EMILE-E Sesh · Legal
Sesh Privacy Policy
This Privacy Policy explains how EMILE-E.tech Corp, a Florida corporation ("EMILE-E," "we," "us"), handles information in connection with EMILE-E Sesh: the web app, the mobile apps for iOS and Android, and related services (together, the "Service"). Sesh is a team communication tool used by the staff of behavioral-health practices and organizations ("practices").
1. The most important thing
Sesh is a staff-to-staff tool. Clients of a practice do not use Sesh, and Sesh is not a way for clients to reach their practice. The practice controls its Sesh workspace: who is a member, what roles they hold, which spaces exist, and how long messages are kept. Where staff discuss client care in Sesh's clinical spaces, that content may include protected health information ("PHI"); we process it only on the practice's behalf, under a Business Associate Agreement ("BAA") as required by HIPAA.
2. Information we process
Account and directory information. Name, work email, title, assigned roles, and presence status. Optionally, a staff member's mobile phone number, used only for SMS escalation fallback, and their quiet-hours preferences.
Content staff create. Messages in channels and direct messages; consults, coverage handoffs, and escalations; required-read notices and the attestations staff sign against them; supervision-hours entries; and message reactions. Content in clinical spaces may include PHI and is handled under the BAA.
Compliance records. An append-only audit log of security- and workflow-relevant events (sign-ins, escalation lifecycle, attestations, administrative changes), written by our servers and readable within the workspace only by roles the practice designates.
Automatically. Technical logs for security and reliability: IP addresses, device and app version information, push notification tokens, and error logs.
Notifications are content-free by design. Push notifications and SMS alerts tell a staff member that something needs their attention (for example, "An escalation needs your acknowledgment") without including message content or client information.
3. How we use information
- To provide the Service to the practice: messaging, zoned spaces, direct messages, on-call escalation with acknowledgment and cascade, consults and handoffs, required reads and attestations, and supervision-hours logging.
- To secure the Service: authentication, role-based access, per-practice tenant isolation, abuse prevention, and immutable audit logging.
- To deliver notifications: content-free push notifications, and SMS fallback for escalations to staff who have added a phone number.
- To support practices and improve reliability, using de-identified, aggregated usage data.
- To bill practices for the Service.
We do not sell personal information. We do not use it for advertising. We do not use Customer Data, including PHI, to train generalized AI models.
4. How information is shared
We share information only with service providers needed to run the Service, each bound by appropriate agreements (including BAAs where they handle PHI): Google Cloud (hosting, database, authentication), our SMS provider (which receives staff phone numbers and the content-free alert text of escalation messages), our push notification delivery provider, and the Apple and Google notification services that deliver alerts to devices. We may also disclose information if required by law, to protect the safety and security of the Service, or as part of a business transfer, in which case this policy continues to apply.
5. HIPAA roles
The practice is the HIPAA covered entity and the custodian of its records. EMILE-E is a business associate with respect to PHI staff place in the Service. The executed BAA governs our handling of PHI, including permitted uses, safeguards, breach notification, and disposition of PHI at termination. Where this policy and the BAA conflict with respect to PHI, the BAA controls.
6. Retention and deletion
Customer Data is retained while the practice's subscription is active, subject to controls the practice configures. A message "removed from view" is tombstoned, hidden from the conversation, retained in the record, consistent with recordkeeping norms. Spaces the practice designates for informal decompression can be set to delete messages automatically after a configured number of days. Audit logs are append-only and kept during the term. After termination, the practice may export its data for 30 days, after which we may delete it, subject to legal retention obligations and the BAA.
7. Security
The Service runs on Google Cloud infrastructure under a BAA, with encryption in transit and at rest, per-practice tenant isolation enforced by server-set access controls, role-based zones that separate everyday operations from clinical discussion, server-authoritative writes for workflows and compliance records, and immutable audit logging. Membership is invitation-only: accounts are created by the practice's administrators, never by open signup. No system is perfectly secure; if we learn of a breach affecting your information, we will notify affected practices consistent with applicable law and the BAA, and support their notification obligations.
8. Your choices and rights
Staff can manage their presence, quiet hours, and SMS phone number in the app's settings. Adding a phone number is optional; it enables SMS fallback for escalations. Quiet hours pause routine notifications; escalations are designed to break through, because that is the feature's purpose, so staff with on-call duties should coordinate schedule changes with their practice rather than relying on device settings.
Device notifications can be turned off in device settings; the app remains usable without them, though on-call staff should not disable them while carrying the pager.
Depending on where you live, you may also have consumer-privacy rights in information we hold as a business; contact us at privacy@emile-e.tech and we will respond consistent with applicable law, coordinating with the practice where HIPAA applies.
9. Children
Sesh is a workplace tool for practice staff and is not directed to children. We do not knowingly collect information from anyone under 18 through the Service.
10. Website visitors
Our marketing site (emile-e.tech) sets no advertising cookies and runs no third-party analytics or tracking scripts. If you submit the Sesh pilot-request form, we use what you provide to respond to your inquiry and for no other purpose.
11. Changes and contact
We will post any material changes to this policy here and, for active practices, provide notice by email or in the app at least 30 days before they take effect. Questions and requests: privacy@emile-e.tech, EMILE-E.tech Corp, Florida, USA.
