Privacy — the straight version.
Written for the therapist, coach, or practice manager who needs to know what happens with data before they subscribe. Not marketing copy. No spin. Forward this to whoever on your team asks.
Last updated: August 2026 · Questions: nik@keepitcivil.app
What Keep It Civil is (and isn't)
KIC is a tactical communication tool. A user describes a hard conversation they're facing ("my dad said X, I want to reply Y") and KIC returns suggested wording. That's the whole product surface.
KIC is not therapy, not a diagnostic tool, and not HIPAA-compliant. Users see this in-app. We don't market it as a clinical instrument and we don't want practices treating it as one. It sits alongside your work, not inside it.
What we collect from your clients
- Account basics: email, first name, chosen display name. Password if they use email/password auth.
- The scenarios they type in: whatever they choose to describe when asking for wording help.
- Any notes they save or export: stored in their own account only.
- Standard technical logs: IP, browser, timestamps — for security and rate limiting.
We do not ask for or store: names of the people they're writing about, clinical diagnoses, session notes, PHI, insurance identifiers, or anything that a therapist would typically log in an EHR.
Where it lives
Client data is stored in MongoDB Atlas (US region), encrypted at rest and in transit. Application infrastructure runs on Railway (backend) and Vercel (frontend), both US-hosted. Payment data is handled by Stripe — KIC never sees or stores card numbers.
Subprocessors
To generate suggested wording, KIC sends the client's typed scenario to OpenAI's API (GPT-5.2). OpenAI's enterprise API terms apply — inputs are not used to train their models and are retained for abuse monitoring only.
- • OpenAI — AI generation (API, no model training)
- • MongoDB Atlas — database (US region, encrypted)
- • Railway — backend hosting (US)
- • Vercel — frontend hosting (US)
- • Stripe — payment processing
- • RevenueCat — iOS subscription management
Who has access
The KIC founder (Nik) and any support staff (currently zero). No third parties beyond the subprocessors listed above. As the practice owner subscribing, you do not have access to your clients' scenarios or account contents. That firewall is intentional — clients can share what they choose (via the PDF export they control), but their private KIC use stays private.
Data retention & deletion
Account data persists as long as the account is active. Clients can delete their account at any time (Settings → Delete Account), which removes their scenarios and data within 30 days. If a client stops being your client and you no longer want them on your subscription, revoke their invite — their account remains, but drops back to the free tier.
Not HIPAA — the honest version
KIC is not HIPAA-compliant and does not enter into BAAs. We won't pretend to be a clinical tool because we aren't one. If your work with a client involves data that must be stored under HIPAA, that belongs in your EHR — not in KIC. The way KIC is designed (client-typed communication scenarios, no session notes, no PHI required) is intentionally structured to sit outside the clinical-data boundary.
Questions from your compliance person
Forward this page. Email nik@keepitcivil.app for anything not covered. Nik responds personally, usually within 24 hours.
The full public privacy policy is at /privacy. This page is the practice-facing summary — same content, plain language, no legalese.