Privacy Policy
Effective: September 3, 2026 (updated) · TexoHealth LLC
DRAFT — FOR LEGAL REVIEW. This policy was prepared to accurately describe how the TexoHealth platform is built, but it has not yet been reviewed by counsel and should not be treated as final until it has been.
TexoHealth provides secure telemedicine: video visits, clinical documentation, prescriptions, and health records, for patients and the clinicians who care for them. Privacy isn't a feature of this product; it is the product. This policy explains what we collect, why, and the rules we hold ourselves to.
The one-sentence version
We collect what's needed to provide your care and run the service, we never sell or share your information for advertising, and your health information is encrypted and access-audited.
What we collect
- Account information — name, email, phone, password (stored only as a cryptographic hash), and for clinicians, professional credentials (NPI, license).
- Health information — the information you or your care team put into the service: visit records, clinical notes, prescriptions and medication lists, allergies, insurance details, documents and images you upload (including text extracted from them so your records are searchable), and — with your explicit consent at each visit — recordings of visits used solely to prepare clinical notes. The audio is deleted automatically once the transcript is prepared, and your clinician can delete a dictation and its transcript entirely at any point before a note is drafted from it. For patients, this is protected health information (PHI) under HIPAA and is also governed by the Notice of Privacy Practices presented in the app.
- Security and audit records — sign-in events and an access log of who viewed or changed health records (including IP address). HIPAA requires this, and it protects you: it is how "who looked at my chart?" gets a real answer.
- Connected devices and apps — if you choose to connect a health device or app (for example a blood-pressure cuff or scale), the readings it sends, labeled with their source. Connecting is optional and you can disconnect at any time in the app.
- Communication preferences — whether you want email/SMS notifications.
What we do NOT do
- No selling or renting personal information — ever.
- No third-party advertising or ad trackers, in the apps or on this site (see the Cookie Notice — the site currently sets no cookies at all).
- No use of your health information to train AI models. AI features (like drafting visit notes) process your information only to produce the draft for your clinician, who reviews and signs it.
How information is used
To provide care and operate the service: connecting you with your care team, preparing and storing clinical documentation, transmitting prescriptions to the pharmacy you chose and authorized, processing insurance information you provide, sending the notifications you asked for, and meeting legal obligations (including HIPAA's).
Who information is shared with
- Your care team — clinicians with an active care relationship with you, and facilities involved in your care.
- Caregivers you (or the law) authorize — a family member or care partner sees your information only through a verified, time-limited authorization, only to the extent that authorization and the law allow, and every access is logged. You can see who has access and revoke it in the app.
- Your pharmacy — when you authorize electronic prescriptions to it.
- Service providers — vendors that host and power the service (cloud infrastructure, video calling, email/SMS delivery, AI processing), bound by contracts (including Business Associate Agreements where PHI is involved) that limit their use of information to providing the service.
- When the law requires it — as described in the Notice of Privacy Practices.
How information is protected
- Encryption in transit (TLS) and at rest; the most sensitive fields carry an additional layer of application-level encryption (AES-256-GCM).
- Every access to health records is logged and auditable.
- App sessions lock automatically and support biometric unlock; no health information is cached on your device.
- Visit recordings are deleted once the clinical note is prepared.
Your rights
You can access the health information in your account directly in the app. Under HIPAA you also have rights to request copies, amendments, and an accounting of disclosures — the Notice of Privacy Practices explains how. California residents: we do not sell or share personal information as defined by the CCPA/CPRA, and we honor Global Privacy Control signals on this website. To exercise any privacy right, email privacy@texohealth.com.
Deleting your account
You can delete your account from inside the app (Settings → Delete account) or by emailing privacy@texohealth.com from your account email. Deletion closes the account, revokes every session and authorization, and removes personal information that we are not legally required to keep. Clinical records are the exception: medical-records law requires clinicians to retain them for a number of years even after an account closes, so those are retained for the legally required period and then disposed of securely.
Retention
Medical records are retained as required by medical-records law, which typically mandates multi-year retention even after an account closes. Visit-recording audio is deleted as soon as its transcript is prepared. Account information not subject to legal retention is deleted or de-identified when no longer needed.
Children
TexoHealth is not directed at children. Pediatric care through the platform happens under a parent or guardian's account and consent.
Changes
If this policy changes materially, we'll say so in the app and on this page, with the effective date above.
Contact
TexoHealth LLC · privacy@texohealth.com