Privacy Policy

What the MedSpañol app collects, how it is protected, who else can see it, and how long it is kept.

Drafted 2026-08-09 · no effective date

What this covers

This policy describes the MedSpañol patient app and the systems that run it. The health information the clinic holds about you as your health care provider is also covered by the Notice of Privacy Practices, which explains your rights under HIPAA.

Information you give us

  • Sign-in details: a mobile phone number, an email address, or both. If you sign in with Google, we receive the email address on that Google account.
  • Your intake, when you create your account: first and last name, date of birth, gender, the reason for your visit, your health goals, the conditions you check off, your medications, your allergies, whether you smoke, alcohol use, activity level, and an emergency contact name and phone number.
  • How you heard about the clinic, if you answer that question.
  • A weight you enter yourself, if you choose to.
  • Anything you type: messages to the clinic, care plan requests, home care requests, and the questions you ask Medbits.
  • A five-digit ZIP code, only if you use the local health lens.

Information the clinic and the app create

  • Appointments you book, reschedule, cancel or decline, including the reason you give when you decline a follow-up.
  • Clinical measurements your clinician records: monthly body-composition readings (weight, body-fat percentage, muscle mass) and lab values (A1C, ALT, ALP), together with who recorded them and when.
  • Provider notes, staff notes about you, your care plan and your care goals.
  • The Beats you earn and the rewards you redeem.
  • Referrals: if another patient invited you, we record that link.
  • Calls and texts handled by the clinic's communications provider: the phone number, whether it was inbound or outbound, the intent and outcome, a summary, and a transcript and recording link when the provider supplies them.
  • Your language, theme and text-message consent choices, including when you consented and to which version of the consent text.
  • A tamper-evident audit record of every read and write of health information: who, what, when, and the IP address the request came from.

Cookies, browser storage, and how you arrive

  • A secure, HTTP-only session cookie keeps you signed in for 30 days. Signing out ends it.
  • A small theme cookie lets the app render in your chosen theme without a flash. Your language and theme are also kept in your browser's storage.
  • If you arrived from an invite link, the opaque referral token stays in your browser until your account is created. It carries no name and no account id.
  • If you arrived from the clinic's marketing site after answering its opening question, the health topic you picked and the campaign you clicked travel in the web address for one page load, are moved into your browser's session storage, and are then removed from the address bar so they are not left in your history or sent onward as a referrer. The topic becomes one of your health goals when you finish onboarding.
  • There are no advertising or analytics cookies.

What we deliberately do not collect

  • No advertising trackers, no advertising cookies, and no sale of your information.
  • Card numbers, ever. The app can require a booking deposit through Stripe, but no deposit amount is configured today, so nothing is charged and no payment details reach us. If the clinic turns deposits on, your card details go straight to Stripe and the app keeps only Stripe's reference ids and whether the deposit was paid.
  • Raw phone numbers and IP addresses are not stored in the counters that protect sign-in from abuse — only one-way SHA-256 hashes are.
  • Your ZIP code is never placed in a web address and is not saved; only a masked form (the first three digits) is displayed back to you.

How the information is protected

  • The most sensitive free text — your medications, allergies and reason for visit, your clinician's notes, staff notes about you, and the saved history of your own intake edits — is encrypted with AES-256-GCM before it is written to the database, and is decrypted only at the moment it is shown to you or your care team. On the live site, if the encryption key is missing, clinical writes are refused rather than saved in the clear.
  • Traffic is served over HTTPS, and the app verifies the database server's TLS certificate before it connects.
  • Access is separated by role. Patients can reach only their own records, and staff screens are blocked for patient accounts both at the edge and inside the app.
  • Every read and write of health data writes an entry to a hash-chained audit log in the same database transaction as the access itself. If the audit entry cannot be written, the access does not happen.
  • Signing in uses a one-time code sent to your phone or email, or Google sign-in. A session lasts 30 days and ends when you sign out.
  • No safeguard is perfect, and the clinic's HIPAA security review is not finished. That is one of the reasons this pilot holds staff and test data only.

Who else sees it

The clinic uses these outside services. Each one is a business associate and must be under a signed agreement before real patient information is admitted — that is one of the open items listed at the top of this page.

  • theChattyAI — the clinic's communications provider. It delivers login codes, appointment reminders and clinic text messages, and it runs the clinic's voice front desk. It receives your phone number and the content of those messages, and it returns call and message records including transcripts and recording links. General Medbits answers are also served through theChattyAI; for those the app sends only a fixed topic code and two random identifiers, never your typed text.
  • The AI model provider (OpenAI models routed through the Vercel AI Gateway) — only if the clinic switches on personalized Medbits. That mode stays off unless it is explicitly enabled and the clinic's AI disclosure approval is set. When it does run, the provider receives only what you typed in that conversation, the clinic's own instructions, and a one-way hash of your account id — not your name, phone, email, date of birth or chart. The request asks the gateway for zero data retention, no training on the content, and HIPAA-eligible routing.
  • Anthropic — only for staff drafting: a suggested text reply or care-plan draft that a person at the clinic reviews and edits before anything is sent. It runs only when that same AI disclosure approval is set; otherwise the app uses a fixed, non-AI draft.
  • Neon — the managed Postgres database, provisioned through Vercel, where everything described above is stored.
  • Vercel — hosts the app and runs its server code.
  • Sentry — error monitoring, when it is configured. Request bodies, cookies, query strings and authorization headers are removed and phone numbers are masked before an error report leaves the app.
  • Upstash — optional storage for the sign-in rate limits. It receives hashed keys and counts, nothing else.
  • Stripe — only if booking deposits are turned on. They are not in use today.
  • Google — only if you choose Google sign-in, to confirm your email address. Calendar sync is off.
  • Public data sources for the local health lens — if you use it, your ZIP code goes to the U.S. EPA's public UV service and approximate coordinates for it go to the National Weather Service. AirNow air-quality data is downloaded as whole-country files, so nothing about you is sent there.

We do not sell your information and we do not share it for advertising.

How long it is kept

  • The app deletes nothing automatically. Your account, intake, appointments, measurements, messages and reward history stay until the clinic removes them.
  • Sign-in sessions expire after 30 days. The sign-in abuse counters expire and are deleted on their own.
  • The audit log is append-only by design: entries are never edited or deleted, because editing one would break the chain that proves the log is intact.
  • There is no self-service account deletion in the app today. Ask the clinic if you want your information removed, and see the Notice of Privacy Practices for what a health care provider is allowed to delete.
  • The retention schedule for clinical records has not been set yet. It is one of the items still to be decided with the clinic's counsel.

Your choices

  • You can edit most of your intake yourself in the app, including your name and date of birth. The how-you-heard-about-us answer and your consent records are not patient-editable, every edit is kept as a dated revision, and a clinically significant change flags your chart for clinician review.
  • You can turn appointment reminder texts on or off at any time in your profile, and you can reply STOP to any text.
  • You can change the app's language and theme at any time.
  • Your rights over your health record itself — access, amendment, an accounting of disclosures, restrictions, confidential communications and complaints — are described in the Notice of Privacy Practices.

Text messages

We do not share, sell, or provide your mobile phone number or messaging consent data to third parties or affiliates for marketing or promotional purposes.

  • You are texted only at a mobile number you typed, and only after you check a consent box for that number. The texts you can receive are one-time sign-in and verification codes and, only after you check the separate reminder box, appointment reminders.
  • The one other text MedSpañol sends is an invitation to a clinic staff member the clinic owner adds. It never goes to a patient.
  • The clinic does not send clinical content or marketing by text.
  • Message frequency varies. Standard message and data rates may apply.
  • Reply STOP to any text to stop appointment reminders and every other text MedSpañol sends on its own. A one-time code is sent only when you ask for it and check the box for that number; replying STOP does not stop a code you ask for yourself. Reply START to a MedSpañol text to allow reminders again. Reply HELP to any text for help.
  • These texts come from MedSpañol through theChattyAI, its communications provider, named under "Who else sees it" above.

Children

The app is built for adult patients. It does not currently check age at sign-up, so a parent or guardian should not create an account for a minor without speaking to the clinic first.

Changes and contact

This draft has no effective date. When the clinic's counsel approves a version, it will be published with an effective date and with how future changes are announced.

For now, questions about privacy go to the clinic's front desk. A named privacy contact, a mailing address and an email address for privacy requests still have to be filled in.