
Your clients trust you with their most private thoughts. Your storage should be worthy of that trust.
Bigby gives private health practitioners encrypted, UK-based cloud storage built around the confidentiality your clients expect and your professional obligations require.
Confidentiality doesn’t stop at the consulting room door
When a client shares something with you, they’re trusting you completely. That trust extends to every note you take, every document you store, every file that holds a trace of their name or their story.
For most practitioners, file storage is an afterthought. A free service that seemed good enough. But the major cloud platforms weren’t designed with therapeutic confidentiality in mind. Their terms are written for general consumers, and the data handling that goes along with them reflects that.

The risks worth understanding
Using a general-purpose cloud service for clinical or therapeutic records isn’t just a privacy question. It touches on your professional obligations, your clients’ rights, and your own exposure if something goes wrong.
GDPR and data controller obligations
As a private practitioner, you are a data controller under UK GDPR. That means you’re responsible for how client data is stored, processed, and protected, including the services you choose to store it with. A breach that originates with a third-party provider is still your breach to account for.
Professional body standards
Bodies such as the BACP, BPS, and UKCP set clear expectations around the confidentiality and security of client records. Storing sensitive case notes or correspondence on a platform that scans files or holds data on overseas servers may not sit comfortably alongside those standards. In the event of a complaint, it’s a question you’d rather not have to answer.
Data stored outside the UK
The major US cloud providers store data on US infrastructure, subject to US law. Legislation such as the CLOUD Act means that data can, in certain circumstances, be accessed by US authorities. For records as sensitive as therapy notes or psychological assessments, that’s a risk worth weighing carefully.
Terms that weren’t written for you
Consumer cloud services are designed for personal photos and documents, and their terms of service reflect that. Broad data usage rights, AI training provisions, and content scanning policies are common. They may be acceptable for general use, but they sit uneasily alongside a duty of care to vulnerable clients.
How Bigby works
Unlike the major cloud platforms, Bigby does not scan, analyse, or profit from the files you store. Here is how that works.
01. Encrypted in transit and at rest
Your files are encrypted on the way to us and while they sit on our UK servers, so they are protected in transit and never stored as readable plain text. We hold the encryption keys, which is what allows features like editing documents in your browser to work.
02. No access to file contents
Bigby does not open, scan, or read the contents of what you store. We have no business reason to and our data processing terms prohibit it.
03. No AI training or secondary use
Your stored content is not used for AI training, advertising targeting, or any analysis of any kind. The subscription fee covers the cost of running the service. That is the entire arrangement.
04. Your clients’ data stays in the UK
All data is stored on UK-based infrastructure. UK GDPR applies. There is no transfer to US servers, no exposure to US data law, and no ambiguity about where your clients’ information sits.
Frequently asked questions
Your clients deserve storage that takes confidentiality as seriously as you do
Private, encrypted, UK-based cloud storage from £3.99/month. Built for practitioners who can’t afford to be cavalier with client data.
See all plansAnnual or monthly billing · All prices in GBP · UK data residency · GDPR compliant