Privacy Policy

Capture (For Therapists) - Privacy Policy & Data Deletion

Last updated: May 2026

Overview

Capture is an offline-first practice management app for mental health professionals. All clinical data is stored locally on your device. There is no Capture-operated server holding client records. Optional encrypted backup to Google Drive or a local folder is the only way data leaves the device, and only by your explicit choice.

Information We Collect

Clinical data (stored locally only)

Everything you enter, including client profiles, case histories, follow-up sessions, treatment goals, assessments, attachments, payments, audio recordings, and exported PDFs, is stored in Capture’s private storage on your device. This data never leaves your device unless you explicitly choose to back it up. Capture has no server to send it to.

Optional encrypted backup

You may choose to back up your data to your own Google Drive or to a local folder on your device. If you do, the data is AES-256 encrypted on this device before being written. The encryption key is derived from a backup PIN that you set, separate from the device unlock that gates access to the app. Capture does not have a copy of your backup PIN. The encrypted file is stored at the destination you pick (Google Drive or a folder you select), not on any server controlled by the developer.

Anonymous usage analytics

Capture collects anonymous usage analytics (which features get used, app version, broad properties about your account) to help improve the app. Analytics never include client names, session content, case-history text, attachment contents, audio, or any identifying information. You can disable analytics at any time in Settings, “Help improve Capture”. Doing so immediately stops collection, deletes your analytics profile from the analytics provider, and clears locally stored analytics state.

Location data

Capture does not collect any location information.

Third-Party Access

No clinical data is shared with any third party. The only outbound traffic from Capture is anonymous usage analytics (described above), which can be disabled. If you opt into Google Drive backup, the encrypted file goes to your own Drive account and is governed by your relationship with Google, not Capture.

Security and HIPAA Alignment

Why we say “HIPAA-aligned” and not “HIPAA-compliant”

HIPAA compliance is achieved by a covered entity (the therapist’s practice), not by an app. An app can implement the technical safeguards that HIPAA’s Security Rule describes; it cannot deliver a Notice of Privacy Practices to a client on the therapist’s behalf, file a breach report with HHS, or sign a Business Associate Agreement with a third-party storage provider. Calling Capture “HIPAA-compliant” would imply that using the app, alone, satisfies HIPAA. It does not, and we do not claim that. “HIPAA-aligned” draws the line honestly: the technical foundation is in the app, the practice itself is yours to run.

What Capture implements

Capture implements the technical safeguards described in 45 CFR §164.312, supported by parts of §164.308 and §164.316:

What stays your responsibility

The administrative, organisational, and operational requirements of HIPAA cannot be implemented by an app. Capture provides templates for several of them under Settings, “HIPAA Documents”, but delivery, sign-off, and reporting are yours:

Why this matters when choosing a backup destination

Either choice is supported.

Audit Log

What gets logged

Every create, update, delete, view, export, backup, restore, wipe, authentication success, authentication failure, encryption-failure, retention-prune, acknowledge, and EULA-acceptance event is recorded. PDF disclosures additionally record the channel used to deliver the password (SMS, clipboard, or manual) and the recipient you entered when you choose to enter one, to give you the raw material for a §164.528 accounting of disclosures.

Where it lives

The audit log lives inside Capture’s AES-256 encrypted database on your device. It is not a separately tamper-proof log; it is encrypted at the same level as your clinical data.

How to export it

Automatic Logoff

Per §164.312(a)(2)(iii), Capture re-prompts for authentication after 15 minutes of inactivity in the foreground, and after the app has been backgrounded for 15 minutes. The threshold is the same in both directions.

Data Deletion

Delete individual records

Within the app, you can delete individual client profiles, follow-up sessions, treatment goals, assessments, and other records using the delete option on each record. Each deletion is logged in the activity log per §164.312(b).

Delete all app data

Settings, “Wipe All Data” requires a fresh biometric prompt. Before the wipe proceeds, Capture asks you to save a CSV copy of the activity log to a destination you pick (§164.316(b)(2)(i) six-year retention). When you confirm the wipe:

Uninstall

Uninstalling Capture removes all locally stored Capture data from your device.

Delete Google Drive backups

If you used the Google Drive backup option, your backup is in your own Google Drive account. To delete it, open Google Drive, locate the Capture backup file, and delete it. Capture does not retain any copy.

Delete local-folder backups

If you chose a local folder for backup, delete the file from that location using your phone’s file manager.

Disable and delete analytics data

Go to Settings, “Help improve Capture” and turn the toggle off. This will:

You can re-enable analytics at any time from the same setting.

No remote clinical data to delete

Capture does not transmit or store your clinical data on any server. There is no remote clinical data to request deletion of. All clinical data resides solely on your device and, if you chose to enable it, in the backup destination you control.

Changes

This policy may be updated from time to time. Changes will be posted on this page. Continued use of the app after changes are posted constitutes acceptance of the updated policy.

Contact

If you have questions about privacy or data deletion, contact us at reflections.dreams.memories@gmail.com.