Privacy Policy

This policy is intended to help you understand what data we collect, how we use it, and your rights related to it. For purposes of this policy and unless otherwise specified, “data” includes data that is linked to one person or household including things like name, email address, phone numbers, device ID, Third-Party identifiers, contact information, communications with therapists using our digital communication platform (the “Platform”) to provide services (“therapists”), and IP address. Some jurisdictions might consider this to be “personal data,” “personally identifiable information,” or “sensitive personal data” in certain circumstances. When you use and access our app or website, you accept and agree to both the Terms and Conditions and this Privacy Policy, including that we’ll share certain data with service providers.

The Company is the data controller of your personal data and is therefore responsible for ensuring that your personal data is processed correctly and securely in accordance with applicable legislation.

The purpose of this Policy is to explain the technical aspects of data Processing in a simple and clear way. Please feel free to email contact@castofminds.com if you have any questions about this Policy, or any suggestions for us to improve it.

Do you collect, store, or Process my data?

In this policy, we refer generally to activities done with data as “Processing.” Examples of Processing include collecting, storing, and using data. The categories of data which we Process are listed below. We Process this data to do things like operate the Platform and make sure you’re able to use our services effectively. We may also Process data to send you periodic emails or text messages. You can opt out of receiving texts or marketing communications at any time. Additionally, provided you opt-in and agree, we may Process and share some data with Third Parties for advertising purposes. You can find more details in the relevant sections of this policy.
We Process depends on how you’re using our website, app, or the Platform. We explain below the specific data we Process.

Visitor data: When you visit the website, we Process information like the particular pages visited or which features you interacted with, the amount of time on the website, information about the type of device and browser you’re using, and IP address. We may Process your Third-Party identifier or advertising ID (if available based on the settings of your device) and will share it if you opt-in.

On boarding data: When an account is created with the Platform, the user fills out a questionnaire. We Process the information used to complete this questionnaire. Some of this information may include identifiers like email address, phone number, chosen name (first name or nickname), and physical address.

Account Registration Data: Once a user registers with the Platform, we Process data such as the account name the user selects, the email that they use, their age, phone number, emergency contact details, and whether a user verifies their email address. We also assign each user (including therapists) who creates an account a sequentially-generated user ID.

Transaction Data: We Process data about payment transactions on the Platform such as whether a user completed payment for our services, signed up for services using a trial offer, canceled or ended a trial, received a discount or financial aid, or received any extensions or refunds.

Checkout Flow Data: We Process data about whether a user registers for the Platform or pays for access to the Platform services.

Therapist Data: In order to identify, match, credential, re-credential, run checks and pay therapists, we Process therapist information such as the therapist’s name, bank account information, gender, date of birth, governmental identification numbers, e-mail address, phone number, address, license information and areas of interest/expertise, education, and job history.

Therapy Quality Data: We Process client feedback about their therapist, ratings and reviews of their therapist, actions regarding switching therapist or quitting therapy, and the reason selected by the client, We Process therapist session availability, session cancellations and no-shows.

Therapist Engagement Data: We Process data about therapist logins to the Platform, the number of live sessions conducted by a therapist, number of messages and words exchanged by a therapist, number of worksheets shared by a therapist, and number of journal entries shared with a therapist.

Therapy Communications Data: We Process communications and related information users share with their therapist to facilitate the therapy. This includes messages with therapists, worksheets, attendance, and journal entries. Users may also choose to utilize our transcribe feature to assist with dictation, otherwise, we do not record the video or audio sessions with therapists.

Why do you collect and Process my data?

We Process some data to connect you with therapy services: In order for us to connect you with therapy services on our Platform, we need to be able to facilitate information sharing between you and your therapist so that you can get the help you need from them. We also Process data like your therapist preferences, your state (if applicable), and your country to determine what therapist to suggest to you based on applicable licensing requirements.

We Process some data to communicate with you, verify your identity and secure your account: For example, we need to make sure that if you ask a question or have a concern about the Platform, we’re able to respond to you and provide an answer.

We Process some data to monitor the Platform and make sure quality services are being provided to you: For example, we track if a live session occurred, was canceled or if the therapist did not show up, to ensure that timely services are being delivered to you. We also track ratings, reviews, complaints and other client feedback to ensure the quality of therapists on our Platform. If you consent, a licensed therapist who is employed as part of the cast of minds Clinical Operations Team may review correspondence with your therapist for quality assurance purposes, For example, if you raise a concern about your therapist, or we have concerns about a specific therapist’s clinical care.

We Process some data to personalize your web or app experience: For example, if you identify as a religious person and would prefer a therapist who utilizes faith-based practices, we Process that information to allow us to match you with an appropriate therapist that can meet these needs. Another example is if you state that you would like help with anxiety, we may recommend content and features that would be helpful to you, such as anxiety-related group sessions.

We Process some data to offer you new features and make the services more convenient for you: For example, we may use some of your data to determine which products and features to roll out to you. We may also Process data to know when you have already seen a “pop-up” on the Platform and do not need to be shown it anymore. Another example of this is when we use your IP address to help conveniently auto-populate your state (if applicable) and country, or assist you with providing your address when completing information about your emergency contact.

We Process some data to comply with laws: For example, a court might subpoena information from us where we would be required to share certain information requested in the subpoena. This is not unique to cast of minds and is applicable to in-person therapy as well. Keep in mind that, as a general rule, we defer to your chosen therapist to decide to produce (or not produce) any psychotherapy notes or messages you have had with them. Many jurisdictions have strict rules governing therapist/client relationships and the confidentiality requirements associated with that. We encourage you to discuss with your therapist early on if you have concerns about their disclosure obligations.

We Process some data to protect your safety and the safety of others: For example, if we have reason to believe that you or any other person may be in immediate danger or your privacy infringed upon, we may use the information to investigate or reach out to you or the appropriate authorities if it is legally appropriate/permitted to do so.

We Process some data to help us understand how you use our service and improve it: For example, we might assess the usage of various features and decide to invest more resources in features that are popular and/or decide to remove features that aren’t providing value to our members. We might also ask you for feedback about how we can improve our Platform or what you like or don’t like about the therapist that is matched to you.

Who can see the interactions I have with my therapist?

You and your therapist are able to see the messages you send, the worksheets you submit or the journal entries you submit (if you opt in to sharing journal entries). A licensed therapist who is employed as part of the Cast of minds Clinical Operations Team may review correspondence with your therapist for quality assurance purposes, For example, if you raise a concern about your therapist, or we have concerns about a specific therapist’s clinical care.

In addition, our internal Legal or Trust and Safety teams may review correspondence for specific accounts if we have a reason to believe that there is a security, legal, fraud or abuse issue occurring on that specific account.

Messages with your therapist are not shared with any Third Party, and your live sessions are not recorded. We also do not share when you send a message, or have a session with your therapist, with any Third Party.

How do you keep my data secure?

We apply industry standards and strive to apply best practices to prevent any unauthorized access and disclosure. Internet-based services carry inherent security risks, but our systems infrastructure, encryption technology, operation and processes are all designed, built, and maintained with your security and privacy in mind. 

Cast of Minds has an experienced team of data security professionals whose job it is to make sure we use secure technology to protect your data. We have security staff who test internal security at Cast of Minds to try and anticipate threat actors and security staff that act defensively and build processes and infrastructure to prevent incidents and attacks. We have numerous robust security practices such as:

All the messages between a member and their therapist are secure and encrypted by 256-bit encryption.

Our browsing encryption system (SSL) follows modern best practices.

Our databases are encrypted and scrambled rendering them useless in the unlikely event that they are stolen or inappropriately retrieved.

We have robust monitoring and alerting systems and procedures in place that include both automated systems and humans (for example, there are always at least one security personnel active in our 365/24/7 on-call rotation).

Regarding payments

The Company may provide you with paid products and/or services. In that case, the Company may use third-party services for payment processing (e.g. payment providers).

The Company will not store or collect your payment card details. That information is provided directly to our third-party payment providers whose use of your personal information is governed by their privacy policy. These payment processors adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, MasterCard, American Express and Discover. PCI-DSS requirements help ensure the secure handling of payment information. The company at the moment uses visa and MasterCard payment gateways for all its users.

Contact information

Do not hesitate to contact the Company if you have any questions about this Privacy Policy, the processing of your personal data or if you wish to exercise your rights under this Privacy Policy or applicable legislation.
Cast of Minds
Corporate registration number: 4220104917965
Email address: contact@castofminds.com