Privacy Policy
Last updated 11 June 2026.
This Privacy Policy explains how Linea processes personal data. It covers the Linea website, public therapist profiles, booking surface, limited client portal and private therapist workspace.
Linea is currently provided as an invitation-only beta service.
Linea is operated by the Linea Platform.
Privacy contact: [email protected]. Support: [email protected].
1. Our roles
Linea has different roles depending on the processing activity.
1.1 When Linea acts as controller
Linea acts as controller for data needed to operate our own service relationship, including therapist-account registration, authentication, subscription administration, service security, legal compliance and minimal website analytics where enabled.
1.2 When Linea acts as processor for therapists
Each therapist determines why and how their clients' personal data is used in connection with their practice. For client records, bookings, appointment history, intake answers, clinical-vault content and related operational data, the therapist generally acts as controller and Linea processes the data on the therapist's documented instructions as processor. This relationship is governed by the DPA.
A therapist's client should normally contact the therapist first to exercise rights concerning therapy records. Linea will support the therapist and route direct requests where appropriate.
2. Data we process
2.1 Therapist account and professional profile
We may process:
- name, email address, password hash and authentication information;
- business and billing information;
- public-profile content, such as biography, services, languages, modalities, availability, pricing, photo, professional credentials and uploaded diplomas;
- calendar settings and optional Google-integration data;
- subscription tier and limited Stripe identifiers; and
- communications with support.
2.2 Client and booking data processed for therapists
Depending on enabled features, Linea may process:
- client name, email, phone number and emergency contact;
- booking requests, appointment times, status, service and rescheduling or cancellation history;
- consent version, timestamp and limited technical evidence;
- client-portal authentication data;
- intake answers where enabled;
- therapist-entered payment metadata relating to a session, but not card or online-banking credentials;
- tags, timestamps and other structural metadata; and
- clinical-vault content described below.
2.3 Technical and security data
We may process IP address, browser and device information, authentication events, session information, request identifiers, security events, audit actions and logs required to secure and operate the service. Sensitive fields are designed to be removed from application logs.
3. Two independent encryption models
Linea does not describe the entire service as “zero knowledge”. The system uses two distinct protection layers.
3.1 Clinical vault: browser-only end-to-end encryption
The following content is encrypted in the therapist's browser before it is transmitted to Linea:
- session-note bodies;
- note titles and risk levels;
- therapy-goal descriptions;
- client core profiles; and
- clinical formulations.
The browser encrypts this content using a master key. The server stores ciphertext and wrapped key material, but does not receive the plaintext master key, vault passphrase or recovery words. Linea cannot decrypt this clinical-vault content.
If a therapist loses both the vault passphrase and every valid recovery method, the clinical-vault content becomes permanently inaccessible. Linea cannot restore it.
3.2 Operational client data: server-side field encryption
Other information required to operate the service is protected using server-side encryption and access controls. This includes client contact data and intake answers where enabled. The API can decrypt this information where necessary to provide the service, follow the therapist's instructions, maintain security or comply with law.
Some structural data remains readable by the server, including appointment timestamps and statuses, selected service, tags, audit-event types and timestamps. Therapists must not place clinical facts in plaintext tag fields.
4. Why we process personal data
Where Linea acts as controller, our main purposes and likely legal bases are:
| Purpose | Data | Likely legal basis under GDPR |
|---|---|---|
| Create and operate therapist accounts | Account and authentication data | Contract — Article 6(1)(b) |
| Administer subscriptions and invoices | Billing data and limited Stripe identifiers | Contract and legal obligations — Articles 6(1)(b), 6(1)(c) |
| Maintain security, prevent abuse and troubleshoot | Technical logs, IP, audit events | Legitimate interests — Article 6(1)(f) |
| Respond to legal requests | Relevant records | Legal obligations — Article 6(1)(c) |
| Measure public-site usage, if Plausible is enabled | Minimal cookieless pageview data | Legitimate interests — Article 6(1)(f) |
Where Linea acts as processor, the therapist is responsible for selecting and documenting the applicable Article 6 basis and, where health data is involved, an applicable Article 9 condition. Depending on the therapist's practice and applicable law, this may involve explicit consent or a healthcare-related condition. Linea does not determine that basis for the therapist.
5. Special-category data
Client intake answers, clinical notes, risk assessments, therapy goals and formulations may reveal mental-health information and therefore may be special-category data under Article 9 GDPR. Clinical-vault content receives browser-only end-to-end encryption. Intake answers are server-readable where enabled and receive server-side encryption and access controls.
6. Public therapist profiles and booking surface
Public therapist profiles are intentionally public. Profile visitors can view the information the therapist has chosen to publish.
When a client uses a booking or client-portal feature, Linea processes the submitted data on behalf of the selected therapist. A short client-facing notice is displayed near the collection point and links to further information.
Do not submit emergency information through Linea. A client who needs urgent help should use the emergency channels applicable in their location.
7. Minors
Linea is a business service for adult therapists. A therapist may use Linea in connection with a minor only where the therapist has determined that doing so is lawful, appropriate and consistent with professional obligations, including any requirements concerning a parent, guardian or representative.
8. Recipients and service providers
Linea limits disclosure to what is reasonably necessary. Depending on enabled features, recipients may include:
- Fly.io for application hosting (EU region, Frankfurt);
- Neon for the managed PostgreSQL database (EU region);
- Cloudflare for edge security, TLS termination, abuse protection and object storage for avatars and credential documents (EU jurisdiction);
- Resend for outbound transactional email (see Section 9);
- Stripe for international subscription billing, and monobank for subscription payments by therapists in Ukraine;
- Plausible for optional cookieless analytics on public pages only;
- Google where the therapist enables Google sign-in or Calendar integration; when automatic meeting links are turned on, Google Meet provides the video room for those online sessions on the therapist's Google account; and
- professional advisers or authorities where required by law.
Optional providers are used only when enabled.
9. International transfers
Linea is designed around EU-hosted infrastructure where available. Some providers may operate globally or process limited data outside the European Economic Area. Where GDPR requires safeguards for a transfer, Linea will rely on an available lawful transfer mechanism, such as an adequacy decision or standard contractual clauses, and apply additional measures where appropriate.
One deliberate exception is documented: our transactional email provider, Resend, sends from the EU but stores email content, addresses and delivery logs in the United States under standard contractual clauses. Emails are kept minimal for this reason — booking and appointment emails never contain session-note content or intake answers.
10. Retention and deletion
The current beta retention settings are listed below.
| Data category | Retention or deletion rule |
|---|---|
| Account closure | Access deactivated promptly; sessions revoked; public profile unpublished |
| Clinical vault on account deletion | Wrapped vault-key material cryptographically destroyed within 24 hours; vault ciphertext becomes inaccessible |
| Operational client data on account deletion | Deleted, zeroed or anonymised through the account-erasure process |
| Soft-deleted notes | Encrypted payload and summary zeroed after 30 days |
| Rejected or cancelled booking requests and linked intake answers | Deleted after 30 days |
| Expired and revoked refresh tokens | Deleted after 30 days |
| Expired OTP or magic-link sessions | Deleted after 7 days |
| Audit logs | 24 months by beta default |
| Infrastructure logs | Finite retention; 30-day default |
| Database backups | Point-in-time recovery window of up to 7 days |
A tombstone mechanism is designed to prevent deleted clinical-vault key material from being revived by restoring an older database backup.
Some limited records may be retained where required for security, legal compliance, billing or the establishment, exercise or defence of claims. Where possible, retained records are minimised or anonymised.
11. Your rights
Subject to applicable law, individuals may have rights to access, correct, delete, restrict or object to processing, receive portable data and complain to a supervisory authority.
Therapists can use export functions for their account data and browser-side vault content. Before account deletion, export any records you need to retain. Account deletion is designed to be irreversible for clinical-vault content after key destruction.
Clients should normally contact their therapist for requests involving therapy records. They may also contact [email protected], and Linea will route or assist with the request as appropriate. During beta, individual-client erasure may be handled through an operator-assisted workflow.
For processing for which Linea acts as controller, you may contact [email protected] directly.
The supervisory authority for Linea's Poland-based operator is the President of the Personal Data Protection Office (UODO). Depending on your location, you may also have the right to complain to another competent authority.
12. Cookies and analytics
Linea uses technically necessary cookies or similar storage for authentication, session security and CSRF protection.
If enabled, Plausible is used only for minimal, cookieless analytics on marketing and public pages. Plausible is not loaded in the private therapist workspace. Linea may also count a small number of anonymous, server-side product events, such as that an account was created or a booking page was published; these counters contain no names, no email or IP addresses and no client data. Linea does not use session replay, advertising trackers or behavioural profiling.
13. Security
Linea uses measures designed for the sensitivity of the data, including browser-only end-to-end encryption for clinical-vault content, server-side field encryption for operational client data, TLS in transit, password hashing, tenant isolation, access controls, security logging, data minimisation and deletion workflows.
Security also depends on production configuration, including database encryption at rest, encrypted backups, EU-region settings, platform secret management, finite log retention, operator MFA and backup-restoration testing.
No system can guarantee absolute security. Contact [email protected] if you suspect a personal-data incident.
14. Changes
We may update this Privacy Policy to reflect changes in the product, law or service providers. We will publish the current version and effective date and provide additional notice where required.
15. Contact
Privacy and data-protection questions: [email protected] General support: [email protected]