Privacy & Trust at Blueprint
At Blueprint, we believe therapists should own their data — full stop. Our job is to be responsible stewards, never gatekeepers. That’s why we’ve built privacy and data control into the foundation of our platform
Trust is the foundation of therapy — and of Blueprint. Other companies anonymize data and claim ownership under the surface. We don’t. Therapists deserve transparency, choice, and real control — not legal loopholes
We’re fully HIPAA-compliant, and all customer data is encrypted in transit and at rest. We sign BAAs with every customer who needs one.View and sign our BAA here.
We undergo annual independent audits to maintain SOC 2 Type II compliance, ensuring our systems meet high standards for security, availability, and confidentiality.
We’re happy to sign a BAA with any organization. All our vendors with access to PHI also meet HIPAA and BAA standards.
AES-256 encryption at rest and TSL 1.2+ encryption in transit.
Fine-grained permissioning ensures only authorized staff have access to sensitive data. Our internal systems are monitored 24/7.
You control how long data is stored and have the ability to delete individual or full client records at any time. Deletion is permanent, and always respected immediately.
Want to walk through our practices with a real person? We welcome your questions and want you to feel confident in how we handle your data
Yes — immediately and permanently. You can also set them to auto-delete.
No. Audio is never stored — it’s processed and discarded in real-time.
Never. We don’t train on your data, and there’s no way to opt in.
Absolutely. Here’s a link to review the BAA you automatically agree to when you start using our product. If you want to sign a doc version, email us at help@blueprint.ai
Yes. We meet all HIPAA standards, encrypt all data, and conduct regular compliance reviews.