Built for Healthcare Privacy

Privacy & Security

Nerve is designed for healthcare privacy and built with HIPAA security principles in mind. Your clients' data — and yours — is treated with the care it deserves.

Built with HIPAA Security Principles

Nerve is designed for healthcare privacy. We are not HIPAA certified, but every engineering decision we make is guided by HIPAA security principles — including access controls, audit logging, encryption, and minimum-necessary data access.

Solo therapists and mental health practitioners handle sensitive protected health information (PHI). We take that seriously. If you need a signed Business Associate Agreement (BAA), contact us at nerve@polsia.app.

Data Encryption

All data is encrypted at rest using AES-256 and in transit using TLS 1.2+. This applies to session notes, client records, appointment data, and everything else stored in Nerve.

At Rest
AES-256 encryption on all database fields
In Transit
TLS 1.2+ enforced on all connections

Payment Security

Nerve never stores credit card numbers. All payment processing is handled by Stripe, which is certified at PCI DSS Level 1 — the highest level of payment security certification available.

When your clients make payments, their card data goes directly to Stripe's secure infrastructure. Nerve only ever sees a transaction ID and amount — never raw card data.

Telehealth Video Sessions

Video sessions use Jitsi Meet with end-to-end encryption. Sessions are not recorded or stored. No third party — including Nerve — can intercept or access the video feed of your sessions.

Data You Control

You own your data. Always. You can export or delete all your data at any time — including client records, session notes, and appointment history.

To request a data export or deletion, contact nerve@polsia.app. We'll process your request within 30 days.

What We Store

Nerve stores only what's needed to run your practice:

  • Client names and contact information
  • Appointment times and scheduling data
  • SOAP notes and session documentation
  • Payment records (transaction IDs and amounts — not card data)

We will never sell your data.

Your client data is never sold, shared for advertising, or used for any purpose outside operating your Nerve account. Ever.

Privacy Questions

Have a privacy question, concern, or request? Reach out directly.

nerve@polsia.app

Last updated: April 2026. Nerve is operated by Polsia, Inc.