist’s account is deleted, all associated session data, transcripts, notes, and patient connection records are deleted from Relvema’s therapist database within 60 days. Patient-side data (journaling, mood logs, homework) is owned by the patient within the mobile app and governed by the patient app’s separate deletion policy.
Therapists may request export or deletion of their data at any time by contacting support@relvema.com. Relvema will complete the request within 30 days.
6. Patient rights
As a Business Associate, Relvema supports the Covered Entity (the therapist) in fulfilling patients’ HIPAA rights. If a patient wishes to exercise the following rights, they should first contact their therapist:
- Right to access: patients may request a copy of their health information held by their therapist, including any data visible through the Relvema platform.
- Right to amendment: patients may request correction of inaccurate health information.
- Right to an accounting of disclosures: patients may request a list of disclosures of their PHI made by Relvema other than for treatment, payment, or healthcare operations.
- Right to restriction: patients may request that certain uses or disclosures of their PHI be restricted.
- Right to delete: patients may request deletion of their data from the patient mobile app directly within the app, or by emailing support@relvema.com.
For privacy questions or concerns, contact Relvema’s Privacy Officer at compliance@relvema.com.
If you believe your privacy rights have been violated, you have the right to file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights at hhs.gov/ocr/complaints. Filing a complaint will not result in retaliation.