Legal
Privacy policy.
Last updated: September 22, 2026
Translation provided for convenience; in case of any discrepancy, the Portuguese version prevails.
1. Who we are
Theravus is a SaaS platform for mental health professionals (psychologists, psychiatrists and clinics). This policy describes how we process the personal data of the platform's users (professionals) and of the patients they register, in accordance with the Brazilian General Data Protection Law (LGPD — Law 13.709/2018).
2. Data we collect
From the professional: name, email, phone number, CRP/CRM, billing data (for the subscription), usage and access logs.
From the patient (provided by the professional): identification data (name, CPF, date of birth), contact details, clinical data (clinical records, diagnoses, prescriptions, video sessions, transcriptions, questionnaire responses). Sensitive mental health data is processed based on the data subject's consent and on the legal grounds of Art. 11 of the LGPD.
3. How we use your data
We use data only to provide the contracted service: scheduling appointments, storing clinical records, processing payments, sending reminders, generating AI summaries/analyses (only with prior anonymization of direct identifiers) and complying with legal obligations. We do not sell data to third parties.
4. Who we share data with
Only with processors necessary for providing the service: hosting and database (Google Cloud, São Paulo region), payment gateway (Stripe / Mercado Pago / Asaas), email delivery (Brevo), WhatsApp (Meta) and AI (Google Gemini on Vertex AI, with prior anonymization). All under a processor agreement (Art. 39 LGPD) and LGPD compliance.
4.1. Google data (Google Calendar and Google Business Profile)
If you connect your Google account, Theravus uses the Google Calendar API only to (a) read your busy times and avoid appointment conflicts and (b) create, update and remove in your calendar the events for appointments booked on the platform; and the Google Business Profile API only to display and reply to reviews of your profile, when you enable this integration. We do not read the content of other events beyond date, time and availability status.
Theravus's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements: this data is not sold, is not used for advertising and is not read by humans, except with your consent, for security purposes or as required by law. You can disconnect your Google account at any time in Preferences > Calendar; upon disconnection, the access tokens are deleted.
5. Retention
Clinical records, prescriptions and clinical documents are kept for the controller's (professional or clinic) legal retention period: up to 20 years after the last entry (CFM Res. 1.821/2007; CFP Res. 001/2009; Law 13.787/2018). Subscription and billing data are kept for the tax period (5 years). Access logs are kept for 6 months (Marco Civil, Art. 15) and the audit trail for 5 years. The complete table is available in the Retention policy (in Portuguese).
5.1. Account deletion and custody
Deleting the account is not the same as erasing everything. When you request deletion (in the app, in the dashboard or at theravus.app/excluir-conta, without needing the app), you read a statement that describes exactly what happens to each type of data, confirm your identity and schedule the deletion. It is carried out 7 days later; until then you can cancel it through the link sent by email.
- Patient: the access account (login, password, biometrics, sessions) is deleted. The clinical records remain with the professional or clinic that treats you, who is required by law to keep them; the request to delete this data is forwarded to their Data Protection Officer (DPO), who responds within 15 days.
- Professional: contact details, CPF, photo, credentials and sessions are deleted. Name and council registration (CRP/CRM) remain only as authorship of the clinical records you signed. If you are linked to a clinic, the clinic decides on your removal within 15 days (it is the data controller and is responsible for your registration); if there is no response, the request is escalated to our DPO.
- Person responsible for a clinic or practice: closes the entire account. A proportional final invoice is issued; clinical records and tax documents go to the Custody Vault, encrypted, for the legal period, with access through the Custody Portal for 90 days (afterwards, via the DPO) and reactivation possible within 30 days.
Each step (request, identity verification, acceptance, cancellation, execution, vault access) is recorded in an immutable audit trail for 5 years (LGPD Art. 37).
6. Your rights (Art. 18 LGPD)
You have the right to: confirmation, access, correction, anonymization, portability, deletion, information about sharing and revocation of consent.
How to exercise them: in the app or in the dashboard, under Privacy → "Export my data" or "Delete my account"; without the app, at theravus.app/excluir-conta. Or reach us via WhatsApp or through the contact channel on this website. We will respond within 15 days.
7. Security
Encryption in transit (HTTPS/TLS 1.3), password hashing (bcrypt 12 rounds), session token rotation, optional two-factor authentication, audit trail of all sensitive actions, daily database backup.
8. Cookies
We use strictly necessary cookies to keep you logged in. We do not use third-party advertising or tracking cookies in the professional's dashboard. On the public website, we use audience measurement cookies (Google Analytics), loaded only if you accept that category. You can manage your preferences in the banner shown on your first visit.
9. Data Protection Officer (DPO)
In accordance with Art. 41 LGPD, our Data Protection Officer is Julio Cesar Amorim. Contact: WhatsApp or through the contact channel on this website.
10. Changes
We may update this policy. Material changes are notified by email 30 days in advance.