PracticeDoorbell

Privacy

PracticeDoorbell is a doorbell. The check-in app tells your provider you have arrived, and the board app shows the front desk who is waiting. Both are built to do that while knowing as little about you as possible.

Last updated 11 September 2026

The short version

What the app records

There are only two kinds of record.

An arrival

Created when you tap to say you have arrived, that you are on your way, or that you cannot make it. It holds:

WhatWhy
Your initials, if you entered them So the provider can tell two people apart in a waiting room. Limited to four characters. Optional โ€” the app works without them.
The time you tapped So the provider knows how long you have been waiting.
Which provider you are seeing So the arrival reaches the right person.
Whether you arrived, are on the way, or cancelled So the provider knows what to expect.
The time the provider saw it So you can see that your message was received.

An arrival does not carry your name, date of birth, address, phone number, email, appointment reference, insurance details, or any clinical information. There is nowhere in the app to enter them.

A device pairing

When you first use the app, it exchanges a one-time code from your practice for an anonymous identifier. That identifier is a random string. It is not linked to a name, an email address, or a sign-in of any kind, and it is what allows your phone to ring one provider's doorbell and to see the reply to your own message.

How long it is kept

Arrivals are a same-day working reference, not a record to retain. At the end of each day, in the practice's own time zone, they are deleted outright rather than archived or marked inactive. This happens on its own and does not depend on anyone remembering to do it. A practice can also clear the day at any point before that, and the board shows only the current day's arrivals regardless.

Your device pairing lasts until the practice revokes it or you remove the app and clear its data.

Who can see it

An arrival can be read by the practice you checked in with โ€” specifically, by a screen that the practice has paired, or by a member of that practice's staff. Your own device can read back the one message it sent, so it can show you when the provider saw it. It cannot see anyone else's.

Knowing a practice's internet address is not enough to read anything. This is enforced by the database itself rather than by the app, so it holds regardless of what a particular page chooses to display.

Who we share it with

Nobody. There are no advertisers, no analytics providers, no data brokers, and no third-party tracking in this app.

Two service providers process data on our behalf in order to run the app at all:

Both act under contract and may not use the data for their own purposes.

Permissions

The app requests no device permissions. It does not access your location, camera, microphone, contacts, photos, files, or calendar. It cannot send you notifications.

Children

The app is intended for use by patients of a healthcare practice and is not directed at children. Where a minor is a patient, a parent or guardian may check in on their behalf. Nothing recorded identifies the person beyond their initials.

Security

All traffic is encrypted in transit. Access rules are enforced at the database, and staff access requires a signed-in practice account. Screens and devices can be revoked by the practice at any time, which immediately ends their access.

Your choices

Changes

If this policy changes in a way that affects what is recorded or who can see it, the date at the top of this page changes with it.

Contact

Questions about this app or the information it holds: pbh@psychologicalbehavioralhealth.com

For questions about your care or your medical record, contact your practice directly. This app holds no part of your medical record.