Back to the app
Legal

Privacy policy

Last updated 11 August 2026 · Version 1.0

MHABot is a writing tool for clinicians. The shortest useful summary of this policy is that the assessment you write never reaches our servers. It is assembled in your browser and stays there. What we hold is an account, a session, and a count of how many notes you have written.

In one paragraph

We store your Google account email and name, a session token, how many notes you have generated, and any feedback you send us. Payments are handled by Stripe, who we never send card details to ourselves because we never see them. We do not store, transmit, or have any means of reading the clinical text you write. No advertising or analytics code runs on the assessment screen at all, and nothing is sold to anyone.

On this page
  1. Who we are
  2. What we collect
  3. What we never collect
  4. Why, and on what legal basis
  5. Cookies
  6. Who else is involved
  7. How long we keep things
  8. Security
  9. Your rights
  10. International transfers
  11. Changes
  12. Contact

1. Who we are

MHABot is registered with the Information Commissioner's Office under reference ZC219541.

For anything in this policy, write to info@mhabot.com.

2. What we collect

When you sign in

We use Google Sign-In. Google gives us three things: a stable account identifier, your email address, and the display name on your Google account. We do not receive your Google password, your contacts, or anything else from your Google account.

While you are signed in

WhatWhy
A random session tokenTo keep you signed in. Stored on our side as a one-way hash, so the value in our database cannot be used to impersonate you.
A one-way hash of your IP address and browser stringTo detect abuse of the free tier. We do not store the address itself and cannot recover it.
A count of notes generated, with a timestampTo enforce the free allowance and to understand how much the tool is used.
Which sections you completed, and how many findingsSection names only — for example that you completed "Cognition". Never what you put in them. This tells us which parts of the tool are working.

If you send feedback

The thumbs up or down, the reason chips you select, and anything you type into the comment box. That box carries a warning not to include patient information, and you should not. If we find clinical content there, we delete it and record it as an incident.

If you subscribe

Stripe processes the payment. We receive from them a customer reference, a subscription reference, and whether the subscription is active. We never see or store your card details. Stripe's own privacy policy governs what they hold.

3. What we never collect

This is the important part

We do not receive the assessments you write. The note is assembled by code running in your browser. PDF and Word files are generated there too. Our database has no field capable of holding an assessment, a patient identifier, or any clinical text — not encrypted, not hashed, not at all.

There is one exception, and only if you choose it: if the email feature is switched on and you ask us to email a note to yourself, the text passes through our server to be sent. It is held in memory for the moment it takes to send, and is written to no database, file, or log. You are asked to confirm before this happens. If you never use that button, no clinical text ever leaves your device.

We do not use session recording or device fingerprinting, and we never sell or share personal data with data brokers.

Advertising measurement. We may use Google Ads and Microsoft Advertising to measure which adverts bring clinicians to this site. These set cookies and are not strictly necessary, so they run only if you agree when asked. If you decline, or ignore the request, none of that code loads and everything on the site continues to work.

Three things are measured: that an account was created, that a subscription was purchased, and that a returning clinician visited again. No clinical content is involved in any of them, because of the following rule.

No third-party code runs on the assessment screen. Google and Microsoft do not read page content by default, but both offer features that scan form fields for contact details. On this site those fields hold clinical narrative. Rather than depend on a setting in someone else's dashboard, we do not load their code on that screen at all. If something worth measuring happens while you are writing an assessment, it is held until you return to an ordinary page.

You can change your mind at any time by clearing this site's data in your browser, which removes the stored preference and causes the question to be asked again.

We also keep our own count of these three events on our server, so that we can tell how the service is being used without depending on the advertising platforms. That record contains an account reference, the type of event, the amount paid where relevant, and the time. It contains no clinical information.

4. Why, and on what legal basis

PurposeBasis under UK GDPR
Creating and running your accountArticle 6(1)(b) — necessary to perform our contract with you
Taking payment and managing your subscriptionArticle 6(1)(b) — contract
Enforcing the free allowance and preventing abuseArticle 6(1)(f) — our legitimate interest in the service being sustainable
Keeping the service secureArticle 6(1)(f) — legitimate interest
Improving the tool using feedback and section countsArticle 6(1)(f) — legitimate interest
Emailing a note to you, if you askArticle 6(1)(a) — your consent, given at the moment you confirm
Keeping accounting recordsArticle 6(1)(c) — legal obligation

Because we hold no clinical or patient information, no Article 9 condition for special-category data is engaged by our processing.

5. Cookies

We set one cookie. It is called mn_session, it holds a random token, and its only job is to keep you signed in. It is marked HttpOnly, Secure and SameSite so that scripts cannot read it and it is not sent to other sites. It expires after 30 days.

This is a strictly necessary cookie under the Privacy and Electronic Communications Regulations, so it does not need a consent banner — but you should know it exists, which is why it is written here rather than buried.

Your browser also stores your notes, your templates and your theme preference using local storage. That is on your device, is never transmitted to us, and is deleted if you clear your browsing data.

6. Who else is involved

WhoWhat they doWhat they get
GoogleSign-inThey already know you are signing in to us
StripePaymentsYour email, card details, billing address
HostingerHostingWhatever is in our database, as our processor
Google FontsTypefacesYour IP address when the page loads fonts
An email providerSending, only if you use the email featureThe message being sent

We do not sell data. We do not share it for marketing. We would disclose information if required to by law, and would tell you unless legally prevented from doing so.

7. How long we keep things

8. Security

The strongest security measure is architectural: the most sensitive information involved in this tool is never sent to us, so it cannot be taken from us.

9. Your rights

Under UK GDPR you may ask us to give you a copy of what we hold about you, correct it, delete it, restrict what we do with it, provide it in a portable format, or object to processing based on legitimate interests. Where we rely on consent, you may withdraw it.

Write to info@mhabot.com. We will respond within one month.

If you are unhappy with how we have handled it, you can complain to the Information Commissioner's Office. We would rather you told us first, but it is your right either way.

10. International transfers

Our servers are in the United Kingdom or the European Union. Google and Stripe are US companies and may process your data outside the UK; both rely on the UK International Data Transfer Addendum and the EU–US Data Privacy Framework. If we ever move data outside the UK ourselves, we will use an approved transfer mechanism and say so here.

11. Changes

If we change this policy in a way that matters, we will update the date at the top and tell signed-in users by email. Small corrections we will simply make.

12. Contact

Second Floor flat, 676, Holloway Rd, London, United Kingdom, N19 3NP
info@mhabot.com

Note to the operator — delete this box before launch

This is a carefully written draft, not legal advice. Fill in every bracketed field, register with the ICO, and have a data protection practitioner read it before you take money. Two things in particular must stay true, because the whole document rests on them: clinical text is never stored, and the email feature stays off unless it is in your DPIA.