Privacy Policy

Last updated: September 25, 2026

The Clinician Network ("TCN," "we," "us," or "our") operates a professional networking platform that connects therapists, clinical supervisors, trainees, and behavioral health organizations for supervision, training, credential management, and licensure tracking. This Privacy Policy describes the information we collect, how we use it, the parties to whom we disclose it, the methods of disclosure, and the security practices we maintain to safeguard your data.

By creating an account or using our services, you acknowledge that you have read and understood this policy. This policy applies to all visitors, registered users, and workforce organization members.

1. Information We Collect

Account & Identity Information

Full name, email address, password (encrypted), display name, professional role (clinician, supervisor, trainee, employer/admin), and profile photo.

Professional & Clinical Information

License type and number, state of licensure, NPI number, clinical status, supervision relationships, session notes, supervision hours, training completions, certificates, and credential documentation uploaded by you or your organization.

Organization & Workforce Data

For workforce organization members: role within the organization, assigned supervisor, training assignments, credential compliance status, audit activity, and organizational unit/group membership.

Payment Information

Billing details, subscription plan, and transaction history. Card numbers and sensitive payment data are handled entirely by our payment processor, Stripe — TCN never stores full card numbers.

Communications

Messages between users (supervisor-supervisee communication, group session discussions), support requests, and contact form submissions.

Usage & Technical Data

IP address, browser type, device information, pages visited, session duration, and interaction data collected through cookies and similar technologies.

2. How We Use Your Information

  • Providing and maintaining your account, profile, and access to platform features
  • Facilitating supervision matching, scheduling, session documentation, and hour tracking
  • Processing subscription payments, supervision payments, and training purchases through Stripe
  • Managing organization workforce rosters, credential compliance, training assignments, and audit logs
  • Sending service notifications, session reminders, and administrative communications via email
  • Verifying professional credentials and training completion certificates
  • Generating aggregate, de-identified analytics to improve platform features and performance
  • Detecting, preventing, and addressing fraud, abuse, and security issues
  • Complying with legal obligations and responding to lawful requests from authorities

3. Parties to Whom We Disclose Information

Service Providers & Processors

We share data with third-party services that support our operations. These providers are contractually limited to using data only to provide services to us:

  • Stripe — Payment processing, subscription billing, and Stripe Connect for supervisor payouts
  • Google (Gmail & Google Meet) — Email delivery and virtual meeting hosting
  • Zoom — Virtual supervision and group session hosting
  • Cloud hosting & database infrastructure — Secure data storage and application hosting

Other Platform Users

Your professional profile (name, credentials, license type, state) is visible to other users for supervision matching and group enrollment. Session notes and private supervision records are visible only to you and your assigned supervisor, unless your organization admin has workforce oversight access.

Workforce Organizations

If you are a member of a workforce organization, your organization admin can view your role, credential compliance, training status, and supervision assignments for compliance oversight purposes.

Legal & Regulatory Authorities

We may disclose information when required by law, court order, or to protect the rights, property, or safety of TCN, our users, or others.

4. Method of Disclosure

  • API integrations — Data transmitted via encrypted API calls to our service providers (e.g., Stripe payment tokens, Google Meet session links)
  • Email notifications — Automated service emails sent through our email provider for session reminders, account updates, and administrative notices
  • In-platform display — Profile and supervision information shown to authorized users within the application interface
  • Document sharing — Credential and certificate documents shared via signed, time-limited download links accessible only to authorized users
  • Organization reports — Compliance and workforce reports generated for organization admins within the platform
  • Legal responses — Disclosures made to legal authorities through formal legal process

5. Security Practices

Encryption in Transit & at Rest

All data is transmitted over HTTPS/TLS encrypted connections. Stored data is protected by database-level encryption and access controls.

Row-Level Access Controls

User data is isolated by account. Supervision records, session notes, and credentials are only accessible to the record owner, their assigned supervisor, and authorized organization admins — not to other platform users.

PCI-DSS Compliant Payments

All payment processing is handled by Stripe, a PCI-DSS Level 1 certified provider. TCN never receives or stores full card numbers or CVV codes.

Role-Based Permissions

Administrative access is restricted by role. Organization admins only see members of their own organization. Platform admins are restricted to operational necessities.

Audit Logging

Workforce organizations have access to audit logs tracking administrative actions including role changes, credential verification, training assignments, and data exports.

Incident Response

We maintain procedures to investigate and respond to security incidents and will notify affected users of any breach requiring notification under applicable law.

While we implement industry-standard security measures, no method of transmission or electronic storage is 100% secure. We cannot guarantee absolute security but are committed to protecting your information.

6. Data Retention

We retain your information for as long as your account is active or as needed to provide services. Professional credentials, supervision records, and training certificates are retained for the duration of your account and may be retained after account closure to comply with legal, professional licensure, or audit requirements. You may request deletion of your account and personal data, subject to these retention obligations.

7. Your Rights

  • Access — You can view your profile, credentials, and supervision records within your account
  • Update — You can edit your profile, credentials, and preferences at any time
  • Export — Organization admins can export workforce compliance reports
  • Deletion — You can request account deletion by contacting us
  • Opt-out — You can unsubscribe from non-essential emails at any time

8. Cookies & Tracking

We use cookies and similar technologies to maintain your session, remember preferences, and understand how the platform is used. You can control cookies through your browser settings. Disabling cookies may affect platform functionality.

9. Children's Privacy

Our services are intended for licensed and pre-licensed mental health professionals and the organizations that employ them. We do not knowingly collect information from children under 16. If you believe a child has provided us with personal information, please contact us.

10. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will notify registered users of material changes via email or in-platform notice. The "Last updated" date at the top of this page indicates when the policy was last revised.

11. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

© 2026 The Clinician Network. All rights reserved.