Clinical Platform

Privacy Policy

Version 1.1 · Last updated July 23, 2026 ·

1. Introduction and Relationship to Your Provider

This Privacy Policy describes how Allheartz, Inc. (“Allheartz”) collects, uses, stores, discloses, and protects information associated with the Allheartz Clinical Platform (the “Clinical Services”).

Business Associate role. When Allheartz handles Protected Health Information (“PHI”) on behalf of a healthcare provider or organization (a “covered entity”), Allheartz acts as a Business Associate under HIPAA, and that provider’s Notice of Privacy Practices — not this policy — governs how your PHI is used and disclosed for treatment, payment, and healthcare operations. This policy explains Allheartz’s own practices and applies primarily to account and non-PHI information, and to PHI only as permitted by the applicable Business Associate Agreement (“BAA”) and law.

2. Scope

This policy distinguishes between (a) PHI, which Allheartz processes on behalf of covered entities under a BAA, and (b) account, device, and other non-PHI information, which Allheartz processes as described here. Where the two conflict with respect to PHI, the BAA and the provider’s Notice of Privacy Practices control.

3. Information We Collect

We may collect patient demographic information; video recordings; skeletal keypoint and movement measurements; patient-reported outcome measures (“PROMs”); pain and symptom reporting; rehabilitation adherence and treatment-completion data; provider-entered clinical information; communications between users; and device and usage information.

4. How Video and Movement Data Are Stored

Submitted recordings are processed to generate movement measurements. Video recordings, derived measurements, and related data are stored on secure cloud infrastructure, protected by administrative, technical, and physical safeguards. Where our cloud hosting provider handles PHI, it does so under a Business Associate Agreement and the security protocols it makes available. We retain this information in accordance with the BAA, the covered entity’s direction, and law.

5. How We Use Information

We use collected information to provide the Clinical Services, support healthcare workflows, generate movement measurements and analytics, facilitate rehabilitation and RTM tracking, maintain security and compliance, and communicate with users — in each case consistent with the BAA and applicable law.

6. Biometric Data

The Clinical Services collect and analyze biometric identifiers and biometric information, including video of the body and derived movement, gait, and biomechanical patterns. Consent for biometric data is obtained where required by law, including through acceptance of the Clinical Terms and this Privacy Policy (by the patient or, for a minor, a parent/guardian), and as further described in our Biometric Data Notice. We do not sell, lease, or trade biometric data, and we retain and destroy it in accordance with the BAA, our retention practices, and law.

7. De-Identified Data, Analytics, and AI Development

Allheartz may use a separate pool of de-identified data — de-identified in accordance with the HIPAA de-identification standard (45 CFR § 164.514), using the Safe Harbor or Expert Determination method — to improve platform performance, refine models and algorithms, develop future capabilities, and support quality improvement, and may retain such de-identified data indefinitely. Where model development requires review of identifiable video or other PHI, Allheartz does so only as expressly permitted by the applicable BAA or a valid patient authorization, and otherwise de-identifies the data first. Allheartz uses or discloses PHI only as permitted by the applicable BAA and law.

8. Sharing of Information

Information may be shared with authorized healthcare providers, affiliated healthcare organizations, authorized care-team personnel, and third-party service providers that support platform operations under appropriate confidentiality and security obligations. Allheartz does not sell personal information.

9. HIPAA Compliance

Allheartz handles PHI in accordance with HIPAA, the applicable BAA, and applicable legal obligations. Healthcare organizations may maintain separate privacy practices governing patient information under their control.

10. Data Security

Allheartz implements reasonable administrative, technical, and physical safeguards designed to protect information from unauthorized access, disclosure, or misuse. However, no system can guarantee absolute security.

11. Research and Clinical Studies

Patient care through the Clinical Services does not automatically constitute participation in research. Separate informed consent may be required for participation in clinical studies or formal research activities.

12. Data Retention

PHI is retained, returned, or destroyed as directed by the covered entity and the applicable BAA and as required by law; some covered entities require longer retention periods. Where no BAA term or covered-entity direction applies, Allheartz retains information only as long as reasonably necessary for the purposes described — including healthcare operations, legal compliance, and quality improvement — in accordance with its internal data-retention policy. Accounts may be deactivated by the user, provider, or organization. De-identified and aggregated information may be retained indefinitely.

13. Patient Rights

You may have rights under applicable law to access your information, request corrections, request deletion where applicable, and request additional information about how your data is handled. Because Allheartz often acts as a Business Associate, many requests concerning PHI are directed to and fulfilled through your healthcare provider as the covered entity. Requests may be submitted through the platform or to hello@allheartz.com, and we will coordinate with your provider as appropriate.

14. Breach Notification

In the event of a breach of unsecured PHI or other personal information, Allheartz will notify the affected covered entity and/or individuals as required by HIPAA, the applicable BAA, and state breach-notification laws, within the timeframes those laws require.

15. State Privacy Rights

Depending on your state of residence, you may have additional privacy rights. For non-PHI personal information that Allheartz processes as a business, California residents may have rights under the CCPA/CPRA, including access, deletion, correction, and the right to limit use of sensitive personal information. Some non-PHI information may also be “consumer health data” under laws such as the Washington My Health My Data Act; information that is PHI handled under HIPAA and the BAA is generally exempt from those laws. Where consumer health data laws apply to non-PHI data, we collect and share it only with your consent or as permitted by law, and do not sell it without a valid authorization. Allheartz does not sell or share personal information. To exercise these rights, contact hello@allheartz.com.

16. Changes to This Policy

Allheartz may update this Privacy Policy periodically and will revise the “Last Updated” date. Continued use of the Clinical Services after updates take effect constitutes acceptance of any revised policy, subject to the BAA and organizational agreements.

17. Contact Information

Allheartz, Inc., Oakland, California. Privacy questions may be sent to hello@allheartz.com.

Bring Allheartz to your program.

info@allheartz.com
allheartz.com · Contact us for pricing
Get a demo
References
[1] Webster & Hewett, TE. J Orthop Res 2018 — meta-analysis of ACL injury-reduction programs (~50% fewer ACL injuries, 67% fewer non-contact in female athletes).
[2] Sugimoto D, et al. Neuromuscular training and ACL injury-risk reduction in female athletes: a meta-analysis. 2012.
[3] Korey Stringer Institute (UConn) national benchmark: only ~37% of US high schools have a full-time athletic trainer.
[4] Allheartz provides movement screening and personalized guidance to support prevention programs; it is not a diagnostic or treatment device.