Legal
Acceptable Use Policy
Effective date: August 24, 2026
Medera operates inside real therapy sessions and handles Protected Health Information. That places limits on what the platform may be used for that go beyond ordinary software terms. This Policy states them plainly, and it is incorporated into the Terms of Service.
Who may use Medera
Medera is a professional tool for licensed clinicians and the care teams working under their supervision. It is not a consumer product and it is not available to patients directly.
- Accounts are held by an organisation or an individually licensed practitioner, and each user is identified individually. Shared logins defeat the audit trail and are not permitted.
- Users must hold the licences and credentials their jurisdiction requires for the care they deliver.
- Supervisees and support staff may use the platform within the scope their supervising clinician defines.
- You are responsible for revoking access promptly when someone leaves your organisation.
Clinical boundaries
These are the limits that matter most, because crossing them puts a patient at risk rather than merely breaching a contract.
- Medera does not diagnose. It is a clinical support tool, not a diagnostic device, and it must not be relied on as one. Every clinical determination remains the clinician's.
- Nothing is filed unreviewed. Notes, codes, letters and messages must be read and approved by a qualified human before they enter a record or leave your organisation. Automating around the approval gate is a breach of this Policy.
- Medera is not a crisis service. Risk detection and escalation support your protocol; they do not replace it, and they must never be the only thing standing between a patient and help.
- Consent is yours to obtain. Recording a session requires whatever consent your jurisdiction and your professional body demand. Medera provides the mechanism; you own the obligation.
- Output is not a substitute for judgment. Where the platform and your clinical judgment disagree, your judgment governs.
Prohibited uses
You may not use Medera to:
- Process data you have no lawful basis to process, or PHI for individuals outside your care relationship.
- Generate documentation for encounters that did not occur, or codes not supported by the encounter. Using the platform to inflate a claim is fraud, and audit logs make it reconstructible.
- Surveil or evaluate staff without their knowledge, or monitor individuals who have not consented to being recorded.
- Attempt to re-identify de-identified data, or to extract another organisation's data.
- Probe, scan, disrupt or reverse-engineer the service, circumvent rate limits or access controls, or test security outside the disclosure process on our Trust Center.
- Resell, sublicense or expose the platform as a service to third parties without a written agreement.
- Train a competing model on outputs, or systematically extract content to build a derivative dataset.
- Break any law that applies to you, including HIPAA, state privacy statutes, telehealth rules and professional licensing requirements.
Your security obligations
- Enable and require multi-factor authentication for every user with access to PHI.
- Keep credentials confidential, and tell us at hi@medera.info as soon as you suspect an account is compromised.
- Configure retention and access to match your own record-keeping obligations. The defaults are reasonable; they are not advice.
- Do not paste PHI into channels not designed for it, including support email and web forms.
How this is enforced
We would rather resolve a problem with a conversation than a suspension, and in almost every case that is what happens.
- First, we contact you. Where a violation appears unintentional we raise it with your administrator and give you a reasonable window to correct it.
- Immediate suspension is reserved for conduct that puts patients, data or the service at risk: suspected fraud, unauthorised access, or use that endangers someone.
- Termination follows repeated or wilful violation, under the process in the Terms of Service.
- Your data comes back. Suspension does not destroy your records. Export rights survive termination, as described in the Terms.
Reporting a violation
If you believe Medera is being misused, tell us at hi@medera.info. Reports are treated confidentially. If you are reporting a security vulnerability, the disclosure process and our commitment not to pursue good-faith research are on the Trust Center.
Changes to this Policy
Notice
Material changes are notified to registered administrators by email at least thirty days before they take effect, and the effective date at the top of this page always reflects the current version. Continued use after that date constitutes acceptance.
Questions about this document?
Our privacy and legal team responds to verified requests within thirty days, and usually much sooner.