Epithel logoEpithelLegal & Compliance · effective June 9, 2026

Privacy Policy

Version 2026.06.09 · Effective June 9, 2026

This Privacy Policy describes how Epithel collects, uses, and protects information when clinicians, facility staff, and administrators ("Users") access the service. PHI handling is additionally governed by the HIPAA Notice of Privacy Practices and the Business Associate Agreement.

1. Information we collect

  • Account data: name, email, facility, role, hashed password, device/IP for audit logging.
  • PHI entered by clinicians: resident identifiers, wound assessments, photos, care plans, orders. We process PHI solely on behalf of the Customer facility under a BAA.
  • Operational telemetry: page views, feature usage, error reports — used to maintain reliability. Telemetry does not contain PHI.
  • Payment data: handled by Stripe (PCI-DSS Level 1). We never receive or store full card numbers.

2. How we use information

  • To provide the rounding, assessment, and care-plan workflows you request.
  • To authenticate users and enforce facility-scoped access.
  • To produce audit logs required for HIPAA Security Rule compliance.
  • To bill facilities and prevent fraud.
  • To improve the service in aggregated, de-identified form.

3. Legal bases (state & federal)

We process PHI under our HIPAA Business Associate Agreement with each Customer facility. We process account and telemetry data based on our legitimate interest in providing the service and your acceptance of these Terms. State privacy laws (including CCPA/CPRA in California, CMIA, and similar statutes in Texas, Virginia, Colorado, Connecticut, Utah, and others) may grant Users additional rights described in Section 7.

4. Sharing

We share information only with: (a) sub-processors we have engaged under written agreements (cloud hosting, error monitoring, payment processing); (b) the Customer facility that owns the underlying record; (c) law enforcement when required by valid legal process; and (d) successors in a merger or acquisition, subject to this Policy. We do not sell personal information.

5. Sub-processors

Current sub-processors: Supabase (database, auth, storage; US-East), Cloudflare (edge runtime), Stripe (payments), ElevenLabs (optional voice features; no PHI). A current list is available at privacy@epithelcare.life.

6. Security

We use TLS 1.2+ in transit, AES-256 at rest, row-level security scoped to facility membership, role-based access control, audit logging of PHI access events, mandatory MFA for administrative roles, and 15-minute idle session timeout. Incident response procedures and breach notification are described in the HIPAA Notice.

7. Your rights

  • Access & correction: Request a copy of your account data or request corrections.
  • Deletion: Request closure of your account. PHI deletion requests must be directed to your facility (the Covered Entity).
  • Opt-out of analytics: Email privacy@epithelcare.life.
  • State rights: California, Virginia, Colorado, Connecticut, Utah, and similar-state residents may have additional rights to know, correct, delete, opt-out of sale or sharing (we do not sell), and non-discrimination. Submit requests to the privacy contact below.

8. Retention

Account data: for the life of the account plus 7 years (HIPAA audit retention). PHI: per Customer instruction, default 7 years from last activity. Telemetry: 13 months. Payment records: 7 years.

9. Children

The service is not directed at individuals under 13. PHI of minor residents is handled under the same facility-scoped controls as adult residents.

10. International transfers

Data is hosted in the United States. We do not currently support EU or Canadian data residency. Customers outside the US should consult with their counsel before processing PHI through Epithel.

11. Changes

We will notify Users by email and via in-app banner at least 30 days before material changes take effect.

12. Contact

Privacy Officer: privacy@epithelcare.life · Mailing address available on request.