Privacy Policy

Think Beyond Practice LLC | Last Updated: June 1, 2026

1. Introduction

This Privacy Policy describes how Think Beyond Practice, LLC ("Think Beyond Practice," "we," "us," or "our") collects, uses, shares, discloses, and retains (cumulatively “Process” or “Processes”) Personal Information (as defined below) about you when visiting our Website (www.thinkbeyondpractice.com) or using the services provided through our Think Beyond Practice Platform, comprised of the Practice Hub, the Credentialing Hub and the Community and Education Hub, as well as all tools, features and services provided through those Hubs (collectively, the "Platform"), and our practices for protecting that Personal Information.

"Personal Information" is information that identifies, relates to, or describes, directly or indirectly, you as an individual, such as your name, email address, telephone number, home address, or payment information (for example, credit card number), and any other identifier we may use to identify you or contact you. We do not collect consumer health data, as defined under state consumer health privacy laws (i.e., health information that falls outside HIPAA). We do, however, Process Protected Health Information (“PHI”) through the Platform – included within the above definition of Personal Information - in accordance with HIPAA, pursuant to a Business Associate Agreement entered into between a Member’s practice/organization and Think Beyond Practice.

As used in this Policy, “Member” means any individual we authorize to access the Platform (through creation of a Member account), including clinicians and their authorized medical, administrative and support staff.

This Privacy Policy applies to Personal Information we collect:

This Policy does not apply to Personal Information or other information:

This Privacy Policy should be read together with our Terms of Service, and is in addition to any state-specific privacy policies that may supplement this Policy, as well as, where applicable, the Business Associate Agreement executed between a Member’s practice/organization and Think Beyond Practice.

By using our website or the Platform, you consent to the practices described in this Privacy Policy.

We may provide additional or different privacy policies that are specific to certain features, services, or activities, when applicable.

2. Categories of Information We Collect

2.1 Personal Information You Provide Directly

When you visit our Website or use the Platform, access content, view demonstrations, attend webinars, meetings or other events that we host, communicate with us, create an account, or subscribe, we collect information you provide, which may include:

Some Personal Information collected may be considered “Sensitive Personal Information” under certain laws. If required under applicable law, we will collect and process Sensitive Personal Information only with your consent. If you choose not to provide or allow us to collect some information, we may not be able to provide you with requested features, services, or information

2.2 Protected Health Information (PHI) About Patients

The Practice Hub enables Members to input PHI about patients for the purpose of generating outputs (such as letters, assessments, treatment plans, chart note content, or reference materials). To the extent the Platform Processes PHI on behalf of a Member’s practice/organization this Processing is governed by HIPAA and the BAA executed with Think Beyond Practice.

Categories of PHI that may be Processed include:

Important: The Platform is designed to minimize PHI persistence, but some PHI is retained for a limited, defined period. Most patient-facing features (such as letters, chart note content, and treatment plans) Process PHI transiently and auto-delete it after delivery to the Member. Certain features, however, retain PHI for a defined period in order to function, as follows:

Assessments. Where a Member sends a patient a validated self-report questionnaire, it uses a secure link that expires fourteen (14) days after it is sent, and may be used only once. Completed patient responses are retained for up to thirty (30) days following completion so that Members can retrieve and review the result, and are thereafter automatically deleted. A Member may delete results sooner if they choose. After deletion, only summary metadata (scores and dates, without direct patient identifiers) is retained (still considered PHI, and protected accordingly), which is used to display the patient's progress trend over time to that Member.

Recurring (scheduled) assessments. A Member may schedule questionnaires to be sent to a patient automatically on a recurring basis (weekly, monthly, or quarterly). Delivery is by email only. Where a Member creates such a schedule, the patient's email address and the schedule are retained for as long as the schedule remains active, so that the Platform can send the scheduled questionnaires without further input from the Member. The Member may pause or end a schedule at any time, and the patient may opt out from any message they receive. The Member is responsible for informing the patient of the risks of including PHI in email and obtaining the patient's consent to include their PHI in email, before using this feature.

PHI retained by these features is retained solely to provide the feature the Member has requested, is accessible only to the Member who created the record, and remains subject to the BAA between the Member and Think Beyond Practice. PHI is removed from active production systems at the end of the applicable retention period, subject to the backup retention described in Section 6.5.

2.3 Categories of Information Collected Automatically

When you use the Website - to the extent you choose to enable certain cookies/automated tracking technologies such as pixels, and web beacons, etc. (see Section 8) - we may automatically collect certain information, including:

While we do not use 3rd party cookies, pixels, web beacons or other similar automated tracking technologies on the Platform, we may collect some of the above information, such as Device Information or Log Information. Where this information is associated with a Member's account, it may be used to maintain/improve the Platform and inform feature development.

Statistics or aggregated information. Statistical or aggregated data does not directly identify a specific person, but we may derive non-personal statistical or aggregated data from Personal Information. For example, we may aggregate Personal Information to calculate the percentage of users accessing a specific Platform feature.

If we combine or connect non-personal statistical or technical data with Personal Information so that it directly or indirectly identifies an individual, we Process the combined information as Personal Information.

2.4 Information We May Receive from Third Parties

We may receive Personal Information about you from other sources. For example, we may obtain Personal Information about you from service providers that we engage to perform services on our behalf, such as

Some of these sources, such as public databases and marketing or referral partners, are not controlled by us, and we do not control the data they collect or retain. If you have questions about an advertisement or other third-party content, you should contact the responsible provider directly. If you have any questions about an advertisement or other third-party content, you should contact the responsible provider(s) directly.

3. How We Use Personal Information

We may use the Personal information we collect for the following purposes (some of which may be subject to your opting-in through our cookie preference choices):

3.1 Provide and Operate the Platform

3.2 Improve the Platform

3.3 Communicate With You

3.4 Maintain Security and Compliance

3.5 Specific to PHI

PHI Processed through the Platform is solely for the purpose of providing the specific tool/feature the Member has requested (such as generating an assessment summary, drafting a letter, or producing a treatment plan), and is Processed pursuant to an agreement between the Platform and the Member – known as a Business Associate Agreement - in which we agree to Process and safeguard that Information in accordance with HIPAA. PHI is not used for advertising, sold to third parties, or used to train AI models, and is not retained beyond the periods described in Sections 2.2 and 6.2. Likewise, any disclosures of PHI by the Platform to our service providers are also subject to a BAA, wherein our providers agree to Process PHI in accordance with our HIPAA obligations and commitment to Members.

4. AI Features and PHI

The Platform provides AI-assisted features, to include:

We do not train AI models. Our AI service providers are contractually prohibited under BAAs from using data submitted through the Platform to train their models. If we develop our own AI training in the future, we will use only data that is de-identified in accordance with HIPAA or synthetically generated, or content Members explicitly contribute under our Terms of Service.

5. Categories of Personal Information We Share

5.1 Information We Share With Third Parties

We may Share Personal Information that we collect or you provide to us, with our trusted contractors, service providers, sub-processors and other third parties we use to support our organization, and for operating and maintaining the Platform, each of whom are bound by contractual obligations to keep Personal Information confidential and use it only for the purposes for which we disclose it to them (and not for their own purposes). These third parties include:

A current list of subprocessors that may Process information on our behalf is available at https://thinkbeyondpractice.com/subprocessors. Where these providers Process PHI on our behalf, we maintain BAAs with them, as required by HIPAA.

5.2 The Categories of Personal Information we may Share with Third Parties include:

5.3 Members Forum and Community Features

Information you choose to share through the Community and Education Hub (such as your name, professional credentials, posts, and comments) is visible to other Members and, where applicable, to the public in general. As such, please do not share information through our Community and Education Hub that you do not want to be visible to others.

5.4 Sharing For Legal and Safety Purposes

We may Share Personal Information when we believe in good faith that disclosure is necessary to:

5.5 Sharing in the Case of Business Transfers

Sharing of Personal Information may occur if Think Beyond Practice, LLC is involved in a merger, acquisition, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which Personal Information is among the assets transferred. We will provide notice before your Personal Information becomes subject to a different privacy policy.

5.6 Sharing With Your Consent

We may share information for any other purpose with your explicit consent.

5.7 Sharing For Advertising/Cross-contextual Advertising

On our public Website, we use advertising provided by Meta and Google. Advertising (to include 3rd party automated tracking technologies) is off by default, and operates only if you affirmatively opt in through our cookie banner. Where you opt in, information about your visit may be shared with third-party advertisers, which may constitute "Sharing" for cross-context behavioral advertising purposes under state privacy laws. This Sharing never involves PHI, as we do not collect or otherwise process PHI on our public Website, and do not use 3rd party analytics or advertising on the Platform. If you opt-in to advertising, you may withdraw consent at any time through our cookie banner or by transmitting a Global Privacy Control signal. We do not sell Personal Information.

6. Data Retention

We keep the categories of Personal Information described in this Policy for as long as reasonably necessary to fulfill the purposes described, or as otherwise legally permitted or required, to include for:

We retain different categories of information for different periods:

6.1 Member Account Information Retained for as long as your account is active. After account closure, we retain account information for a reasonable period to comply with tax, accounting, and legal obligations Some information may be retained longer if required by law, legal hold, dispute resolution, or regulatory compliance.

6.2 PHI provided by Members Most PHI is auto-deleted after delivery of the requested output to the Member. Where a feature requires retention in order to function, the following periods apply: assessment links expire fourteen (14) days after being sent; completed patient assessment responses (which are PHI) are retained for up to thirty (30) days following completion and are then automatically deleted (a Member may delete them sooner); summary metadata (scores and dates, without direct patient identifiers) is retained after that deletion in order to display a progress trend to the Member; and where a Member has created a recurring assessment schedule, the patient's email address and the schedule are retained for as long as that schedule remains active, and are deleted when the Member ends the schedule. Some metadata without direct patient identifiers (such as timestamps of feature use) may be retained for usage analytics.

6.3 Forum Content Forum posts, comments, and contributed content remain on the Platform after your account closure unless you specifically request deletion, in which case we will determine on a case-by-case basis (unless we are required to retain the data by law, regulation, preservation order, etc.). Anonymized or aggregated forum content may be retained for community continuity.

6.4 Communications With Us Support emails, feedback, and other communications are typically retained for two years after the conversation ends, unless retained longer for legal or operational reasons.

6.5 Backups Information in encrypted backups may persist for a limited period after deletion from production systems before being overwritten through our normal backup rotation.

6.6 Audio Recordings Uploaded by Members. Where a Member uses the ambient documentation feature, the audio recording is transcribed and then deleted. The Member is responsible for securing the patient's legal consent to record. The transcript is used only to pre-populate the structured inputs the Member reviews, and is not retained. We keep only the documentation the Member reviews and approves. Any speech-to-text provider we use processes the audio as our subprocessor under a Business Associate Agreement that prohibits it from using or retaining the audio or transcript.

At the end of the retention period, Personal Information will be deleted or de-identified in accordance with HIPAA.

As noted above, we do not control third parties’ processing of Personal Information, and thus retention of that information will be in accordance with those third parties’ retention policies.

7. Data Security

We implement administrative, technical, and physical safeguards designed to protect information, including your Personal Information, from accidental or unauthorized access, use, alteration, or destruction, including:

No security measures are perfect. While we work to protect your Personal Information, we cannot guarantee absolute security. Likewise, email, texts, and other communications may not be secure, so you should carefully decide what information you send to us via such communications channels. Any transmission of Personal Information is at your own risk.

You are responsible for maintaining the confidentiality of your account credentials and notifying us promptly of any suspected compromise at privacy@thinkbeyondpractice.com.

8. Cookies and Tracking Technologies

A. Cookies and Similar Technologies

Cookies are small text files placed on your device when you visit a website. We do not set our own first-party cookies; features that require it (such as keeping you signed in and remembering display preferences like a light or dark theme) use first-party browser storage kept on your device, not cookies. Our Website may also use third-party cookies and similar automated technologies, such as web beacons and pixels - subject to your opt-in consent - which come from or send information to third-party partners like Google Analytics and Meta. The purposes for which we may use third-party cookies, as set out in Sections 3, 4 and 5.

The first time you visit our public Website, you will be asked to choose which cookies to allow or decline (you cannot decline strictly necessary cookies). By default, only strictly necessary cookies are active; analytics and advertising cookies are turned off by default, and are set to on only if you affirmatively opt in. Please note that if you enable third-party cookies, the use of data collected through those cookies may be governed by that third-party’s privacy policy, which is not binding on us.

When you make your cookie choices, we document those choices, along with your IP address and the date and time. Cookie choices are specific to a user’s browser, so if you choose cookies with one browser (e.g., Google Chrome), but visit the Website next time using a different browser (e.g., Microsoft Edge) – or a browser whose cache you’ve recently cleared– you may be asked to make new cookie choices.

B. Global Privacy Control (GPC) / Do Not Track (DNT)

We honor GPC and DNT signals where technically feasible. Because support for these signals varies across browsers and extensions, and because there is no consistent industry standard, we cannot guarantee recognition in every case. To ensure that your information is not shared with third-parties for analytics or advertising purposes, we recommend leaving analytics and advertising cookies turned off in our cookie banner (they are off by default).

C. Authenticated Platform Pages

The distinction between our public Website and our authenticated Platform pages (i.e., pages accessible only to Members after logging in), hereafter “authenticated pages”, including the Practice Hub, the Credentialing Hub, and the Community and Education Hub, is important. On authenticated pages we do not use analytics or advertising cookies, pixels, web beacons or any other automated tracking technologies. While you are not presented with cookie choices when logging into the Platform, it’s important to note that cookies on these authenticated pages are limited to strictly necessary cookies to authenticate you, maintain your session, and operate the tools you request. Because we place no analytic, advertising or other third-party cookies/technologies on authenticated pages, there is no third-party data sharing through these pages.

9. Your Privacy Rights

We extend the same privacy options to all Members and visitors regardless of state of residence. We extend these as a matter of practice, drawing on the California Consumer Privacy Act (CCPA)/California Privacy Rights Act (CPRA) and other state privacy laws, regardless of whether a given law applies to us.

9.1 Your Options

We extend the following options to everyone:

If you believe we have not handled your request appropriately, or disagree with an Appeal finding, you may have the option to:

9.2 How to Exercise Your Options

To exercise any of these options, contact us at privacy@thinkbeyondpractice.com with:

You may also submit requests by mail to the address listed in Section 15.

9.3 Verification and Response Timeframes

We will respond to your request within forty-five (45) days. We may extend the response period by an additional forty-five (45) days where reasonably necessary, in which case we will notify you of the extension and the reason.

To protect your privacy, we will verify your identity before responding to requests. The verification process may require you to provide Personal Information that matches information we already have on file. For sensitive requests, we may require additional verification steps.

9.4 Limitations and Exceptions

We may decline to fulfill a request, or fulfill it only partially, where:

If we decline a request in whole or in part, we will explain the reason and describe any options you have to appeal.

9.5 Patient Rights Under HIPAA

Patients of Members seeking to exercise rights under HIPAA (including access to records, amendment requests, accounting of disclosures, etc.) should direct those requests to their healthcare provider, not to Think Beyond Practice. As a Business Associate, we will support Members in responding to patient requests as required by our BAA with Members.

10. Payments

We use third-party service provider Stripe for payment processing. Stripe may collect Personal Information including via cookies and similar technologies. The Personal Information Stripe collects may include transactional data and identifying information about devices that connect to its services.

We do not store your payment card details. That information is provided directly by you to Stripe whose use of your Personal Information is governed by their privacy policy. Personal Information collected by Stripe may include name, email address, billing address, and payment information (e.g., credit card number and associated data) and/or payment account ID, as applicable. Stripe uses this information to operate and improve the services it provides to us, including for fraud prevention and detection, authentication, analytics related to the performance of its services, and to enhance and customize the user experience.

The Platform will generally have access to certain anonymized, limited and/or truncated versions of payment/transaction information through Stripe, such as customer name and email, the amount of the transaction, the last four digits of the card used, the card brand, and the date.

Stripe adheres to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, Mastercard, American Express, and Discover. PCI-DSS requirements help ensure the secure handling of payment information.

For more information about the privacy practices of Stripe, please visit their privacy policy: https://stripe.com/us/privacy.

11. Children's Privacy

Our website and the Platform are intended for use by adult Members and visitors that are 18 years of age or older. We do not knowingly collect information directly from children under eighteen. If you believe a minor under eighteen has provided information to us, please contact privacy@thinkbeyondpractice.com so we can take appropriate action.

To the extent Members provide information about minor patients through use of the Platform, Processing is governed by HIPAA and the BAA which Members have signed with the Platform (and as directed by Members, in accordance with their HIPAA obligations and Notice of Privacy Practices).

12. Where Our Services Are Available

Our services are available only to users located in the United States, and are designed for and directed to U.S. residents. We do not knowingly target or market to individuals outside the United States, or to individuals temporarily visiting or residing in the U.S. from other countries. To help us maintain this geographic limitation, we use technology such as IP address detection to identify where visitors are accessing our Services from. If our systems detect that you're trying to access our Services from outside the U.S., we may restrict your access.

13. Third-Party Links and Services

The Platform may contain links to third-party websites or services that we do not control. This Privacy Policy does not apply to those third parties. We are not responsible for the privacy practices or content of third-party services, so you should review the privacy policies of those third-party services.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

Continued use of the Platform after the effective date of the updated Privacy Policy constitutes acceptance of the updated policy. If you do not agree to the updated policy, you must stop using the Platform.

15. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your information, contact us at:

Think Beyond Practice, LLC: 9631 N Nevada St, Suite 209 Spokane, WA 99218

Privacy and Security: privacy@thinkbeyondpractice.com General Support: support@thinkbeyondpractice.com Legal Notices: legal@thinkbeyondpractice.com

For HIPAA-related concerns where you believe your protected health information has been mishandled, contact privacy@thinkbeyondpractice.com. You may also file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights at https://www.hhs.gov/hipaa/filing-a-complaint/.