Log in

Privacy Policy

Privacy Policy

Last Updated: December 15, 2025

Introduction

Prana Health Inc. ("Prana Health," "we," "us," or "our") is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website (www.pranahealth.ai), mobile applications, and related services (collectively, the "Services").

We implement security controls designed to meet HIPAA requirements and take the protection of your health information seriously. Please read this Privacy Policy carefully to understand our practices regarding your data.

Information We Collect

Information You Provide

  • Account Information: When you create an account, we collect your email address and any profile information you choose to provide.
  • Health Information: When you use our AI doctor service, you may provide symptoms, health concerns, medical history, and other health-related information.
  • Communications: We collect information from your interactions with our AI, including chat messages and uploaded documents.
  • Payment Information: If you purchase paid services, we collect billing information through our secure payment processor.

Information Collected Automatically

  • Device Information: We collect information about the device you use to access our Services, including device type, operating system, and browser type.
  • Usage Data: We collect information about how you use our Services, including pages visited and features used.
  • Log Data: Our servers automatically record information including your IP address, access times, and referring URLs.

How We Use Your Information

We use your information to:

  • Provide, maintain, and improve our Services
  • Process your health inquiries and provide AI-powered health guidance
  • Communicate with you about your account and our Services
  • Process payments for paid services
  • Ensure the security and integrity of our Services
  • Comply with legal obligations
  • Respond to your requests and support needs

Important: We do NOT use your health conversations to train our AI models. Our AI training is based on the work of our medical team, not user data.

Data Security

We implement industry-standard security measures to protect your information, including:

  • Encryption: All data is encrypted in transit (TLS/SSL) and at rest (AES-256)
  • Access Controls: Strict access controls limit who can access your data
  • Security Standards: We implement controls designed to meet HIPAA requirements
  • Regular Audits: We conduct regular security audits and assessments
  • Secure Storage: Your data is stored in secure, compliant cloud infrastructure

Data Sharing and Disclosure

We may share your information in the following circumstances:

  • Service Providers: With trusted third-party service providers who assist in operating our Services (e.g., cloud hosting, payment processing)
  • Telehealth Providers: If you use our telehealth services, with licensed healthcare providers who provide care
  • Legal Requirements: When required by law, subpoena, or other legal process
  • Safety: To protect the safety of any person or to address fraud or security issues
  • Business Transfers: In connection with a merger, acquisition, or sale of assets

We do NOT sell your personal information to third parties.

Your Rights and Choices

You have the following rights regarding your data:

  • Access: Request access to the personal information we hold about you
  • Correction: Request correction of inaccurate personal information
  • Deletion: Request deletion of your personal information
  • Portability: Request a copy of your data in a portable format
  • Opt-out: Opt out of marketing communications at any time

To exercise these rights, please contact us at support@pranahealth.io.

Health Information Security

Protected Health Information (PHI)

Prana Health is committed to protecting your Protected Health Information (PHI). We implement administrative, technical, and physical safeguards designed to meet the requirements of the Health Insurance Portability and Accountability Act (HIPAA).

If you use our telehealth services, you will receive a separate Notice of Privacy Practices that describes how your PHI may be used and disclosed by the healthcare providers.

Data Retention

We retain your information for as long as necessary to provide our Services and comply with legal obligations. Specifically:

  • Account Data: Retained while your account is active and for a reasonable period thereafter
  • Health Conversations: Retained as required by healthcare regulations (typically 6-10 years)
  • Usage Data: Generally retained for 2 years

You may request deletion of your data at any time, subject to legal retention requirements.

Cookies and Tracking

We use cookies and similar technologies to:

  • Keep you logged in to your account
  • Remember your preferences
  • Understand how you use our Services
  • Improve our Services

You can control cookies through your browser settings. Note that disabling cookies may affect the functionality of our Services.

Children's Privacy

Our Services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

International Users

Our Services are based in the United States. If you access our Services from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States where our servers are located.

California Privacy Rights

California residents have additional rights under the California Consumer Privacy Act (CCPA), including:

  • Right to know what personal information is collected
  • Right to know if personal information is sold or disclosed and to whom
  • Right to opt out of the sale of personal information
  • Right to equal service and price, even if you exercise privacy rights

We do not sell personal information. To exercise your California privacy rights, contact us at support@pranahealth.io.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. For material changes, we will provide additional notice via email or through our Services.

Contact Us

If you have questions about this Privacy Policy or our privacy practices, please contact us:

Prana Health Inc.
Email: support@pranahealth.io
Website: www.pranahealth.ai

Related Documents