You didn't go to grad school to read software contracts. But when an AI tool listens to your sessions and writes your notes, its contract decides three things. Who owns the note. What the company can do with the recording. And whether any of it ever trains an AI model. This post pulls the actual terms of three well-known note tools and quotes them, with dates.
The short version: one vendor answers the ownership question in plain text. One makes training a choice. One says nothing at all. If you're looking at these tools because documentation is eating your nights, that's a fair reason. The pull is real. Just read the terms before the demo wins you over.
Why is "who owns the data" suddenly a clinical question?
Because clients are already scared of this. In May 2026, NPR reported on therapists using AI note tools, and the trust numbers were rough. A YouGov survey found only 8% of Americans trust AI for mental health care. Just 11% would even be open to using it. And a KFF survey cited in the same report found about 77% of Americans worry about how AI systems would store and use their health information (NPR, May 26, 2026).
The report also told a story worth sitting with. Molly Quinn, a 31-year-old client in Fayetteville, Arkansas, learned an AI tool had been recording her sessions. She ended therapy, because nobody had clearly asked her first.
That's the stake for us. Clients tell us things they've never said out loud anywhere else. If a machine in the room has unclear rules, the work itself gets thinner. Guarding the data is part of guarding the frame.
These tools are everywhere now. NPR named Berries, SimplePractice, and Blueprint, priced from $19 to $99 a month. So odds are you've tried one, or you will. The trust fix is old-fashioned: ask the client first, in plain words. There's a full consent walkthrough in AI Scribe in Therapy: Consent and Whose Note It Is.
Who owns the data? The contract decides
Ownership isn't decided by vibes, and it isn't decided by HIPAA. It's decided by the vendor's legal terms. So start there. The terms of service and the privacy policy are the documents that bind. A sales email doesn't bind, and neither does a homepage.
Blueprint's Platform Services Agreement, last updated January 30, 2026, answers the question directly: "Clinic retains all right, title, and interest in and to Clinic Data." It adds: "Blueprint does not acquire ownership of Clinic Data." In plain words: under these terms, your practice owns the data. The vendor gets permission to handle it so the product works. That's the clause you want to see in any tool you buy.
Mentalyc's privacy policy, last updated March 2026, is the other case. It contains no data-ownership clause at all. No sentence says who owns the notes, the audio, or the transcripts. Silence isn't proof of anything bad. But silence means the answer lives somewhere you can't read. If the terms don't say, email the vendor and get an answer in writing before you sign.
Why care so much about ownership? Because notes outlive vendors. Your practice has to produce records for a client request, a subpoena, an audit, or a licensing board. Many states require you to keep records for years after a case closes. If a vendor folds, gets bought, or locks your account, "you own your data" stops being an abstract line very fast.
Does your client's session train someone's AI?
Ownership is question one. Question two matters more day to day: what may the vendor do with the data? Here, three vendors give three different answers.
Blueprint says "never." Its contract says a little more.
Blueprint's public Privacy & Security page is as clear as marketing gets: "Client data is never used to train AI models." It repeats the promise: "Your client information is never sold, shared, or used to train AI models" (accessed July 2026; the page shows no last-updated date).
The binding legal document uses narrower words. The Platform Services Agreement (January 30, 2026) says Blueprint "will not... use Clinic Data to train artificial intelligence models outside the provision of the Services." It also permits de-identified data, meaning data with names and identifying details stripped out, to be used for "the development of models, features, or functionality used as part of the Services."
Read those side by side. The marketing page says never. The contract says never outside the service, and it lets de-identified data feed model work inside the service. Those are different promises. To be clear, nothing here says Blueprint misuses data. The point is simpler: the contract is the one that binds, and it allows more than the marketing line suggests. Ask the vendor to explain the gap. A good one will.
Upheal makes training a choice
Upheal's client privacy policy takes a middle path: training happens only with consent. "With your consent we will use the summaries and insights to train the AI and improve our app," the policy states. It adds that "it is always optional to provide us with your data and consent," and says data is anonymized after 6 months of app usage (accessed July 2026). That's an honest setup. The lever exists, and you and your client hold it.
Mentalyc doesn't say
Mentalyc's policy (March 2026) contains no training clause in either direction. It says user data, like audio recordings, transcripts, and notes, is "collected solely to provide and improve the Service." "Improve the Service" is stretchy language. It could mean fixing bugs. It could mean more. The policy doesn't define it, so the text alone can't tell you. Again: ask, in writing.
One more data point from NPR's report. Berries co-CEO Tal Salman said audio is "processed in real time and deleted immediately," and that session content "is not repurposed for training" (NPR, May 26, 2026). Good words. The check is whether the vendor's legal terms say the same thing.
What about the new HIPAA security rules?
They're proposed, not final, and that word matters. The HIPAA Security Rule is the federal rule for how electronic health data must be protected. HHS's Office for Civil Rights published a proposed update to it in the Federal Register on January 6, 2025. The fact sheet explains why. In 2023, large health-data breaches affected more than 167 million people. From 2018 to 2023, reports of large breaches rose 102%, and the number of people affected rose 1,002%, driven by hacking and ransomware (HHS OCR fact sheet, January 6, 2025).
The proposal would require multi-factor authentication (a second login step, like a code on your phone), encryption, vulnerability scans every six months, and a yearly penetration test, which means paying experts to try to break in. As of this writing, none of that is a final rule. Don't let a vendor's sales page imply that it is.
Why does a proposed rule matter when you're picking a note tool today? Because it tells you where the floor is heading. A vendor already doing scans, encryption, and multi-factor logins won't have to scramble later. Ask them which of these they do now.
Keep the bigger point, though. Even the current rules are a floor, and floors crack. NYU medical ethicist Kellie Owens made that point in NPR's report: following HIPAA does not erase breach risk. A privacy badge on a vendor's homepage is only a start.
Five things to check before you sign
You don't need a law degree. You need thirty minutes and this list.
1. Find the ownership clause. Search the terms for "right, title, and interest." If your practice doesn't keep ownership in writing, keep shopping. 2. Find the training clause. Search for "train," "improve," and "de-identified." Silence is a question, and the marketing page is not the contract. 3. Get a signed BAA. A BAA (business associate agreement) is the contract that binds a vendor to federal health-privacy rules when it handles client data. Ask whether every AI feature is covered by it. No BAA, no client data. 4. Ask what happens to the audio. Deleted the moment the note is done? Kept 30 days? Kept forever? Get the retention answer in writing. 5. Ask about leaving. Can you export every note and get written proof of deletion? Ownership means little if you can't take your data and go.
If a sales rep can't answer these five in one short email, that silence is also an answer. And one thing that isn't on the vendor's list: tell your clients, and ask them first. No vendor setting can grant consent for you. Only your client can give it.
The bar any note tool should clear
A therapist should be able to answer "who owns my client data, and does it train anything?" in one sentence, without a treasure hunt through three documents. That's the bar VibeCheck.luxury is built to, by a clinician who writes these notes too: plain answers, HIPAA-eligible infrastructure, and executed BAAs. It's also close to what therapists keep saying they want from AI in the first place: help with the paperwork, and clear rules about the data.
If you're weighing a note tool and want a second set of clinician eyes on the fine print, book a call. Reading contracts is easier with company.
FAQ
Who owns client data when a therapist uses an AI note tool?
Whoever the vendor's contract says. Blueprint's agreement (January 30, 2026) states the clinic "retains all right, title, and interest" in its data. Mentalyc's March 2026 policy has no ownership clause at all. If the terms are silent, get the vendor's answer in writing before you sign.
Do AI note tools train their models on therapy sessions?
It varies by vendor. Upheal trains only with opt-in consent. Blueprint's marketing page says client data never trains AI models, while its legal terms allow de-identified data to support model development inside the service. Mentalyc's policy doesn't address training at all. Read the legal document, since the marketing page doesn't bind anyone.
Is a signed BAA enough to make an AI note tool safe?
No. A BAA binds the vendor to federal health-privacy rules, which helps. But NYU ethicist Kellie Owens told NPR (May 2026) that following HIPAA doesn't erase breach risk, and HHS reported that large breaches affected more than 167 million people in 2023 alone. Treat the BAA as the floor and the checklist above as the rest.
Do I need client consent before using an AI note tool?
Get explicit consent, every time, even where the law is fuzzy. NPR's May 2026 report described a client who ended therapy after learning her sessions were recorded without clear consent. For wording you can adapt, see AI Scribe in Therapy: Consent and Whose Note It Is.