Legal & Privacy

Privacy Policy

What this website collects, who it goes to, and how to have it removed — in plain language, without the legal fog.

Effective
August 7, 2026
Last updated
August 7, 2026
Applies to
softpowerpsychotherapy.com · Texas & New Jersey

At a glance

  • We never sell, rent, or trade your information, and we do not use it for advertising.
  • Our contact form runs on Paubox, a HIPAA-compliant provider, and asks four things — name, email, phone, and the days that suit you.
  • Once you are a client, your records are protected by HIPAA and described in our Notice of Privacy Practices.
  • You can ask us what we hold, correct it, or have it deleted at any time by calling (510) 877-0950.

This summary is here to orient you. The full sections below are what actually govern.

§ 01

The short version#

We use the information you share with us for one purpose: to respond to you and figure out together whether we are the right fit. We do not sell it, we do not share it with advertisers, and we do not add you to marketing lists you did not ask for.

If you ever want your information removed, call (510) 877-0950 or reply to any email from us and ask. We will take care of it and confirm when it is done.

§ 02

Two kinds of information, two different rules#

Soft Power Psychotherapy is a health care provider and a HIPAA covered entity. That means the information we hold falls into two buckets, and different rules apply to each. This trips people up constantly, so here it is plainly:

Website information — governed by this policy

What you type into our contact form, what you say in an email or voicemail before you are a client, and the basic technical data our host records when you load a page. This policy is the document that governs it.

Protected health information — governed by HIPAA

Once you become a client, your records, session notes, diagnoses, billing records, and everything else tied to your care become protected health information (PHI). PHI is protected by federal HIPAA rules, by Texas Health & Safety Code Chapters 181 and 611, and by New Jersey law. How we use and disclose it — and the rights you hold over it — are described in our Notice of Privacy Practices, not here.

Information you send through this website before you are a client is not yet part of a clinical record. But we still treat it as sensitive, because the fact that you contacted a therapist at all is private.

§ 03

Who we are#

Soft Power Psychotherapy (“we,” “our,” “us”) is a telehealth psychotherapy practice with clinicians licensed in Texas and New Jersey. We operate the website at softpowerpsychotherapy.com.

Our Privacy Officer is responsible for this policy and for any privacy question or complaint. You can reach that person at (510) 877-0950 or through our contact form.

If anything here is unclear, please ask us before you submit your information.

§ 04

What we collect#

Information you give us

Our contact form asks for four things, and only these four:

  • Your full name
  • Your email address
  • Your phone number
  • Which days of the week work best for you

That is the whole form. There is no free-text box, no question about what brings you here, no dropdown of services, no insurance field. We do not ask for a Social Security number, a date of birth, an insurance ID, a diagnosis, or a medication list anywhere on this website.

The form itself is hosted and encrypted by Paubox, a HIPAA-compliant communications provider, and it lives on Paubox’s own secure domain rather than on this website. Your submission goes from your browser to Paubox to us — it is never stored on this site.

If you call, email, or text us instead, we keep what you send in that message, along with the number or address it came from.

Information collected automatically

When you load a page, our hosting provider records basic technical information:

  • Which pages were visited and how long they were open
  • Approximate location, at the country or region level
  • Device type, browser, and operating system
  • The site or search that referred you

We use this to understand which pages are useful and where the site is slow. It is aggregate — it is not tied to your name or to a form submission.

§ 05

How we use your information#

We use what you give us to:

  • Reply to you by phone or email
  • Schedule a free 15-minute consultation
  • Follow up if we have not heard back from you
  • Answer questions about insurance, availability, fees, or services
  • Refer you elsewhere if we are not the right fit or you are outside the states where we are licensed

We use the automatic technical information to keep the site working, fix errors, and improve pages that are confusing.

That is the entire list. We do not profile you, score you, feed your information into advertising systems, or use it to train any AI model.

§ 06

Cookies, analytics, and advertising trackers#

Health-related browsing is unusually revealing — the fact that someone read a page about trauma therapy is sensitive on its own. Federal regulators have specifically warned health care providers about tracking technologies that hand that kind of browsing data to advertising companies. We take that seriously.

What we do use

  • Vercel Web Analytics and Speed Insights, from our hosting provider. These record aggregate page views and performance timings. They do not use cookies to build a cross-site profile of you.
  • A contact form embedded from Paubox, our HIPAA-compliant forms provider. The form runs on Paubox’s domain inside a frame on our contact page; it may set cookies of its own to keep your entry working while you fill it out. It is not an advertising tool and does not profile you.

What we do not use

  • No advertising or remarketing pixels — no Meta Pixel, no Google Ads remarketing tag, no TikTok pixel on this site
  • No selling or sharing of browsing behavior with data brokers or ad networks
  • No cross-site tracking of the pages you read here

Your controls

Your browser can block or clear cookies, and most browsers offer a “Do Not Track” setting. There is no single industry standard for how sites must answer that signal, so here is ours: we honor Global Privacy Control (GPC) and Do Not Track signals by treating them as a request not to be tracked — which is already how this site behaves.

§ 07

Companies that help us run the practice#

We use a small number of vendors, and each one only gets what it needs to do its job:

  • Paubox — hosts our contact form and carries secure messages to us. Paubox is built for health care, is HITRUST certified, and signs a Business Associate Agreement. Privacy policy
  • Vercel — hosts the website and provides the aggregate analytics described above. Privacy policy
  • Our telephone provider — carries calls to and from our practice number
  • Our electronic health record, scheduling, and telehealth platforms — used only for clients, never for website visitors

We do not allow any of these vendors to use your information for their own marketing.

§ 08

We do not sell or share your information#

We do not sell, rent, trade, or share your personal information for anyone’s marketing or advertising — ever. We do not disclose that you are a client, a former client, or a prospective client to anyone who is not entitled to know.

There are only four situations where your information leaves our practice:

  1. To the vendors listed above, strictly to operate the website and respond to you
  2. When the law requires it — a valid court order, subpoena, or lawful request we are legally obligated to answer
  3. To prevent serious, imminent harm to you or someone else, as our professional ethics and state law require
  4. When you tell us to — for example, if you sign a release asking us to coordinate with a physician, a school, or a family member

If a disclosure involves protected health information, the rules in our Notice of Privacy Practices apply on top of everything here.

§ 09

Calls, texts, and email#

When you give us your phone number or email address, you are telling us it is okay to use them to reply. We use them to answer you and to arrange a consultation — nothing else. We do not run marketing campaigns, automated text blasts, or newsletters, so there is no list to be added to and none to unsubscribe from.

Text messages

If you text our practice number, a person reads it and a person answers. Texting is convenient but it is not a secure or confidential channel — messages sit unencrypted on your phone, your carrier’s systems, and ours. We keep texts to scheduling and logistics for that reason, and we never share your number with anyone for their marketing.

Email

Ordinary email is not encrypted end to end. It can be intercepted, forwarded, or read on a shared device. We keep our replies brief and general for that reason, and we will never put clinical detail in an unsecured email unless you have asked us in writing to communicate that way and understand the risk.

Voicemail

Tell us if it is not safe to leave a voicemail at your number, or if we should not say the name of the practice. We will follow whatever instruction you give us — no explanation needed.

You can change how we contact you at any time, and you can ask us to stop contacting you entirely.

§ 10

Which channels are secure, and which are not#

Not every way of reaching us carries the same protection, so here it is plainly:

Secure

Our contact form. It runs on Paubox, a HIPAA-compliant provider that signs a Business Associate Agreement with us, and your entry is encrypted in transit. It also asks for nothing about your health, so there is little to protect there in the first place.

Not secure

"I would like to talk to someone about anxiety, and I am in Houston" is all we need to route you to the right clinician. Everything else can wait until we speak.

Once you become a client, all clinical communication, intake paperwork, and session scheduling move to our secure, HIPAA-compliant systems. The public part of this website is never part of that.

§ 11

How long we keep information#

  • Website inquiries that do not become a client relationship — we keep them for up to 24 months in case you come back, then delete them. Ask us sooner and we will delete them sooner.
  • Clinical records — retained as required by law and by our licensing boards. In Texas, mental health records are generally retained for at least seven years after the last date of service, and for records of a minor, until the client’s 21st birthday or seven years after the last service, whichever is longer. New Jersey requires a comparable seven-year retention.
  • Billing and insurance records — retained as long as required by tax law, insurers, and state regulation.
  • Aggregate website analytics — retained in aggregate form only, and never tied back to you.

Retention rules for clinical records exist to protect you: they mean your record is still there years later if you or a future provider need it.

§ 12

How we protect it#

Reasonable safeguards, in the language HIPAA uses — administrative, physical, and technical:

  • Encrypted connections (TLS) for this website and our clinical systems
  • Encryption of records at rest in the systems that hold them
  • Access limited to the workforce members who need it, on the “minimum necessary” principle
  • Unique accounts and multi-factor authentication on systems holding client information
  • Devices that are password-protected, encrypted, and screen-locked
  • Workforce training on privacy and security, and signed confidentiality agreements
  • Business Associate Agreements with vendors that touch protected health information

No website, email, or internet transmission is ever completely secure, and we will not pretend otherwise. What we can promise is that we take this seriously, and that if something does go wrong we will tell you — see below.

§ 13

Your choices and rights#

For information this website holds, you can ask us to:

  • Tell you what we have about you
  • Correct anything that is wrong
  • Delete it
  • Stop contacting you, by any or all channels
  • Send you a copy of it

To make any of these requests, call (510) 877-0950 or reply to any message from us. We will respond within 45 days, and we will tell you if we need more time. We may need to verify who you are first — for your protection, not to slow you down. There is no fee, and we will never treat you differently for asking.

If you are already a client, your rights over your clinical record are broader and are set out in our Notice of Privacy Practices — including the right to inspect and copy your record, request an amendment, and receive an accounting of disclosures.

§ 14

State privacy rights#

Texas, New Jersey, California, and a growing number of other states give residents specific rights over personal data. Those laws generally carve out protected health information held by a HIPAA-covered health care provider, because HIPAA already governs it — which is most of what we hold.

We are not going to make you work out which statute applies to which sentence. Whatever state you live in, we will honor the requests listed above: know, correct, delete, port, and stop contacting. We do not sell personal data or use it for targeted advertising, so there is nothing to opt out of on that front.

If we decline a request, we will tell you why in writing, and you may appeal that decision by calling us or writing to our Privacy Officer. If we deny the appeal, you may contact your state Attorney General.

§ 15

Notice of electronic disclosure (Texas)#

Texas law requires health care providers to tell Texas residents when their protected health information may be disclosed electronically. This is that notice.

§ 16

Children and teens#

This website is written for adults. We do not knowingly collect information from anyone under 18 through this website, and children should not submit our contact form.

We do treat adolescents. When we do, a parent or legal guardian handles the inquiry and the intake, and the parent or guardian signs the paperwork. A minor client’s records carry additional protections under state law, and we talk openly with families at the start of care about what is shared with parents and what stays between the teen and their therapist — because therapy does not work without that clarity.

If you are a parent or guardian and believe a minor submitted information through this site, contact us and we will remove it.

§ 17

If there is ever a breach#

If protected health information is ever breached, HIPAA requires us to notify you without unreasonable delay and no later than 60 days after we discover it. We will tell you what happened, what information was involved, what we are doing about it, and what you can do to protect yourself. Larger breaches are also reported to the U.S. Department of Health and Human Services and, where required, to the media and to state authorities.

For information that is not protected health information, we will still notify you promptly if a breach creates a real risk to you, as state law requires.

§ 18

Changes to this policy#

If we update this policy, the new version will be posted here with a new effective date, and the “last updated” date at the top of this page will change. If a change is significant, we will flag it plainly rather than burying it.

Changes to how we handle protected health information are made through our Notice of Privacy Practices, and we reserve the right to apply a revised notice to information we already hold.

§ 19

Contact our Privacy Officer#

Questions, requests, or complaints about privacy all go to the same place:

You may also file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights, at hhs.gov/ocr/complaints or 1-877-696-6775. We will never retaliate against you for filing a complaint — not by refusing care, not by treating you differently, not in any way.