This Privacy Policy describes how Creative Labs AI, LLC ("Company," "we," "us," or "our") collects, uses, retains, discloses, and protects information about you in connection with the viVO web and mobile applications and related services, including the facescan feature and the Virtual Triage Assistant (collectively, the "App"). Section 8 of this Privacy Policy serves as our written policy, made available to the public, establishing our retention schedule and guidelines for permanently destroying biometric identifiers and biometric information. This Privacy Policy also describes your rights and choices, including under HIPAA and applicable state health data, consumer privacy, and biometric privacy laws. It does not cover the practices of your healthcare provider or of independent third parties, including advertisers and Sponsored Content affiliates, each of which maintains its own privacy practices. By using the App, you acknowledge that you have read and understood this Privacy Policy; if you do not agree with our practices, please do not use the App. Capitalized terms used but not defined here have the meanings given in the applicable viVO Terms of Use. This is a single Privacy Policy that applies to every viVO user in every access mode; Section 1 explains the two ways you can use viVO and which rules apply to you, and where a practice applies in only one mode, this Privacy Policy says so expressly.
You can use viVO in one of two access modes, and your mode determines which parts of this Privacy Policy apply to you.
Provider-Connected Mode. Your healthcare provider, clinic, or care organization (your "Provider") makes viVO available to you, and the App is connected to your Provider's workflows. In this mode both of the roles described below apply: some of your information is Protected Health Information handled under HIPAA, and the rest is consumer data governed by this Privacy Policy. The App in Provider-Connected Mode contains no advertising of any kind, as described in Sections 4 and 5.
Direct Mode. You sign up for viVO on your own, without a Provider connection, under the consumer viVO Terms of Use. Direct Mode includes a free tier, which may be supported, where available, by the contextual advertising described in Section 4, and a paid subscription tier, which contains no advertising. In Direct Mode we are not a business associate of any Provider and no information we hold about you is PHI; everything we collect is personal information or consumer health data governed by this Privacy Policy and applicable consumer privacy, consumer health data, and biometric privacy laws. Every protection in this Privacy Policy that is not expressly limited to Provider-Connected Mode applies fully in Direct Mode, including the biometric policy in Section 8 and the health data advertising firewall in Sections 4 and 5.
Switching modes. If you begin in Direct Mode and later accept an invitation to connect with a Provider, we will tell you before the connection takes effect, and information created in your Provider's workflows from that point forward is handled in Provider-Connected Mode. If your Provider relationship ends, your account may
continue in Direct Mode; records already delivered to your Provider remain part of your medical record under your Provider's obligations, and the information we continue to hold is governed by this Privacy Policy.
In Provider-Connected Mode, the rules that apply to a given piece of information depend on the context in which it is collected, as follows.
When we create, receive, maintain, or transmit identifiable health information on behalf of your Provider, such as your intake conversations, recordings and transcripts, and the pre-visit summaries prepared for your Provider and your medical record, that information is Protected Health Information ("PHI") under the Health Insurance Portability and Accountability Act ("HIPAA"). We handle PHI solely as a business associate of your Provider, and we use and disclose it only as permitted by our Business Associate Agreement with your Provider and by HIPAA. Your Provider's Notice of Privacy Practices also applies to that information. Requests to access, amend, or obtain an accounting of disclosures of PHI in your medical record should be directed to your Provider, and we will support your Provider in honoring them.
Other information we collect is not received on behalf of your Provider, such as your account and profile details, device and usage data, wellness readings you generate for your own tracking, and the goals, interests, and preferences you declare in the App. That information is personal information or consumer health data governed by this Privacy Policy and applicable consumer privacy laws, including state consumer health data and biometric privacy laws. The same category of information can fall on either side of this line depending on how it is collected and used. Where information is PHI, HIPAA and our Business Associate Agreement control over any conflicting term of this Privacy Policy. In Direct Mode, no PHI exists and all of your information is governed by this consumer framework.
Information you provide
You choose what to share with viVO. Depending on how you use the App, this may include: • Account and profile information: your name, contact details, date of birth, login credentials, and your insurance and coverage information, which we collect and keep current for one purpose: determining which App features are available to you, including applying the federal healthcare program restrictions described in Section 4. • Subscription and payment information: if you purchase a paid subscription in Direct Mode, your payment is processed by the app store or payment platform you use (such as Apple or Google), which handles your payment card details under its own terms and privacy policy. We receive confirmation of your transaction, your subscription tier and status, and the limited billing information needed to manage your subscription and required by tax and accounting law; we never receive or store your full payment card number. • Health intake information: the information you choose to share with the Virtual Triage Assistant by chat or voice, such as your symptoms, history of present illness, current medications, medical history, and any other health details you volunteer, together with the recordings and transcripts of those conversations, which are made only after you are informed and have given your consent. • Stated goals and interests: health goals and interests you expressly and voluntarily declare in the App, such as a weight management goal. Declaring goals and interests is always optional, and these declared statements are the only signals ever used for Sponsored Content matching, as described in Section 4.
• Communications with us: messages, support requests, feedback, and survey responses you send us, which we use to respond to you and improve the App.
• Foods you create: the name and nutrition values of custom foods you add in the nutrition feature, which are stored privately for you and, if you leave the sharing switch on, are also offered to our food team as described in Section 6.
Health documents you upload • Health documents you upload: The App lets you add your own laboratory results, imaging reports, and clinician notes by photographing them, choosing them from your photo library or your files, or opening a one-time link on a computer and uploading them from there. We collect the document itself, meaning the page images or the PDF file you provide, together with what is printed on it and read from it, which for a laboratory report typically includes the test names, values, units, and reference ranges, the collection date, the performing laboratory, the ordering clinician, and the patient name printed on the page. For an imaging report we read only the filing details, meaning the study date, the modality, the body region, the facility, and a short title; we do not read, store, or interpret the radiologist's findings or impression as data. Uploading is always your choice, document by document, and it operates only after you have given the separate health document upload consent described in Section 10. That consent is distinct from every other consent in the App because it is the only one under which a document you supply is sent to a third-party artificial intelligence vendor.
• Clinician notes you upload: A note written by a clinician who has seen you, such as a visit or consultation note or a discharge summary, is a third kind of document you may add, and it is read differently from a laboratory or imaging report. From it we read only what was documented and where on the page it was printed: each diagnosis code and diagnosis name exactly as printed, the qualifier printed with it, for example active, resolved, ruled out, or family history, the date of the note and any onset date printed on it, and the patient name, the facility, and the name and, where printed, the National Provider Identifier of the clinician who authored it. We keep the passage each diagnosis was read from so that you can see it on the page; apart from that passage we do not store or interpret the clinician's narrative, assessment, or plan as data, and we never record a code the clinician did not write. What we hold is a record of what was documented about you, by whom, and when, and never a determination by us that you have a condition. Clinician notes are covered by the same health document upload consent described in Section 10, are added one document at a time by your choice, and follow the same on-device-first handling, security, retention, and destruction rules as every other document you upload.
• What leaves your device when you upload, and what we send onward. The page images or the PDF file you provide are uploaded to our own file storage as soon as you add the document, in every case and before any reading takes place. They are held in the private, account-scoped file store described in Section 11, retained and destroyed on the schedule in Section 9, and keeping them is what allows you to reopen, re-crop, and check the original page against what was read from it. What the on-device reading changes is therefore not whether your page image reaches us; it is what we send onward to the third-party artificial intelligence vendor that reads the document for you. Every page is first read on your device itself. When that on-device reading comes through cleanly, we send that vendor only the resulting text, and your page image is not sent to it. When it does not, we send the page image to that vendor as well, because text alone would produce wrong values. The App tells you, for each page, which of the two is expected before you add the document. If a page was sent as text only and what came back is visibly incomplete, we read that page again with the image so that the values are not silently wrong, and the App records that this happened. You may turn on a setting that asks for text-only reading, which keeps a page on the text route even when the on-device reading is poor, so that such a page produces no results rather than have its image sent onward; the re-reading just described still applies to a page sent that way. A document added through the one-time computer link is always sent as an image or as the original PDF file, because a web browser cannot perform the on-device reading step, and the upload page says so before you add a file.
• Corrections you make: if a value was read incorrectly you can correct it, confirm it, or remove it. We keep what was originally read alongside your correction, so that what the App showed you and what you changed it to both remain answerable. Your correction is what appears on your timeline.
Camera and biometric information • Camera and biometric information: The facescan feature operates only after you have been informed of the specific purpose and the length of time for which your biometric information will be collected, stored, and used, and have provided your express written consent, which may be given electronically. With that consent, the feature captures short video of your face through your device camera and derives facial geometry from it solely to estimate vitals and wellness indicators, such as heart rate and respiratory rate. Raw camera frames are processed in real time to compute your readings and are retained only transiently as needed for that computation; they are not stored as part of your profile. The facescan feature is never used to identify you, verify your identity, or recognize you. No part of the facescan pipeline is ever used for advertising, Sponsored Content matching, or any other commercial targeting: not the camera frames, not the facial geometry, and not the vitals or wellness readings derived from them. Sponsored Content is matched only to goals and interests you expressly declare, as described in Section 4. Our retention schedule, destruction guidelines, and all other biometric practices are governed exclusively by Section 8.
Information collected automatically • Device and usage information: When you use the App, we automatically collect technical information from your device, including device type and model, operating system and version, app version, device and app-level identifiers, IP address, log data such as access times, pages viewed, and crash reports, approximate location derived from your IP address, and how you interact with App features. We use this information to operate, secure, troubleshoot, and improve the App, and to apply the correct feature availability for your account. In the Direct Mode free tier we use only device type, operating system, language, and approximate location from this category to select the contextual advertising described in Section 4; we never use your device and usage information for Sponsored Content matching or for any other advertising purpose. We do not collect your precise GPS location. In Provider-Connected Mode, the App does not contain any third-party advertising trackers, advertising pixels, or advertising software development kits (SDKs). In the Direct Mode free tier, advertising vendors process limited non-health information solely on our behalf as described in Section 4, and in every mode we never permit any third party to collect information from the App for its own advertising purposes.
Information from your Provider (Provider-Connected Mode only) • Information from your Provider: Your Provider may supply information about you so the App can function for you, including enrollment and roster information such as your name and contact details, appointment and scheduling information, care program information such as the care programs you are enrolled in and preventive care items your Provider is tracking, and insurance and coverage information, including whether you are enrolled in a federal healthcare program. We receive this information on behalf of your Provider and handle it as described in Section 1. We use it to set up and maintain your account, prepare your intake and pre-visit workflows, support your Provider's care programs, and apply the correct feature availability to your account, including the federal healthcare program restrictions described in Section 4. We rely on your Provider for the accuracy of this information, and it is never used to select or target Sponsored Content.
We use your information for the purposes described below. Each use is either necessary to provide the App features you request, undertaken with a consent you have given, or required of us by law. • To provide the App: to create and maintain your account; manage your free tier or paid subscription in Direct Mode; capture your intake conversations and prepare pre-visit summaries for your Provider; compute and display your vitals and wellness readings; deliver care navigation, educational content, and appointment and care reminders; support the care programs your Provider enrolls you in; and respond to your messages and provide support. • To operate the App safely and reliably: to authenticate you and secure your account; protect the security and integrity of the App; detect, investigate, and prevent fraud, abuse, and violations of our Terms of Use; troubleshoot, debug, and repair errors; and apply the correct feature availability to your account, including enforcing the federal healthcare program restrictions described in Section 4. • To meet legal obligations: to comply with applicable law, including medical record retention requirements, to respond to lawful requests and legal process, and to establish, exercise, or defend legal claims. • To read the health documents you upload: to turn the results printed on a document you provide into structured entries, to check those entries for transcription errors, and to place them on a per-analyte timeline alongside your other results so you can see one measurement across every laboratory you have used. This processing is performed by an artificial intelligence service provided by Anthropic, PBC, which acts as our service provider under a business associate agreement and is contractually prohibited from using your information for its own purposes, including training or improving its models. If that agreement is not in force, the App refuses to send anything to that vendor: your document is still stored for you, you can still read it, and you can still enter values by hand, but no automated reading takes place. The App organizes and charts what you upload; it does not interpret your results, and nothing it shows you is a diagnosis, a clinical opinion, or medical advice. For a clinician's note, that same reading records which diagnoses were documented, by whom, and when, so that you can see what your clinicians have written down and, where you disagree, ask them to amend it; the App does not decide whether a diagnosis is correct, current, or complete. • To improve viVO: we use identifiable information for one improvement purpose only: creating de-identified data in accordance with Section 7. Once created, we use de-identified data, and only de-identified data, to develop, train, and improve our models, features, and services. We do not train our models on information that identifies you. • For Sponsored Content: only if you opt in, only using the goals and interests you expressly declare, and only as described in Section 4. • To display advertising in the Direct Mode free tier: only as described in Section 4, using only the limited non-health signals listed there, and never using your health information. The App uses automation, including artificial intelligence, to operate, for example to generate draft summaries and apply eligibility rules, but we do not use your information to make decisions that produce legal or similarly significant effects about you, such as decisions about your care, coverage, or treatment, without human involvement; all clinical decisions are made by your Provider. We use your information only for the purposes described in this Privacy Policy or otherwise disclosed to you at the time of collection, and we will not use it for materially different purposes without providing notice and obtaining any consent required by law.
This Section describes the only two ways commercial content can ever appear in viVO: contextual advertising in the Direct Mode free tier, and the optional Sponsored Content feature. One rule applies to both, in every mode and every tier, without exception, and we call it the health data advertising firewall: your health information is never used to select, target, or measure advertising of any kind. Your intake conversations, recordings and transcripts, biometric and facescan data, vitals and wellness readings, information supplied by a Provider, and any health condition our systems could infer are never used for any advertising purpose. In Provider-Connected Mode, the App contains no advertising at all.
Advertising in the Direct Mode free tier
The Direct Mode free tier is supported by advertising, which is what allows us to offer it at no charge; upgrading to a paid subscription removes advertising entirely. Free tier advertising works as follows, and only as follows:
● Contextual, not behavioral. Ads are selected using only non-health signals: the general placement in the App where the ad appears, your device type, operating system, and language, your approximate (city-level) location derived from your IP address, and your subscription status. We never select ads using your health information (see the firewall above), the goals and interests you declare, your identity or contact information, or your activity in other apps or on other websites. We do not build advertising profiles of you, and we do not engage in cross-app or cross-site tracking.
● Advertising vendors work only for us. Ads may be delivered and measured through advertising vendors acting as our service providers. They may process device identifiers, IP address, coarse location, and ad delivery and interaction events (such as the fact that an ad was shown or tapped) solely to serve, cap, measure, and secure advertising for viVO. They are contractually prohibited from using this information for their own purposes, from combining it with information from other apps, websites, or companies, from building profiles of you, and from receiving any of your health information.
● Ad content standards. Ads are always visually distinct from App content and from anything relating to a Provider, are not medical advice, and are not an endorsement or recommendation by us. We do not permit advertising for unlawful products or services, and advertising for healthcare items and services is subject to the federal healthcare program restrictions described below.
● Your choices. You can remove all advertising at any time by upgrading to a paid subscription. Because ads are contextual, there is no advertising profile of you to manage and no cross-app tracking to opt out of, and your device-level advertising settings are respected in all cases. Free tier advertising never appears in Provider-Connected Mode and is never shown to anyone under eighteen.
Sponsored Content (optional, off by default)
The App includes an optional Sponsored Content feature that, where available, displays clearly labeled offers, programs, and educational content from independent third-party affiliates, matched to health goals and interests you expressly declare. The feature is engineered so that all matching happens inside viVO, and your information is never disclosed to any advertiser or affiliate unless and until you individually direct it. It works as follows, and only as follows:
Off by default; specific opt-in. No Sponsored Content is shown, and no commercial matching, personalized advertising targeting, or behavioral profiling for commercial purposes occurs, unless you first opt in through a dedicated consent screen that is never pre-selected for you and that describes how the feature works. Opting in is voluntary, is never a condition of receiving care or using the App, and does not change the care you receive or your relationship with your Provider.
Declared interests only. Matching is based solely on the goals and interests you expressly declare in the App. We never use the following to select Sponsored Content: your biometric or facescan data, including the vitals and wellness readings derived from them; the content of your clinical conversations beyond your declared goals; health conditions inferred by our systems; your device and usage information; or information your Provider supplies about you, including care gap and coverage information.
Clearly labeled, never a recommendation. Sponsored Content is always conspicuously labeled as sponsored, is ordered by relevance to your declared interests and not by how much an affiliate pays us, and is not medical advice, an endorsement, or a recommendation by us or by your Provider.
Your information stays inside viVO. All matching happens inside our systems. We do not sell, share, license, or disclose your identity, contact information, health information, interests, or activity to advertisers or affiliates, and affiliates receive only aggregate statistics, subject to minimum group sizes, that cannot reasonably be used to identify anyone. The only exception is the limited information you individually direct us to send when you choose to connect, described next.
Connections only at your direction. Information is transmitted to an affiliate only when you affirmatively ask to connect and then confirm a consent screen listing exactly what will be shared, which is limited to your basic contact information and the single interest you selected. If you decline at that screen, nothing is sent. Once you direct us to send information to an affiliate, that affiliate handles it as an independent business under its own privacy practices, so review its privacy policy before connecting.
Instant revocation. You may opt out of Sponsored Content, and end any affiliate connection going forward, at any time in settings, without penalty and without losing any communication access to your Provider. Revocation applies prospectively: it stops all future matching and transmissions, but it cannot retrieve information an affiliate already received at your direction.
Federal program enrollees. If our records indicate you are enrolled in Medicare, Medicaid, TRICARE, CHIP, or another federal healthcare program, Sponsored Content, subsidies, and affiliate offers are disabled for your account as required by federal law, and any prior opt-in is suspended. This applies automatically if your coverage later changes to a federal program, so please keep your coverage information accurate. In the Direct Mode free tier, advertising for healthcare items and services is likewise not shown to federal healthcare program enrollees.
Where PHI would be used to display Sponsored Content, we and your Provider will first obtain a separate, signed HIPAA marketing authorization from you that states the purpose, discloses any payment we receive in connection with that use, and explains your right to revoke it at any time; if you revoke, PHI-based display stops going forward.
• We never sell your personal information, your consumer health data, or your PHI. We do not "sell" or "share" personal information as those terms are defined under the California Consumer Privacy Act, and we do not sell consumer health data as defined under applicable consumer health data laws.
• We never disclose information that identifies you to advertisers or Sponsored Content affiliates, other than the limited information you individually direct us to send at a connect screen as described in Section 4.
• We never sell, lease, trade, or otherwise profit from your biometric identifiers or biometric information; no part of the facescan pipeline, including the vitals and wellness readings derived from it, is ever used for advertising or Sponsored Content matching; and biometric identifiers are never included in any data we license, sell, or transfer in any form, identifiable or de-identified.
• We never use the health documents you upload, or anything read from them, for advertising or Sponsored Content matching, and we never allow the artificial intelligence service that reads them, or any other service provider, to use them to train or improve its own models.
• We never use your health information to select, target, or measure advertising. This is the health data advertising firewall described in Section 4, and it applies in every access mode and every tier, to free tier
advertising and to Sponsored Content alike.
• We never permit any third party to collect information from the App for its own advertising purposes, we never engage in cross-app or cross-site tracking, and we never build behavioral advertising profiles of you. In Provider-Connected Mode, the App contains no advertising and no advertising trackers, pixels, or advertising SDKs of any kind; in the Direct Mode free tier, advertising vendors act solely as our service providers under Section 4.
• We never direct advertising or Sponsored Content to anyone under eighteen, and we never direct Sponsored Content, affiliate offers, or healthcare advertising to federal healthcare program enrollees.
To be transparent about how our business works: like many health technology companies, we do create, use, license, and sell data that does not identify you. This includes de-identified and aggregated measures such as care gap closure rates, stated interest and intent trends, engagement patterns, and program outcomes, including benchmark analytics provided to health plans, researchers, and other healthcare organizations. Before any such data is used or shared, it is de-identified under the HIPAA standards described in Section 7 so that it no longer identifies you and cannot reasonably be re-identified; it never includes your biometric identifiers; we commit not to attempt to re-identify it; and everyone who receives it from us must make the same commitment. Nothing in this paragraph changes the promises above: information that identifies you is never part of these data products.
We share information only as described in this Section. We never sell information that identifies you, as stated in Section 5. • With your Provider and care team: your intake conversations, recordings, and transcripts, the pre-visit summaries generated from them, and your vitals readings (heart rate and respiratory rate). Once delivered, these records become part of your medical record maintained by your Provider and are governed by your Provider's Notice of Privacy Practices and retention obligations. Wellness Metric readings are displayed to you in the App for your own tracking and are not delivered into your Provider's clinical workflows or your medical record; you are always free to discuss them with your Provider yourself.
• At your direction: when you ask us to share information, for example when you confirm a connect screen for a Sponsored Content affiliate as described in Section 4, or when you export or share your own records.
• Foods you add to the shared food list: When you create a custom food in the nutrition feature, it is saved privately to your account and only you can see it. You can also offer it — the food's name and its nutrition values, and nothing else — to our food team for possible inclusion in the shared Colombian food list that all viVO users can search. The sharing switch is on by default when you add a food, and you can turn it off with one tap before saving, or decline to share any future food; declining never affects your ability to log meals. Your submission is reviewed by a curator who does not see your name, your account, or anything else about you: the review screen is built so that your identity is never available to it. If approved, as submitted or with corrections by our team, the food's name and nutrition values become part of the shared list, where they are not associated with you in any way. Because the food name is text you typed, do not include personal details in it; our team may decline or rename a submission whose name could identify someone. Sharing a food never shares your meals, your photos, or anything about when or whether you ate it.
• With service providers: companies that help us operate viVO, such as cloud hosting and infrastructure providers, communications delivery vendors, security and crash-reporting tools, and support platforms, including Lucas Health Corporation, whose embedded artificial intelligence technology powers transcription, conversational, and voice features. Service providers may use your information only to provide services to us, are contractually prohibited from using it for their own purposes, including advertising, and, where they handle PHI, are bound by business associate obligations.
• With the artificial intelligence service that reads your uploaded documents: when you upload a health document, the text read from each page, and the page image or PDF file itself where Section 2 says an image is sent, is transmitted to Anthropic, PBC, which returns the structured result. Anthropic acts solely as our service provider under a business associate agreement, may use what it receives only to perform that processing for us, is contractually prohibited from using it for its own purposes including training or improving its models, and receives nothing else about you: not your account, not your other records, and no identifying detail beyond what is printed on the document you chose to upload. Where that agreement is not in force, no document is sent at all, as described in Section 3.
• With advertising vendors (Direct Mode free tier only): vendors that serve and measure the contextual advertising described in Section 4 receive device identifiers, IP address, coarse location, and ad delivery and interaction events. They act solely as our service providers and are contractually prohibited from using that information for their own purposes, combining it with information from other sources, building profiles of you, or receiving any of your health information.
• With health plans and payers: where your Provider participates in quality reporting programs, care gap closure and quality measure information may be reported to your health plan at your Provider's direction and as permitted by HIPAA, in some cases as a limited data set under a data use agreement. Your health plan already maintains its own records of your coverage and care; this reporting is care measurement, not advertising, and it is never used to select Sponsored Content.
• De-identified and aggregated data: we provide de-identified and aggregated analytics, such as the benchmark measures described in Section 5, to health plans, researchers, and other healthcare organizations, subject to the de-identification standards and no re-identification commitments in Section 7.
• For legal reasons: to comply with applicable law, legal process, or enforceable governmental requests; to enforce our Terms of Use; to establish, exercise, or defend legal claims; or to protect the rights, safety, and security of users, the public, or viVO. Where legally permitted, we direct requests for your medical records to your Provider.
• Corporate transactions: if Company is involved in, or evaluates, a merger, acquisition, financing, reorganization, bankruptcy or similar proceeding, or a sale of all or substantially all of its assets, information may be reviewed during due diligence under confidentiality obligations and transferred as part of the transaction. Any successor's use of information that identifies you remains subject to this Privacy Policy as in effect when the information was collected, any biometric information transfers only to a successor that assumes the commitments in Section 8, and any material change by a successor is subject to Section 13, including any notice and consent required by law. De-identified data may be transferred subject to the no re-identification commitments in Section 7.
We create de-identified data from information collected through the App in accordance with the HIPAA de-identification standards (45 C.F.R. Section 164.514(b)), using the safe harbor method or a documented expert determination, so that it no longer identifies you and cannot reasonably be used, alone or in combination with other information, to identify you. Aggregated data is additionally combined across many individuals and reported subject to minimum group sizes.
We own de-identified and aggregated data and may use, license, sell, and otherwise commercialize it for any lawful purpose. Examples include care gap closure and quality benchmark analytics for health plans and healthcare organizations, stated interest, intent, and engagement trend insights, research, improving and training our models, creating industry insights, and transfers in connection with corporate transactions as described in Section 6.
These commitments always apply to de-identified data:
● We will not attempt to re-identify it, and we maintain technical and organizational safeguards designed to prevent re-identification.
● Everyone who receives de-identified data from us must contractually commit not to attempt re-identification and not to onward-transfer it except under the same commitment.
● It never includes your biometric identifiers, facial geometry, facial templates, camera frames, or the raw content of your clinical conversations; conversation-derived insights are included only as de-identified topics, categories, and trends.
● If we ever learn that data we treated as de-identified can identify someone, we will treat it as personal information under this Privacy Policy and require its return or destruction by recipients.
Once data is de-identified under these standards, it is no longer personal information, consumer health data, or PHI, and this Section, rather than the individual rights in Section 10, governs it; deleting your account does not recall previously created de-identified data, as described in Section 9.
This Section is our written policy, made available to the public, establishing our retention schedule and guidelines for permanently destroying biometric identifiers and biometric information, including under the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act, and similar laws. We apply this policy to all users, regardless of where you live.
● What we treat as biometric. When you use the facescan feature, we treat the scan of your facial geometry derived from your camera feed as biometric information. Raw camera video is processed in real time to derive that geometry and compute your readings, and is not retained after your readings are computed or stored as part of your profile; we do not retain photographs of your face. The vitals and wellness readings that result are measurements, not biometric identifiers, but as described in Sections 2 and 4, no part of the facescan pipeline, including those readings, is ever used for advertising or Sponsored Content matching.
● One purpose only. We collect and process biometric information for a single purpose: estimating the vitals and wellness indicators displayed to you and, for heart rate and respiratory rate, shared with your Provider. We never use biometric information to identify you, verify your identity, recognize you, or track you, and we never use it for profiling.
● Consent first. Before any capture, we inform you in writing that biometric information will be collected and stored, the specific purpose of collection, and the length of time for which it will be collected, stored, and used, and we obtain a written release from you, which you may provide electronically. We do not knowingly collect biometric information from anyone under eighteen.
● Withdrawal. You may withdraw your facescan consent at any time in settings. Withdrawal stops all further collection, and we treat the purpose of collection as fulfilled for your previously collected biometric information, which triggers destruction under the schedule below without requiring you to delete your account.
● No profit. We do not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information, and they are never included in any data we license, sell, or transfer, in any form.
● Limited disclosure. We do not disclose biometric identifiers or biometric information to third parties except with your consent, to complete a transaction you request or authorize, or as required by law or pursuant to a valid warrant or subpoena. Our service providers that host or process data on our behalf (Section 6) may store or process biometric information solely for us, under contracts imposing restrictions at least as protective as this Section; we treat that as our own storage, and they may not use it for any other purpose. In a corporate transaction, biometric information transfers only to a successor that assumes the commitments in this Section, as described in Section 6.
● Voice is not a voiceprint. The App records and transcribes your voice conversations only with the consents described in Section 2. We do not create voiceprints, and we do not use your voice to identify or authenticate you. If we ever introduce voice-based identification, this Section will govern it and we will obtain a new, separate consent first.
● Storage and security. We store, transmit, and protect biometric information using the reasonable standard of care within our industry and in a manner the same as or more protective than the manner in which we protect other confidential and sensitive information, including encryption in transit and at rest, access controls limited to personnel who need it to operate the feature, and audit logging.
● Retention and destruction schedule. We permanently and irrecoverably destroy biometric identifiers and biometric information upon the earliest of: (a) fulfillment of the purpose of collection, including your withdrawal of consent; (b) your verified deletion request under Section 9; or (c) three (3) years after your last interaction with the App. Destruction covers our active systems, extends to backup systems on their standard purge cycles, includes instructions to service providers to do the same, and is documented in our internal records.
We retain information for as long as needed for the purposes described in Section 3, and we explain here what that means in practice. Biometric information follows the stricter schedule in Section 8.
● While your account is active. Your chat logs, transcripts, and generated summaries are retained while your account is active because they serve as reference points for your ongoing care and your communication with your Provider, and because medical record retention laws may require it. Account, device, and usage information is retained for as long as needed to operate and secure the App. We may delete or de-identify information associated with accounts that have been inactive for an extended period.
● Health documents you upload: retention and destruction schedule. A document you upload, the page images or PDF file behind it, and the values read from it are retained while your account is active, for the same reasons as your chat logs above: they are reference points for your ongoing care, and medical record retention laws may require it. We permanently and irrecoverably destroy them upon the earliest of: (a) you delete the document in the App; (b) you withdraw the health document upload consent described in Section 10; (c) your verified deletion request under this Section; or (d) three (3) years after your last interaction with the App. Every destruction is recorded, including the reason for it and the time it completed, and you can see that record for your own account.
● What deleting a document covers. Deleting a document removes the stored file itself, not only the entry that points at it. The page images and any PDF you uploaded are purged from our file storage, the values read from that document are removed from your timeline, and the destruction is recorded as described above. Deleting your account does the same for every document you have uploaded. Backup and archived copies are purged on their standard cycles and in any event within the six (6) month window described below. Our audit records continue to show that a document existed, when it was created, and when it was destroyed, with the content of the document redacted, because we are required to retain that accounting; they are not a copy of your results.
● How to request deletion. You may request deletion of your account and information in the App settings or through the contact information in Section 14, and your Provider may submit the request on your behalf. We take reasonable steps to verify the identity of the requester before acting, to protect your information against fraudulent deletion requests.
● You may also request deletion of your account and information without reinstalling the App by emailing support@cre8ivelabs.ai.
● What happens when we delete. Upon a verified deletion request, we will permanently and irrecoverably purge information containing personal identifiers, including recordings, unredacted chat histories, camera-derived data, and demographic identifiers, from our active production systems within sixty (60) days, and we instruct our service providers to do the same. Backup and archived systems are purged on their standard cycles and in any event within six (6) months of the verified
request. Before purging records connected to active care, we notify your Provider and make the affected records available for export for thirty (30) days; that window runs inside, and does not extend, the sixty (60) day period. Prior to or concurrent with the purge, we may de-identify the affected data in accordance with Section 7.
● Exceptions. We retain information where and only for as long as required by applicable law, medical record retention requirements, or a bona fide legal hold or litigation preservation obligation. Information retained under an exception remains protected by this Privacy Policy, is not used for any other purpose, and is deleted when the obligation ends.
● What deletion cannot do. Deletion applies to Company's systems. Records already delivered to your Provider are part of your medical record and are retained by your Provider under their own legal obligations; direct requests about your medical record to your Provider. Deletion cannot retrieve information an affiliate already received at your direction under Section 4, and it does not recall de-identified data previously created under Section 7, which no longer identifies you.
All users • Access and portability: you may view and update your profile information directly in the App at any time, and you may request a copy of the information we hold about you in a portable and readily usable format. • Correction: if you believe any information we hold about you is inaccurate, you may correct it in the App where editable or ask us to correct it, and we will do so or explain why we cannot. • Deletion: you may request deletion of your account and information as described in Section 9. • Records held by your Provider: your HIPAA rights to access, amend, and receive an accounting of disclosures of your medical record are exercised through your Provider, and we support your Provider in honoring those requests. • Consent withdrawal: you may withdraw facescan consent, recording consent, communications consent, the health document upload consent, and Sponsored Content participation at any time in settings, each independently of the others. Withdrawal takes effect prospectively: it stops further collection and use but does not undo processing that already occurred with your consent. Withdrawing facescan consent also triggers destruction of your previously collected biometric information under the schedule in Section 8. Withdrawing the health document upload consent stops any further document processing and triggers destruction of the documents you have already uploaded, and of the values read from them, under the schedule in Section 9, without requiring you to delete your account. Features that depend on a consent will stop working when you withdraw it, for example vitals readings require the facescan consent, but withdrawing any consent never affects your care, your access to the rest of the App, or your communication with your Provider. • Communications: unsubscribe links are included in marketing emails, and you may reply STOP to opt out of text messages. Consenting to marketing communications is never a condition of receiving care or using the App. We will still send essential service communications, such as security notices and, where enabled by your Provider, appointment and care reminders. Where a marketing communication is based on PHI under a HIPAA authorization, you may also revoke that authorization as it describes.
How we handle your requests
• When you submit a privacy request, we verify your identity using information associated with your account, and we may ask for additional information where reasonably necessary to protect your information from fraudulent requests. An authorized agent may submit a request on your behalf with proof of authority. We respond within forty-five (45) days, and where permitted by law we may extend that period once by an additional forty-five (45) days with notice to you. Exercising your rights is always free of charge, and we will never discriminate or retaliate against you for doing so. If we cannot honor a request, we will explain why and tell you how to appeal.
Washington, Nevada, and Connecticut residents
These rights apply if you are a resident of Washington or Nevada, or a person whose consumer health data is collected in those states, or a resident of Connecticut. "Consumer health data" means personal information that is linked or reasonably linkable to you and that identifies your past, present, or future physical or mental health status. In viVO, this includes, for example, your health intake information, your declared goals and interests, your wellness readings, and your biometric data; it does not include information we handle under HIPAA as described in Section 1 or data that has been de-identified as described in Section 7.
Consent architecture. We collect consumer health data only as necessary to provide the App features you request or with your prior consent, and we obtain a separate and distinct consent before sharing consumer health data with any third party, which in viVO occurs only at your individual direction through a connect screen as described in Section 4. Consent is never obtained through pre-checked boxes, is never a condition of care, and may be withdrawn at any time. Advertising vendors in the Direct Mode free tier never receive consumer health data, as described in Section 4.
No sale, no geofencing. We do not sell consumer health data, and we will never ask you to sign an authorization to sell it. We do not use geofencing around any facility that provides health care services to identify or track you, to send you notifications or content, or to collect your consumer health data.
Your rights. You have the right to confirm whether we collect, share, or sell consumer health data about you; to access it, including a list of all third parties and affiliates with whom we have shared it and an active way to contact them (because of our zero-egress design, for most users that list is empty or contains only the affiliates you yourself connected with); to withdraw any consent you have previously given; and to have your consumer health data deleted, including from archived and backup systems, within the timelines described in Section 9.
Exercising rights and appeals. Exercise these rights at no charge as described in "How we handle your requests" above. If we decline your request, you may appeal using the contact information in Section 14, and if we deny your appeal, our response will include a way to contact your state Attorney General to raise a concern.
California residents
If you are a California resident, California law treats your viVO information in two lanes, and if you use viVO in Provider-Connected Mode, most of your information sits in the first one.
● Your medical information. Information we create, receive, maintain, or transmit as a business associate of your Provider under HIPAA (Section 1) is exempt from the California Consumer Privacy Act ("CCPA") and is protected instead by HIPAA and the California Confidentiality of Medical Information Act ("CMIA"). In addition, to the extent viVO maintains medical information so that you can manage your health information or your care, California law treats us as a provider of health care
under the CMIA for that information, and we maintain its confidentiality in accordance with the CMIA. Rights over your medical record, including access, amendment, and an accounting of disclosures, are exercised through your Provider as described in Section 1. Patient information that has been de-identified under the HIPAA standards described in Section 7 is likewise outside the scope of the CCPA under California law.
● Your other personal information. For personal information not described above, such as account, device, and usage information, you have the right to know the categories and specific pieces of personal information we collect, our sources and purposes, and the categories of third parties to whom it is disclosed, all of which are described in Sections 2, 3, and 6, with retention periods described in Sections 8 and 9; the right to access it in a portable format; the right to correct it; the right to delete it; and the right not to be discriminated or retaliated against for exercising any of these rights.
● No sale or sharing. We do not sell your personal information, and we do not share it for cross-context behavioral advertising; all Sponsored Content matching happens inside viVO, and free tier advertising is contextual and served by vendors acting only as our service providers, in each case as described in Section 4. The App is for adults eighteen and older, and we have no actual knowledge of selling or sharing the personal information of consumers under sixteen.
● Sensitive personal information and your right to limit. Your health information, including the goals and interests you declare, is "sensitive personal information" under the CCPA. We collect and use it to provide the App features you request and for the other purposes the CCPA regulations permit. If you opt in to Sponsored Content, we additionally use your declared goals and interests to match content to you; you may limit that use at any time through the Sponsored Content controls in settings, which stop it entirely, and this is how we honor the CCPA right to limit the use of sensitive personal information. We never use your sensitive personal information to infer health conditions for advertising, and we never disclose it to advertisers or affiliates except at your individual direction under Section 4.
● Exercising your rights. Exercise these rights at no charge as described in "How we handle your requests" above, including through an authorized agent with proof of authority. These rights apply equally to patients and to Workforce Users at California Provider organizations.
Illinois and Texas residents Our biometric practices, including consent, no-profit, retention, and destruction commitments, are described in Section 8.
We maintain administrative, technical, and physical safeguards designed to protect your information, including encryption in transit and at rest, role-based access controls, audit logging, and workforce training, aligned to the HIPAA Security Rule for PHI. Health documents you upload are held in a private file store that is not publicly reachable and is scoped so that each document can only be reached from your own account; the App retrieves a page for you through a link that is limited to that single page and expires within a minute, and every such retrieval is logged. The identifying free text read off a document, including the patient name, the facility, the ordering clinician, and the page text, is additionally encrypted in our database. No system is perfectly secure, and you are responsible for protecting your login credentials. If a breach affecting your information occurs, we will notify you and regulators as required by applicable law, including the HIPAA Breach Notification Rule and, where applicable, the FTC Health Breach Notification Rule.
The App is intended for adults eighteen (18) and older. We do not knowingly collect information from anyone under eighteen, and we do not direct any advertising or Sponsored Content to minors. If you believe a minor has provided us information, contact us and we will delete it.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the App or by email and update the effective date. Material changes to how we use previously collected identifiable information will be applied only with any consent required by law. If we materially change the Sponsored Content framework, your participation will remain off until you review and opt in again.
Privacy questions, requests, and appeals: Creative Labs AI, LLC, Attn: Privacy, Email: support@cre8ivelabs.ai. For questions about your medical record or your Provider's privacy practices, contact your Provider directly.