Privacy Policy
Last updated: August 4, 2026
This Privacy Policy describes how Melissa Treat ("we", "us") processes personal data when you use Melissa, including the Melissa Custom GPT in ChatGPT connected to your account via OAuth.
1. Scope
Operator: Melissa Treat. Contact: melissatreat.main@gmail.com. Website: https://melissatreat.dev. Application: https://app.melissatreat.dev.
This policy applies to licensed mental health professionals who use Melissa. The Melissa Custom GPT is intended for professional use only, not for patients or the general public.
2. What the Custom GPT does
When connected, the GPT can search clients in your Melissa account (clients.read) and create new client records (clients.write) on your instructions.
Patient data accessed may include: patient identifier, first name, last name, birth year, and active status.
The current GPT integration does not access clinical notes, session content, or billing details.
3. Data we collect and process
Account authentication data (via Firebase / Google Identity) to verify that you are an authorized Melissa user.
OAuth authorization data (client ID, redirect URI, state) to complete the secure connection between ChatGPT and Melissa.
Patient data listed above to perform search and create actions you request in ChatGPT.
Technical logs (API requests, timestamps, errors) for security, debugging, and service reliability.
We do not sell your personal data.
4. How OAuth works
You authorize the GPT in ChatGPT, sign in to Melissa (Firebase authentication), and we issue a short-lived access token to ChatGPT with scopes clients.read and clients.write.
ChatGPT calls our API only to perform actions you request. You can disconnect by revoking access in ChatGPT and by not using the GPT.
5. Third-party services
We use service providers that may process data on our behalf: OpenAI (ChatGPT), Google / Firebase (authentication), Google Cloud Platform (hosting and infrastructure), and our PostgreSQL database for account and patient data.
Each provider processes data according to its own privacy policy and our agreements with them.
6. Data location and security
Personal data is stored and processed in the European Union (EU), primarily on Google Cloud infrastructure in EU regions.
We use encryption in transit (HTTPS/TLS) and industry-standard access controls. Access to patient data is limited to your authenticated account.
7. Retention
We retain account and patient data for as long as your Melissa account is active and as required to provide the service and comply with applicable law.
OAuth authorization codes and access tokens are short-lived and are not stored longer than necessary for authentication.
8. Your rights
Depending on your location, including the EU and UK under GDPR, you may have the right to access, correct, delete, restrict or object to processing of your data, withdraw consent where applicable, and lodge a complaint with a supervisory authority.
To exercise your rights, contact us at melissatreat.main@gmail.com.
9. Children
Melissa and this GPT are not directed at children under 16. The service is for professional use only.
10. Changes
We may update this policy. The "Last updated" date will change. Continued use after changes constitutes acceptance of the updated policy.
11. Contact
Melissa Treat. Email: melissatreat.main@gmail.com.