Terms of Service
Effective 1 October 2026 · Last updated 28 September 2026
These terms are an agreement between chERP OCD (“chERP”, “we”, “us”) and the therapy practice that subscribes to chERP (“the practice”, “you”). They also cover the practice’s staff and clients when they use chERP. By subscribing, signing in or using chERP, you agree to them. If you’re accepting for a practice, you’re confirming you have authority to bind it.
The short version
- Your practice owns its records. We hold them to run chERP for you, and for nothing else.
- We sign a Business Associate Agreement (BAA) with you before any client information goes in.
- chERP is a record-keeping tool. Clinical decisions, and what goes in a signed note, stay with your clinicians.
- You can export your data at any time, and for 30 days after you leave, at no charge.
- chERP is not an emergency service. A client in crisis should call or text 988, or 911.
1. The service
chERP is web-based clinical record software for practices that provide exposure and response prevention (ERP) therapy. It includes the clinician app, a client portal for homework, check-ins and forms, and email appointment reminders. chERP doesn’t bill your clients, take payments from them or process insurance claims.
2. Client health information and the BAA
When your practice puts client health information into chERP, we handle it as your business associate under HIPAA. Before any of it goes in, you and we sign a Business Associate Agreement. chERP won’t let a practice create client records until that agreement is on file.
The BAA governs how we use, protect and disclose protected health information. If it conflicts with these terms on anything to do with that information, the BAA wins.
If there’s a breach of unsecured client health information, we tell your practice without unreasonable delay, and no later than 30 calendar days after we discover it. Your practice’s own duties to notify clients, HHS and others stay as the law sets them.
3. Accounts and access
- Staff accounts are by invitation only. Each person gets their own account; accounts can’t be shared.
- Staff sign in with a password or Google, and then a second step: a code from an authenticator app, or a passkey.
- Clients sign in to the portal with a password, or with Google if they prefer.
- Your practice decides who is invited, what role they have, and when their access ends. Remove people promptly when they leave.
- You’re responsible for what happens under your practice’s accounts. Tell us right away at [email protected] if you think an account has been used without permission.
4. Your responsibilities
Using software that supports HIPAA doesn’t make a practice compliant on its own. Your practice remains responsible for:
- Its own HIPAA risk analysis, policies, workforce training and sanctions
- Getting any consents or authorizations your clients need to give, including for portal use
- Getting each client’s informed consent before you turn on email for them, and recording it in chERP. Reminders and form links are ordinary email, not encrypted end to end, and they name the client, the clinician and your practice
- Giving clients your Notice of Privacy Practices and responding to their requests to see, correct or get an accounting of their records
- Reviewing your own staff’s activity. chERP keeps an audit log; we don’t watch your staff for you
- Securing your devices, screens and premises
- Following the laws that apply to your practice and your clinicians’ licenses, including state rules on record retention and on minors’ records
5. Clinical judgment
chERP helps you keep records. It doesn’t diagnose, recommend treatment or give medical advice. Where chERP drafts a note from what was captured in a session, the clinician reviews it, writes the assessment and signs it. The signed note is the clinician’s record, and the clinician is responsible for its content.
6. Acceptable use
You agree not to:
- Use chERP for anything unlawful, or to store information you have no right to hold
- Try to reach another practice’s data, or any record your role doesn’t give you access to
- Probe, scan or test chERP’s security without our written permission
- Interfere with or overload the service, or get around its limits or access controls
- Copy, resell or reverse-engineer chERP, or use it to build a competing product
- Upload malicious code
If you think you’ve found a security problem, tell us at [email protected]. We’re glad to hear it.
7. Fees and payment
- chERP costs $59 per clinician per month, billed yearly in advance. People who only co-sign notes aren’t counted as clinicians.
- We send your practice a Stripe payment link for each invoice, and you pay through Stripe’s payment page. Stripe processes the payment under its own terms. We never see or store full card numbers, and Stripe never receives client or health information.
- If you add clinicians during the year, we bill for them from the date they’re added until the end of your current year.
- Prices don’t include taxes. You’re responsible for any sales or similar taxes that apply.
- We’ll give you at least 30 days’ notice before any price change, and it takes effect at your next renewal.
- If a payment is more than 30 days late, we may suspend access after telling you in writing. Suspension never deletes your data, and you can still export it.
- Fees you’ve paid aren’t refundable, except where these terms or the law say otherwise.
8. Your data
Your practice owns everything it and its clients put into chERP. You give us permission to host, copy, process and display it only as needed to provide chERP to you, to keep it secure, and as the BAA and the law allow.
We don’t sell your data or use it for advertising. We don’t use your clients’ information for analytics, research, product development or training AI models without your separate written permission.
Our Privacy Policy explains what we collect and how we use it.
9. Ending your subscription
- Your subscription runs for a year and renews for another year unless either of us gives notice at least 30 days before renewal.
- Either of us may end the agreement if the other seriously breaks it and doesn’t fix it within 30 days of written notice.
- We may suspend an account right away if we need to, to stop a security threat or unlawful use. We’ll tell you why as soon as we can.
- You can export your practice’s data in a documented, machine-readable format at any time, and for 30 days after the agreement ends, at no charge.
- After that, we return or destroy your data as the BAA sets out. Deleted data stays in our encrypted backups for up to 30 more days before it ages out. We keep our audit and compliance records for as long as the law requires.
10. Our property
chERP, including its software, design and documentation, belongs to us. These terms give you the right to use it while your subscription is active. They don’t transfer ownership of it. If you send us suggestions or feedback, we may use them freely, without owing you anything.
11. Confidentiality
Each of us will keep the other’s non-public business information confidential and use it only for this agreement. This doesn’t cover information that is already public, that the recipient already had or developed independently, or that must be disclosed by law. Client health information is covered by the BAA, not this section.
12. Availability and changes
Uptime
We aim to keep the clinician app and the client portal available at least 99% of the time in each calendar month. That allows for about 7 hours of downtime in a month.
These don’t count as downtime:
- Scheduled maintenance we’ve told you about at least 48 hours ahead. We schedule it outside 8am to 6pm Mountain Time on weekdays wherever we can.
- Urgent work to fix a security problem, where waiting would put records at risk. We’ll tell you as soon as we can.
- Problems with your own devices, internet connection or email, or with services you choose to use alongside chERP.
- Events outside reasonable control (section 17), and any suspension under these terms.
This website (www.cherpocd.com) isn’t covered. If we miss the target in a month, tell us, and we’ll explain what happened and what we’re changing. There are no service credits.
Changes to chERP
We may improve and change chERP over time. We won’t remove anything that materially reduces the core record-keeping, security or export features during your paid term.
13. Warranties
We’ll provide chERP with reasonable skill and care, and with the safeguards described in the BAA.
Apart from that, and to the extent the law allows, chERP is provided “as is”. We disclaim all other warranties, express or implied, including merchantability, fitness for a particular purpose and non-infringement. We don’t promise that chERP will be error-free, or that it alone makes your practice compliant with any law.
14. Limits of liability
To the extent the law allows, neither of us is liable to the other for indirect, incidental, special, consequential or punitive damages, or for lost profits or revenue, even if we were told they were possible. Each party’s total liability arising out of this agreement is limited to the fees the practice paid for chERP in the 12 months before the event that gave rise to the claim.
These limits don’t apply to your obligation to pay fees, to either party’s indemnity obligations, or to liability that the law doesn’t allow to be limited. Liability for breaches of the BAA is set by the BAA.
15. Indemnity
We’ll defend you against a third-party claim that chERP, used as permitted, infringes their intellectual property, and pay any resulting damages or settlement we agree to.
You’ll defend us against a third-party claim arising from the information your practice puts into chERP, from your clinical services, or from your use of chERP in breach of these terms, and pay any resulting damages or settlement you agree to.
The party asking for defense must tell the other promptly, let them control the defense, and cooperate reasonably.
16. If you’re a client using the portal
Your practice invites you to the chERP portal so you can do homework, check-ins and forms between sessions. Your relationship is with your practice and your clinician, not with us. Questions about your care or your records go to them. The practice decides what you can see in the portal.
Please keep your password, and any links your practice sends you, to yourself, and only enter information about yourself.
If you agree to email reminders, remember they’re ordinary email. Anyone who can open your inbox can read them. You can ask your practice to stop them at any time.
The portal isn’t monitored in real time. Nobody may see what you enter until your next session. If you’re in crisis or thinking about hurting yourself, call or text 988 (the Suicide & Crisis Lifeline), or call 911.
17. General terms
- Changes to these terms. We’ll give practices at least 30 days’ notice by email of any material change. If you don’t agree, you can end your subscription before the change takes effect, and we’ll refund any prepaid fees for the unused part of your term.
- Governing law. These terms are governed by the laws of the State of Utah, without regard to conflict-of-laws rules. Disputes go to the state or federal courts for Utah County, Utah.
- Assignment. Neither of us may transfer this agreement without the other’s consent, except to a successor in a merger or sale of substantially all the business, who takes on these terms and the BAA.
- Things outside our control. Neither of us is responsible for delays caused by events beyond reasonable control, such as a major cloud provider outage, natural disaster or war. This doesn’t excuse payment.
- Entire agreement. These terms, the BAA and any signed order form are the whole agreement between us. If a signed order form conflicts with these terms, the order form wins.
- Severability and waiver. If part of these terms can’t be enforced, the rest still applies. Not enforcing a term right away doesn’t mean giving it up.
- Notices. We send notices to the email address on your practice’s account. You send them to [email protected].
18. Contact
chERP OCD
607 S 360 E
Salem, UT 84653
[email protected]