Privacy Policy
Last Updated: June 2, 2026
Introduction
MyAlly Care, LLC (“MyAlly,” “we,” “us,” or “our”) is committed to protecting your privacy. MyAlly is a technology platform that connects individuals seeking mental health support with licensed healthcare providers. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at myally.care, use our platform, or communicate with us.
Information We Collect
We do not collect any personal information unless you voluntarily provide it to us. When you choose to contact us, request services, or create an account, you may provide:
- Personal Information: Name, email address, phone number, and other contact details you voluntarily provide when contacting us or requesting services.
- Health Information: Information related to your mental health care that you provide through our platform, which is handled in accordance with HIPAA requirements. Your healthcare providers are the covered entities responsible for your protected health information; MyAlly acts as a business associate to facilitate the delivery of services.
- Matching Preferences: Therapeutic preferences, mental health concerns, and approach preferences you provide through our matching quiz. Your answers are sent to our servers so we can calculate your matches — that calculation cannot happen on your device alone. If you do not have an account, we do not save them to a profile or keep them in our database; your answers stay in your browser, and the calculated results are held in a temporary cache for up to 60 seconds so that repeating the same quiz gives you a consistent answer. If you create an account, your preferences are saved to your profile so you can return to them.
- Communication Data: Records of communications you initiate with us or with providers through our platform, including messages, emails, phone calls, and text messages.
Cookies and local storage: Our public pages do not use cookies for tracking. When you use our authenticated portal, session cookies are used to maintain your login session. We also use browser local storage to save your matching preferences on your device. We do not use third-party tracking cookies or advertising cookies.
SMS/Text Message Communications
When you opt in to receive text messages from MyAlly, you agree to receive appointment reminders and other account-related notifications via SMS. Please note:
- Message Frequency: Message frequency varies based on your appointments and account activity. You may receive multiple messages per month.
- Message and Data Rates: Standard message and data rates may apply depending on your mobile carrier and plan.
- Opt-Out: You can stop receiving text messages at any time by replying STOP to any message. You will receive a confirmation message and will no longer receive SMS communications from us.
- Help: For assistance, reply HELP to any message or email us at support@myally.care.
- No Sharing for Marketing: We do not sell, share, or use your phone number or SMS data for marketing purposes or share it with third parties for their marketing use.
Consent to receive text messages is not required as a condition of receiving services from MyAlly.
How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our platform and its features
- Send appointment reminders and account notifications
- Respond to your inquiries and requests
- Comply with legal and regulatory requirements
- Protect the safety and security of our services
Google API Services User Data
MyAlly Care's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
What Google Data We Access
When providers connect their Google Calendar, MyAlly Care accesses: calendar free/busy status to determine available appointment slots, and creates/modifies/deletes appointment events on calendars the provider owns. MyAlly Care does not access event details from other attendees' calendars, shared calendars, or calendar settings.
How Google Data Is Used
Google Calendar data is used exclusively to: (a) display available appointment times to patients, (b) create appointment events when patients book sessions, (c) update events when appointments are rescheduled, and (d) remove events when appointments are cancelled.
How Google Data Is Stored and Protected
OAuth refresh tokens are encrypted at rest using HSM-backed KMS envelope encryption (FIPS 140-2 Level 3). Access tokens are short-lived (1 hour) and never stored. Calendar event data is stored in our HIPAA-compliant database with encryption at rest.
How Google Data Is Deleted
When a provider disconnects their Google Calendar, all stored tokens are immediately and permanently deleted. Providers can also revoke access at any time from their Google Account permissions page.
Information Sharing
We do not sell your personal information. We do not transfer your information to advertising platforms, data brokers, or information resellers. We may share your information only in the following circumstances:
- With your explicit consent
- With the healthcare providers you are matched with through our platform, to facilitate your care
- With service providers who assist in operating our platform (under strict confidentiality and business associate agreements)
- When required by law or to protect rights and safety
- As permitted under HIPAA for treatment, payment, or healthcare operations conducted by your healthcare providers
Service Providers We Rely On
We engage a limited set of vetted service providers to operate the platform. Where these providers may handle protected health information, they do so under a Business Associate Agreement:
- Google Cloud and Google Workspace — secure hosting and infrastructure for platform data, and, for providers who choose to connect it, Google Calendar scheduling.
- Paubox — encrypted delivery of transactional email such as account and appointment notifications.
- Stripe — payment processing. Card details are handled directly by Stripe and are not stored on our servers.
- SMS delivery providers — to send appointment reminders and account notifications by text message. They receive only your phone number and the message content, which never includes clinical information.
Data Security
Your health information is stored in encrypted databases on secure servers located in the United States. All protected health information is encrypted using hardware security modules (HSMs) that meet federal standards (FIPS 140-2 Level 3). This means your data is protected by the same level of security used by banks and government agencies.
Access controls: Your account requires authentication to access. We support secure login methods including passkeys (Face ID, Touch ID, fingerprint). Sessions automatically expire after 15 minutes of inactivity to protect against unauthorized access.
Audit logging: We maintain records of access to your health information as required by HIPAA.
While we implement strong security measures, no method of transmission over the Internet is 100% secure. If you have concerns about the security of your information, please contact us.
Your Rights
You have the right to:
- Access your personal information held on our platform
- Request correction of inaccurate information
- Request deletion of your MyAlly account and the information we hold about you — your quiz answers, matching preferences, match results, saved providers, and anything in your saved-info vault. See “What deletion does and does not cover” in the Data Retention section below, because it cannot include your clinical records.
- Withdraw consent for optional data processing at any time
- Opt out of marketing communications
- Request a copy of your data in a portable format
To exercise any of these rights, contact us at support@myally.care or by phone. We will respond within 30 days.
For health information rights related to your care, please refer to the Notice of Privacy Practices provided by your healthcare provider during intake.
State Privacy Rights & Consumer Health Data
Depending on where you live, you may have additional rights under state privacy laws — for example, the California Consumer Privacy Act and the comprehensive privacy laws of states such as Colorado, Virginia, and Connecticut. These may include the rights to access, correct, delete, and obtain a portable copy of your personal information, and the right not to be discriminated against for exercising them. We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
Consumer health data. Information you provide through our therapist-matching quiz may be considered “consumer health data” under laws such as the Washington My Health My Data Act. We treat this information accordingly: the matching quiz is anonymous by default, we do not load analytics or advertising trackers on it, and your responses are not saved or transmitted to us unless you explicitly choose to save them. We do not sell consumer health data or share it for advertising.
To exercise any of these rights, contact us at support@myally.care. You may use an authorized agent where permitted by law.
Data Retention
Healthcare providers who use our platform are required by law to retain medical records for a minimum period after the last date of treatment. Under HIPAA and applicable state regulations, providers retain adult patient records for at least six (6) years.
MyAlly retains account data and platform usage information for as long as your account is active or as needed to provide our services.
What deletion does and does not cover. There are two different kinds of information here, held by two different parties, and they follow different rules.
We delete what MyAlly holds about you. That is your account, your quiz answers and matching preferences, your match results and saved providers, anything you stored in your saved-info vault including uploaded insurance cards, and your sign-in credentials. We keep an internal record that a deletion happened — the date and what was removed, not the contents — because we are required to be able to show that we honored your request.
We cannot delete your clinical records. If you became a client of a practice through MyAlly, that practice — not MyAlly — is the custodian of your treatment records, and the law requires them to keep those records for at least six years after your last visit. Deleting your MyAlly account does not, and legally cannot, erase them. You keep the right to see and get a copy of those records, and requests for them go to the practice that treated you. If you are currently in care, we leave your sign-in working so you do not lose access to your own records.
We also keep records showing that you asked us not to contact you. Deleting those would let messages start again, which is the opposite of what you asked for.
To request data deletion: Contact us at support@myally.care or by phone. We will respond to your request within 30 days.
Children's Privacy
Our platform is intended for users who are at least 18 years of age. We do not knowingly collect personal information from anyone under 18. If we become aware that we have collected personal information from a person under 18, we will take steps to delete that information promptly. If you believe we may have collected information from someone under 18, please contact us.
Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us:
MyAlly Care, LLC
Email: support@myally.care
Location: New York City, NY
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the “Last Updated” date.