Skip to content

Legal

Privacy policy

What we collect, why and for how long — and what we never collect: TripleRoute is not a health record and holds no client-identifying information.

Version 2026-10-07.1 · All documents

Last updated: 8 October 2026

This policy explains what information TripleRoute collects, why, who it is shared with, how long it is kept, and the choices you have. TripleRoute is operated by Arise Above Holdings, LLC, doing business as TripleRoute ("TripleRoute", "we", "us").

We have written it to describe what the software actually does. Where a statement below is a property of how the system is built rather than a promise of good behavior, we say so, because a built-in limit is a stronger assurance than a policy.

1. The short version

  • We never collect information that identifies a client or patient. No client names, dates of birth, addresses, phone numbers, medical record numbers, insurance details, psychotherapy notes, treatment plans or intake records. There is no field in the system that could hold them.
  • We do not sell your personal information, and we do not share it for targeted advertising. We run no advertising trackers.
  • Our marketing website sets no cookies and loads no third-party scripts. The application sets one cookie, needed to keep you signed in.
  • Supervision video sessions are never recorded. The system has no capability to record them.
  • Sealed supervision records cannot be deleted or altered by anyone, including us. Section 8 explains what that means for your privacy rights and why it is the design.

2. Who this policy covers

TripleRoute is a professional platform for clinicians working toward independent licensure ("supervisees"), their clinical supervisors, the employers or organizations that confirm practice experience ("practice verifiers"), and the people who administer the service. It covers our website at tripleroute.io, the application at app.tripleroute.io, our mobile applications when released, and our emails.

It also covers TripleRoute Practicum at practicum.tripleroute.io, used by students on a practicum, internship or field placement, the site and faculty supervisors who sign for them, and the schools that run their programs. Where a school enrolls its students, the school decides who is enrolled and who supervises them, and we hold those students' placement records to provide the service to the school and to the student — see the Practicum Terms, Part C, and What we hold about a student.

TripleRoute is intended for adults acting in a professional capacity. It is not directed to anyone under 18, and we do not knowingly collect information from children.

3. What we never collect

TripleRoute is not an electronic health record and is not a place for information about the clients or patients you serve. The following does not exist anywhere in our database, our forms or our file uploads:

Never collected
Client or patient names, initials used as identifiers, or photographs
Dates of birth, ages tied to a person, or addresses
Phone numbers, email addresses or other contact details of clients
Medical record numbers, account numbers or insurance information
Diagnoses tied to an identifiable person, psychotherapy notes, treatment plans or intake records

Case discussion in supervision must remain de-identified. Every place in the application that accepts written content about cases shows a reminder, and our Terms of Service prohibit entering client-identifying information. If you believe identifying information has been entered by mistake, contact us and we will help remove it where the record is not sealed (see section 8).

Because we do not collect protected health information, TripleRoute is not a "covered entity" or "business associate" under the U.S. Health Insurance Portability and Accountability Act (HIPAA), and we do not describe the service as "HIPAA compliant". Using TripleRoute does not change your own obligations under HIPAA or your professional ethics code.

4. What we collect

4.1 Information you give us

Category Examples Who provides it
Account Name, email address, password (stored only as a one-way hash), time zone, the roles you hold Everyone
Multi-factor authentication An authenticator secret and hashed recovery codes, if you turn on MFA Everyone who enables it
Professional profile License type, licensing jurisdictions, license number, specialties, therapeutic approaches, supervision formats, availability and rates Supervisors
Verification documents License scans and identity documents submitted so we can confirm a supervisor's credentials Supervisors
Licensure pathway Your jurisdiction, profession and the license you are working toward Supervisees
Supervision relationship Requests, supervision agreements and their signatures, agreed format, frequency and rate Supervisees and supervisors
Hours and attestations Supervision and practice hours, their categories, dates, supervisor review, signatures and sealed periods Supervisees, supervisors, practice verifiers
Practice verification Confirmation of employment-based practice hours, without access to supervision content Practice verifiers
Session preparation Notes a supervisee writes before a session. These are private to the supervisee and are not included in any export or shown to anyone else Supervisees
Messages Messages exchanged within a supervision relationship Supervisees and supervisors
Development goals and documents Goals, evaluations and documents shared within a relationship Supervisees and supervisors
Billing Plan, billing contact, and who pays. Card numbers are entered directly with our payment processor and never reach our servers Whoever pays
Support What you tell us when you contact us Anyone

In Practicum, in addition to the account information above:

Category Examples Who provides it
School and class list The school's name, its programs and cohorts, and the names and email addresses of the students it enrolls School coordinators
Placement The site, the dates, and who the site and faculty supervisors are Students and school coordinators
Placement hours Hours, their categories and dates, and notes about the work — never anything identifying a client Students
Signatures and evaluations A supervisor's signature on a week, evaluations, site visits and concerns raised Supervisors and students
Site documents The title and dates of a site's agreement or certificate. The document itself is not uploaded School coordinators
School billing Invoices, who they were sent to, and whether they were paid. Card details never reach our servers Schools

We do not hold a student's grades, transcripts, disciplinary or financial-aid records, student identification number or social security number. We do not sell student records and do not use them for advertising.

4.2 Information collected automatically

Category What and why
Security and audit records When a consequential action happens — signing in, changing a role, accessing a document, signing or sealing a record — we record who did it, what, when, the IP address and the browser or device's user-agent string. This is how we detect misuse and how a signed record can later be shown to be genuine.
Signature evidence When you sign a supervision agreement or attest to a period of hours, the time, IP address and user-agent are stored with that signature as evidence of who signed and when.
Sign-in sessions The devices you are signed in on, so you can see and end them.
Session attendance When a supervision session takes place in a TripleRoute room, the times each participant joined and left, so the system can record the time you were both present. Audio and video are never recorded.
Aggregate usage counts Daily totals, such as how many times a state's requirements page was viewed. These counts contain no user identifier, IP address, device identifier or referrer, and no time finer than a day.

We do not use fingerprinting, and we do not collect precise location.

5. How we use information

We use personal information only to:

  1. Provide the service — create your account, match supervisees and supervisors, run supervision relationships, record and seal hours, host sessions, and produce exports you request.
  2. Verify credentials — confirm that a supervisor holds the license they claim before they appear in search.
  3. Keep records trustworthy — preserve sealed records and the evidence of who signed them, so they can be relied on later, including by a licensing board you choose to share them with.
  4. Secure the service — detect and prevent fraud, abuse and unauthorized access, and investigate incidents.
  5. Process payments — bill the party who pays and calculate applicable tax.
  6. Communicate with you — send service messages such as verification links, security alerts, reminders and receipts. Service messages cannot be turned off while your account is open because they concern your account and records. If we send marketing email, you can unsubscribe at any time.
  7. Improve the service — using the aggregate counts described in 4.2.
  8. Meet legal obligations — respond to lawful requests and enforce our terms.

We do not use your information to train artificial-intelligence models, and we do not make decisions with legal or similarly significant effects about you based solely on automated processing.

6. When information is shared

We do not sell personal information and do not share it for cross-context behavioral advertising.

Within a supervision relationship. The record of hours, attestations, agreements, messages and shared documents is visible to the supervisee and the supervisor in that relationship, because it is a record of work they did together. A practice verifier sees only the practice-hour evidence they are asked to confirm — never supervision messages or notes. Nothing is visible to other supervisees or other supervisors.

When you choose to share. If you export your record or give it to a licensing board, employer or anyone else, you control that disclosure.

Service providers. We use the following providers to run TripleRoute. Each receives only what it needs to perform its function for us, under contract:

Provider Purpose Data involved
Stripe Payment processing and tax calculation Billing contact, plan, payment details (entered directly with Stripe)
Resend Sending email Email address and message content (no case content)
LiveKit Real-time video for supervision sessions Session connection metadata; media is not recorded
Vercel Hosting the website and application interface Request data in transit
Hostinger Hosting our servers and database All service data, encrypted in transit
Cloudflare Domain name service, TLS and protection against attacks Request data in transit
Sentry Error monitoring Technical error details, with personal data removed before sending

Legal and safety. We may disclose information if required by law, subpoena or court order, or where necessary to protect the rights, property or safety of our users or the public. Where permitted, we will tell you before disclosing your information in response to a legal request.

Business transfers. If TripleRoute is involved in a merger, acquisition or sale of assets, information may transfer as part of that transaction, subject to this policy.

7. Cookies

Our marketing website sets no cookies and runs no third-party scripts.

The application sets one cookie, tripleroute_session, which keeps you signed in. It is strictly necessary, encrypted, not readable by scripts on the page (HttpOnly), sent only over HTTPS in production, restricted to our own site (SameSite=Lax), and expires after 30 days. See our Cookie Policy.

8. How long we keep information, and why some records cannot be deleted

Information Retention
Account details While your account is open. On closure, your account is de-identified as described below.
Sealed attestation records Retained for at least 10 years after the period is sealed, and never altered
Security and audit records Retained for as long as the records they relate to, because they are the evidence those records are genuine
Verification documents While you are a listed supervisor, and afterwards only as long as needed to answer questions about a verification decision
Messages and shared documents While the relationship record exists
Session preparation notes Until you close your account
Billing records As long as tax and accounting law requires
Aggregate usage counts Indefinitely — they identify no one

Where information is no longer needed for the purposes above, we delete it or de-identify it.

Why sealed records are permanent. A sealed attestation is a signed statement, by two professionals, about supervised practice that a licensing board may rely on years later. It concerns both parties: a supervisor may be asked to account for a signature long after a placement ends, and a supervisee should never lose the evidence of hours they earned because the other person left. For that reason the system has no function — for any user, administrator or for us — that edits or deletes a sealed record. Corrections are made by adding an amendment that preserves the original.

What happens when you close your account. Your account is de-identified: your name, email and profile are removed from active use and you can no longer sign in. Sealed records you were a party to are preserved, because the other party has a legitimate need for them and they may be required for licensure, legal claims or regulatory purposes. Where the law gives you a right to deletion, it provides exceptions for records like these, and we rely on those exceptions only for sealed records and the evidence attached to them.

9. Your rights

Wherever you live in the United States, you can ask us to:

  • Access the personal information we hold about you, and receive a copy in a portable format (the application also lets you export your record yourself)
  • Correct information that is inaccurate — for sealed records, by amendment
  • Delete your personal information, subject to the exceptions in section 8
  • Opt out of any sale of personal information or sharing for targeted advertising (we do neither) and of marketing email
  • Appeal a decision we make about your request

Residents of states with comprehensive privacy laws (including California, Colorado, Connecticut, Texas, Virginia and others) have these rights by law; we extend them to all users. We will not discriminate against you for exercising them.

To make a request, call +1 (701) 660-4778 or write to us at the address in section 13, quoting the email address on your account. We will verify your identity before acting, respond within 45 days, and tell you if we need up to 45 more. You may use an authorized agent, who must provide proof of authority. If we decline a request, we will explain why and how to appeal.

California residents. In the last 12 months we have collected the categories in section 4: identifiers, professional information, commercial information (billing), internet activity limited to security records, and sensitive personal information limited to account credentials and identity documents used for verification. We use sensitive personal information only to provide and secure the service, and do not use it to infer characteristics about you. We have not sold or shared personal information.

10. Security

Measures include encryption in transit (TLS), encryption at rest of identity documents and license scans, one-way hashing of passwords, optional multi-factor authentication, role- and relationship-based access checks on every request, malware scanning of uploads, rate limiting, append-only audit logs, and a cryptographic chain linking sealed periods so that alteration can be detected. No system is perfectly secure. If a breach affects your personal information, we will notify you and any required authorities as the law requires.

11. Where information is processed

TripleRoute is operated from, and stores data in, the United States. If you access it from elsewhere, your information will be processed in the United States.

12. Changes to this policy

If we make a material change, we will notify you by email or in the application before it takes effect. The date at the top shows when this policy was last updated, and previous versions are available on request.

13. Contact

Arise Above Holdings, LLC, doing business as TripleRoute

3003 32nd Ave S, Ste 240, Fargo, ND 58103, United States

Privacy questions and requests, by telephone: +1 (701) 660-4778

By email: privacy@tripleroute.io for privacy questions, requests about your information and student records; support@tripleroute.io for anything else. A person reads both.