Skip to content

Privacy Policy

Last updated 18 August 2026. This is a working draft describing what Casebook actually does with your data today — it has not yet been reviewed by a lawyer, and may change as we get that review and as the product changes.

Who we are

Casebook is built by The Ego Studio (https://casebook.theego.studio), a small team based in India. This policy covers the Casebook web app at https://casebook.theego.studio and its backend API. Questions about this policy or your data: privacy@theego.studio.

Not therapy, not a crisis service

Casebook is an educational simulation for psychology students. The "patients" you talk to are entirely AI-generated fiction — there is no real person on the other end, and nothing the simulation says is clinical advice for a real patient.

Casebook is not a crisis or emergency service and cannot respond to one. If you or someone you know is in crisis, please contact a real helpline immediately: Tele-MANAS (14416, Government of India, 24/7), iCall (9152987821, TISS), or the Vandrevala Foundation helpline (1860-2662-345).

What we collect, and why

Account data. When you sign up, our authentication provider, Clerk, collects your name and email address and issues the login session that identifies you to our backend. We store your Clerk-verified email, name, and (if you provide it) your institution, so we can associate your sessions with your account and let you sign back in.

Session transcripts. During a simulated therapy session, what you say (transcribed from your voice, or typed) and the AI patient’s replies are stored as text, tied to your account, so the conversation can continue and so you can review past sessions.

Performance assessments. After each turn, and again at the end of each session, an AI model scores your clinical technique — things like empathy, therapeutic technique, and communication — and writes feedback. These assessments, scores, and reports are personal data about your performance as a student, and are stored alongside the session so you can see your progress over time.

Technical and usage metrics. We record per-turn timing (e.g. how long transcription and response generation took), a rough usage counter (the size, in bytes, of an audio upload — used only to estimate our own API costs, not the audio itself), and basic product analytics (which pages are visited, how the app performs) so we can keep the service working and fix problems.

Voice: your recording is not kept

When you speak during a session, your browser records audio and sends it to our backend, which forwards it to a speech-to-text provider (OpenAI Whisper, or Groq’s Whisper model where configured) purely to produce a text transcript. The audio is discarded once that transcript comes back — we do not save a copy of your recording. The only thing we retain from that step is the transcript text, plus a count of how many bytes were uploaded (used to estimate transcription cost, not to reconstruct or store the audio).

Who we share data with

We don’t sell your data. We share it with the vendors that make Casebook work, each strictly for the purpose below. Several of these process data outside India:

  • Clerk — authentication; holds your account email, name, and login session (processes data on infrastructure outside India).
  • OpenAI — generates the AI patient’s responses, converts text to speech, transcribes your voice (Whisper) when Groq isn’t configured, and runs an automated moderation check for safety (e.g. self-harm signal, abusive language) on messages sent during a session.
  • Groq — where configured, transcribes your voice to text instead of OpenAI; automatically falls back to OpenAI if it fails.
  • Vercel — hosts the Casebook web app and runs privacy-oriented, cookieless page-view analytics (@vercel/analytics): aggregate page views and performance, no cross-site advertising tracking.
  • Render — hosts our backend API and PostgreSQL database, in Render’s Singapore region. This is where your session transcripts, assessments, and account data are actually stored.
  • Sentry — error tracking, active since 31 July 2026. When something breaks, Sentry receives the technical details of the error — which page or API call failed, the code path, your browser and account identifier — so we can find and fix it. It is not sent your session transcripts.

Who at The Ego Studio can see your sessions

We can. Casebook is built by a very small team, and to fix bugs, look into problems you report to us, and check that the AI patient is behaving safely and scoring fairly, we can read stored session transcripts, assessments, and reports — including yours, identified to your account. We do that for those reasons only, we don't share your transcripts outside the team, and we don't read them for curiosity, marketing, or any purpose unrelated to running and improving Casebook. If you would rather your sessions weren't available to us this way, email privacy@theego.studio and we'll talk about what we can do.

Retention and deletion

We keep your account, session transcripts, and assessments for as long as your account exists, so you can track your progress over time. We don’t yet have an automated self-serve deletion flow. If you want your account or data deleted, email privacy@theego.studio and we will delete it manually, as promptly as we can.

Your rights (India, DPDP Act 2023)

Under India’s Digital Personal Data Protection Act, you have the right to access the personal data we hold about you, ask us to correct it, ask us to erase it, and raise a grievance about how we’ve handled it. To exercise any of these, email privacy@theego.studio — that inbox is our grievance-redressal contact for this policy.

Cookies and analytics

Clerk sets a session cookie so you stay signed in. Vercel Analytics records aggregate page views and performance metrics without cross-site advertising cookies. We don’t run third-party ad tracking on Casebook.

Who can use Casebook

Casebook is intended for psychology students aged 18 and over, or students using it under the supervision of their institution. It is not intended for members of the public seeking mental health support.

Security

We serve Casebook over HTTPS and restrict database access to our own backend service — though see above for who on our team can read your sessions. We’re a small team and don’t claim a perfect security record, any particular certification, or compliance with a specific standard (e.g. HIPAA, GDPR, SOC 2) — we haven’t sought or obtained any of those. If we discover a data issue that affects you, we’ll tell you.

Changes to this policy

We may update this policy as Casebook changes and as we get proper legal review. We will update the "last updated" date above when we do.

See also our Terms of Service.