Version 1.6.1 — Last Updated: August 4, 2026 · Effective Date: August 5, 2026
This Policy explains what TMatch collects, why we use it, when we share it, and the choices and rights available to Clients, Providers, and website visitors.
1. Scope and Who We Are
TMatch is a technology platform operated by Tmind AI Inc., doing business as TMatch ("TMatch," "we," "us," or "our"). TMatch supports provider discovery, AI-assisted intake and matching, care navigation, booking, communication, telehealth access or integrations, self-pay payment support, provider payouts, account billing, and related services.
This Policy applies to information processed through TMatch websites, applications, accounts, Tracy, and related services. It does not replace the privacy notice or Notice of Privacy Practices provided by a therapist, practice, clinic, school, placement site, or other healthcare organization. Those organizations are independently responsible for their own clinical records and privacy practices.
TMatch is not a healthcare provider. When TMatch handles Protected Health Information ("PHI") on behalf of a HIPAA Covered Entity, TMatch may act as a Business Associate and handles that PHI under HIPAA and the applicable Business Associate Agreement. Health-related information that is not PHI may still be protected by consumer health data, privacy, confidentiality, or other laws.
2. Information We Collect
We collect information that you provide, information created through your use of TMatch, and information received from authorized sources. Depending on how you use TMatch, this may include:
Account and identity information, such as name, email address, phone number, date of birth or age range, login credentials, account role, and authentication information.
Health-related and matching information, such as mental health concerns, symptoms, goals, preferences, history you choose to share, language, cultural preferences, location, availability, insurance or EAP preferences, accessibility needs, and information entered during intake or conversations with Tracy.
Provider and practice information, such as professional biography, photograph, credentials, license and registration information, supervision status, education, specialties, practice location, services, rates, availability, insurance or EAP participation, liability insurance, tax and payout setup, and organizational affiliation.
Booking and service information, such as provider selections, appointment requests, scheduling, session status, cancellations, no-shows, reminders, communications, and telehealth connection metadata. TMatch does not record therapy sessions unless a separate feature and consent expressly permit recording.
Payment and payout information, such as transaction amount, currency, refunds, disputes, subscription status, billing authorization, and processor references. When a payment processor directly collects card or bank credentials, TMatch does not store complete card or bank account numbers.
Support and communications, including messages sent to TMatch, complaint information, feedback, and records of customer support interactions.
Device and usage information, such as IP address, browser and device type, operating system, page views, feature interactions, login activity, referral information, approximate location derived from IP address, and security or diagnostic logs.
Derived or AI-generated information, such as non-diagnostic intake summaries, matching indicators, profile completeness indicators, fraud or security signals, and inferences used to provide requested platform functions.
3. Categories of Consumer Health Data
For purposes of applicable consumer health data laws, the information described above may include consumer health data. Categories may include:
Mental or physical health conditions, symptoms, concerns, treatment goals, or health history that you choose to provide.
Information identifying that you are seeking, considering, booking, or receiving mental health or related professional services.
Social, psychological, behavioral, cultural, accessibility, or care preferences relevant to provider matching.
Insurance, EAP, payment arrangement, appointment, and provider interaction information that relates to health services.
Location or availability information used to identify providers who may lawfully or practically serve you.
Information derived or inferred from intake responses, conversations, profile data, or platform activity for matching, navigation, safety, or administrative purposes.
4. Sources of Information
We may receive information from the following categories of sources:
You, including through account registration, profile creation, intake, Tracy conversations, booking, support, payment, payout, and consent flows.
Providers, supervisors, practices, clinics, universities, placement sites, employers, billing entities, or other organizations you or the Provider authorize.
Public licensing boards, professional registries, and other lawful public sources used for limited provider review.
Your device, browser, cookies, logs, and similar technologies.
Service providers that support authentication, cloud hosting, AI processing, communications, scheduling, payment, payouts, video or calendar integrations, analytics, security, and customer support.
Legal, safety, fraud-prevention, or compliance sources where permitted or required by law.
5. How We Use Information
We may use information for the following purposes:
Create and manage accounts and verify account access.
Provide provider discovery, intake, matching, care navigation, booking, scheduling, reminders, communication, telehealth access or integrations, and support.
Operate Tracy and generate non-diagnostic summaries, matching explanations, and administrative recommendations.
Publish and maintain Provider profiles and conduct limited platform eligibility review.
Process self-pay transactions, refunds, disputes, Provider payouts, and TMind plan billing.
Respond to requests, complaints, safety concerns, and technical issues.
Prevent fraud, misuse, unauthorized access, security incidents, and other harmful activity.
Comply with law, contracts, professional requirements, audit obligations, and valid legal process.
Maintain, analyze, and improve the Platform using information that is appropriately protected, aggregated, or de-identified where required.
6. Tracy and AI-Assisted Processing
Tracy may analyze information you provide, including conversation history and account or profile data, to organize intake information, summarize stated needs and preferences, explain potential fit, suggest potentially compatible Providers, and help with administrative next steps.
Tracy is an automated system and is not a therapist, physician, nurse, licensed case manager, clinical supervisor, crisis service, or emergency service. AI-generated content may be incomplete, inaccurate, or based on limited information.
We do not use identifiable Client health information to train generalized or third-party AI models unless we separately disclose the proposed use and obtain consent when required. We may use information that has been lawfully de-identified or aggregated for analytics, security, research, quality improvement, and product development.
7. How We Disclose Information
We disclose information only as described in this Policy, as requested or authorized by you, or as permitted or required by law. Categories of recipients may include:
Providers you select, book with, are matched with, or authorize us to connect you with. We may share relevant intake, matching, scheduling, contact, payment-status, or administrative information needed to support the requested connection or service.
Supervisors, practices, clinics, schools, placement sites, employers, billing entities, or other authorized organizations when needed for supervision, practice operations, billing, compliance, or the service you requested.
Processors and service providers supporting cloud hosting, authentication, AI processing, communications, email or text delivery, scheduling, payment, payouts, video or calendar integrations, analytics, security, fraud prevention, legal support, and customer support. These parties may process information only for contracted services and subject to applicable restrictions.
Government authorities, regulators, licensing bodies, courts, law enforcement, or other recipients when disclosure is required by law or reasonably necessary to protect safety, rights, security, or the integrity of the Platform.
A successor or transaction participant in connection with a merger, acquisition, financing, reorganization, bankruptcy, or transfer of all or part of the business, subject to applicable law and required notice or consent.
We do not sell personal information or consumer health data. We do not use consumer health data for targeted advertising. As of the Last Updated date, Tmind AI Inc. does not share consumer health data with a separate corporate affiliate. If this changes, we will update this Policy before the new sharing begins, as required by law.
8. HIPAA and Provider Records
When TMatch creates, receives, maintains, or transmits PHI on behalf of a HIPAA Covered Entity, the applicable Business Associate Agreement and HIPAA requirements govern that PHI. A Provider or healthcare organization generally controls the clinical record and is responsible for responding to requests regarding treatment records, amendments, restrictions, and accountings, although TMatch may assist as required by the applicable agreement.
TMatch does not become the legal custodian of a Provider's clinical record merely because the Platform supports matching, booking, communication, payment, or telehealth access.
9. Consumer Health Data Rights
Depending on applicable law, including Washington's My Health My Data Act, you may have the right to:
Confirm whether TMatch collects, shares, or sells consumer health data about you and access that data.
Receive a list of third parties and affiliates with which your consumer health data has been shared or sold, where required.
Withdraw consent from future collection or sharing when processing relies on consent.
Request deletion of consumer health data, subject to permitted legal, security, billing, record-retention, and technical exceptions.
Appeal a refusal to act on a request.
To submit a privacy request, email hi@tmind.ai with the subject line "Privacy Request" or use an available privacy request tool in your account. We may take reasonable steps to verify your identity and authority. You do not need to create a new account to exercise a right, although we may require use of an existing account when appropriate. We will respond within the period required by applicable law.
10. Other Privacy Choices and Rights
Depending on your location and the type of information involved, you may also request access, correction, deletion, restriction, portability, or information about certain disclosures. You may update many account and profile fields directly through your account.
You may unsubscribe from non-essential marketing emails by using the unsubscribe link. You may still receive transactional, safety, legal, billing, appointment, or account communications.
11. Cookies and Similar Technologies
TMatch may use cookies, local storage, pixels, and similar technologies for authentication, account preferences, security, performance, analytics, and service operation. You may control some technologies through browser or device settings, but blocking required cookies may prevent account login or other features from working.
12. Security
We use administrative, technical, and physical safeguards designed to protect information handled through TMatch. No system can be guaranteed completely secure. You are responsible for protecting account credentials, using secure devices and networks, and promptly reporting suspected unauthorized access.
13. Data Retention
We retain information for as long as reasonably necessary to provide the Platform, maintain business and transaction records, protect safety and security, resolve disputes, enforce agreements, and comply with legal, contractual, professional, tax, audit, and record-retention requirements. Retention periods vary based on the type of information and the reason it is maintained.
Deletion from active systems may not immediately remove information from backups or archives. Where applicable law requires deletion from backups, deletion may occur through the ordinary restoration or deletion cycle within the time permitted by law.
14. Processing Locations
TMatch and its service providers may process information in the United States and other locations where they operate. Privacy and data protection laws in those locations may differ from the laws where you live. We use contractual and other safeguards where required.
15. Children and Minors
TMatch accounts are intended for adults age 18 or older unless TMatch expressly offers a parent, guardian, or minor-specific workflow. A parent or legal guardian may use TMatch to seek services for a minor only where permitted by law and the applicable Provider. Providers remain responsible for determining consent, confidentiality, and documentation requirements for minor Clients.
16. Changes to This Policy
We may update this Policy to reflect product, business, legal, security, or regulatory changes. We will update the Last Updated date and provide additional notice or obtain consent when required for a material change.
17. Contact
Questions, privacy requests, or appeals may be sent to hi@tmind.ai.
Tmind AI Inc., doing business as TMatch
1100 NE Campus Pkwy,
Suite 200,
Seattle, WA 98195