Mi[]rovaPrivacy Policy

Privacy Policy

Effective DateAugust 8, 2026
EntityBinaryel

Our Privacy Promise

Your clinical data and your clients' information are deeply sensitive. We built Mirova with privacy-first principles because we believe healthcare data deserves the highest protection. We never sell your data, period.

This Privacy Policy explains how Mirova ("we," "our," or "us") collects, uses, protects, and shares personal information when you use our practice management platform. We're committed to transparency—this policy is written in plain English, not legal jargon.

§ 01

Information We Collect

Information You Provide Directly:

  • Account Information: Email address, name, password (encrypted), professional credentials for providers.
  • Clinical Documentation: Session notes, therapy notes (SOAP, DAP, progress notes), treatment plans, assessment forms.
  • Audio Recordings: Session recordings (with consent) and between-session client check-ins from the mobile app.
  • Transcripts: Text transcriptions of audio recordings.
  • Client Information: Demographics, contact information, appointment history, secure messages.
  • Billing & Payment Information: Invoices, superbills, fee schedules. Full payment card numbers are processed by third-party processors and never stored by Mirova.
  • Insurance Information: Payer details, policy numbers, claims data, eligibility information.
  • Appointment Data: Scheduling information, reminders, cancellations.
About Recordings: Mirova collects audio recordings only when you or your provider voluntarily choose to record, with appropriate consent. These recordings are used to provide transcription and clinical documentation tools and are never shared with any third-party for marketing or advertising.

Information Collected Automatically:

  • Usage Data: Features used, session duration, interaction patterns
  • Device Information: Device type, operating system, browser type
  • Log Data: IP address, timestamps, error reports
  • Analytics: Aggregated, anonymized usage statistics to improve our service

Information From Automated Processing:

  • Transcription: Automated transcription of recorded sessions and check-ins
  • Drafted Notes: AI-assisted clinical note drafts for provider review
  • Mood & Sentiment Analysis: Emotional tone and patterns detected in client check-ins
  • Engagement Insights: Client engagement alerts and session prep summaries
§ 02

How We Use Your Information

We use your data to:

  • Provide the Service: Scheduling, client management, clinical documentation, billing, insurance claims, secure messaging.
  • Clinical Documentation Tools: Transcribe recordings, draft notes for provider review, generate session prep summaries.
  • Communication: Send appointment reminders, service updates, security alerts (you can manage notification preferences).
  • Improvement: Analyze aggregated, anonymized data to enhance features and reliability.
  • Security: Detect fraud, prevent abuse, and protect against security threats.
  • Legal Compliance: Meet legal obligations and enforce our Terms of Service.
What We DON'T Do: We never sell your personal data or your clients' data to advertisers, data brokers, or third parties. Your clinical data is NEVER used to train external AI models. We do not use health information for targeted advertising.
§ 03

How We Protect Your Data

We employ industry-leading security measures:

  • Encryption at Rest: All data encrypted using AES-256 via AWS KMS with dedicated keys per environment.
  • Encryption in Transit: TLS 1.2 or higher for all data transmission.
  • Secure Infrastructure: Data stored on enterprise-grade AWS cloud servers with SOC 2-compliant practices.
  • Access Controls: Role-based authorization—providers see only their assigned clients' data.
  • Audit Logging: All access to protected health information is logged for compliance.
  • Regular Security Reviews: Third-party security assessments and penetration testing.
No system is 100% secure. While we use best practices, you should also use a strong, unique password and enable two-factor authentication when available.
§ 04

When We Share Your Data

We only share your information in these limited circumstances:

  • Service Providers: Third-party vendors who help us operate (e.g., cloud hosting, payment processing, AI transcription, insurance clearinghouses, SMS providers). They are contractually obligated to protect your data, are bound by Business Associate Agreements where required, and cannot use it for their own purposes.
  • At Your Provider's Direction: Insurance claims submitted through clearinghouses at your provider organization's direction.
  • Legal Requirements: If required by law, court order, or to protect rights and safety. We'll notify you unless legally prohibited.
  • Business Transfers: If Mirova is acquired or merged, your data may transfer to the new owner. You'll be notified and have the option to export or delete your data.
§ 05

Your Privacy Rights & Choices

  • Access Your Data: Request a copy of all your personal information we hold.
  • Download Your Data: Export your clinical documentation, recordings, and data anytime.
  • Correct Inaccuracies: Update or correct your account information.
  • Delete Your Account: Request deletion of your account and associated data (subject to clinical record retention requirements).
  • Opt Out of Communications: Unsubscribe from marketing emails; manage SMS and notification preferences in the app.
  • Withdraw Consent: You can withdraw consent for data processing at any time.

To exercise these rights, email us at [email protected] or use the account settings within the app.

§ 06

How Long We Keep Your Data

  • Active Accounts: Data retained as long as your account is active.
  • Clinical Records: Retained according to your provider organization's record retention requirements and applicable law (commonly 6–10 years, longer for minors).
  • After Termination: Provider organizations have 60 days to export data after account termination, after which data is deleted (except where legally required to retain).
  • Backups: May remain in encrypted backups for up to 90 days for disaster recovery.
  • Anonymized Data: Aggregated analytics may be retained indefinitely (cannot identify you).
§ 07

Children's Privacy

Client accounts for individuals under 18 may be created only by a provider organization, which is solely responsible for obtaining and documenting parental or guardian consent as required by applicable law before the minor uses the platform. Mirova does not accept direct sign-ups from individuals under 18. If you believe a minor has created an account without going through a provider organization, please contact us immediately at [email protected].

§ 08

Data Storage & Location

Your data is stored on secure AWS cloud servers in the United States. All data is encrypted both in transit and at rest.

§ 09

Cookies & Tracking

We use cookies and similar technologies for:

  • Essential Cookies: Keep you logged in and remember your preferences.
  • Analytics Cookies: Understand how you use Mirova (anonymized).
  • Performance Cookies: Improve app speed and functionality.

You can control cookies through your browser settings. See our Cookie Policy for details. We do not place advertising or tracking pixels on authenticated pages containing protected health information.

§ 10

Changes to This Policy

We may update this policy from time to time. Material changes will be notified via email or in-app notification at least 30 days before taking effect. Continued use after changes constitutes acceptance.

§ 11

Privacy Team

Our privacy team is here to address your privacy concerns:

Privacy Team[email protected]
Response TimeWithin 45 days of receipt
§ 12

Your US State Privacy Rights

Depending on your state of residence (including California, Colorado, Connecticut, Texas, Virginia, Washington, and other states with comprehensive privacy laws), you may have some or all of the following rights regarding your personal information:

  • Right to Know / Access: Request the categories and specific pieces of personal information we have collected about you, our sources, our purposes, and the categories of third parties with whom we share it.
  • Right to Delete: Request deletion of your personal information, subject to legal exceptions (including clinical record retention obligations of your provider organization).
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Portability: Receive a copy of your data in a portable, machine-readable format.
  • Right to Opt Out of Sale or Targeted Advertising: We do not sell personal information and do not use your health information for targeted advertising. If this ever changes, you will have the right to opt out first.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of these rights.

Note for clients of provider organizations: Health information created or maintained as part of your care is Protected Health Information governed by HIPAA and controlled by your provider organization. Requests to access, amend, or delete clinical records should be directed to your provider; we support your provider in fulfilling them.

To exercise any right, email [email protected] with the subject line "Privacy Request" or use your account settings in the app. We will respond within 45 days (extendable by an additional 45 days where reasonably necessary, with notice). If we decline a request, you may appeal by replying to our decision; if the appeal is denied, you may contact your state Attorney General.

Authorized Agents: You may designate an authorized agent to make requests on your behalf. We may require verification of the agent's authority.

§ 13

How Your Information Is Processed

Mirova is used through provider organizations (therapy practices, clinics, and counseling centers). Health information in your account — including session recordings, transcripts, clinical notes, treatment plans, messages with your provider, and check-in data — is Protected Health Information under HIPAA. It is governed by the Business Associate Agreement between Mirova and your provider organization alongside this Privacy Policy, and your provider organization controls the clinical record.

Automated processing: Some features use automated analysis, including artificial intelligence, to transcribe audio, draft clinical notes for provider review, and generate mood, sentiment, and engagement insights. This processing is performed by Mirova and by contracted service providers bound by Business Associate Agreements that prohibit them from using your information to train their models. Your information is never sold and is never used for advertising.

Audio recordings: Session recordings and between-session audio check-ins are encrypted, are accessible only to you and your care team under your provider organization's access controls, and are retained according to your provider organization's clinical record retention requirements. Recording only occurs with consent, as described in the Client Consent Agreement.

Billing and insurance information: Payment card processing is handled by third-party payment processors; Mirova does not store full card numbers. Insurance information is used to prepare and submit claims at your provider organization's direction, through healthcare clearinghouses.

§ Contact

Questions or Concerns?

We're here to help. If you have questions about this Privacy Policy or how we handle your data:

Privacy Team[email protected]
General Support[email protected]

Privacy-First GuaranteeYour clinical data deserves the highest protection. We'll never compromise your privacy for profit.