REFLEO HEALTH, INC.
PRIVACY POLICY
1. Start Here: What This Policy Covers, and What It Does Not
Refleo Health, Inc. ("Refleo," "we," "us," or "our") provides a between-session continuity tool for mental health care. A patient or client records short voice or text entries between appointments, and the clinician receives a brief summary before the next session, together with the underlying entries.
Refleo handles information in two very different roles, and it matters which one applies to you.
Role one: information we hold for a clinician (this policy does not govern it)
When a licensed clinician subscribes to Refleo and invites their patients or clients to record entries, those entries and the summaries built from them are protected health information ("PHI") that belongs to the clinician's record of care. Refleo holds that information as a business associate under the Health Insurance Portability and Accountability Act ("HIPAA").
That information is governed by our Business Associate Agreement with the clinician, by HIPAA, and by the clinician's own Notice of Privacy Practices. It is not governed by this Privacy Policy. If you are a patient or client and you want to see, correct, obtain a copy of, restrict, or delete your entries, contact your clinician. See Section 14.
Role two: information we collect for ourselves (this policy governs it)
Separately, Refleo collects information for its own business purposes. That includes information a clinician gives us when opening and paying for an account, information anyone gives us through our website or by contacting support, and technical information collected automatically when someone visits refleohealth.com. This Privacy Policy describes that information.
If you are a patient or client using Refleo at your clinician's invitation
The entries you record are between you and your clinician. Refleo does not read them for its own purposes, does not sell them, does not use them for advertising, and does not use them to train artificial intelligence models in any form that identifies you. Nobody at Refleo reviews your entries as you submit them, and Refleo is not a crisis or emergency service. If you need help right away, call or text 988, call 911, or go to the nearest emergency room.
2. Who We Are and How to Reach Us
Refleo Health, Inc. is a Delaware corporation. You can reach us about privacy at privacy@refleohealth.com or at Refleo Health, Inc., Attn: Privacy, 6245 Rufe Snow Drive, Suite 280-1044, Fort Worth, Texas 76148.
3. Information We Collect for Our Own Purposes
3.1 Information you give us
(a) Clinician account information: name, professional email address, practice name, license type and jurisdiction, phone number, and the credentials you create.
(b) Billing information: billing name, billing address, and a record of your plan, invoices, and payments. Payment card numbers are collected and stored by our payment processor, Stripe, Inc., and are not stored by Refleo.
(c) Support and correspondence: the content of emails, support tickets, and messages you send us, and our replies.
(d) Marketing and interest information: information submitted through demo requests, waitlist forms, newsletter signups, and similar forms.
(e) Feedback: comments, suggestions, and survey responses. Please do not include PHI in feedback.
3.2 Information collected automatically
When you visit our website or use the Services, we and our service providers may collect device and usage information such as IP address, browser type, operating system, referring page, pages viewed, dates and times of access, and general location inferred from IP address. We also collect security and audit information, including sign-in events, access logs, and records of activity within an account, which we use to secure the Services and to meet our obligations under the Business Associate Agreement.
3.3 Information from third parties
We receive limited information from our payment processor confirming that a payment succeeded or failed, and from our infrastructure providers as described in Section 8.
3.4 What we do not collect for our own purposes
We do not collect Participant entries, transcripts, summaries, or any other PHI for our own purposes. We process that information only to provide the Services to the clinician, and only as permitted by the Business Associate Agreement.
4. How We Use Information
We use the information described in Section 3 to:
(a) create and administer accounts, authenticate users, and provide the Services;
(b) bill for subscriptions, process payments, and maintain financial records;
(c) provide customer support and respond to inquiries;
(d) secure the Services, detect and investigate fraud, abuse, and security incidents, and maintain audit logs;
(e) operate, evaluate, troubleshoot, and improve the Services;
(f) send administrative messages about your account, billing, security, and changes to our terms or policies, which you cannot opt out of while you hold an account;
(g) send marketing communications to clinicians and prospective clinicians who have not opted out; and
(h) comply with legal obligations and enforce our agreements.
5. Artificial Intelligence and Model Training
5.1 Refleo does not use PHI that identifies an individual to train, tune, fine tune, or otherwise improve any artificial intelligence model. This commitment appears in our Business Associate Agreement and in our Terms of Service, and it is a contractual obligation, not a statement of current practice that we may change at will.
5.2 Refleo uses third-party artificial intelligence services to transcribe entries and to generate summaries and themes. Each such provider is engaged as a subcontractor under a written agreement that obligates it to protect PHI on the same terms that bind Refleo, and that prohibits it from using PHI to train its own models. A current list of subprocessors is available at https://refleohealth.com/subprocessors.
5.3 Refleo may use De-Identified Data, as described in Section 6, to evaluate and improve the Services, including to evaluate and improve the models used in the Services.
5.4 Automated processing can be incomplete and can be wrong. Refleo does not make, and its models do not make, any diagnosis, prognosis, treatment recommendation, or clinical decision. The clinician reviews the underlying entries and exercises their own professional judgment.
6. De-Identified and Aggregated Data
6.1 Refleo may de-identify information in accordance with 45 C.F.R. Section 164.514(b) and may combine de-identified information with information from other sources to create aggregated data (together, "De-Identified Data"). De-Identified Data does not identify any individual and cannot reasonably be used to identify any individual.
6.2 Refleo may use De-Identified Data to operate, evaluate, secure, and improve the Services, to develop new features, and for research, benchmarking, and other lawful business purposes. Refleo owns all right, title, and interest in De-Identified Data.
6.3 Refleo will not attempt to re-identify De-Identified Data and will not permit any third party to do so.
7. What We Never Do
7.1 We do not sell personal information or PHI, and we have not sold personal information or PHI in the preceding twelve months.
7.2 We do not receive any payment or other remuneration in exchange for PHI.
7.3 We do not use PHI, and we do not use information about a Participant, for marketing, advertising, or fundraising of any kind.
7.4 We do not share personal information with advertising platforms or data brokers, and we do not engage in targeted advertising, cross-context behavioral advertising, or profiling in furtherance of decisions producing legal or similarly significant effects.
7.5 We do not disclose to any third party the fact that a particular individual is a patient or client of a particular clinician, except as required by law or as permitted by the Business Associate Agreement.
8. Cookies, Analytics, and Tracking Technologies
8.1 Our website uses only cookies and similar technologies that are strictly necessary to make the site work and to keep it secure. We do not use analytics cookies, analytics services, or any other technology that measures how the site is used.
8.2 We do not place advertising pixels, conversion trackers, or other third-party advertising or marketing tags on our website or within the Services. We do not transmit information about your visit to advertising platforms.
8.3 We do not use cookies or similar technologies within the authenticated portions of the Services other than those strictly necessary to operate and secure them.
8.4 Most browsers let you refuse or delete cookies. Blocking strictly necessary cookies may prevent parts of the site or the Services from working. We do not currently respond to browser "Do Not Track" signals, but we honor recognized universal opt-out mechanisms where applicable law requires it.
9. How and When We Share Information
We share information only in the following circumstances:
(a) Service providers and subprocessors. Vendors that host, secure, transcribe, analyze, process payments for, or support the Services, each under a written agreement limiting their use of the information to providing services to us, and each bound by a business associate agreement where they handle PHI. A current list is available at https://refleohealth.com/subprocessors.
(b) At a clinician's direction. Information we hold for a clinician is disclosed as that clinician directs and as the Business Associate Agreement permits.
(c) Legal requirements. Where required by law, subpoena, court order, or other valid legal process, or where necessary to investigate or prevent fraud, a security incident, or a threat of harm. Where we receive legal process seeking PHI, we will notify the affected clinician unless we are legally prohibited from doing so, so that the clinician may respond or object.
(d) Business transfer. In connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to the acquirer being bound by obligations at least as protective as these, and subject to the Business Associate Agreement as to PHI.
(e) With your permission. Where you direct us to share information, or otherwise consent.
10. Where Information Is Stored
Refleo stores and processes information in data centers located in the United States. The Services are intended for use in the United States only, and we do not offer them to individuals located outside the United States.
11. Security
11.1 Refleo maintains administrative, physical, and technical safeguards designed to protect information against unauthorized access, use, and disclosure, including encryption of information in transit and at rest, role-based access controls, audit logging, workforce training, and vendor diligence.
11.2 No system is perfectly secure. We cannot guarantee the security of information transmitted over the internet or stored on any system.
11.3 If a breach of unsecured PHI occurs, Refleo will notify the affected clinician within the time and in the manner required by the Business Associate Agreement and by HIPAA, and the clinician, as covered entity, is responsible for notifying affected individuals. If a breach affects information Refleo holds for its own purposes, Refleo will provide notice as required by applicable state and federal law.
12. How Long We Keep Information
12.1 PHI. Information Refleo holds for a clinician is retained and disposed of as provided in the Business Associate Agreement. Following expiration or termination of a subscription, Refleo makes the clinician's information available for export for thirty (30) days, after which it returns or destroys PHI as the Business Associate Agreement provides. De-Identified Data is not returned or destroyed.
12.2 Clinicians remain responsible for their own record retention obligations under state law and their licensing board's rules, which typically extend well beyond Refleo's thirty (30) day export period and, for a patient who was a minor, may run for years after that patient reaches adulthood.
12.3 Other information. Account and billing records are retained while an account is active and for as long as needed afterward to meet tax, accounting, and legal obligations. Support correspondence, security and audit logs, and marketing contact information are retained for as long as needed for the purpose described in Section 4, and then deleted or de-identified.
13. Children and Minors
13.1 Refleo is built for adolescent and adult care, and our Terms of Service require every Participant to be at least 13 years of age. The Services are not offered to and may not be used by children under 13, and Refleo does not knowingly collect personal information from a child under 13. If we learn that a Participant is under 13, we will terminate that Participant's access and return or destroy the associated information in accordance with the Business Associate Agreement and applicable law. A parent or guardian who believes a child under 13 has provided information to us should contact privacy@refleohealth.com.
13.2 A Participant who is at least 13 but under 18 may use the Services only where a parent or legal guardian has completed Refleo's parental consent and authorization process, or where the Participant is permitted by applicable law to consent to their own care and the clinician has determined that the Participant may proceed without parental involvement.
13.3 Refleo does not decide which consent path applies. That is a matter of professional and legal judgment for the clinician, governed by state law and by the clinician's licensing board. Where a minor may lawfully consent to their own care, the clinician is responsible for determining what may and may not be disclosed to a parent or guardian, and Refleo follows the clinician's direction.
14. Your Choices and Your Rights
14.1 If you are a patient or client (Participant)
Your entries are part of your record of care with your clinician. To see them, correct them, obtain a copy, restrict their use, receive an accounting of disclosures, or ask that they be deleted, contact your clinician. Those rights run through your clinician as the covered entity, not through Refleo. If you send such a request to Refleo, we will forward it to your clinician and will support your clinician's response as the Business Associate Agreement requires.
14.2 If you are a clinician or a website visitor
You may ask us to access, correct, or delete the information we hold about you for our own purposes, and you may ask us to confirm whether we hold any. Email privacy@refleohealth.com. We will verify your identity before acting, will respond within the time applicable law requires, and will tell you if we cannot honor a request and why. We do not discriminate against anyone for exercising a privacy right.
14.3 Communications
You may opt out of marketing email at any time using the unsubscribe link in any marketing message or by emailing privacy@refleohealth.com. You will continue to receive administrative messages about your account, billing, security, and changes to our terms while you hold an account. Where the Services send text message reminders, we send them only with prior consent, and you may stop them at any time by replying STOP. Message and data rates may apply.
15. State Privacy Laws
15.1 Several states have comprehensive privacy laws, and several have laws specific to consumer health data. Most of them exclude PHI handled under HIPAA and information handled by a business associate, so the majority of what Refleo processes falls outside them. The rights described in Section 14.2 are available where those laws apply.
15.2 Texas. Refleo is subject to the Texas Medical Records Privacy Act, Chapter 181 of the Texas Health and Safety Code, in addition to HIPAA. Texas residents may exercise the rights described in Section 14.2 to the extent the Texas Data Privacy and Security Act applies. We do not sell sensitive personal data.
15.3 Washington and Nevada. Washington's My Health My Data Act and Nevada's health data law regulate consumer health data that is not governed by HIPAA. Refleo does not collect, use, share, or sell consumer health data for advertising, and does not sell consumer health data at all. Residents of those states may contact privacy@refleohealth.com with any request under those laws.
15.4 California. Where the California Consumer Privacy Act applies, California residents have the rights described in Section 14.2, together with the right to know the categories of information collected and disclosed. We do not sell or share personal information as those terms are defined in that statute.
15.5 Authorized agents. You may use an authorized agent to submit a request where applicable law permits. We will require proof of the agent's authority and will verify your identity directly.
16. Third-Party Websites
Our website and the Services may link to sites we do not operate. We are not responsible for the privacy practices of those sites, and this Privacy Policy does not apply to them.
17. Changes to This Policy
We may update this Privacy Policy. We will post the updated version with a new "Last Updated" date. If a change materially affects how we handle information, we will notify account holders by email at least thirty (30) days before it takes effect. Changes to how we handle PHI are governed by the Business Associate Agreement.
18. How This Policy Fits With Our Other Agreements
This Privacy Policy is incorporated into the Refleo Terms of Service. If there is a conflict, the Business Associate Agreement controls as to the use, disclosure, and safeguarding of PHI; the Terms of Service control as to all other matters; and this Privacy Policy is subordinate to both.
19. Contact
Questions, requests, and complaints may be directed to Refleo Health, Inc. at privacy@refleohealth.com or at Refleo Health, Inc., Attn: Privacy, 6245 Rufe Snow Drive, Suite 280-1044, Fort Worth, Texas 76148. You also have the right to complain to the U.S. Department of Health and Human Services, Office for Civil Rights, and to your state attorney general. We will not retaliate against anyone for filing a complaint.