Privacy Policy

Last updated 11 June 2026.

This Privacy Policy explains how Linea processes personal data. It covers the Linea website, public therapist profiles, booking surface, limited client portal and private therapist workspace.

Linea is currently provided as an invitation-only beta service.

Linea is operated by the Linea Platform.

Privacy contact: [email protected]. Support: [email protected].

1. Our roles

Linea has different roles depending on the processing activity.

1.1 When Linea acts as controller

Linea acts as controller for data needed to operate our own service relationship, including therapist-account registration, authentication, subscription administration, service security, legal compliance and minimal website analytics where enabled.

1.2 When Linea acts as processor for therapists

Each therapist determines why and how their clients' personal data is used in connection with their practice. For client records, bookings, appointment history, intake answers, clinical-vault content and related operational data, the therapist generally acts as controller and Linea processes the data on the therapist's documented instructions as processor. This relationship is governed by the DPA.

A therapist's client should normally contact the therapist first to exercise rights concerning therapy records. Linea will support the therapist and route direct requests where appropriate.

2. Data we process

2.1 Therapist account and professional profile

We may process:

  • name, email address, password hash and authentication information;
  • business and billing information;
  • public-profile content, such as biography, services, languages, modalities, availability, pricing, photo, professional credentials and uploaded diplomas;
  • calendar settings and optional Google-integration data;
  • subscription tier and limited Stripe identifiers; and
  • communications with support.

2.2 Client and booking data processed for therapists

Depending on enabled features, Linea may process:

  • client name, email, phone number and emergency contact;
  • booking requests, appointment times, status, service and rescheduling or cancellation history;
  • consent version, timestamp and limited technical evidence;
  • client-portal authentication data;
  • intake answers where enabled;
  • therapist-entered payment metadata relating to a session, but not card or online-banking credentials;
  • tags, timestamps and other structural metadata; and
  • clinical-vault content described below.

2.3 Technical and security data

We may process IP address, browser and device information, authentication events, session information, request identifiers, security events, audit actions and logs required to secure and operate the service. Sensitive fields are designed to be removed from application logs.

3. Two independent encryption models

Linea does not describe the entire service as “zero knowledge”. The system uses two distinct protection layers.

3.1 Clinical vault: browser-only end-to-end encryption

The following content is encrypted in the therapist's browser before it is transmitted to Linea:

  • session-note bodies;
  • note titles and risk levels;
  • therapy-goal descriptions;
  • client core profiles; and
  • clinical formulations.

The browser encrypts this content using a master key. The server stores ciphertext and wrapped key material, but does not receive the plaintext master key, vault passphrase or recovery words. Linea cannot decrypt this clinical-vault content.

If a therapist loses both the vault passphrase and every valid recovery method, the clinical-vault content becomes permanently inaccessible. Linea cannot restore it.

3.2 Operational client data: server-side field encryption

Other information required to operate the service is protected using server-side encryption and access controls. This includes client contact data and intake answers where enabled. The API can decrypt this information where necessary to provide the service, follow the therapist's instructions, maintain security or comply with law.

Some structural data remains readable by the server, including appointment timestamps and statuses, selected service, tags, audit-event types and timestamps. Therapists must not place clinical facts in plaintext tag fields.

4. Why we process personal data

Where Linea acts as controller, our main purposes and likely legal bases are:

PurposeDataLikely legal basis under GDPR
Create and operate therapist accountsAccount and authentication dataContract — Article 6(1)(b)
Administer subscriptions and invoicesBilling data and limited Stripe identifiersContract and legal obligations — Articles 6(1)(b), 6(1)(c)
Maintain security, prevent abuse and troubleshootTechnical logs, IP, audit eventsLegitimate interests — Article 6(1)(f)
Respond to legal requestsRelevant recordsLegal obligations — Article 6(1)(c)
Measure public-site usage, if Plausible is enabledMinimal cookieless pageview dataLegitimate interests — Article 6(1)(f)

Where Linea acts as processor, the therapist is responsible for selecting and documenting the applicable Article 6 basis and, where health data is involved, an applicable Article 9 condition. Depending on the therapist's practice and applicable law, this may involve explicit consent or a healthcare-related condition. Linea does not determine that basis for the therapist.

5. Special-category data

Client intake answers, clinical notes, risk assessments, therapy goals and formulations may reveal mental-health information and therefore may be special-category data under Article 9 GDPR. Clinical-vault content receives browser-only end-to-end encryption. Intake answers are server-readable where enabled and receive server-side encryption and access controls.

6. Public therapist profiles and booking surface

Public therapist profiles are intentionally public. Profile visitors can view the information the therapist has chosen to publish.

When a client uses a booking or client-portal feature, Linea processes the submitted data on behalf of the selected therapist. A short client-facing notice is displayed near the collection point and links to further information.

Do not submit emergency information through Linea. A client who needs urgent help should use the emergency channels applicable in their location.

7. Minors

Linea is a business service for adult therapists. A therapist may use Linea in connection with a minor only where the therapist has determined that doing so is lawful, appropriate and consistent with professional obligations, including any requirements concerning a parent, guardian or representative.

8. Recipients and service providers

Linea limits disclosure to what is reasonably necessary. Depending on enabled features, recipients may include:

  • Fly.io for application hosting (EU region, Frankfurt);
  • Neon for the managed PostgreSQL database (EU region);
  • Cloudflare for edge security, TLS termination, abuse protection and object storage for avatars and credential documents (EU jurisdiction);
  • Resend for outbound transactional email (see Section 9);
  • Stripe for international subscription billing, and monobank for subscription payments by therapists in Ukraine;
  • Plausible for optional cookieless analytics on public pages only;
  • Google where the therapist enables Google sign-in or Calendar integration; when automatic meeting links are turned on, Google Meet provides the video room for those online sessions on the therapist's Google account; and
  • professional advisers or authorities where required by law.

Optional providers are used only when enabled.

9. International transfers

Linea is designed around EU-hosted infrastructure where available. Some providers may operate globally or process limited data outside the European Economic Area. Where GDPR requires safeguards for a transfer, Linea will rely on an available lawful transfer mechanism, such as an adequacy decision or standard contractual clauses, and apply additional measures where appropriate.

One deliberate exception is documented: our transactional email provider, Resend, sends from the EU but stores email content, addresses and delivery logs in the United States under standard contractual clauses. Emails are kept minimal for this reason — booking and appointment emails never contain session-note content or intake answers.

10. Retention and deletion

The current beta retention settings are listed below.

Data categoryRetention or deletion rule
Account closureAccess deactivated promptly; sessions revoked; public profile unpublished
Clinical vault on account deletionWrapped vault-key material cryptographically destroyed within 24 hours; vault ciphertext becomes inaccessible
Operational client data on account deletionDeleted, zeroed or anonymised through the account-erasure process
Soft-deleted notesEncrypted payload and summary zeroed after 30 days
Rejected or cancelled booking requests and linked intake answersDeleted after 30 days
Expired and revoked refresh tokensDeleted after 30 days
Expired OTP or magic-link sessionsDeleted after 7 days
Audit logs24 months by beta default
Infrastructure logsFinite retention; 30-day default
Database backupsPoint-in-time recovery window of up to 7 days

A tombstone mechanism is designed to prevent deleted clinical-vault key material from being revived by restoring an older database backup.

Some limited records may be retained where required for security, legal compliance, billing or the establishment, exercise or defence of claims. Where possible, retained records are minimised or anonymised.

11. Your rights

Subject to applicable law, individuals may have rights to access, correct, delete, restrict or object to processing, receive portable data and complain to a supervisory authority.

Therapists can use export functions for their account data and browser-side vault content. Before account deletion, export any records you need to retain. Account deletion is designed to be irreversible for clinical-vault content after key destruction.

Clients should normally contact their therapist for requests involving therapy records. They may also contact [email protected], and Linea will route or assist with the request as appropriate. During beta, individual-client erasure may be handled through an operator-assisted workflow.

For processing for which Linea acts as controller, you may contact [email protected] directly.

The supervisory authority for Linea's Poland-based operator is the President of the Personal Data Protection Office (UODO). Depending on your location, you may also have the right to complain to another competent authority.

12. Cookies and analytics

Linea uses technically necessary cookies or similar storage for authentication, session security and CSRF protection.

If enabled, Plausible is used only for minimal, cookieless analytics on marketing and public pages. Plausible is not loaded in the private therapist workspace. Linea may also count a small number of anonymous, server-side product events, such as that an account was created or a booking page was published; these counters contain no names, no email or IP addresses and no client data. Linea does not use session replay, advertising trackers or behavioural profiling.

13. Security

Linea uses measures designed for the sensitivity of the data, including browser-only end-to-end encryption for clinical-vault content, server-side field encryption for operational client data, TLS in transit, password hashing, tenant isolation, access controls, security logging, data minimisation and deletion workflows.

Security also depends on production configuration, including database encryption at rest, encrypted backups, EU-region settings, platform secret management, finite log retention, operator MFA and backup-restoration testing.

No system can guarantee absolute security. Contact [email protected] if you suspect a personal-data incident.

14. Changes

We may update this Privacy Policy to reflect changes in the product, law or service providers. We will publish the current version and effective date and provide additional notice where required.

15. Contact

Privacy and data-protection questions: [email protected] General support: [email protected]

    Privacy Policy · Linea