Privacy Policy
Effective October 7, 2026 · Zentient AI, LLC
1. Who we are
Hypnocube is practice software for hypnotherapists, run by Zentient AI, LLC ("we", "us"). This policy covers hypnocube.app, the Hypnocube app, and the pages clients open from a practitioner's links (booking, intake, consent, manage, listen and unsubscribe pages).
We hold two kinds of data, and our role differs for each:
- Practitioner account data. We decide how this is used, as described below.
- Client records. Practitioners keep their clients' records in Hypnocube. The practitioner decides what is collected and why. We store and process those records only to run Hypnocube for that practitioner. If you are a client, contact your practitioner first about your records. We will help them answer your request.
Hypnocube is offered in the United States only.
2. What we collect about practitioners
- Account: name, email, phone, time zone, password (stored as a hash), and two-factor settings if you turn them on (stored encrypted).
- Practice profile: booking page address, bio, photo, logo, credentials, location, testimonials, and your records custodian's name and email.
- Sign-in and security records: the IP address and browser of each sign-in, failed sign-in, password change, export, client deletion and account deletion.
- Billing: your plan, trial and renewal dates, credit balance, and Stripe customer and subscription IDs. Stripe holds your card details. We never see them.
- Connected accounts: if you connect Google Calendar, Outlook, Apple Calendar, Zoom or Stripe, we store the access tokens they give us, encrypted. From your calendars we read and store only your busy times, not event titles or details.
- Voice: if you clone your voice, we store your recorded sample, the voice ID from our voice provider, and the consent statement you agreed to with its date and time.
- Push notifications: if you turn them on, your browser's push address and browser name.
- Preferences: audio, Session mode and display settings.
3. Client records we hold for practitioners
Depending on what a practitioner records, a client's file in Hypnocube can include:
- Name, email, mobile number, date of birth, pronouns and emergency contact.
- Health information: presenting issue, medications, contraindications, previous therapy, primary care doctor, and intake form answers (which include health questions such as epilepsy, psychosis and heart conditions).
- Session notes and attached files, scripts, recordings, and play counts for recordings.
- Consent records: the wording as signed, the typed signature, the date, a hashed IP address, and paper scans.
- Appointments and payments, including the Stripe IDs of a saved card. Card numbers stay with Stripe.
- Messages sent from a practitioner's booking page, and the IP address of a booking made there (used to stop abuse).
4. How we use data
- To run Hypnocube: bookings, emails to clients, reminders, payments, scripts, recordings and exports.
- To keep accounts secure and prevent abuse.
- To bill practitioners and keep financial records.
- To fix errors and support you when you contact us.
We do not sell personal data, share it for advertising, or use it to train AI models. Hypnocube has no analytics or advertising trackers.
5. AI features
- Script writing (Anthropic). When you generate a script section, we send Anthropic the presenting issue, imagery and pronoun settings, the client's first name (unless you turn "Use name" off), earlier sections of the script, and your instructions. "Split into sections with AI" sends the text of the script you imported. Session notes and intake answers are not sent.
- Voice and audio (ElevenLabs). Previews and recordings send the script text, which can include the client's name. Cloning your voice sends your recorded sample.
AI output can be wrong. Practitioners review every script before using it with a client. See theTerms of Service.
6. Service providers
We share data only with providers that help us run Hypnocube, and only what each one needs:
- Render: hosts the app, the website and the database.
- Cloudflare: stores files (recordings, attachments, consent scans, exports, voice samples) and protects our servers. Private files are reachable only through short-lived signed links.
- Resend: sends emails to practitioners and their clients.
- Stripe: Hypnocube billing, and client payments into a practitioner's own Stripe account.
- Anthropic: writes script sections (see section 5).
- ElevenLabs: voices, audio and voice cloning (see section 5).
- Trigger.dev: runs background jobs such as audio mixing and exports.
- Sentry: error reports from our servers, with personal data removed.
- Google, Microsoft, Apple and Zoom: only if you connect them, to read your busy times or create meetings for online sessions.
- Your browser's push service: delivers notifications if you turn them on.
We may also disclose data when the law requires it, or to protect someone's safety.
7. Cookies and browser storage
Hypnocube sets no cookies of its own. The app keeps your sign-in token and some settings (theme, schedule view, Session mode preferences) in your browser's local storage, and caches the app's own files so Session mode opens without a connection. You are signed out automatically after 3 hours without activity.
8. Security
- Passwords are hashed. Two-factor authentication is available.
- Connected-account tokens and two-factor secrets are stored encrypted.
- Recordings, attachments and other private files are only reachable through links that expire within hours.
- Sign-ins and sensitive actions are logged.
No system is perfectly secure. If a breach affects your data, we will tell you as the law requires.
9. How long we keep data
- While your account is open, we keep your data, including after your trial or plan ends.
- Client records follow your retention setting: deleted 7 or 10 years after the last session (counted from age 18 for a minor), or kept until you delete them.
- When you delete a client, their notes, intake answers, appointments, scripts, recordings and files are erased. Their consent records are kept for 6 years and then anonymized.
- When you delete your account, we cancel your plan, disconnect your connected accounts, delete your cloned voices, and erase your account, every client record and every file.
- Exports are deleted 48 hours after they are made.
- Records Stripe holds about payments are kept by Stripe under its own policy. Deleted data can remain in our providers' backups for a limited time until those backups are replaced.
10. Health information and HIPAA
Client records in Hypnocube can include health information. Practitioners are responsible for collecting it lawfully and with their clients' consent. We do not currently sign Business Associate Agreements. If you are a covered entity under HIPAA, talk to your adviser before you store protected health information in Hypnocube.
11. Your choices and rights
- Practitioners can see and correct their data in the app, export everything in Settings, and delete their account at any time.
- Clients can ask their practitioner to see, correct, export or delete their records, and can stop follow-up emails with the unsubscribe link in them.
- Depending on your state (for example California), you may have further rights to know, correct or delete personal data. Email us to use them. We won't treat you differently for doing so.
12. Children
Practitioner accounts are for adults only. A practitioner who keeps records for a client under 18 is responsible for getting a parent or guardian's consent.
13. Changes
We will update the date at the top when this policy changes, and email practitioners before a material change takes effect.
14. Contact
Zentient AI, LLC · support@hypnova.ai