Upheal handles sensitive personal information, and we're committed to upholding the highest possible standards of data protection and privacy. Therefore, to comply with privacy regulations, care providers must obtain client consent before using Upheal.
If your clients want to know more about the consent they are asked for when using Upheal, please send them a link to this page for clients.
What consent do I need to collect?
Consent for data processing
This is the agreement between your practice and your client, which you might call informed consent or your practice-client privacy policy. Any client whose data enters Upheal must consent to data processing, regardless of how you hold sessions.
As a provider, it is your responsibility to collect client consent for data processing so you stay compliant with your regional data protection standards including HIPAA, GDPR, PHIPA, PIPEDA, etc.
Important: Regulations are regional.
Privacy and data laws differ by region, and the forms we provide you and your clients are tailored to local regulations. Please make sure you set your region in Settings > Consent collection.
If you’ll be using Upheal with clients under the age of 16, you need consent from their parent or legal guardian to use Upheal. Read more here.
How consent collection works
Consent is collected through a consent form that lives alongside your other practice forms. You send it to your client to sign in their Client Portal, or you record consent you've already collected offline. Because it's a form, you can also send it as part of an intake packet, so your client completes their legal consent and intake questionnaires in one Client Portal session.
A consent form can cover up to three agreements:
Provider Privacy Policy: the data processing agreement between your practice and your client.
Upheal's Terms of Service: added automatically when it applies (see below).
Use of de-identified data for AI training: optional, and only included if you've turned it on in your Practice Settings.
Collecting consent from a client
You can collect consent one of two ways:
Email: choose this when your client will sign digitally in their Client Portal.
Mark as collected: choose this when you've already collected consent outside of Upheal using your preferred forms and methods.
Collecting consent via email
To collect consent via email:
On your client's page, click Consent in the right sidebar.
Next to Data processing, click Collect.
Select Collect consent via email.
Click the eye icon to preview the consent form.
Click Send form.
Your client will get an email letting them know they have a new form waiting in their Client Portal. When your client completes and submits the form, their consent is recorded automatically.
You can check back on your client's page, where a green check mark next to Data processing indicates that consent has been collected.
Marking consent as collected
If you've collected consent on paper, verbally, or through your own process, you can confirm this in Upheal by marking consent as collected in the client's chart.
To mark consent as collected:
On your client's page, click Consent in the right sidebar.
Next to Data processing, click Collect.
Select Manually collected.
Click Mark as collected.
No email is sent, and your client doesn't need to do anything in the Client Portal.
On the client's page in the consent section, a green check mark next to Data processing indicates that consent has been collected.
Tracking consent status
On the client's page under consent, the icon next to Data processing indicates that status of consent collection.
Pending: An open circle indicates that you haven't requested consent yet.
Requested: A blue arrow indicates that you've sent the form via email, and are waiting for your client to sign.
Collected: A green check mark indicates that consent has been collected.
Withdrawing consent
If you need to withdraw a recorded consent:
On your client's page, click Consent in the right sidebar.
Click Manage next to Data processing.
Click Withdraw consent confirmation.
To confirm, click Withdraw.
If you sent the consent form via email by mistake and wish to withdraw the form:
On your client's page, click Consent in the right sidebar.
Click Manage next to Data processing.
Click Withdraw sent form.
To confirm, click Withdraw.
Using your own consent documents
If you'd rather manage consent entirely on your own, you don't have to send anything through Upheal. You can add Upheal's statements to your existing informed consent documents, or use our downloadable templates, then record consent with Mark as collected. You can find the statements and templates for your region here.
Turning off in-app consent management
You can hide the consent section from client profiles if your practice already manages consent independently of Upheal. This also prevents other practice members from collecting consent in Upheal when it's already handled elsewhere.
Click Settings in the left menu.
Click Consent collection on the left.
Scroll to the Consent in client profiles section, and deselect Show consent collection in client profiles.
What additional consent does Upheal collect?
Depending on how you use Upheal, we might ask your clients to consent to two more agreements. Unlike consent to data processing, Upheal manages these automatically.
Upheal’s Terms of Service
If you hold video calls using Upheal or the Upheal Zoom integration, your client also needs to agree to our Terms of Service. If you capture audio from in-person sessions, use our browser extension, or upload your own recordings, your client never interacts with Upheal directly and will never be asked to agree to Upheal’s Terms of Service. Upheal handles this agreement automatically.
The use of de-identified data for AI training (optional)
Clients can also optionally agree to their de-identified data being used to train our AI to improve the Upheal app (read the policy or learn more from our blog). This data is anonymized and can't be traced back to the client or provider. When the AI-training option is turned on in your Practice settings, it's included as a checkbox on the consent form. Clients can withdraw this consent at any time from their Client Portal.
For now, Upheal only asks clients to opt in to de-identified data use for AI training if you hold sessions on Upheal's video calling platform or with our Zoom integration. You can automatically opt out all clients in your settings.
Consent when using Upheal with non-clients or collaterals
If you add a participant to a session who isn’t your client (such as a client’s family member), you're responsible for obtaining their consent to record the session and have their data processed by Upheal. There's no required method, but we recommend getting it in writing and keeping it for your records. More information here.
Want to know more about Upheal’s policies?
Visit our Privacy and compliance page.






