LoveCode
Security & privacy

Built for the clinical standard.

PHI is not a feature. It's the foundation. Here's exactly what we protect, how — and what we do not claim.

BAA in place

HIPAA-compliant. BAA in place. Built on SOC 2 Type II and ISO 27001-certified infrastructure.

Role isolation

Each partner’s data is isolated at the API layer. Partners cannot see each other’s records or your clinical notes.

AI transparency

AI drafts are labeled, attributed, and deny-by-default without clinician attestation.

Clinician-in-the-loop

AI drafts are never auto-filed. Safety alerts never auto-dispatch. Every clinical action requires your explicit sign-off.

Encrypted storage

Data encrypted in transit and at rest.

Audit trail

Every AI output, note signing, consent action, and safety record is timestamped and attributed.

HIPAA compliance

LoveCode is HIPAA-compliant. A Business Associate Agreement is in place. The platform is built on Google Cloud infrastructure certified to SOC 2 Type II and ISO 27001. PHI is encrypted in transit and at rest. Role isolation is enforced at the API layer — each partner's records are separated from the other's, and clients never see clinical notes.

What LoveCode is and is not

  • LoveCode is a clinical documentation platform — a support tool for licensed clinicians.
  • It is not a licensed mental health provider and does not provide therapy or clinical advice.
  • We do not publish uptime SLAs without a real measurement.
  • LoveCode makes no claims of clinical outcomes, recovery rates, or FDA clearance. It is not a medical device.
LoveCode is a clinical documentation and support platform. It is not a licensed mental health provider, does not provide therapy or clinical advice, and is not a substitute for the judgment of a licensed clinician. Session rubrics and outcome instruments are built on evidence-based couples-therapy frameworks; LoveCode operates independently and is not endorsed by or affiliated with any methodology's institutional owner.