Security & Care

A safe environment for therapists & patients

Protecting clinical data is not a feature, it is the foundation upon which we build the future of mental health. We protect every interaction with cutting-edge technology.

Therapist and patient security

End-to-End Encryption

All patient data is encrypted at rest and in transit, using military-grade standards.

GDPR Compliant

We strictly adhere to European data protection regulations (GDPR), ensuring patients' rights are always protected.

Secured Infrastructure

Hosted on a secure Cloud platform with multi-region redundancy, 24/7 continuous monitoring, and exhaustive audit logs.

Privacy by Design

We implement proactive measures that guarantee data protection from the conceptual phase of every feature (Privacy by Design & by Default).

Multi-Factor Authentication (MFA)

We protect access through two-factor authentication (OTP), ensuring only you can access sensitive information.

Your AI, Your Data

Unlike typical systems, Alchely never uses your sessions or patient data to train our global AI models.

Your data is never for sale

We've built a radical privacy policy: we strictly prohibit selling information to third parties or data brokers. Your trust is our greatest asset.

What this means day to day

A session note is the most sensitive document a therapist writes, so the platform treats it that way. Clinical records are encrypted, access is protected by two-step verification, and every action on a record leaves an entry in the audit log — who opened it, when, and what changed. Nothing about a patient is shared with another therapist, another practice or another account unless you share it yourself.

Your patient has their own boundary. From the portal they see the date and title of each session, the agreements and consents they signed — which they can revoke at any time — and their own data, downloadable. They never see your clinical notes. Where a tool sends data somewhere else, such as a video call, a transcript or a payment, the setup guides state what leaves, to whom, and what consent has to be in place first.

If you need something in writing for your own records, or want to exercise a right under the GDPR, write to our team and we will answer in writing.