Legal

Privacy Policy

Practice Held LLC · Effective date: [EFFECTIVE DATE — set on publication] · Last revised: August 2026

Draft for review. This is a working draft prepared to give you something concrete to react to and to hand to a licensed attorney. It is not legal advice and should not be published as-is. Because Practice Held handles information connected to mental-health practices, an attorney should review it before launch — especially the sections on health information (HIPAA), state-specific privacy rights, service-provider agreements, and limitation of liability. Items shown in [brackets] need confirmation.

Contents

  1. Who We Are
  2. Our Privacy-First Design
  3. Information We Collect
  4. How We Use Information
  5. How We Share Information
  6. Client & Third-Party Information
  7. Data Retention
  8. How We Protect Information
  9. Your Choices & Rights
  10. Children's Privacy
  11. United States Users
  12. Third-Party Links
  13. Changes to This Policy
  14. Contact Us

1.Who We Are

Practice Held LLC (“Practice Held,” “we,” “us,” or “our”) is a Pennsylvania limited liability company that provides Practice Held (“Held” or the “Service”), software that helps licensed mental health professionals create and maintain a professional will and practice-continuity plan. This Privacy Policy explains how we collect, use, and share information when you visit practiceheld.com (the “Site”) or use the Service.

2.Our Privacy-First Design

Held is built to be local-first. The continuity plan you create — including information about your practice, your records, and the colleagues you designate — is encrypted on your own device. We do not host your plan. Your sealed plan stays on your device and any storage you choose, and decrypting it requires keys held by you and the people you designate (your “keyholders” or executors). Because of this design, the contents of your plan — the most sensitive information — are never available to Practice Held in any form, readable or sealed. Please read the rest of this Policy with that architecture in mind.

What our servers do hold is limited operational information: your account and billing details, your subscription status, and the contact details of the keyholders you add so that we can send them readiness reminders. We never receive your encryption keys, your plan contents, or your clients' information.

3.Information We Collect

Account and contact information. Your name, email address, and professional details you choose to provide when you create an account or contact us.

Billing and subscription information. Payments are processed by our payment provider, Stripe. We receive limited transaction details (such as a confirmation, the amount, and the last four digits of your card) and your subscription status. We do not store full payment card numbers.

Keyholder contact details. When you designate keyholders or executors, we store their names and contact details (such as email) so the Service can send them readiness reminders and, when you have arranged it, succession-related notifications. We do not store the contents of your plan.

Technical and usage data. Device type, application version, diagnostic logs, approximate location derived from IP address, and basic Site analytics. We aim to keep this minimal.

Communications. Records of messages you send us, such as support requests.

4.How We Use Information

We use information to provide, maintain, and improve the Service; to process payments and manage your subscription; to send account, renewal, policy-update, and keyholder-readiness reminders; to provide customer support; to secure the Service and prevent fraud or abuse; and to comply with legal obligations.

5.How We Share Information

Service providers. We share limited information with vendors who help us operate: Stripe (payment processing), Resend (email delivery), Cloudflare (Site hosting and DNS), and Railway (application hosting and our operational metadata database). These providers may access only the information needed to perform their services.

Keyholders and executors. The people you designate can gain access to your plan under the conditions you set, using the keys you distribute. This is a core function of the Service that you control. We facilitate reminders to these people using the contact details you provide.

Legal and safety. We may disclose information to comply with applicable law, respond to lawful requests, enforce our agreements, or protect the rights, safety, and property of Practice Held, our users, or others.

Business transfers. If we are involved in a merger, acquisition, or sale of assets, information may be transferred subject to this Policy.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

6.Client and Third-Party Information

Your plan may reference information about your clients or patients and other third parties. You are responsible for ensuring you have the right to include that information and for meeting your professional and legal obligations, which may include the Health Insurance Portability and Accountability Act (HIPAA) and state confidentiality laws. Because your plan is encrypted on your own device and we never receive its contents, we do not process your clients' information. [If Practice Held is or becomes a HIPAA “business associate,” a separate Business Associate Agreement would govern any protected health information — confirm scope with counsel.]

7.Data Retention

We retain account, billing, subscription, and keyholder-contact metadata for as long as your account is active and as required by law. We do not store your plan contents at any time. When you cancel or request deletion, we delete or de-identify the information we hold within a reasonable period, except where retention is required for legal, tax, or security purposes.

8.How We Protect Information

We use technical and organizational measures including on-device encryption of your plan, encryption in transit and at rest for the metadata we hold, and access controls built around the keyholder model. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9.Your Choices and Rights

You may access, update, export, or request deletion of your account information, and you may opt out of non-essential communications. Depending on where you live (for example, California and certain other states), you may have additional rights to access, correct, delete, or limit the use of your personal information, and to be free from discrimination for exercising those rights. To make a request, email us at the address below.

10.Children's Privacy

The Service is intended for licensed professionals and is not directed to anyone under 18. We do not knowingly collect personal information from children.

11.United States Users

Practice Held is based in the United States and the Service is intended for users in the United States. If you access the Service from outside the United States, you do so on your own initiative.

12.Third-Party Links

The Site may link to third-party websites or services that we do not control. This Policy does not apply to those third parties, and we are not responsible for their practices.

13.Changes to This Policy

We may update this Policy from time to time. We will post the updated version with a new effective date and, for material changes, provide additional notice where appropriate.

14.Contact Us

Questions about this Policy or your information can be sent to [email protected]. Practice Held LLC, 1569 McFarland Road, Pittsburgh, PA 15216, United States.