Legal

Privacy Policy

Effective 1 October 2026 · Last updated 28 September 2026

This policy explains what chERP OCD (“chERP”, “we”, “us”) collects through this website and the chERP app, why, and who we share it with.

The short version

1. Two kinds of information

Client health information. Practices use chERP to keep their clients’ clinical records. That information belongs to the practice. We handle it only on the practice’s behalf, as its business associate under HIPAA. Section 2 covers it.

Everything else. This covers people who visit this website, write to us or book a demo and the practice staff who hold chERP accounts. We’re responsible for this information ourselves. The rest of this policy covers it.

2. Client health information

Before a practice enters any client information, it signs a Business Associate Agreement (BAA) with us. That agreement, HIPAA, and the practice’s own Notice of Privacy Practices govern what happens to it. In short:

If you’re a client: requests to see, correct or get a copy of your records go to your practice, which decides how to respond. If you contact us, we’ll pass your request to your practice and help them answer it.

3. This website

The “Time saved” calculator runs entirely in your browser. The numbers you enter aren’t sent anywhere.

4. Using the chERP app

For practice staff with accounts, we collect:

For clients the practice invites to the portal, we store their name, email address, a hashed password (or, if they choose to sign in with Google, the name and email Google confirms) and what they enter in homework, check-ins and forms. All of this is client health information and is covered by section 2.

Email to clients

If a practice turns it on, chERP emails clients appointment reminders and links to intake forms. A reminder names the client, their clinician, the practice and the appointment time. These are ordinary emails. They aren’t encrypted end to end, and once one reaches a client’s inbox, anyone who can open that inbox can read it. The name of a therapy practice can itself say something about a person’s care.

So chERP sends these emails only to clients whose practice has switched them on for that client. Practices should get the client’s informed consent first. Practice staff record that consent in chERP, which notes who recorded it and when, and they can turn it off at any time.

Asking about becoming a client

The chERP sign-in page has a form, “Ask about becoming a client”, for people who’d like to be seen by a practice that uses chERP. It asks for your name and email address and, if you like, a phone number and what brings you here. We also record the IP address the form was sent from.

5. How we use information

We don’t sell personal information or share it for targeted advertising.

6. Who we share it with

We use a small number of service providers. Each one may use information only to provide its service to us. This is the complete list. The two that store or send client health information do so under a Business Associate Agreement with us.

Otherwise, we disclose information only:

7. Cookies

This website sets cookies only if you choose “Accept” in the cookie banner: two Google Analytics cookies, _ga and _ga_TP1NBT1QJ3, which last up to two years. If you choose “Decline”, none are set. Your choice itself is saved in your browser’s storage, not in a cookie. You can change it any time with “Cookie settings” at the bottom of each page, or clear it in your browser.

The chERP app uses only the cookies it needs to keep you signed in. We don’t use them for tracking or advertising.

8. How we protect it

No system is perfectly secure. If there’s a breach of unsecured client health information, we tell the practice without unreasonable delay, and no later than 30 calendar days after we discover it. The practice then notifies affected clients, and others, as the law requires of it. If a breach affects other personal information we hold, we notify people as the law requires.

9. How long we keep it

10. Your choices and rights

Practice staff and website visitors can ask us to show, correct or delete personal information we hold about them. Write to [email protected], and we’ll reply within 30 days. Depending on where you live, you may have more rights under state law. We’ll honor them, and we won’t treat you differently for using them.

Some things can’t be deleted. We can’t delete audit log entries, because they’re a legal record of who accessed what. And we can’t delete a practice’s clinical records on an individual’s request; the practice decides what happens to them.

To stop website analytics, choose “Cookie settings” at the bottom of any page and then “Decline”.

Clients: see section 2. Your practice is the right first contact.

11. Children and teens

This website isn’t aimed at children. Practices that treat children and teens may invite them, or their parents or guardians, to the client portal. The practice decides who is invited and handles consent under the laws that apply to it. Information about minors is client health information, covered by section 2.

12. Changes to this policy

If we make a material change, we’ll update the date at the top and email practices at least 30 days before it takes effect. We won’t use information we already hold in a materially different way without the consent the law requires.

13. Contact

Questions about privacy, or a request about your information:

chERP OCD
607 S 360 E
Salem, UT 84653
[email protected]

© 2026 chERP OCD Home Terms of Service [email protected]