Privacy Policy
Effective 1 October 2026 · Last updated 28 September 2026
This policy explains what chERP OCD (“chERP”, “we”, “us”) collects through this website and the chERP app, why, and who we share it with.
The short version
- This website sets analytics cookies only if you say yes in the cookie banner. The chERP app has no analytics at all.
- Client health information belongs to the practice that entered it. We hold it for them under a Business Associate Agreement and HIPAA.
- We don’t sell personal information, use it for advertising, or use client information to train AI.
- If you’re a client with a question about your records, ask your practice first. They decide who sees them.
1. Two kinds of information
Client health information. Practices use chERP to keep their clients’ clinical records. That information belongs to the practice. We handle it only on the practice’s behalf, as its business associate under HIPAA. Section 2 covers it.
Everything else. This covers people who visit this website, write to us or book a demo and the practice staff who hold chERP accounts. We’re responsible for this information ourselves. The rest of this policy covers it.
2. Client health information
Before a practice enters any client information, it signs a Business Associate Agreement (BAA) with us. That agreement, HIPAA, and the practice’s own Notice of Privacy Practices govern what happens to it. In short:
- We use it only to run chERP for that practice, to keep it secure, and as the law requires.
- We don’t sell it, use it for marketing, or use it for analytics, research, product development or training AI models without the practice’s written permission.
- Each practice’s records are kept separate from every other practice’s.
- Inside a practice, clinicians see only their own clients, unless the practice has set up supervision or group access. Every look at a chart is recorded in an audit log.
- Our own staff don’t browse client records. If we ever need to see one to fix a problem, it happens at the practice’s request, and it’s logged.
If you’re a client: requests to see, correct or get a copy of your records go to your practice, which decides how to respond. If you contact us, we’ll pass your request to your practice and help them answer it.
3. This website
- Analytics. This website uses Google Analytics, loaded through Google Tag Manager, to count visits and see which pages help practices decide. Both load on every page of this website.
- Before you choose, or if you decline. No analytics cookies are set and nothing is stored on your device. Google still receives basic signals without cookies, such as that a page was loaded, which it uses to estimate traffic.
- If you choose “Accept”. Google Analytics sets cookies (section 7) so it can tell a returning visit from a new one. It collects the pages you view, the page you came from, your device and browser type, and your approximate location (city level). Google Analytics doesn’t log or store IP addresses.
- No advertising. Advertising signals stay switched off whatever you choose, and there are no ad pixels on this site.
- Never in the app. Neither tool runs anywhere in the chERP app, where practices and clients sign in.
- Hosting. The site is served by Cloudflare. Like any web host, Cloudflare processes basic request data such as your IP address and browser type to deliver pages and block attacks.
- Fonts. Our typefaces load from Google Fonts, here and in the chERP app, so your browser sends your IP address and browser type to Google when it fetches them.
- Email. If you email us, for example to book a demo, we keep your message and contact details to reply and follow up.
The “Time saved” calculator runs entirely in your browser. The numbers you enter aren’t sent anywhere.
4. Using the chERP app
For practice staff with accounts, we collect:
- Account details: name, work email, role and practice. If you sign in with Google, we receive your name and email address from Google.
- Sign-in security: a securely hashed version of your password (we never store the password itself), and your second step: the secret for your authenticator app, a passkey, or both. For a passkey we keep only its public key, an ID, the name you gave it, the kind of device it’s on, and when it was added and last used. The private key never leaves your device. Recovery codes are stored hashed.
- Activity: an audit log of sign-ins and of what each account viewed and changed, with times. This is how practices and HIPAA auditors see who did what.
- Technical data: IP address, browser and error logs, used to run and secure the service. Our logs are built to leave out client health information and sign-in links. When we find something in them that shouldn’t be there, we fix the logging, and logs age out after 30 days (section 9).
- Billing details: who to send the practice’s subscription payment link to, and a record of what it has paid. Card details are entered on Stripe’s payment page; we never see or store them.
For clients the practice invites to the portal, we store their name, email address, a hashed password (or, if they choose to sign in with Google, the name and email Google confirms) and what they enter in homework, check-ins and forms. All of this is client health information and is covered by section 2.
Email to clients
If a practice turns it on, chERP emails clients appointment reminders and links to intake forms. A reminder names the client, their clinician, the practice and the appointment time. These are ordinary emails. They aren’t encrypted end to end, and once one reaches a client’s inbox, anyone who can open that inbox can read it. The name of a therapy practice can itself say something about a person’s care.
So chERP sends these emails only to clients whose practice has switched them on for that client. Practices should get the client’s informed consent first. Practice staff record that consent in chERP, which notes who recorded it and when, and they can turn it off at any time.
Asking about becoming a client
The chERP sign-in page has a form, “Ask about becoming a client”, for people who’d like to be seen by a practice that uses chERP. It asks for your name and email address and, if you like, a phone number and what brings you here. We also record the IP address the form was sent from.
- If only one practice uses chERP, your inquiry goes straight to it. If there are several, chERP staff read it only to send it to the right practice.
- Once a practice has it, the practice decides how to respond. If it takes you on, your inquiry becomes part of your record there, covered by section 2.
- Please keep the note short. The practice will ask for anything else it needs.
5. How we use information
- To provide chERP: create accounts, sign people in, send appointment reminders and form links, pass inquiries to practices, and take practices’ subscription payments
- To keep chERP and its users secure, and to detect and investigate misuse
- To answer questions and give support
- To send practices service and billing notices. We don’t send marketing email to clients, ever.
- To meet our legal obligations, and to enforce our Terms of Service
We don’t sell personal information or share it for targeted advertising.
6. Who we share it with
We use a small number of service providers. Each one may use information only to provide its service to us. This is the complete list. The two that store or send client health information do so under a Business Associate Agreement with us.
- Google Cloud: runs the chERP app and client portal, their database, backups and server logs. Handles client health information, under a BAA (accepted 17 September 2026).
- Google Workspace (Gmail): sends appointment reminders and intake form links to clients, from [email protected], and keeps a copy of each in that mailbox. Handles client health information, under a BAA.
- Google sign-in: optional, for staff and clients who choose “Sign in with Google”. Google confirms who you are and gives us your name and email address. Google learns that you signed in to chERP, but receives no records from it. No client records; we don’t rely on a BAA for it. You can sign in with a password instead.
- Google Fonts: supplies the typefaces for this website and the chERP app. Your browser sends Google its IP address and browser type when it loads them. No client records; no BAA.
- Google Analytics and Google Tag Manager: analytics for this website only (section 3). No health information; no BAA needed.
- Stripe: takes practices’ subscription payments through the payment links we send. It receives the practice’s billing contact and card details, and never any client or health information. No health information; no BAA needed.
- Cloudflare: hosts this website, www.cherpocd.com, on Cloudflare Pages. No health information; it doesn’t handle the app.
Otherwise, we disclose information only:
- to the practice it belongs to
- when the law requires it, such as a valid subpoena or court order. Where we’re allowed to, we’ll tell the practice first.
- to protect someone’s safety, or the security of chERP
- to a successor if our business is merged or sold. The successor has to honor this policy and every BAA we’ve signed.
7. Cookies
This website sets cookies only if you choose “Accept” in the cookie banner: two Google Analytics cookies, _ga and _ga_TP1NBT1QJ3, which last up to two years. If you choose “Decline”, none are set. Your choice itself is saved in your browser’s storage, not in a cookie. You can change it any time with “Cookie settings” at the bottom of each page, or clear it in your browser.
The chERP app uses only the cookies it needs to keep you signed in. We don’t use them for tracking or advertising.
sid, for staff: lasts at most 12 hours. The session behind it ends sooner, after 30 minutes without activity or when you sign out.pid, for the client portal: lasts at most 8 hours. The session ends sooner, after 20 minutes without activity or when you sign out.oauth, during Google sign-in only: lasts at most 10 minutes, and is deleted as soon as sign-in finishes.
8. How we protect it
- Two-step sign-in is required for every staff account
- Data is encrypted in transit (TLS) and at rest (AES-256)
- Access is limited by role and caseload, and every chart view is logged in an audit log that shows any tampering
- Sessions time out after inactivity
- Backups are taken automatically every day. We’ve tested that they restore, and our policy is to repeat that test every quarter
No system is perfectly secure. If there’s a breach of unsecured client health information, we tell the practice without unreasonable delay, and no later than 30 calendar days after we discover it. The practice then notifies affected clients, and others, as the law requires of it. If a breach affects other personal information we hold, we notify people as the law requires.
9. How long we keep it
- Client records stay in chERP for as long as the practice is a customer, following the practice’s instructions, because they’re legal clinical records the practice must keep. chERP archives records rather than deleting them. When a practice leaves, it can export its data for 30 days. We then return or destroy it as the BAA sets out.
- Backups age out automatically after 30 days, so deleted data can remain in encrypted backups for up to 30 days.
- Audit logs and compliance records are kept for at least six years, as HIPAA requires. We never delete audit log entries to save space.
- Server logs are kept for 30 days, then deleted automatically. Google keeps its own record of administrative changes to our cloud account for 400 days.
- Staff accounts are switched off, not deleted, when a practice removes someone, so the audit log can still show who did what.
- Inquiries sent through “Ask about becoming a client”, including ones a practice declines, are kept until they’re deleted. We don’t yet delete them automatically. If yours didn’t lead to care, you can ask us to delete it.
- Emails chERP sends to clients are kept in the sending Google Workspace mailbox until they’re deleted. We don’t yet delete them automatically.
- Emails and demo requests you send us are kept as long as we have a reason to follow up, then deleted.
10. Your choices and rights
Practice staff and website visitors can ask us to show, correct or delete personal information we hold about them. Write to [email protected], and we’ll reply within 30 days. Depending on where you live, you may have more rights under state law. We’ll honor them, and we won’t treat you differently for using them.
Some things can’t be deleted. We can’t delete audit log entries, because they’re a legal record of who accessed what. And we can’t delete a practice’s clinical records on an individual’s request; the practice decides what happens to them.
To stop website analytics, choose “Cookie settings” at the bottom of any page and then “Decline”.
Clients: see section 2. Your practice is the right first contact.
11. Children and teens
This website isn’t aimed at children. Practices that treat children and teens may invite them, or their parents or guardians, to the client portal. The practice decides who is invited and handles consent under the laws that apply to it. Information about minors is client health information, covered by section 2.
12. Changes to this policy
If we make a material change, we’ll update the date at the top and email practices at least 30 days before it takes effect. We won’t use information we already hold in a materially different way without the consent the law requires.
13. Contact
Questions about privacy, or a request about your information:
chERP OCD
607 S 360 E
Salem, UT 84653
[email protected]