Privacy Policy
Effective date: 2026-06-27
This Privacy Policy explains how Mind Turf Private Limited collects, uses, stores, shares, and protects personal data when you use Therefy.
Therefy is an audio-first online counselling and emotional support platform operating in India.
Therefy offers two services:
- Therapy: structured audio counselling support for adults, delivered by verified counselling psychologists.
- Vent-Out Emotional Support: emotional support for adults, delivered by trained support practitioners.
Vent-Out Emotional Support is not therapy, counselling, psychotherapy, medical care, or emergency support.
Therefy is not an emergency service. If there is immediate risk to your safety or someone else's safety, call 112 or contact Tele-MANAS 14416 / 1800-89-14416.
This Privacy Policy meets the disclosure requirements under Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and supports notice, consent, security, rights, and grievance obligations under India's digital personal data law.
1. Who this policy applies to
This policy applies to:
- clients who create an account or book a session
- people who visit the Therefy website
- people who contact Therefy for support
- people who register for webinars or workshops
- verified counselling psychologists who provide Therapy through Therefy
- trained support practitioners who provide Vent-Out Emotional Support through Therefy
- applicants who apply to work with Therefy
- anyone else who interacts with Therefy's website, platform, forms, support channels, or services
Therefy is for adults aged 18 years and above.
If we become aware that a person under 18 has created an account or attempted to use Therefy as a client, we may restrict access and take reasonable steps to delete or limit the related personal data, subject to safety, legal, payment, dispute, and record-keeping needs.
Legal basis: Rule 4 of the SPDI Rules 2011 requires a clear privacy policy for users. The DPDP Act 2023 recognises rights and obligations around digital personal data and includes specific duties for children's personal data.
2. What personal data we collect
We collect personal data that is needed to provide, manage, secure, and improve Therefy.
Account and contact data
- name
- preferred name
- email address
- mobile number
- login details
- account status
- communication preferences
Booking data
- selected service
- booking type
- selected slot
- selected provider
- booking status
- session date and time
- cancellation or reschedule requests
- payment status
- receipt or invoice details
Pre-booking information
Before payment, we collect limited information needed to help you book safely and correctly. This may include age confirmation, selected service, broad support area, preferred language, city or state, availability, provider preference, and confirmation that the booking is not for an emergency.
Post-booking intake and consent data
After a booking, we may collect information needed to prepare for the session. This may include preferred name, age confirmation, current city or state, emergency contact details, broad reason for the session, prior counselling experience if shared, current medication support if shared, accessibility or audio needs, safety-check responses, and consent confirmations.
For Couple Therapy and Family Therapy, we may collect adult participant details and consent status for each adult participant.
Vent-Out Emotional Support data
For Vent-Out Emotional Support, we may collect broad reason for wanting emotional support, safety acknowledgements, service-boundary confirmations, and consent confirmations.
Vent-Out Emotional Support is emotional support only. It is delivered by trained support practitioners.
Payment and refund data
Payments on Therefy are processed through Razorpay.
Therefy does not store your card number, UPI PIN, bank password, or full payment credentials.
We may store limited payment records such as order ID, payment ID, amount, payment status, refund status, receipt or invoice details, payment-provider reference, and date and time of transaction.
Session-room technical data
All sessions on Therefy are audio-only. Therefy does not provide video, screen share, or session recording.
We may process technical data needed to run the audio session room, such as booking ID, participant role, access status, join and leave status, device or browser information, connection issue reports, and error logs.
Webinar and workshop data
If you register for a webinar or workshop, we may collect registration details, attendance status, payment status if paid, feedback, general questions submitted for the session, and support requests.
Webinars and workshops are for learning and information. They are not Therapy or Vent-Out Emotional Support.
Support and grievance data
If you contact Therefy, we may collect your email address, phone number, message, request type, support history, documents or screenshots you choose to share, and our response history.
Please do not send more sensitive information than needed.
Provider and applicant data
For verified counselling psychologists, trained support practitioners, and applicants, we may collect identity details, contact details, education details, work background, profile information, service eligibility, availability, declarations, verification documents, interview or review notes, conduct records, and payment details after approval.
Technical and usage data
We may collect IP address, browser type, device type, operating system, page visits, timestamps, cookie identifiers, analytics events, error logs, and security logs.
Legal basis: Rule 4 of the SPDI Rules 2011 requires disclosure of the types of personal information collected. Rule 5 requires consent for collection of sensitive personal data and requires collection for a lawful purpose. Sections 5, 6 and 8 of the DPDP Act 2023 support clear notice, consent where applicable, and lawful processing.
3. Sensitive personal data
Because Therefy works in counselling and emotional support, some information you share may be sensitive. This may include health-related information you choose to share, emotional well-being information, safety-check responses, emergency contact details, broad reason for booking, session-related information, payment information, and identity verification details for providers and applicants.
Therefy handles such information with care. We collect sensitive information only where needed for service delivery, safety, payment, legal compliance, support, or platform security.
We do not ask for unnecessary sensitive information before booking. We do not ask clients to upload prescriptions, full identity documents, or detailed personal records unless a specific legally reviewed process requires it.
Legal basis: Rule 3 of the SPDI Rules 2011 includes health condition, medical records, financial information, and other listed categories as sensitive personal data. Rule 5 requires consent and purpose limitation for such collection. Section 43A of the IT Act 2000 creates liability for negligent security practices in relation to sensitive personal data.
4. How we use personal data
We use personal data to:
- create and manage accounts
- verify adult-use eligibility
- process bookings
- process payments through Razorpay
- issue receipts and invoices
- manage refunds under the Refund Policy
- match clients with available providers where requested
- help verified counselling psychologists prepare for Therapy sessions
- help trained support practitioners prepare for Vent-Out Emotional Support sessions
- run the audio-only session room
- manage consent and intake status
- send booking confirmations and reminders
- respond to support requests
- handle grievances and data-rights requests
- manage provider applications and verification
- run webinars and workshops
- improve platform safety and reliability
- detect misuse, fraud, technical issues, or unauthorised access
- comply with legal, tax, audit, payment, accounting, and dispute requirements
We do not use your personal data to provide emergency services. We do not provide medical prescriptions or medication services. We do not guarantee any outcome from using Therefy.
Legal basis: Rule 4 of the SPDI Rules 2011 requires disclosure of the purpose of collection and usage. Rule 5 requires that information be collected for a lawful purpose connected with the function or activity of the body corporate. The DPDP Act 2023 supports processing for lawful purposes, with notice and consent where applicable.
5. Advertising, analytics, and sensitive data
Therefy may use privacy-safe analytics and advertising measurement tools to understand website performance and campaign results.
Therefy does not share sensitive intake answers, private session content, safety-risk responses, emergency-risk information, counselling context, Vent-Out context, support messages, or refund reasons with advertising platforms for targeting, retargeting, custom audiences, lookalike audiences, or behaviour-based advertising.
Therefy does not use therapy interest, Vent-Out interest, booking behaviour, intake answers, consent status, emergency-page behaviour, support messages, refund reasons, safety-risk responses, or session attendance to create advertising audiences.
Advertising measurement, if used, must be limited, privacy-safe, and compliant with applicable law and advertising platform policies.
Legal basis: Rule 4 of the SPDI Rules 2011 requires disclosure of information-use and disclosure practices. Rule 6 requires consent before disclosure of sensitive personal data to third parties, except in permitted cases. The DPDP Act 2023 supports purpose limitation and lawful processing.
6. Cookies and similar technologies
Therefy may use cookies and similar technologies for secure login, account protection, booking flow continuity, payment flow support, remembering cookie choices, website performance, error detection, basic analytics, and security and fraud prevention.
Some cookies are necessary for the website and booking process to work. You may be able to control some cookies through your browser settings or a cookie preference tool, where available. Blocking some cookies may affect login, booking, payment, dashboard access, or security features.
More details are available in the Cookie Policy.
Legal basis: Rule 4 of the SPDI Rules 2011 requires disclosure of information collection and use practices. The DPDP Act 2023 supports clear notice and purpose-specific processing of digital personal data.
7. When we share personal data
We share personal data only where needed and with appropriate safeguards.
With verified counselling psychologists: If you book Therapy, relevant booking, intake, consent, and safety information may be shared with the verified counselling psychologist assigned to your session, limited to what is needed for the session.
With trained support practitioners: If you book Vent-Out Emotional Support, relevant booking, consent, broad reason, and safety information may be shared with the trained support practitioner assigned to your session.
With Razorpay: Razorpay processes payments and refunds. Razorpay may receive information needed to complete payment or refund processing, such as transaction details, amount, payment status, and payment reference. Therefy does not store your card number, UPI PIN, bank password, or full payment credentials.
With technology and service providers: We may use trusted service providers for hosting, authentication, database storage, email, notifications, payment support, security, analytics, error monitoring, customer support, and operational tools. These providers may process limited personal data needed to provide their services.
For legal, safety, and compliance reasons: We may use or disclose information if reasonably needed to respond to immediate safety concerns, comply with applicable law, respond to lawful requests, protect clients or providers, investigate misuse or security issues, handle complaints or disputes, enforce platform terms, or protect legal rights.
With advisers: We may share limited information with lawyers, accountants, auditors, or insurers where required for lawful business, legal, tax, or dispute-related purposes.
Business transfer: If Therefy or Mind Turf Private Limited is involved in a merger, investment, restructuring, sale, or transfer of business assets, personal data may be reviewed or transferred as part of that process, subject to applicable law and safeguards.
Legal basis: Rule 6 of the SPDI Rules 2011 requires prior permission for disclosure of sensitive personal data to third parties, except where disclosure is necessary for legal compliance or where a government agency requires information under law. The DPDP Act 2023 requires lawful processing and reasonable safeguards.
8. Confidentiality and its limits
Therefy respects privacy and confidentiality. However, confidentiality is not absolute.
Information may need to be used or shared where there is immediate safety risk, risk to another person's safety, legal obligation, court or government request, complaint or dispute, platform misuse, payment dispute, security issue, provider conduct review, or emergency routing need.
Therefy does not record audio sessions. Clients must not record, publish, or share session content.
Legal basis: Sections 72 and 72A of the IT Act 2000 protect confidentiality and restrict disclosure of personal information. Rule 6 of the SPDI Rules 2011 governs disclosure of sensitive personal data.
9. Data storage, security, and access control
Therefy uses reasonable security practices to protect personal data. These may include access controls, secure hosting, encrypted connections where applicable, account protection, role-based access, security logging, restricted access to sensitive information, vendor controls, backup and recovery practices, and incident review.
No online platform can promise perfect security. You are responsible for keeping your device, email, phone number, password, and account access secure. If you believe your account or data has been misused, contact us as soon as possible.
Legal basis: Section 43A of the IT Act 2000 requires reasonable security practices for sensitive personal data. Rule 8 of the SPDI Rules 2011 recognises reasonable security practices and procedures. The DPDP Act 2023 also requires reasonable security safeguards to prevent personal data breach.
10. Data retention
We keep personal data only for as long as needed for the purposes described in this policy. Retention may depend on service delivery, consent records, booking history, payment and refund records, tax and accounting duties, legal obligations, complaints and disputes, safety incidents, provider verification, platform security, and audit needs.
Some records may need to be kept even after account closure, such as payment records, tax records, refund records, dispute records, or safety-related records.
When data is no longer needed, we will take reasonable steps to delete, anonymise, or restrict it, subject to applicable law and operational needs.
Legal basis: The DPDP Act 2023 supports purpose-linked processing and erasure where retention is no longer necessary, subject to legal obligations. Rule 5 of the SPDI Rules 2011 requires information not be retained longer than required for the purpose for which it may lawfully be used.
11. Your privacy and data rights
Subject to applicable law, you may request:
- access to information about your personal data
- correction of inaccurate or incomplete data
- update of outdated data
- deletion or erasure where legally applicable
- withdrawal of consent where processing depends on consent
- information about how your data is used
- grievance redressal
- nomination of another person to exercise your rights in case of death or incapacity, where applicable
Some requests may be limited by legal, safety, tax, payment, audit, dispute, or platform-security requirements. If you withdraw consent needed to provide a service, Therefy may not be able to continue that service. We may need to verify your identity before acting on a request.
We aim to respond to data-rights requests within the timeline required by applicable law.
Legal basis: The DPDP Act 2023 recognises rights of access, correction, erasure, grievance redressal, consent withdrawal, and nomination. Rule 5 of the SPDI Rules 2011 also gives users the option to withdraw consent, subject to the consequences of such withdrawal.
12. Personal data breach
If Therefy becomes aware of a personal data breach affecting your personal data, we will assess the incident and take reasonable steps required by applicable law. This may include reviewing what happened, taking steps to reduce harm, notifying affected clients where required, notifying the appropriate authority where required, and improving safeguards where needed.
Legal basis: The DPDP Act 2023 and applicable rules require security safeguards and breach-related action. Section 43A of the IT Act 2000 also supports responsibility for reasonable security practices.
13. Third-party websites and services
Therefy may link to third-party websites or use third-party services, including Razorpay, hosting providers, authentication providers, email providers, analytics providers, or other operational tools. Their privacy practices are governed by their own policies. Therefy is not responsible for third-party websites or services that it does not control.
14. Cross-border processing
Some service providers used by Therefy may process or store data outside India. Where this happens, Therefy will take reasonable steps to use service providers that apply appropriate safeguards and process personal data for permitted purposes. Therefy will follow applicable Indian law on cross-border processing of personal data.
15. Communications
Therefy may send you service-related communications such as account messages, booking confirmations, session reminders, payment receipts, refund updates, policy updates, safety or support messages, and webinar or workshop updates.
We may also send optional promotional communications where permitted by law and your preferences. You can opt out of optional promotional communications. You may still receive important service, safety, payment, or policy messages.
16. Advertising platform data safety
Therefy may run ads on platforms such as Google, Meta, or other advertising platforms. Therefy does not use sensitive counselling, emotional support, safety, intake, emergency, or session data for ad targeting. Therefy does not create retargeting, custom audience, or lookalike audience lists from sensitive service behaviour.
If Therefy uses messaging or contact flows, they should be used for simple contact, support, or routing only. They should not be used to conduct sessions or collect detailed sensitive session information.
17. Emergency situations
Therefy is not an emergency service.
If there is immediate risk to your safety or someone else's safety, call 112 or contact Tele-MANAS 14416 / 1800-89-14416.
Do not wait for a Therefy session, dashboard update, provider reply, support response, webinar, workshop, or email response in an emergency.
If safety risk is disclosed through Therefy, we may take reasonable steps such as showing emergency resources, routing the matter for internal review, or using emergency contact information where legally and operationally appropriate.
18. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make important changes, we may update the effective date and notify clients through the website, account, email, or another reasonable method.
Your continued use of Therefy after an updated policy applies means the updated policy will govern your use from that point onward.
19. Contact and grievance details
For privacy, data-rights, or grievance matters, contact:
Email: grievance@therefy.com
Phone: 011-4103 4988
Operator: Therefy by Mind Turf Private Limited
Registered address: 419 Sant Nagar, East of Kailash, New Delhi 110065
For booking, payment, refund, or general support:
Email: support@therefy.com