Trust & Safety

Trust, Privacy & Security

Nirvanas Creation is designed around consent, privacy, appropriate access, and respect for the whole person. We believe wellness technology should help people feel more connected—not watched, exposed, or reduced to data.

Member-Controlled Sharing

Members control which eligible reflections, body-map information, and feedback they choose to share with practitioners. Body-map entries, session check-outs, and member summaries each require an explicit share action.

Information that has not been explicitly shared must not appear in practitioner-facing views. Sharing can be revoked, and the practitioner projection is updated accordingly.

Role-Based Access

Owners, managers, front-desk staff, practitioners, members, and platform administrators have different permissions. Each role is intended to access only the information required for its authorized responsibilities.

Access is enforced through server-side row-level authorization rules, not only by hiding elements in the interface.

Organization Separation

Each wellness business operates within its own organization environment. Client, appointment, staff, waiver, and operational information is scoped to the correct organization.

Cross-organization access is prevented by server-side authorization that checks the user’s active organization membership and role before returning or modifying records.

Practitioner Notes and Member Summaries

Internal practitioner notes and member-facing summaries are separate. Internal session notes remain on the appointment and practitioner side of the record.

Members should only see a summary when an authorized practitioner intentionally shares it. Internal notes must never automatically become member-facing content.

AI and Connection Intelligence

AI-generated insights are supportive and non-diagnostic. They are intended to organize permitted reflections into understandable themes.

AI does not replace medical, mental-health, or professional judgment, and does not define a person or make clinical conclusions.

Member consent and role permissions remain authoritative. We do not claim that AI conversations are private, encrypted, anonymized, or excluded from training unless those facts are technically verified.

Data Protection

Nirvanas Creation is hosted on infrastructure that provides standard transport and storage protections. Data in transit is protected via HTTPS.

Access to information is gated by authenticated sign-in and server-side authorization, including role-based rules, organization scoping, and restricted service-role backend actions for privileged operations.

Sensitive platform administration is recorded through audit logging. We do not claim “military-grade security,” “end-to-end encryption,” that “no one on the backend can ever access your information,” or that the platform is HIPAA compliant. Authorized support and administrative processes may access records under controlled, role-limited circumstances.

HIPAA Readiness in Progress

Nirvanas Creation is actively working toward the administrative, technical, contractual, and operational safeguards required for HIPAA compliance. The platform should not currently be represented as HIPAA compliant, and businesses should not use it to store protected health information unless and until Nirvanas Creation has completed its compliance review, confirmed the required safeguards, and made any necessary Business Associate Agreement available.

Please contact us to discuss your organization’s privacy, security, and compliance requirements before beginning a pilot.

Your Data Rights

  • Review or update account information

    Signed-in members can view and edit their profile and contact details under Profile.

  • Control consent and sharing

    Members choose what to share—body-map entries, session reflections, and summaries—and can revoke sharing. Sharing is never pre-checked.

  • Request account deletion

    Signed-in members can start account deletion directly under Profile → Delete account; contacting support is not required to initiate the request.

  • Contact us about privacy

    Reach the Nirvanas Creation team through the website’s contact page to raise any privacy concern.

  • Export, correction, retention, and revocation

    Available by request. Where a fully automated feature does not exist today, we handle these requests individually rather than claiming self-service automation.

Privacy Contact

For privacy, security, or compliance questions, contact Nirvanas Creation through our website’s contact page. We will route your request to the appropriate person and respond with care.

Website: nirvanascreation.com

Last updated: October 2026. This page describes our current practices and safeguards; it is general information, not legal advice. We will update it as our practices evolve.