Privacy policy

How Miwa handles your data

Miwa is built for mental health clinicians and the sensitive information that comes with clinical work. This policy explains what we collect, how we use it, who we share it with, and how to contact us.

Effective date: July 5, 2026 |Last updated: July 5, 2026

1. Who we are

Miwa is operated by Miwa Health Technologies LLC, a California limited liability company. We provide an electronic health record (EHR) and AI clinical assistant - clinical documentation, assessment, scheduling, billing, and workflow tools - for mental health professionals.

Privacy questions can be sent to privacy@miwa.care.

2. Who this policy covers

This policy covers therapists who create a Miwa account and clients whose information is entered into Miwa by their therapist.

Therapists are Miwa's direct customers. When a therapist uses Miwa for client care, that therapist or their practice remains responsible for the clinical relationship and the medical record. For covered clinical workflows, Miwa acts as a HIPAA Business Associate under the applicable Business Associate Agreement.

3. Information we collect

Therapist account information

  • Name, email address, login credentials, practice information, license details, phone number, time zone, and account settings.
  • Billing status and subscription information. Payment card numbers are handled by our payment processor and are not stored by Miwa.
  • Device, browser, usage, and error information needed to keep the service secure and reliable.

Client information entered by therapists

  • Client names, contact details, dates of birth, appointment history, and other identifiers entered by the therapist.
  • Session notes, treatment plans, diagnoses, assessments, scores, and related clinical documentation.
  • Client responses submitted through secure assessment links created by the therapist.

Audio, phone, and mobile app data

  • If a therapist uses recording or transcription features, audio may be processed to create clinical documentation.
  • If a therapist enables the optional Miwa Front Desk phone line, an AI assistant answers overflow or after-hours calls for the practice. The assistant discloses to every caller that it is an AI, collects intake information for the therapist to review, follows a crisis protocol that refers callers to 911 or 988, and does not record call audio by default. Caller audio is streamed through our telephony provider and is not persisted by Miwa.
  • The mobile app may use microphone access only when the therapist turns on a recording or voice feature.
  • The app does not access contacts, photos, SMS history, or location for clinical documentation.

4. How we use information

  • To provide Miwa's clinical documentation, assessment, scheduling, and workflow features.
  • To generate AI-assisted drafts and summaries for therapist review.
  • To manage accounts, billing, support, and product communication.
  • To protect Miwa from abuse, security incidents, and unauthorized access.
  • To meet legal, compliance, accounting, and operational obligations.

Miwa does not sell client data, therapist data, notes, transcripts, assessment results, or clinical datasets. Miwa also does not use protected health information to train AI models.

5. AI-assisted features

Miwa uses AI to help therapists draft, organize, summarize, and review clinical material, and to power an optional Front Desk phone assistant. AI output is a draft for professional review. It does not replace the therapist's judgment, documentation duties, supervision requirements, or client consent obligations.

Miwa's AI is a tool. It is not a licensed health professional and does not provide medical, psychological, or clinical advice, and it does not imply that it is a licensed professional or that any AI output is the advice, care, report, or service of a licensed professional. The therapist (or their practice) is the Covered Entity and the licensed provider of care; the clinician reviews every AI-generated draft before it enters the chart.

Clinical data is handled through approved service paths for covered workflows under signed Business Associate Agreements, and Miwa is designed to send only the information needed for the requested task. Miwa does not use protected health information to train AI models.

6. How we share information

We share information only when needed to run Miwa, support users, protect the service, comply with the law, or complete a business transaction under appropriate protections.

Service providers and subprocessors

Miwa works with service providers for hosting, storage, AI processing, email, telephony, payments, security, analytics, support, and other operations. When a provider may handle protected health information for a covered workflow, we require a signed Business Associate Agreement (or equivalent contractual safeguards) before that use.

Current subprocessors that may handle PHI for covered workflows, and their BAA status:

ProviderPurposeBAA status
Microsoft Azure (US)Hosting, PostgreSQL, Blob storage, Azure OpenAI, transactional emailSigned
OpenAIClinical reasoning, realtime voice, audio diarization (Zero-Data-Retention lane)Signed; ZDR
Google WorkspaceEmail (Gmail + Gemini in Workspace)Signed (Gemini in Chrome excluded)
TwilioSMS notifications and optional Front Desk voice lineSigned (SMS + Voice)
StripeClinician subscriptions; optional clinician client billingNo BAA — kept PHI-free by design
ResendLegacy non-PHI email fallbackNo BAA — non-PHI only

SMS message bodies are fixed, minimum-necessary, and PHI-free (no names or clinical content; links go to the authenticated portal). Front Desk call audio is PHI and is handled under the Twilio BAA; it is not persisted by Miwa, and recording is off by default.

Legal and safety reasons

We may disclose information when required by valid legal process, to protect against fraud or abuse, or to help prevent serious and imminent harm, consistent with applicable law.

Business transfers

If Miwa is involved in a merger, acquisition, financing, or sale of assets, information may transfer as part of that transaction. Protected health information would remain subject to required safeguards and notice obligations.

7. HIPAA and clinical records

When Miwa processes protected health information for a covered therapist or practice, Miwa acts as a Business Associate. We use that information to provide the service requested by the therapist and to meet obligations in the applicable Business Associate Agreement.

Clients who want to access, amend, or receive an accounting of disclosures for their clinical record should contact their therapist directly. The therapist or practice is the Covered Entity and has the primary relationship with the client.

For California residents, medical information — including mental health information — is also protected by the California Confidentiality of Medical Information Act (CMIA). Miwa does not sell medical information and does not share it with third parties except as permitted by HIPAA, the CMIA, and the therapist's instructions.

8. Security

Miwa uses administrative, technical, and organizational safeguards intended to protect sensitive clinical information. These include encryption, access controls, secure authentication, operational logging, restricted production access, and secure patient links.

No internet service can promise perfect security. If you believe you found a vulnerability, email security@miwa.care.

9. Retention

Miwa keeps information only as long as needed for the service, legal obligations, account administration, security, backup, or clinical recordkeeping.

  • Therapist account data is kept while the account is active and for a limited period after deletion for recovery, billing, legal, and security needs.
  • Clinical records are retained according to the therapist's recordkeeping obligations and the settings or instructions available in Miwa.
  • Operational logs and backups are retained under Miwa's security and retention practices.
  • Audio is retained only as needed for transcription, troubleshooting, or therapist-requested storage.

10. Your choices and rights

Therapists

Therapists can request access, correction, export, or deletion of account information by contacting privacy@miwa.care. Some information may need to be retained for legal, billing, security, or clinical recordkeeping reasons.

Clients

Clients should contact their therapist to exercise HIPAA rights connected to their clinical record. Miwa will assist the therapist as required.

California residents

California residents may have rights to know, access, correct, delete, or limit certain personal information. Some clinical information regulated by HIPAA may be exempt from California consumer privacy law. To make a request, email privacy@miwa.care from the address connected to your account or care relationship.

11. Children

Miwa is not directed to children under 13, and children do not create Miwa accounts. Therapists may document care involving minors when clinically appropriate and legally permitted.

12. International use

Miwa is built for use by clinicians in the United States. If you use Miwa from outside the United States, your information may be processed in the United States.

13. Changes to this policy

We may update this policy when Miwa changes, when our legal obligations change, or when our privacy practices need to be clarified. If a change is material, we will provide notice by email or inside the product before the change takes effect.

14. Contact

Miwa Health Technologies LLC

California Secretary of State entity no. B20260260162

Los Angeles, California, United States

Privacy: privacy@miwa.care

Security: security@miwa.care

If you believe your HIPAA rights have been violated, you may also file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights at hhs.gov/hipaa/filing-a-complaint.