Your information
Privacy Policy
Kairn is built to help people find and contact independent therapists without selling their information or following them around the web with advertising trackers.
Scope and our role
This policy describes how Kairn handles information through its therapist directory, search, accounts, provider onboarding, basic first-contact messaging, waitlist alerts, optional consultation-time coordination, optional masked call forwarding, and notification features. Kairn is a technology and directory service, not a therapist or clinical practice. Kairn does not provide therapy, select a provider for someone, monitor clinical care, or coordinate care between providers.
When Kairn handles protected health information on behalf of a healthcare provider that is subject to HIPAA, Kairn acts as that provider's business associate and handles that information under a Business Associate Agreement. This policy is not a provider's HIPAA Notice of Privacy Practices and does not replace one. A provider's own notice explains how that provider uses and discloses medical information.
Information we handle
- Directory and search information. We process the location, care preferences, insurance, availability, and other filters you choose. If you use the optional free-text match, the text is sent in a private request, processed to rank results, and not saved as a search record. We record content-free counts such as profile views and appearances in results.
- Client account information. This can include your email address, a securely hashed password, email-verification status, notification choices, saved providers, and saved structured searches.
- Communications and care-seeking activity. If you contact a provider or ask to be notified, we handle your email address, inquiry and conversation messages, waitlist request, consultation time, and related delivery and response status. If masked calling is enabled, the call provider also handles the phone numbers and routing information needed to connect the call. The fact that someone is seeking mental-health care can itself be sensitive.
- Provider information. We handle identity and contact details, NPI and license information, practice details, availability, service locations, profile text and media, verification documents and results, account activity, and subscription status. Approved profile information is public; identity and verification documents are not.
- Technical and security information. Our hosting systems receive ordinary request information such as IP address, browser and device details, timestamps, requested pages, and security events. We use it to operate, protect, troubleshoot, and prevent abuse of the service.
- Support information. We receive the information you choose to include when you ask for account help, report an error, or contact us for another reason.
How we use information
We use information to:
- run directory search, guided search, waitlist alerts, and account features;
- deliver basic first-contact messages, optional consultation-time requests, and masked calls to the provider you selected;
- show replies and contact status to the right participants;
- verify provider identity, licensure, and profile information;
- send account, security, conversation, consultation-time, availability, and requested alert emails;
- maintain directory accuracy, measure content-free service performance, and improve reliability;
- detect abuse, investigate incidents, enforce our terms, and comply with law; and
- administer provider subscriptions and support requests.
When information is disclosed
We disclose information only as needed to provide and protect the service, fulfill your request, or comply with law. That can include:
- The provider you choose. When you start a conversation, join that provider's waitlist, or request a consultation, the provider receives the information needed to respond.
- Service providers. Google Cloud hosts the application, databases, encryption, storage, and private search-text processing; Amazon SES delivers email; Stripe supports provider identity verification and billing; and Twilio may route a masked call if that optional feature is enabled. These companies receive only the information needed for their function. Kairn is designed to keep client health information out of Stripe.
- Verification sources. We may compare provider-supplied professional information with licensing boards, the NPI registry, ORCID, and other authoritative or public sources.
- Legal and safety needs. We may preserve or disclose information when reasonably necessary to comply with law, respond to valid legal process, protect people, investigate fraud or security incidents, or defend legal rights.
- A business transition. If Kairn is involved in a financing, reorganization, acquisition, or sale, information may be reviewed or transferred subject to appropriate confidentiality and applicable healthcare obligations.
We do not sell personal information. We do not use personal information for targeted advertising, and Kairn does not place third-party advertising or analytics pixels on the service.
Cookies and browser storage
Kairn uses functional browser storage, not advertising cookies. A signed, HTTP-only session cookie keeps an account signed in for up to 30 days. We may briefly use browser session storage to carry an optional private search description between Kairn pages; it is removed after redemption. Provider onboarding may use local browser storage to resume an application after a Stripe identity-check redirect. A password-protected staging site may use a separate access cookie. You can clear these items through your browser, but doing so may sign you out or discard unfinished work.
Retention and deletion
We keep information only for as long as needed for the feature, account, security, legal, or healthcare-record purpose for which it is held. Used and expired sign-in tokens are removed. Saved providers and saved searches remain until you delete them or the client account.
Under Kairn's current service retention schedule, conversations, their messages and consultation records, and provider-reopening waitlist entries are scheduled for deletion after 24 months. If a client deletes an account sooner, Kairn immediately deletes the account, saved items, notification choices, and identifiers that tie retained conversations to that account. Conversation content and related consultation records may remain temporarily as the selected provider's BAA-governed record until the retention window ends. Providers can request account offboarding through support.
Your choices and requests
- Change optional email choices in account settings or use the category-level unsubscribe link in an optional email.
- Delete a client account from the account page.
- Delete saved searches and saved providers from their respective pages.
- Ask us to access, correct, or delete other account information by contacting support.
- Direct a request about a provider's medical record or HIPAA rights to that provider; Kairn will assist the provider when its Business Associate Agreement requires it.
Applicable law may provide additional privacy rights. We may need to verify your identity before completing a request.
Security
Kairn uses safeguards including encryption in transit, additional application-layer encryption for private client communications, access controls, audit logging, private document storage, and service-provider agreements where required. No internet service can promise perfect security. If you believe information is at risk, contact us promptly and do not include clinical details in ordinary email.
Policy changes
We may update this policy as the service or law changes. We will post the revised policy here with a new effective date and provide additional notice when required.
Contact
Privacy questions and requests can be sent to support@kairn.health. Please do not send message content, diagnoses, treatment details, or other clinical information by ordinary email.
In a crisis
Kairn support and messaging are not emergency services. If you're in crisis, call or text 988 — free, 24/7. Text HOME to 741741 to reach a crisis counselor. In an emergency, call 911.