For Clinicians
Security and privacy

How 3A protects personal information

The 3A Toolkit is built to hold as little personal information as possible. This page explains what we keep, where, and how it is protected, for clients, clinicians and the organisations that review us.

What we keep, and what we do not

Reflections stay on the person's own device

What someone writes in the program is saved on the phone, tablet or computer they use. It is not stored on 3A servers, and neither 3A nor a clinician can read it.

What 3A holds

A mobile number for sign-in, the plan and its end date, and, for clients of a clinician, which code was used so a seat can be counted. For clinicians: name, practice, contact and billing details.

What clinicians see

Seat counts and whether each code has been used. Never names, phone numbers, activity or reflections.

What we never ask for

Clinicians never send us client information. Clients sign themselves in.

How it is protected

Sign-in without passwords

People sign in with their mobile number and a one-time code sent by text, with an automated check that blocks bots. There is no password to steal or reuse.

Encrypted connections

Every page and request uses HTTPS, and browsers are told to use only secure connections to 3atoolkit.com.

Access rules in the database

Each signed-in person can reach only their own account. Clinician and client records are reached only through functions that check who is asking.

Protected course content

Program videos and files are kept in private storage and opened with short-lived links after sign-in. Content is watermarked.

Payments handled by Paddle

Paddle is our merchant of record. Card and bank details go to Paddle, never to 3A.

Data location

Account data is stored with our database provider in [hosting region].

Our service providers

3A uses a small number of established providers. Each publishes its own security and compliance information.

Supabase

Database and sign-in.

Vercel

Website hosting.

Paddle

Payments, invoices and sales tax, as merchant of record.

Cloudflare

The automated bot check at sign-in.

SOC 2

3A does not have a SOC 2 report yet. We plan to complete a SOC 2 report by July 2027, depending on demand from organisations that require it. If your organisation needs SOC 2, or would like us to complete a security questionnaire, please tell us at sales@3atoolkit.com. Requests help us set the timing.

If something goes wrong

If we become aware of a breach that affects personal information, we notify the people affected and the relevant regulators as the law requires. To report a security concern, write to sales@3atoolkit.com with "Security" in the subject.

See also our privacy policy.