Privacy Policy

Last updated: January 2025

Your Privacy is Our Priority

We implement enterprise-grade security measures to protect your health information. All data is encrypted, access-controlled, and stored securely in compliance with healthcare industry standards.

1. Information We Collect

Personal Health Information

  • Health metrics and wellness data
  • Symptom reports and health concerns
  • Fitness and activity tracking data
  • Medication and treatment information
  • Genetic information (educational purposes only)

Account Information

  • Name, email address, and contact information
  • Authentication credentials (encrypted)
  • Usage patterns and preferences
  • Communication history with AI agents

2. How We Use Your Information

  • Provide personalized AI health insights and recommendations
  • Improve our AI models and service quality
  • Enable secure communication between you and healthcare providers
  • Generate wellness reports and health analytics
  • Ensure system security and prevent fraud
  • Comply with legal and regulatory requirements

3. Data Security and Protection

Security Measures

  • End-to-end encryption for all data transmission
  • AES-256 encryption for data at rest
  • Multi-factor authentication for account access
  • Regular security audits and penetration testing
  • Access controls and role-based permissions
  • Secure cloud infrastructure with enterprise-grade security

4. Information Sharing

We do NOT sell, trade, or rent your personal health information to third parties. We may share information only in the following limited circumstances:

  • With your explicit consent for specific purposes
  • With healthcare providers you authorize
  • To comply with legal obligations or court orders
  • To protect our rights, property, or safety
  • With service providers under strict confidentiality agreements

5. Your Rights and Controls

Access Your Data

Request a copy of all your personal health information stored in our systems.

Data Portability

Export your health data in standard formats for use with other services.

Data Deletion

Request complete deletion of your account and all associated health data.

Consent Withdrawal

Withdraw consent for specific data processing activities at any time.

6. HIPAA and Healthcare Compliance

Healthcare Data Protection

  • We implement safeguards consistent with HIPAA requirements
  • Business Associate Agreements (BAAs) available for healthcare providers
  • Regular compliance audits and assessments
  • Staff training on healthcare data protection
  • Incident response procedures for data breaches

7. Data Retention

We retain your personal health information for as long as necessary to provide our services and comply with legal obligations. You can request data deletion at any time, and we will process such requests within 30 days.

8. International Data Transfers

Your data may be processed in countries other than your residence. We ensure appropriate safeguards are in place for international transfers, including standard contractual clauses and adequacy decisions.

9. Children's Privacy

Our service is not intended for children under 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected such information, we will take steps to delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by email or through our service. Your continued use of the service after such changes constitutes acceptance of the updated policy.

11. Contact Us

For questions about this Privacy Policy or to exercise your rights, please contact us at:
Email: privacy@cognoodle.ai
Data Protection Officer: dpo@cognoodle.ai
Address: COGNOODLE Health AI System, Privacy Department