Skip to main content
TherapyAlly
PracticeAllieChannelEarly accessFeaturesSolutionsPricingSecurity
Sign inBook a demo
PracticeAllieChannelEarly accessFeaturesSolutionsPricingSecurityBook a demo

TherapyAlly legal

TherapyAlly Privacy Policy

Effective date: August 29, 2026

Bethel Therapy LLC (“Bethel Therapy,” “Company,” “we,” “us,” or “our”) operates the TherapyAlly product family, including our public websites, TherapyAlly Practice, Allie by TherapyAlly, Channel by TherapyAlly, APIs, integrations, and client, guardian, and workforce portals (collectively, the “Services”).

This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information across the Services. It should be read with our Terms of Service and, where applicable, a customer agreement and Business Associate Agreement (“BAA”).

In this policy
  1. Our role and HIPAA
  2. Information we collect
  3. How we use information
  4. How we disclose information
  5. Allie and AI processing
  6. Security and retention
  7. Rights and choices
  8. Minors and guardians
  9. Third-party services
  10. Changes and contact

1. Our role and HIPAA

1.1 When we act as a business associate

A healthcare practice may use TherapyAlly to process identifiable health information on behalf of the practice. When Bethel Therapy LLC performs a function involving Protected Health Information (“PHI”) for a practice that is a HIPAA Covered Entity, we act as its Business Associate as described in the applicable BAA and HIPAA. The practice remains responsible for the clinical record and for responding to most client or patient rights requests concerning that record.

Information is PHI only when it meets the legal definition and is maintained or transmitted by a Covered Entity or Business Associate. If this Policy conflicts with an executed BAA regarding PHI, the BAA controls.

1.2 Information we handle for our own purposes

We also process information outside our Business Associate role, including public-website activity, demo requests, business contact details, account administration, subscription records, and general service analytics. This Policy governs that information directly.

2. Information we collect

2.1 Account, practice, and professional information

We collect names, business and email addresses, phone numbers, job titles, practice affiliations, roles, professional identifiers and credentials, identity-provider details, account preferences, and other information supplied during registration, onboarding, or company setup.

2.2 Client, clinical, scheduling, and insurance information

At a practice’s direction, the Services may process client and guardian demographics, contact information, intake forms, appointments, attendance, locations, plans of care, goals, session and progress notes, signatures, provider assignments, insurance coverage, member identifiers, eligibility responses, claims, fee schedules, remittances, and related clinical or billing information. This information may be PHI.

2.3 Payments and workforce information

Payment providers collect payment-card, bank, identity-verification, and payout information under their own terms. TherapyAlly generally receives limited transaction, status, account-readiness, and reconciliation information rather than complete payment credentials. Practice Complete may also process payable activity, time review, supervision, approvals, exceptions, and payroll-export information.

2.4 Communications and support

We collect information submitted through demo and support forms, emails, surveys, feedback, and other communications. When Channel features are enabled, we may process messages, participant identifiers, virtual-waiting-room activity, call or session metadata, connection and quality information, presence, transcripts, translations, recordings, and auditable communication events according to the practice’s settings and instructions.

2.5 Device, usage, and cookie information

We may collect IP address, browser and device type, operating system, referring page, access time, requested route, feature interaction, authentication event, diagnostic data, and security or audit events. We use cookies, local storage, and similar technologies for authentication, session security, preferences, analytics, and marketing attribution. Advertising technologies are not intended for authenticated areas where PHI is processed.

3. How we use information

We use information to:

  • provide, operate, configure, and support TherapyAlly Practice, Allie, Channel, portals, APIs, and integrations;
  • authenticate users, enforce roles and practice boundaries, and protect accounts;
  • support intake, scheduling, documentation, billing, payments, workforce, payroll, supervision, messaging, and telehealth workflows;
  • process subscriptions, maintain transaction records, and administer customer relationships;
  • diagnose errors, monitor availability, prevent fraud, investigate security events, and improve reliability;
  • respond to support, privacy, legal, and contractual requests;
  • comply with law, BAAs, customer agreements, and valid legal process; and
  • send service, security, account, and product communications and, where permitted, marketing communications.

4. How we disclose information

We do not sell personal information or PHI, and we do not disclose it for cross-context behavioral advertising. We may disclose information as follows:

  • At the practice’s direction: to Authorized Users, clients, guardians, providers, facilities, payers, clearinghouses, and other recipients selected or authorized by the practice.
  • Service providers and subprocessors: to vendors supporting cloud hosting, identity, communications, email, support, analytics, payments, payroll, insurance clearinghouse services, and AI processing. Depending on the enabled workflow, these may include Google Cloud; Stripe for payment processing; SendGrid for email delivery; Claim.MD as the insurance clearinghouse for payer information, eligibility requests, claim submission, and ERA/remittance processing; Square for payroll integration; and other contracted providers.
  • Legal and safety purposes: when required by law or valid legal process, or when reasonably necessary to protect users, the public, our rights, or the security and integrity of the Services.
  • Business transactions: in connection with financing, due diligence, merger, acquisition, reorganization, sale of assets, or insolvency, subject to appropriate confidentiality protections.

Service providers may process information only for contracted purposes and subject to applicable confidentiality, security, data-processing, and BAA requirements.

5. Allie and AI processing

Allie and AI-assisted documentation features may process prompts, authorized TherapyAlly context, documented session evidence, transcription fragments, and generated outputs to answer a request or create a draft. TherapyAlly currently uses enterprise Google Cloud generative-AI services, including Vertex AI, for these workflows.

We do not use Customer Data or PHI to train a general-purpose AI model. AI providers may process inputs and outputs to deliver and secure the contracted service under their applicable enterprise terms and, where required, a BAA. TherapyAlly stores only the information needed for the requested workflow, account operation, security, and audit purposes according to its product behavior and retention controls.

AI Outputs require authorized human review before they are relied on, signed, placed in a clinical record, submitted to a payer, or used for another consequential clinical or financial action.

6. Security and retention

6.1 Security safeguards

We use administrative, technical, and physical safeguards designed to protect information, including encrypted connections, encryption at rest where supported by the service, authentication, role-based access, practice separation, audit and security events, environment separation, backups, monitoring, vulnerability management, and incident-response processes. No method of storage or transmission is completely secure.

6.2 Retention and deletion

We retain information for as long as reasonably necessary to provide the Services, maintain active accounts, follow customer instructions, meet contractual and BAA commitments, protect the Services, resolve disputes, and comply with applicable law. Practices determine the retention requirements for their clinical records. When an account ends, information is made available, retained, deleted, or de-identified according to the applicable agreement, BAA, product controls, our retention schedule, legal holds, and backup practices.

7. Rights and choices

  • Account information: Authorized Users may review or update certain account information in the Services or through their practice administrator.
  • Clinical records and PHI: clients, patients, parents, and guardians should direct requests to access, amend, restrict, or receive an accounting of PHI to the practice responsible for the record. We assist the practice as required by the BAA.
  • Marketing: recipients may unsubscribe from promotional email using the link in the message. Essential service, security, billing, and account communications will continue.
  • Applicable privacy rights: depending on residence and the type of information, a person may have rights to access, correct, delete, or obtain a copy of certain non-PHI personal information, or appeal a request decision. Legal exemptions may apply.

We may verify identity and authority before completing a request. To submit a request concerning information Bethel Therapy controls directly, use the contact information below.

8. Minors, parents, and guardians

Our public marketing websites and practice-administration tools are directed to adults, not children. TherapyAlly may process information about minor clients when a practice, clinician, parent, or authorized guardian uses the Services for care, scheduling, billing, intake, or communication. The practice is responsible for determining and documenting the authority and consent required for a minor’s care and portal or Channel access. We do not knowingly collect personal information from children for behavioral advertising.

9. Third-party services and links

The Services may link to or integrate with third-party services. A connected service may receive information at Customer’s direction and is governed by its own terms and privacy policy, except where it acts as our contracted service provider or subprocessor. We are not responsible for independently operated third-party websites or services.

10. Changes and contact

10.1 Changes to this Policy

We may update this Policy as the Services, laws, or data practices change. We will revise the effective date and provide reasonable notice of material changes through the Services, email, or another appropriate channel.

10.2 Contact us

For privacy questions, requests, or regulatory notices, contact:

Bethel Therapy LLC
Attn: Privacy & Compliance Officer
3 Summer St.
Chelmsford, MA 01824
contactus@betheltherapy.com
(978) 206-1518
TherapyAlly

One platform for the work behind better care.

Made for allied health practices.

Products

TherapyAlly PracticeAllie by TherapyAllyChannel by TherapyAlly

Explore

FeaturesSolutionsWorkflow tourPricing

Resources

Help CenterSecurity & trustContactPrivacyTerms
© 2026 TherapyAllyAllie and Channel are TherapyAlly products.