Reflective Training Privacy Policy
Last updated: September 13, 2026
Plain-Language Summary
We value your privacy at Reflective Training (“RT”). This policy explains how we protect your data when you use our website. We collect account details (e.g. name, email), training activity (e.g. feedback, video roleplays, progress), and—if you choose to connect them—certain data from your Google account for sign-in and Google Calendar. Google user data is used only to sign you in and to manage the training-session events you ask us to create; it is never shared with third parties, used for research or analytics, or sent to any AI/ML system (see Section 6A). We use strong security, de-identify training data for educational research where appropriate, and don’t sell your information. You can request data access or roleplay removal; see below. We’ll notify you and any required authorities without undue delay if a data breach affects your information, in accordance with applicable law. Depending on where you live, you may have additional rights under laws such as the GDPR (EEA/UK/Switzerland) or the CCPA/CPRA (California). Questions? Email mfredrick@reflective-learning.org.
1. Introduction
Reflective Training (“RT,” “we,” “us,” or “our”) is committed to protecting the privacy of our users, who are healthcare providers, healthcare students, corporate trainees, and other legitimate human learners aged 18 and older. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website (the “Site”). By accessing or using the Site, you agree to this Privacy Policy.
2. How We Protect Your Privacy
We use the following measures to safeguard your information:
- User Verification: We require email verification at signup and ask users to self-identify as eligible learners (18 or older, in a healthcare or training context).
- Data Security: We use industry-standard encryption, U.S.-based secure cloud application hosting, database services, and Amazon Web Services (AWS) for file storage, plus access controls to protect your data from unauthorized access, disclosure, alteration, or destruction. Video roleplays are stored securely to prevent unauthorized copying.
- De-identification: Before data is used for educational research, we remove or pseudonymize directly identifying information (such as name and email) and apply technical and procedural safeguards designed to reduce the risk of re-identification.
- Limited Access: Only authorized RT personnel (such as coaches assigned to you, designated scorers, and authorized administrators) may access identifiable data, and only for the purposes described in this policy. Internal reviewers or research partners may access de-identified data for quality and program-evaluation purposes.
- Data Breach Notification: If a data breach affecting your information occurs, we will notify affected users and any required authorities without undue delay, in accordance with applicable law (for example, the GDPR’s 72-hour regulator-notification requirement and breach disclosure rules under U.S. state laws such as the CCPA/CPRA).
3. Information We Collect
We collect:
- Personal Information: Name, email address, role (e.g. learner, instructor), profile image (if you use Google sign-in or upload one), and user ID you provide when you register, sign in, or use the Site.
- Educational Data: Feedback you submit, video roleplays (mock sessions) you or your coaches upload, quiz and journey/progress data, and related training content. We also record scheduling and attendance data for group sessions (times, check-in, confirmation). We do not automatically record the audio or video of live meetings as part of the Site; any meeting-style recording would come only from content you or your team upload as training material.
- Google account data (if you use Google): If you sign in with Google, we receive profile information that Google makes available to us for authentication (Google account email, name, and profile image) using the standard
openid,userinfo.email, anduserinfo.profilescopes. If you separately connect Google Calendar from your dashboard, we only access Google Calendar data to schedule training sessions requested by the user. Specifically, RT requests the scopehttps://www.googleapis.com/auth/calendar.eventsto: (a) create new events on your primary calendar for training sessions, (b) add Google Meet conference links to those events when you use that option, (c) update the title, description, or time of an event RT created when the session is edited or rescheduled through RT, and (d) delete events that you or your coach cancel through RT. All Google Calendar actions (creating, updating, and deleting events) are only performed in response to explicit user actions in the RT interface, such as connecting your calendar, creating a session, joining a session, editing a session, or canceling a session. RT does not read your existing calendar events, does not modify events on your calendar that it did not create, and runs no background jobs against your calendar. We store the OAuth refresh and access tokens that are needed to call these APIs on your behalf, and the Google event ID of each event RT creates so that it can later update or delete that event. Section 6A describes exactly how this Google user data is used, protected, retained, and deleted. You can disconnect Google Calendar at any time from/dashboard/calendar; on disconnect we delete the stored tokens. Events already created on your Google Calendar will remain there unless you delete them. You can also revoke RT’s access at any time via myaccount.google.com/permissions. Google’s own handling of your Google account and Calendar data is described in Google’s policies (see Section 6). - Payment Data: If you purchase a course or subscription, payments are processed by Stripe. We do not store your full card number; we keep records of your purchases and subscription status (e.g. plan, billing state) needed to provide access.
- Usage Data: Data related to your use of the Site (e.g. session and security logs) collected through cookies and similar technologies as described in the next section.
4. Cookies and Tracking Technologies
We use cookies and similar technologies that are necessary to run the Site, including:
- Types: Essential, first-party cookies and similar storage (e.g. to keep you signed in, protect security, and remember interface preferences such as sidebar layout).
- Purpose: Authentication, security, and basic Site functionality.
- Control: You can control cookies and local storage through your browser settings. Disabling essential cookies may prevent sign-in or limit functionality.
- Compliance: Where required (for example, under the GDPR or the CCPA/CPRA), we process information in line with applicable law. We do not use advertising cookies, and we do not sell your personal information. California residents and EEA/UK/Swiss users have additional rights described in Section 9.
5. How We Use Your Information
We use your information to:
- Improve Learning: Analyze de-identified feedback and training activity (including RT’s own session scheduling and attendance records, where available) to enhance training effectiveness. This excludes Google user data: OAuth tokens and Google Calendar event data are never included in analytics or improvement datasets (see Section 6A).
- Conduct Educational Research: Use de-identified training data for educational research to advance psychotherapy training. Reports never identify RT learners. Google user data is never used for research (see Section 6A).
- Manage Video Roleplays: Your mock video roleplays may be viewed by:
- Coaches assigned to you and designated scorers, for the purpose of giving you feedback on your training.
- Authorized RT administrators, for quality assurance and moderation.
- Authorized internal reviewers or research partners, using de-identified data, for program evaluation and the educational research described in this policy.
- Where the Site makes shared viewing or library features available, other authorized RT users for collaborative learning, under strict confidentiality. Users agree not to capture, reproduce, or distribute others’ roleplays, as per the Terms of Service.
- Deliver Services: Provide Site access, manage accounts, and communicate about training.
6. Third-Party Services
We don’t sell or rent your personal information. We share data with the following service providers (subprocessors) so we can operate the Site:
- Google (Sign-In and Calendar): If you use Sign in with Google or Connect Google Calendar, your use of those Google services is also subject to Google’s terms and Privacy Policy. RT’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only use Google user data to provide the user-facing features of RT described in this policy (authentication; creating, updating, deleting, and adding Google Meet links to events for training sessions). We do not use it for analytics, research, or any other purpose.
- We do not transfer Google user data to third parties except to the infrastructure providers that host RT (application hosting and database, listed below) as necessary to provide those user-facing features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users. Google user data is never shared with educational research partners.
- We do not use Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising.
- We do not allow humans to read Google user data, except: (i) with your affirmative consent for specific data, (ii) when necessary for security purposes (such as investigating abuse), (iii) when necessary to comply with applicable law, or (iv) when the data has been aggregated and de-identified for internal operations and in accordance with applicable privacy and other laws.
- We do not use Google user data to develop, improve, or train any AI/ML models, and we do not transfer it to any third-party AI/ML service. RT does not currently use any artificial-intelligence or machine-learning models or services at all (see Section 6A).
- Amazon Web Services (AWS): We use AWS (including S3) in U.S. regions to store and serve uploaded videos and other files. See AWS Privacy.
- Vercel (application hosting): The RT web application is deployed on Vercel’s U.S. infrastructure. See Vercel’s privacy policy.
- Managed PostgreSQL database: Account, training activity, and scheduling data are stored in a managed PostgreSQL database hosted in the United States.
- Stripe (payments): We use Stripe to process course and subscription payments. Your payment details are provided directly to Stripe; RT does not store full card numbers. See Stripe’s privacy policy.
- Resend (transactional email): We use Resend to send transactional emails (e.g. verification codes, password reset). See Resend’s privacy policy.
- Educational research partners: De-identified training data may be shared with academic partners for educational research, with technical and contractual safeguards designed to prevent re-identification. Google user data is never included in these datasets.
- Legal requirements: We may disclose data to comply with law, enforce our terms, or protect the rights, safety, or property of RT, our users, or others.
We will keep this list reasonably up to date if our subprocessors change.
6A. Google User Data (Limited Use Disclosure)
This section describes, in one place, exactly how RT handles data received from Google APIs. It applies to data obtained through Sign in with Google and through the optional Google Calendar connection.
The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
- What Google user data we access.
- Sign in with Google: your Google account email address, display name, and profile image, via the
openid,userinfo.email, anduserinfo.profilescopes. - Google Calendar (optional): an OAuth access token and refresh token for the
https://www.googleapis.com/auth/calendar.eventsscope, and the Google event ID (and, where applicable, the Google Meet link) of each event RT creates on your primary calendar. RT does not read, list, or search your existing calendar events, and does not access any other calendar. - We do not create aggregated, anonymized, or derived datasets from Google user data.
- Sign in with Google: your Google account email address, display name, and profile image, via the
- How we use it. Sign-in data is used only to create and authenticate your RT account and display your name and picture within RT. Calendar data is used only to create, update, and delete training-session events on your primary calendar in direct response to actions you or your coach take in RT (connecting your calendar, creating, joining, editing, or canceling a session). Google user data is not used for analytics, product research, educational research, advertising, profiling, or any purpose other than providing these user-facing features.
- Whether we share it. We do not sell, rent, or share Google user data with any third party. It is processed only within RT’s own systems, which run on our infrastructure providers (Vercel for application hosting and a managed PostgreSQL provider for the database, both in the United States) acting solely as data processors on our behalf. Google user data is never transferred to educational research partners, to AWS S3, to Stripe, to Resend, or to any AI/ML service. We may disclose it only if required by law, or as part of a merger, acquisition, or sale of assets with notice to users.
- No AI/ML processing. RT does not use any artificial-intelligence or machine-learning models or third-party AI services in the operation of the Site. Google user data (raw, aggregated, anonymized, or derived) is never transmitted to any AI/ML system or provider and is never used to develop, improve, or train any AI/ML model. If RT introduces AI-assisted features in the future, this policy will be updated first, and Google user data will not be used by those features.
- How we protect it. Google user data is transmitted only over TLS-encrypted connections and stored in a managed database that encrypts data at rest. OAuth tokens are accessible only to the server-side code that calls the Google Calendar API on your behalf; they are never exposed to the browser, to other users, or to third parties. Access to production systems is restricted to authorized RT personnel using role-based access controls.
- How long we keep it and how it is deleted. OAuth tokens are retained only while your Google Calendar connection is active. They are deleted immediately when you disconnect Google Calendar from
/dashboard/calendar, when you revoke RT’s access at myaccount.google.com/permissions (RT deletes the tokens as soon as it detects the revocation), or when your account is deleted. Google event IDs (opaque identifiers that are unusable without your tokens) are deleted when the corresponding session or your participation record is deleted, and on request. Sign-in profile data (email, name, picture) is retained as part of your account and deleted with it. You may request deletion of any Google user data at any time by emailing mfredrick@reflective-learning.org; we process such requests within 30 days.
7. International Data Transfers
Our systems and your files are processed in the United States (application hosting, database, and AWS storage). If you access the Site from outside the U.S., your information may be transferred to and processed in the U.S. For users in the EEA, UK, or Switzerland:
- Safeguards: We use appropriate transfer mechanisms as required by applicable law, which may include Standard Contractual Clauses (or successor frameworks) and supplementary measures as appropriate.
- Rights: EEA, UK, Swiss, and California residents have additional rights described in Section 9. We do not sell personal information for money and do not share it for cross-context behavioral advertising.
- Contact: Email mfredrick@reflective-learning.org for international data concerns.
8. Data Retention
We retain:
- Personal Information: Up to 7 years after account closure, unless you request earlier deletion or a shorter period is required by law.
- Educational Data: Video roleplays, feedback, and related training records (including scheduling and attendance metadata) are retained for educational research and platform improvement while your account is active, and thereafter for up to 7 years, unless you request earlier removal of specific materials.
- Aggregated or de-identified training data: May be retained indefinitely for analytics, platform improvement, and educational research. This never includes Google user data, which is not aggregated or de-identified (see Section 6A). Where data has been aggregated or de-identified to a degree that it can no longer reasonably be associated with you, it is no longer treated as your personal data.
- Google account and Calendar data: OAuth tokens are retained only while you keep Google Calendar connected to RT, and are deleted when you disconnect, when we detect that the tokens have been revoked, or when your account is deleted. Full details are in Section 6A.
- Usage and server data: Security and application logs are retained for a limited operational period (typically up to 90 days) and then deleted or aggregated, unless a longer period is required by law or needed to investigate a security incident.
Note: “de-identified” here refers to records from which direct identifiers have been removed. Where applicable law (e.g. the GDPR) requires anonymization rather than de-identification before data ceases to be personal data, we treat that data as personal data until the higher standard is met.
9. Your Rights
All RT users have the following baseline rights:
- Access & Correction: Request a copy of the personal data we hold about you, or correction of inaccurate data, by emailing mfredrick@reflective-learning.org.
- Deletion: Request deletion of your account, your uploaded roleplays, or other data associated with you. We’ll process requests within 30 days, subject to legal obligations and to data we are required to retain (for example, audit logs).
- Opt out of future research use: You can ask us to exclude your future activity from datasets used for educational research. Data that has already been aggregated or de-identified before your request cannot be unwound, but we will not include new identifiable activity going forward.
- Disconnect Google services: You can revoke Google Sign-In or Google Calendar access at any time from your dashboard or at myaccount.google.com/permissions.
Additional rights for EEA, UK, and Swiss residents (GDPR / UK GDPR)
Subject to applicable law, you may also have the right to: data portability, restriction of processing, objection to certain processing (including processing based on legitimate interests), withdrawal of consent (where processing is based on consent), and lodging a complaint with your local supervisory authority. Our lawful bases include performance of a contract (operating your account), legitimate interests (security, service improvement, educational research with safeguards), consent (where you connect Google Calendar or opt in to specific processing), and compliance with legal obligations.
Additional rights for California residents (CCPA / CPRA)
California residents have the right to know what personal information we collect and how we use it, to request deletion or correction, to opt out of “sale” or “sharing” of personal information for cross-context behavioral advertising, to limit the use of sensitive personal information, and to be free from discrimination for exercising these rights. RT does not sell your personal information for money and does not share it for cross-context behavioral advertising.
To exercise any of these rights, email mfredrick@reflective-learning.org. We may need to verify your identity before completing your request. You may use an authorized agent where applicable law permits.
10. Video Roleplay Control
- Storage: Mock video roleplays are stored on AWS S3 in U.S. regions, with access limited to authenticated RT users who have a legitimate need (the uploader, the learner, the assigned scorer, and the learner’s coach).
- Removal: You can request removal of any of your roleplays at any time — during a course, after a course, or after account closure — by emailing mfredrick@reflective-learning.org. We will confirm removal from the Site within 30 days. Any de-identified derivative data already incorporated into research datasets is governed by Section 9 (opt out of future research use).
11. Legal Compliance
RT is an educational training platform. RT does not collect, create, or store Protected Health Information (PHI) subject to HIPAA. All training materials, including mock video roleplays, must be simulated; users must not upload recordings of real patients or any content that contains real clinical encounters or PHI. We comply with applicable laws, including the GDPR (and UK GDPR) and the CCPA/CPRA, and we maintain confidentiality standards appropriate to an educational setting.
12. Reporting a Security Concern
If you believe you have found a security vulnerability or that your account or data has been compromised, please email mfredrick@reflective-learning.org with details. Please do not publicly disclose the issue until we have had a reasonable opportunity to investigate and respond.
13. Contact Us
For questions or concerns:
Reflective Training Support
mfredrick@reflective-learning.org
7703 Floyd Curl Dr, San Antonio, TX 78229