Back
Privacy Policy
Last updated: March 2026 · Effective immediately upon account creation
Self Shelf is committed to protecting your privacy and the privacy of your clients. This Privacy Policy explains how we collect, use, and protect your information.
1. Information We Collect
We collect information you provide directly to us, including:
- Account information: Name, email address, role (clinician or client), and profile details.
- Credential information: License numbers, insurance certificates, and verification documents submitted by clinicians.
- Clinical data: Session notes, intake responses, prescriptions, and other protected health information (PHI) entered on the Platform.
- Usage data: How you interact with the Platform, including pages visited and features used.
- Communications: Messages, support requests, and any other communications you send us.
2. HIPAA and Protected Health Information
Self Shelf is designed as a HIPAA-compliant platform. Protected Health Information (PHI) entered by clinicians and clients is:
- Stored with encryption at rest and in transit.
- Accessible only to authorized users with a legitimate need.
- Never sold or shared with third parties for advertising purposes.
- Governed by executed Business Associate Agreements with all applicable vendors.
3. How We Use Your Information
- To provide, maintain, and improve the Platform.
- To verify clinician credentials and maintain platform integrity.
- To communicate with you about your account, updates, and support requests.
- To comply with legal obligations, including HIPAA reporting requirements.
- To detect and prevent fraud, abuse, or security incidents.
4. How We Share Your Information
We do not sell your personal information. We may share your information with:
- Service providers: Vendors who help us operate the Platform (e.g., cloud infrastructure, video conferencing, payments), all under BAAs where applicable.
- Verification services: Third-party credential verification services to validate clinician licenses.
- Legal compliance: When required by law, subpoena, or legal process.
- Business transfers: In connection with a merger, acquisition, or sale of assets, with appropriate notice to users.
5. Data Security
We implement industry-standard security measures including:
- TLS encryption for all data in transit.
- AES-256 encryption for data at rest.
- Role-based access controls (RBAC) enforced at the database level.
- Automatic session timeouts after 15 minutes of inactivity (HIPAA §164.312(a)(2)(iii)).
- Audit logging of all PHI access and modifications.
6. Data Retention
We retain your data for as long as your account is active or as needed to provide services. Clinical records may be retained for a minimum of 7 years in accordance with HIPAA record retention requirements. You may request deletion of non-clinical account data by contacting us.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access a copy of the personal information we hold about you.
- Correct inaccurate information in your account.
- Request deletion of your personal data (subject to legal retention requirements).
- Opt out of non-essential communications.
To exercise these rights, contact us at privacy@selfshelf.com.
8. Cookies and Tracking
We use essential cookies to maintain your session and keep you logged in. We do not use advertising or tracking cookies. You can configure your browser to refuse cookies, though this may affect Platform functionality.
9. Children's Privacy
Self Shelf is not intended for users under 18 years of age. We do not knowingly collect personal information from minors. If you believe a minor has created an account, please contact us immediately.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or a prominent notice on the Platform. Continued use after the effective date constitutes acceptance.
11. Contact
Questions or concerns about this Privacy Policy? Contact our Privacy Officer at privacy@selfshelf.com.
© 2026 Self Shelf. All rights reserved.