Skip to main content
Your reviews are posted anonymously|Crisis support: Call or text 988

Rate My Therapist

Privacy Policy

How we collect, use, and protect your information

Effective May 7, 2026Last updated May 7, 2026

Your reviews are anonymous

When you write a review on Rate My Therapist, your name and identity are never shown to the public. We want you to feel comfortable sharing your honest experience. This Privacy Policy explains what information we collect, how we use it, and how to get the most out of the platform while keeping your personal details private.

01Scope & who this applies to

This Privacy Policy applies to all individuals who use the Rate My Therapist website, mobile applications, and related services (collectively, the "Platform"), including:

  • Visitors who browse the platform without creating an account
  • Registered users who create accounts to submit reviews or engage with content
  • Mental health professionals who claim or manage profiles on the Platform

This Policy does not govern data practices of any third-party websites or services linked from our Platform. We encourage you to review the privacy policies of any third-party services you access.

02Information we collect

2.1 Information you provide directly

Data typeExamplesRequired?
Account dataEmail address, username, passwordYes (to register)
Profile dataDisplay name, avatar (optional)No
Review contentWritten reviews, star ratings, commentsTo post reviews
Professional dataLicense number, practice name, credentials (therapists only)To claim profile
CommunicationsSupport tickets, emails, feedback formsWhen contacting us

2.2 Information collected automatically

When you visit the Platform, we automatically collect certain technical information, including:

  • IP address and approximate geographic location (city/region level)
  • Browser type, version, and operating system
  • Pages visited, time spent, and navigation patterns
  • Referring URL and exit pages
  • Device identifiers and screen resolution
  • Timestamps of all activity

This data is collected using cookies and similar technologies described in Section 7.

2.3 Information from third parties

We may receive limited information about you from third-party sources, such as social login providers (if you choose to sign in via a third-party service) or fraud-prevention services. We do not purchase data about you from data brokers.

03Keeping your reviews private

Your identity is never shown on your reviews

Reviews are posted anonymously. The public only sees your written content, not who you are. To keep it that way, we recommend sticking to your experience of the therapist (their communication style, professionalism, approach) rather than including personal details about yourself.

You never need to mention your diagnosis, medications, or specific conditions to write a helpful review. Details like those could potentially identify you even in an anonymous post, so it's best to leave them out. The same goes for your real name, workplace, or specific location.

Because review text is publicly visible, anything you do choose to include can be seen by anyone visiting the site. If you ever want to remove a review, you can do so from your account, though we can't control whether it has already been indexed externally by search engines.

A note on HIPAA

Rate My Therapist is not a healthcare provider and is not subject to HIPAA. Your therapist's records and clinical notes remain protected under HIPAA on their end. But content you voluntarily post here is not covered by those protections.

04How we use your information

We use the information we collect for the following purposes only:

  • Platform operation: To create and manage your account, display reviews, operate the rating system, and provide core functionality
  • Communication: To send transactional emails (password resets, account notices), respond to support requests, and send service updates (you may opt out of non-essential communications)
  • Safety & integrity: To detect, investigate, and prevent fraudulent reviews, spam, abuse, and Terms violations
  • Legal compliance: To comply with applicable legal obligations, court orders, or regulatory requirements
  • Analytics: To understand how the Platform is used in aggregate and improve our services (using anonymized or aggregated data where possible)
  • Security: To monitor for unauthorized access, vulnerabilities, and protect user data

We do not use your information for automated individual decision-making or profiling that produces legal or similarly significant effects on you.

05How we share your information

We do not share your personal information except in the following limited circumstances:

  • Service providers: We share data with vetted third-party vendors who assist us in operating the Platform (hosting, email delivery, analytics, fraud prevention). These vendors are contractually prohibited from using your data for their own purposes and must maintain appropriate security standards.
  • Legal requirements: We may disclose information when required by valid legal process (subpoena, court order, government request) or when we believe in good faith that disclosure is necessary to comply with applicable law, protect our rights, or prevent imminent harm.
  • Business transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity. We will provide notice before your data is transferred and becomes subject to a different privacy policy.
  • With your consent: For any other purpose, only with your explicit consent.

We do not share your data with advertising networks, marketing platforms, data brokers, or analytics companies for targeted advertising.

5.1 Subprocessors we currently use

The following third-party service providers (subprocessors) may process limited personal data on our behalf, strictly to operate the Platform. Each is contractually bound to confidentiality, security, and use-limitation terms. This list is current as of the "Last updated" date and may change; material changes will be reflected in this section.

SubprocessorPurposeData categoriesRegion
Microsoft ClarityAnonymous usage analytics, heatmaps, session replay (PII masked)Pseudonymous device/session identifiers, page interactionsUnited States
Google Analytics 4Aggregate traffic + conversion measurement (IP-anonymized)Pseudonymous client ID, page paths, event metadata; no PIIUnited States
StripePayment processing for therapist subscriptionsBilling email, payment instrument tokens (no card numbers held by us)United States
SentryApplication error reportingError stack traces, user-agent strings, anonymized request metadataUnited States
ipapi.coApproximate (city-level) geolocation for nearby-therapist searchVisitor IP address (not stored by us)United States / Australia
Google (OAuth, reCAPTCHA, Maps where used)Optional sign-in, abuse prevention, map renderingAccount email (only if you sign in with Google), challenge tokens, IP addressUnited States / Global
CloudflareCDN, DDoS protection, Turnstile bot challengeIP address, request headers, challenge tokensGlobal edge network
AWS (compute, storage, email)Hosting infrastructure, file storage, transactional email deliveryAll Platform data (encrypted in transit, encrypted at rest where supported)United States (us-east-1)
NPI Registry (NPPES, U.S. HHS / CMS)Therapist license verification (public registry lookup)NPI number, public provider name (no claimant data sent)United States

Inclusion of a subprocessor here is a disclosure, not an endorsement. We do not control these third parties' own privacy practices once data lawfully reaches them; review their respective privacy policies for details on their independent processing.

06We do not sell your data

Explicit data sale prohibition

Rate My Therapist does not sell, rent, lease, or otherwise commercially transfer your personal information (including your email address, review content, behavioral data, or any mental health information) to any third party for monetary or other consideration. This prohibition applies regardless of any opt-out mechanisms available under applicable law. We make this commitment unconditionally.

This commitment extends to any parent company, subsidiary, or successor entity to the extent legally permissible.

07Cookies & tracking technologies

We use the following types of cookies and similar technologies:

  • Strictly necessary cookies: Required for authentication, security, and core functionality. Cannot be disabled.
  • Performance & analytics cookies: Help us understand how visitors use the Platform (e.g., pages visited, time spent). We use anonymized data only. You may opt out via our Cookie Preferences tool.
  • Functional cookies: Remember your preferences (e.g., language, region). Optional.

We do not use advertising or cross-site tracking cookies.

You can control cookie settings through your browser and our Cookie Preferences panel. Note that disabling certain cookies may impair Platform functionality.

We do not respond to browser "Do Not Track" signals at this time, as there is no established industry standard. However, we do not engage in cross-site behavioral tracking regardless.

08Data security

Important security limitation

Rate My Therapist does not employ specialized or heightened security measures beyond standard website practices. Do not treat this platform as a secure environment for sensitive information. Any personal or health-related information you share on this site should be considered public.

We apply standard technical measures to protect account and login data, including:

  • Encryption of data in transit (TLS/SSL)
  • Secure password hashing (we never store passwords in plain text)
  • Basic access controls for internal systems

No internet transmission or storage system is secure. We cannot and do not guarantee the security of any information you transmit to us or post on this platform. You transmit and post information entirely at your own risk.

We strongly reiterate: do not post mental health diagnoses, protected health information, medication details, or any other sensitive personal information on this platform. Such content is publicly visible and is not protected by any special security controls on our end.

If you believe your account has been compromised, contact us at security@ratemy-therapist.com

09Data retention

We retain your personal data for as long as your account is active or as needed to provide services, comply with legal obligations, resolve disputes, and enforce our agreements. Specific retention periods:

  • Account data: Retained while your account is active and for 2 years after deletion (for fraud prevention and legal compliance)
  • Review content: May be retained even after account deletion if required for legal proceedings or platform integrity
  • Log and technical data: Generally retained for 12 months
  • Support communications: Retained for 3 years

When data is no longer needed, we securely delete or anonymize it.

10Your privacy rights

Depending on your jurisdiction, you may have some or all of the following rights regarding your personal data:

Right to access

Request a copy of the personal data we hold about you.

Right to correction

Request correction of inaccurate or incomplete personal data.

Right to deletion

Request deletion of your personal data, subject to legal exceptions.

Right to restriction

Request restriction of processing your data in certain circumstances.

Right to portability

Receive your data in a structured, machine-readable format.

Right to object

Object to processing based on legitimate interests or for direct marketing.

Right to withdraw consent

Withdraw consent at any time where processing is consent-based.

Right to complain

Lodge a complaint with your local data protection authority.

To exercise any of these rights, send a request to privacy@ratemy-therapist.com. We process valid requests within the timelines required by applicable law (see Sections 12 and 13). Identity verification may be required before processing. We will not discriminate against you for exercising your privacy rights.

11Children's privacy

Rate My Therapist is not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If we learn that we have inadvertently collected data from someone under 18, we will promptly delete it. If you believe we have collected data from a minor, please contact us immediately at privacy@ratemy-therapist.com

12California residents (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) provides you additional rights:

  • Right to know: You may request disclosure of the categories and specific pieces of personal information we have collected about you in the preceding 12 months
  • Right to delete: You may request deletion of personal information we have collected, subject to exceptions
  • Right to correct: You may request correction of inaccurate personal information
  • Right to opt-out of sale or sharing: We do not sell or share personal information for cross-context behavioral advertising
  • Right to limit use of sensitive personal information: You may direct us to limit use of sensitive personal information to what is necessary to perform the requested services
  • Non-discrimination: We will not discriminate against you for exercising your CCPA rights

To submit a CCPA request, contact: privacy@ratemy-therapist.com or visit our Privacy Request Portal. We will verify your identity and respond within 45 days (extendable by an additional 45 days with notice).

Shine the Light: California Civil Code Section 1798.83 permits California residents to request information regarding our disclosure of personal information to third parties for direct marketing purposes. We do not make such disclosures.

13International users & GDPR

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, additional protections apply under the General Data Protection Regulation (GDPR) or UK GDPR.

Legal basis for processing

We process your data on the following legal bases:

  • Contract performance: to provide the services you request
  • Legitimate interests: for security, fraud prevention, and platform improvement (where not overridden by your interests)
  • Legal obligation: where required by law
  • Consent: for optional features, marketing, and analytics (withdrawable at any time)

Data transfers: If we transfer your data outside the EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.

EEA/UK representative: Rate My Therapist primarily serves United States residents and has not yet appointed an EU/UK representative under GDPR Article 27. If you are based in the EEA or UK and wish to exercise your data rights, contact us directly at legal@ratemy-therapist.com; we will respond within applicable statutory timelines.

To exercise your GDPR rights or lodge a complaint, contact your national supervisory authority. In the EU, find your authority at: edpb.europa.eu

14Changes to this Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page
  • Post a prominent notice on our website
  • Send an email notification to registered users (where required by law or where changes are significant)

Your continued use of the Platform after the effective date of any changes constitutes your acceptance of the revised Policy. If you do not agree to the updated Policy, you must stop using the Platform and may request deletion of your account.

Contact our privacy team

For all privacy-related questions, requests, or concerns: privacy@ratemy-therapist.com
Statutory requests (CCPA, GDPR) are processed within the timelines required by law. Other inquiries are reviewed on a best-effort basis with no committed response time.

Back to home