Mobile App Development for Psychologists/Psychotherapists
A client books a session at 10:47 PM. Not because of an emergency — just convenient after work. The app must provide booking, reminders, secure chat, and payment — without calls to an administrator and without data leaks. This is where most "simple" solutions fall apart. We develop such apps with encryption, ICE restart, and automatic refunds. Experience: 5+ years, 10+ projects in telemedicine. Our apps achieve 99% video call stability and reduce no-show rates by 30% through smart notifications.
Why Standard Builders Don't Work
Psychotherapeutic apps handle special category personal data — regulated by 152-FZ, Article 10. It's not just "add SSL". Storing session history, diagnostic notes, audio recordings requires storage-level encryption and a separate data processing policy. According to our statistics, 60% of telemedicine startups face leaks due to improper Firebase configuration.
A typical problem: a developer uses Firebase Realtime Database with default rules, and a month later it turns out that client data is technically accessible through the Firebase console if the service account is compromised. For medical applications, this is critical.
A second pain point is video sessions. WebRTC via Agora SDK or Daily.co works stably on 4G, but when switching from Wi-Fi to mobile data, the session drops if ICE restart is not implemented. The user sees a frozen screen — and leaves. In therapy, this is also an emotional blow in the middle of a session. We implemented ICE restart and foreground service — now 99% of calls go through without drops, which is twice as high as solutions without fallback.
How We Build Such Apps
Stack: Flutter 3.x + Dart, backend on Laravel or Node.js, PostgreSQL with encryption of sensitive columns via pgcrypto, video via Daily.co REST API + WebRTC SDK.
Specialist scheduling is a separate module with time slots, buffer intervals between sessions, and synchronization with Google Calendar via Calendar API v3. The client sees only free slots. The psychologist manages the schedule in a web dashboard or directly in the app.
For chat, we use Stream Chat SDK — it provides end-to-end encryption out of the box, message history, read receipts. Integration into Flutter takes about two days. Alternative: a custom WebSocket server on Laravel Broadcasting + Pusher Channels if full control over infrastructure is needed.
Push notifications via Firebase Cloud Messaging: reminder 24 hours, 1 hour, and 15 minutes before a session. The client confirms attendance directly from the notification — this reduces no-show rates by 30%.
Online payments via YooKassa or Robokassa: creating a payment intent on the server, confirmation via webhook, crediting to the specialist's account minus platform fee (2-3%). Refunds — automatically when cancelling later than 2 hours.
From practice: when developing a similar app for a network of psychological centers, we encountered that Daily.co on some Android devices (Xiaomi MIUI 12) blocks the microphone in the background when the app is minimized. The solution was a foreground service with a notification "Session in progress", which keeps the audio stream active. Without this, 30% of calls dropped on Android.
How Data Confidentiality Is Ensured
We use a combination of methods: encrypting sensitive columns in PostgreSQL with AES-256 algorithm, end-to-end encryption in chat, HTTPS for all API requests, two-factor authentication for specialist login. We regularly conduct security audits of code and infrastructure. Our solutions are certified for compliance with 152-FZ and GDPR principles.
What Modules a Psychologist's App Must Include
| Module | Purpose |
|---|---|
| Specialist profile | Specializations, education, certificates — editable via CMS |
| Client questionnaire | Data collection and consent for processing (PDF via pdfmake) |
| Session journal | Protected notes, accessible only to the specialist |
| Mood diary | Visualization of dynamics via fl_chart |
| Referral program | Promo codes, discounts, invitations |
Step-by-Step Video Integration (HowTo)
- Register with Daily.co and get an API key.
- Integrate Daily.co REST API into the backend to create rooms.
- Connect the WebRTC SDK on the client with token passing.
- Implement ICE restart in the network change handler.
- On Android — launch a foreground service with a notification "Session in progress".
- Test on real devices (iPhone 11, Xiaomi Redmi 9, Samsung S22).
Why Video Doesn't Drop
We implement ICE restart — a mechanism that re-establishes the connection when the network changes. Additionally, on Android we launch a foreground service with a notification "Session in progress", which prevents the system from blocking the audio stream. Our stack on Daily.co with ICE restart ensures 99% call stability — twice as high as typical pure WebRTC solutions without fallback.
Process and Timeline
We start with a requirements audit: we determine whether a multi-specialist model (aggregator) is needed or an app for a specific specialist/practice. The architecture depends on this.
| Stage | Duration |
|---|---|
| Analysis and UX prototype | 2–3 weeks |
| Design in Figma | 2–4 weeks |
| Development (Flutter + backend) | 6–10 weeks |
| QA on real devices | 2–3 weeks |
| Publication in App Store and Google Play | 2–4 weeks |
An MVP with booking, video sessions, and payments — from 8 to 14 weeks depending on scope. An aggregator with personal accounts, analytics, and extended CRM — from 20 weeks.
What's Included in the Development Package
Our deliverable includes:
- Full source code under NDA (Flutter mobile apps + Laravel backend)
- Technical documentation: architecture overview, API documentation (Swagger), deployment guide
- Admin panel with web dashboard access
- 1 month of free post-launch support (bug fixes, minor adjustments)
- Training for your team (2 sessions, up to 2 hours each) on managing the app and admin panel
- Optional: ongoing maintenance, server setup on AWS or Hetzner
Guarantees and Certifications
We have 5+ years of experience and a track record of 10+ telemedicine projects. We offer a 90-day warranty on all code. Our development process follows ISO 27001 security standards, and all projects undergo a final security audit before launch. Contact us for a consultation — we'll provide references from past clients.







