Trust & Safety

How we look after your practice data

This page is maintained by the ClientWell team to answer common security and privacy questions about the platform. It describes practices and controls that are enabled today. It is not an independent audit or certification.

Who is responsible for what

ClientWell is a shared-responsibility service. We operate the platform, its security controls, and its infrastructure. You, as the practitioner, are responsible for how you configure your workspace, who you invite into it, and how you collect and use your clients' information under the laws that apply to your practice.

Access & authentication

  • Sign-in with email + password or Google. Sessions are managed through our authentication provider.
  • Every workspace is isolated. Row-level security policies enforce that one workspace cannot read another's clients, sessions, notes, or documents at the database layer.
  • Team members you invite receive scoped roles (owner, admin, member). Only owners and admins can change billing or delete records.

Hosting & infrastructure

  • The application runs on managed edge infrastructure. The database is a managed Postgres instance with automated backups.
  • Data in transit is encrypted using HTTPS/TLS.
  • Data at rest is encrypted by our infrastructure providers.

What we collect

  • Account data: the name and email you sign up with, and basic workspace settings.
  • Practice data you enter: clients, sessions, notes, intake responses, newsletters, website content. This belongs to you.
  • Usage analytics: product-level metrics we use to improve ClientWell. We do not sell this data.

Subprocessors & integrations

We rely on a small set of trusted providers to run the platform. Each is bound by its own security terms:

  • Hosting and database: managed edge + Postgres provider.
  • Payments: Stripe (tax calculation only, for New Zealand).
  • Email delivery: transactional email provider.
  • SMS delivery: SMS gateway provider (where enabled).
  • AI features: LLM provider used by Sage (see below).

Sage (AI assistant)

  • Sage is a drafting and Q&A assistant. It never sends messages, charges cards, or changes bookings without you confirming.
  • Sage will not write clinical, diagnostic, or medical claims on your behalf. It defaults to softer, non-clinical wording and will tell you when a claim needs your professional judgement.
  • We do not use your client records or Sage conversations to train third-party models.
  • You can clear your Sage chat history at any time from the Ask Sage panel.

Security policy & HISF checklist

We publish a shared-responsibility security policy that maps the Health Information Security Framework (HISF) checklist to the controls we provide and the controls your practice must maintain. It covers physical security, passwords, anti-virus, firewalls, Security Officer nomination, incident reporting, and off-shore connectivity.

You can request the latest version by emailing hello@myclientwell.com. It is provided as editable practice-owned content, not as an independent certification.

Retention & deletion

  • Your data stays in your workspace for as long as your account is active.
  • You can delete individual clients, sessions, notes, and newsletters at any time from within the app.
  • You can request full workspace deletion by emailing us. We will remove your workspace data from our production database; routine backups age out on their normal cycle.

Client & privacy requests

If one of your clients asks you to export or delete their record, you can do that yourself from the client's page. If you need help, contact us and we will help you fulfil the request.

Reporting a security issue

If you believe you have found a vulnerability or a data-handling issue, please email security@myclientwell.com. Please do not post details publicly before we have had a chance to respond. We will acknowledge your report and keep you updated as we investigate.

What this page is not

This page describes controls and practices we have in place today. It is not a SOC 2, HIPAA, ISO 27001, or GDPR certification, and it is not a legal agreement. Your contract with us is the Terms and Privacy Policy. If you need specific compliance wording for your own regulator or insurer, get in touch and we will do our best to help.

Last updated: 3 September 2026

Have a look around before you decide

Click through a fully loaded practice, or start your own in under five minutes. No card, no sales call.