Privacy

Privacy policy

EFFECTIVE DATE · 13 July 2026

Short version. Mayva is a hosted service that runs the front desk of your therapy or counselling practice. To do that job, we store your clients' contact details, appointment history, conversation logs, and your session notes on our servers. Session notes and client conversations are encrypted at rest. Every action the AI takes is logged and reviewable by you. Your clients' data is never used to train AI models, never sold, and never shown to advertisers. Confidentiality is the foundation of your practice, so it has to be the foundation of ours. If anything in the product doesn't match this document, tell us at hello@mayva.ai — we treat policy/behaviour mismatches as bugs.

This policy is written in plain language on purpose. We're a small team building for practitioners in India practitioners across Europe practitioners in the US, and we'd rather you actually read this than scroll past ten pages of legalese. It applies to the mayva.ai website and the Mayva service (the web app, the booking pages we host for you, and the WhatsApp assistant that acts on your behalf).

Throughout, "we" / "us" is the team operating Mayva. "You" is the practitioner (or clinic) holding the Mayva account. "Your clients" are the people you see in your practice, whose information you manage through Mayva.


1. Two kinds of data, two kinds of responsibility

Mayva handles two distinct categories of personal data:

  • Your data — your name, email, phone number, practice details, calendar connection, and billing state. You gave this to us directly when you signed up.
  • Your clients' data — names, phone numbers, appointment history, WhatsApp conversations with your practice number, payment status, and the session notes you write or dictate. This data belongs to your practice. We process it on your instructions, to run your front desk — and for no other purpose.

You remain responsible for the clinical relationship with your clients, including obtaining whatever consent your professional standards require for keeping records. Mayva's job is to keep that data safe and to do only what you've configured it to do.


2. What we store

CategoryWhat it isWhy we store it
Practitioner accountYour name, email, phone, practice name, timezone, plan and billing state.To operate your account, bill you, and send you service emails.
Client contact detailsNames and phone numbers of your clients, plus any intake-form answers they submit.So Mayva can recognise returning clients, send reminders, and route new inquiries to you.
AppointmentsSession dates, times, mode (online/in-person), status (booked, completed, cancelled, no-show), and the Google Meet link for online sessions.Scheduling, reminders, reschedules, and your weekly digest.
Session notesNotes you write or dictate after sessions, and the voice-dictation transcripts they're drafted from. Encrypted at rest.So you have a searchable, private record. Notes are visible only to you (and, on Clinic plans, to practitioners you explicitly grant access).
Client conversationsWhatsApp messages between clients and your practice number, and the AI's replies. Encrypted at rest.So you can review everything the assistant said, and so context carries across a conversation.
Payment recordsWhich sessions have a payment link, whether it's paid or pending, and amounts. We never see or store card numbers or UPI credentials — Razorpay handles those. — Stripe handles those.Payment follow-ups and monthly reconciliation.
AI action logA record of every action the AI took on your behalf — every message sent, slot offered, booking made, reminder dispatched, escalation raised — with timestamps.So you can audit your front desk. This log is a feature, not telemetry.

Voice dictation audio is processed to produce a transcript and note draft; we don't keep raw audio longer than needed to complete that processing.


3. The services we use to run your front desk

Mayva doesn't work alone. Here is every external service on the path, what flows to it, and why.

ServiceWhat flows to itWhy
Google Calendar & Google MeetSession events (title, time, client's name as you've saved it, Meet link) written to the calendar you connect. We read your availability to offer slots.Scheduling and video-session links. We touch only the calendar you connect; your personal events are read for availability, never copied into Mayva.
WhatsApp Business API (Meta)The messages sent and received on your practice number.This is how your clients reach you. Meta processes WhatsApp messages under its own terms, as it does for any WhatsApp Business number.
RazorpayStripePayment link details (amount, reference) and payment status. Your clients pay RazorpayStripe directly; money lands in your account.Payment links and follow-ups, plus billing for your Mayva subscription.
LLM provider (AI drafting)Focused prompts only — the minimum context needed for the specific task, e.g. the current conversation thread to draft a reply, or your dictation transcript to draft a note. Never your full client database, never bulk exports.Drafting replies, structuring session notes, classifying inquiries. We use providers whose API terms commit to not training models on API content, and we contractually don't permit our data to be used for training.
Cloud infrastructureThe encrypted databases and application servers Mayva runs on.Hosting. Bound by data-processing terms that limit use to providing the service.

Each of these providers has its own privacy policy for the data that passes through it. We pick providers with clear, published privacy postures, and we send each one only what its job requires.


4. How the AI uses data — and how it doesn't

  • Focused prompts only. Each AI call includes only the context needed for that one task. Drafting a reply to a reschedule request doesn't require — and doesn't receive — your session notes.
  • Never for training. Your data and your clients' data are not used to train AI models — not by us, and not by our LLM provider under the API terms we operate on.
  • Logged and reviewable. Every AI action lands in your audit log. You can read exactly what was sent, to whom, and when.
  • Logistics only. The assistant handles bookings, reminders, forms, and payments. It does not give clinical or therapeutic advice.
  • Crisis-aware. Messages that appear urgent, emotional, or safety-related bypass AI replies entirely and are escalated to you immediately. This routing decision is itself logged.

5. Security

  • Encryption at rest for session notes and client conversations, and encrypted storage for the rest of your practice data.
  • Encryption in transit — all connections use TLS; we don't speak plain HTTP.
  • Data isolation per practice. Every query in our system is scoped to your practice. Practitioners on Clinic plans see only the clients assigned to them, per the roles the admin sets.
  • Access controls internally. Our team does not browse client conversations or session notes. Production access is restricted, logged, and used only to fix a problem you've asked us to fix — and we'll tell you when that happens.
  • Audit trail of AI actions and of access to your data.

More detail, including what's on our security roadmap, lives on the Security & Confidentiality page.


6. What we will never do

  • Sell, rent, or trade your data or your clients' data.
  • Use client data for advertising, profiling, or marketing — ours or anyone else's.
  • Use your data or your clients' data to train AI models.
  • Contact your clients for any purpose other than the front-desk work you've configured.
  • Share data with anyone except the service providers in §3 — unless a binding legal process (a court order or equivalent) compels us, in which case we disclose only the specific records identified and will notify you where the law allows.

7. Retention, export, and deletion

  • While your account is active, we keep your practice data so your records stay complete — clinical record-keeping usually requires history, so nothing is auto-purged without your instruction.
  • Deleting individual records. You can delete a client's record, a conversation, or a note from inside Mayva at any time.
  • Export. You can request a full export of your practice data (clients, appointments, conversations, notes) in a machine-readable format at any time — including during your trial and on cancellation. Email hello@mayva.ai.
  • On account closure, we delete your practice data within 30 days of your confirmation that you have the export you need. Exceptions: billing records we're required to keep for tax purposes, and short-lived encrypted backups that age out on their own schedule.

8. Your rights, and your clients' rights

Mayva is built India-first, and we've designed our data handling to align with the spirit of the Digital Personal Data Protection Act, 2023.Mayva is built to align with the EU General Data Protection Regulation (GDPR), with EU data residency.Mayva is built with strong, modern data-protection practices for coaches and cash-pay practices. The principle is the same everywhere: collect only what's needed, use it only for the stated purpose, keep it secure, and delete it when it's no longer required. We don't claim any certification — we claim the practice.

You can, at any time:

  • Access and export the data we hold for your practice.
  • Correct anything that's wrong.
  • Delete records, or close your account and have your data erased (§7).
  • Withdraw any integration — disconnecting Google Calendar or WhatsApp stops those data flows immediately.

If one of your clients asks about their data, that request comes through you — you own the relationship, and we act on your instructions. If a client contacts us directly, we'll refer them to you and help you fulfil the request (for example, by producing an export of that client's records).


9. Children

Mayva accounts are for practising professionals aged 18 or over. Some practices see minor clients; where that's the case, you are responsible for obtaining guardian consent as your professional standards and applicable law require. We apply the same confidentiality protections to every client record regardless of age.


10. Changes to this policy

When we add or change a feature in a way that changes what data we handle, we'll update this page, change the effective date at the top, and email account holders before any material change takes effect. If you don't agree with a change, you can export your data and close your account before it applies.


11. Contact

Questions, rights requests, exports, deletions, or anything that doesn't look right: hello@mayva.ai. We aim to respond within 3 business days, and to complete rights requests within 30 days.


Last updated: 13 July 2026.