Security & Confidentiality

Confidentiality isn't a feature. It's the job.

Your clients trust you with the most private material of their lives. A tool that sits between you and them has to earn a piece of that trust — so here is exactly how Mayva protects client conversations and session notes, in plain language, with nothing invented.

Encrypted at rest

Session notes and client conversations are encrypted at rest on our servers, and every connection is encrypted in transit. If confidentiality is the foundation of your practice, it has to be the foundation of your tools.

A full audit trail of every AI action

Every message the assistant sends, every slot it offers, every booking it makes, every reminder it dispatches — logged with a timestamp, readable by you. You never have to wonder what was said on your behalf. You can check.

Crisis-aware by design

Messages that sound urgent, emotional, or safety-related never get an AI reply. They bypass automation entirely and reach you immediately, and the client sees the crisis-support information you configured — not a chatbot. That routing decision is logged too.

Never used to train models

Your clients’ conversations and your notes are not training data. Not for us, and not for our AI provider — we operate on API terms that prohibit training on this content, and each AI call receives only the focused context needed for that one task.

Data isolation per practice

Every record in Mayva is scoped to your practice at the database level. In a clinic, each practitioner sees only their own clients and notes unless an admin explicitly grants access. There is no shared pool.

Access controls, including for us

Our team does not browse client conversations or session notes. Production access is restricted to a small number of engineers, is logged, and is used only to fix a problem you’ve asked us to fix — and we tell you when that happens.

The assistant never plays therapist

The clearest security boundary in Mayva isn't technical — it's behavioural. The AI handles logistics: bookings, reminders, intake forms, Meet links, payment nudges. It does not discuss feelings, symptoms, or anything clinical with your clients. Anything in that territory is escalated to you, untouched. Your clients get a very organised practice; they never get an AI pretending to be you.

What our servers hold, and why

Mayva is a hosted service, and we're plain about what that means: your clients' contact details, appointment history, WhatsApp conversations with your practice number, and your session notes live on our servers so your front desk can run 24/7. The full inventory — every category, every third-party service on the path, and every commitment about what we'll never do — is in our Privacy Policy. The short version:

  • Notes and conversations encrypted at rest; everything encrypted in transit.
  • Data flows only to the services that run your desk: Google Calendar and Meet for scheduling, the WhatsApp Business API for messaging, RazorpayStripe for payments, and an LLM provider for drafting — focused prompts only.
  • No selling, no advertising use, no model training. Ever.
  • Full export of your practice data whenever you ask, and deletion within 30 days of account closure.

You stay in control

  • Review everything. The audit log shows every action the AI took, in order, with the exact text sent.
  • Approve outreach. Follow-up messages the AI proposes — after a missed session, an overdue check-in — go out only when you approve them.
  • Sign your notes. Dictated notes are drafts until you review, edit, and sign them.
  • Disconnect any time. Unlinking Google Calendar or WhatsApp stops those data flows immediately; closing your account triggers export and deletion.

Where we are on formal certifications

Honesty over badges: we are an early-stage team and do not yet hold SOC 2 or ISO 27001 certification, and we won't pretend otherwise. Formal audits are on our roadmap as clinic and institute customers grow. What we have today is the engineering above — encryption, isolation, access controls, and audit logging — built in from day one, and a data posture designed to align with the spirit of India's DPDP Act, 2023the EU's GDPR, with EU data residencymodern US data-protection norms for coaches and cash-pay practices.

Found a vulnerability?

Email hello@mayva.ai with the subject "Security". We'll acknowledge within 3 business days, keep you posted while we fix it, and credit you publicly if you'd like. Please give us reasonable time before publishing, don't access data that isn't yours, and don't run automated scanners against production.