⚕ Monitor Health LLC — Mental Health Services — Privacy Policy

Privacy Policy

MonitorHealth.ai — Your Privacy Rights & Data Practices
Effective Date: September 24, 2025  |  Last Updated: September 24, 2025  |  Next Review: September 4, 2026
🔖 Reading Guide — Highlighted sections indicate critical areas you should review carefully:
Critical — Must-read clauses
HIPAA — Health information protections
Your Rights — Privacy rights & choices
Security — Data & platform security
Biometric & Audio — Special data categories

Table of Contents

  1. Introduction
  2. HIPAA Compliance & Protected Health Information
  3. Information We Collect
  4. Biometric Data & Face ID Technology
  5. Audio Data & Voice Processing
  6. Advanced Sensor & Monitoring Technologies
  7. Mobile Device Permissions & Access
  8. Who Will Your Information Be Shared With?
  9. International Data Transfers & Regional Compliance
  10. How Long Do We Keep Your Information?
  11. Information Security Measures
  12. Your Privacy Rights & Choices
  13. Cookies & Tracking Technologies
  14. Changes to This Privacy Policy
  15. Contact Information & Complaints

1. Introduction

Thank you for choosing to be part of our community at MonitorHealth.ai, doing business as MonitorHealth.ai ("MonitorHealth.ai", "we", "us", or "our"). We are committed to protecting your personal information, your health information, and your right to privacy. If you have any questions or concerns about our policy, or our practices with regards to your personal information, please contact us at support@monitorhealth.ai.

The use of our Platform — which includes the MonitorHealth.ai Mobile Application and the MonitorHealth.ai Website (www.monitorhealth.ai), together with our related Websites, Applications, Services, Products, and content (collectively, "Services") — is possible without any indication of personal data. However, if a data subject wants to use our services via our website or mobile application, processing of personal data could become necessary.

The processing of personal data, such as the name, address, e-mail address, date of birth, telephone number, and protected health information of a data subject shall always be in accordance with the USA privacy laws applicable, including but not limited to HIPAA (Health Insurance Portability and Accountability Act), FERPA (Family Educational Rights and Privacy Act) when applicable, state privacy laws, and federal regulations.

Please read this privacy policy carefully and thoroughly as it helps you make informed decisions about sharing your personal information and protected health information with us.

⚠ Critical — Please Read

IF YOU DO NOT AGREE WITH THE TERMS OF THIS PRIVACY POLICY, PLEASE DO NOT ACCESS THE WEBSITE/MOBILE APPLICATION OR USE OUR SERVICES.

2. HIPAA Compliance & Protected Health Information

🛡 HIPAA — Health Information Protection

MonitorHealth.ai is committed to protecting your health information in compliance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the HITECH Act, and all applicable federal and state privacy regulations.

Any individually identifiable health information created, received, maintained, or transmitted through our platform is classified as Protected Health Information (PHI) and is handled with the highest level of care and security.

HIPAA Compliance Note: MonitorHealth.ai is working to establish formal Business Associate Agreements (BAAs) with infrastructure providers to ensure full HIPAA compliance. We implement healthcare-grade security measures including encryption, access controls, and audit logging.

3. Information We Collect

In Short: We collect personal information and protected health information necessary to provide mental health monitoring services when you create an account with us.

Information You Provide

Personal Information:

Protected Health Information (PHI):

Information Automatically Collected

In Short: We automatically collect device information, behavioral patterns, and biometric data through various sensors and technologies for mental health monitoring.

Device and Usage Information:

Biometric and Sensor Data:

4. Biometric Data & Face ID Technology

In Short: We collect and process biometric identifiers including facial recognition data for secure authentication and health monitoring purposes.

🔬 Biometric & Audio — Special Data Category

Biometric Data We Collect and Process:

Face ID and Facial Recognition:

Your Biometric Rights — Under applicable state biometric privacy laws (including BIPA where applicable):

5. Audio Data & Voice Processing

In Short: We collect, analyze, and automatically manage audio recordings for mental health assessment with strict retention controls.

🎤 Audio Data — Special Handling

Audio Data Collection and Processing:

Third-Party Audio Processing: Audio data may be processed by specialized third-party services including:

All audio processors are HIPAA-compliant Business Associates with appropriate safeguards.

Automatic Audio File Management:

Audio Data Security:

6. Advanced Sensor & Monitoring Technologies

In Short: We utilize multiple advanced technologies for comprehensive mental health monitoring with appropriate privacy safeguards.

Passive Monitoring Technologies:

Machine Learning and AI Processing:

7. Mobile Device Permissions & Access

In Short: We request specific device permissions necessary for comprehensive mental health monitoring, with clear opt-out options.

If you use our mobile application, we may request access to the following:

Permission Purpose & Details
Camera Access Purpose: Face ID authentication
Can be disabled: Yes, through device settings
Impact if disabled: Alternative authentication required; reduced mood monitoring accuracy
Microphone Access Purpose: Voice pattern analysis for mental state assessment and audio recording
Can be disabled: Yes, though voice-based features will be unavailable
Storage Access Purpose: Temporary storage of encrypted health assessments
All data encrypted at rest using AES-256
Regular automated cleanup of temporary files

8. Who Will Your Information Be Shared With?

Current Infrastructure Partners:

Service Purpose
AWS App Runner Application hosting
Supabase Encrypted database storage for health data, patient responses, and audio files
SignalWire SMS delivery services
AWS Rekognition Face ID authentication templates (templates only — no images stored)
Email Systems Secure transmission of patient responses to healthcare providers
OpenAI Whisper Audio transcription services (local processing — no data transmitted externally)
Hugging Face Transformers Sentiment analysis (on-premise processing only)

Data Sharing with Healthcare Providers:

Data Protection Measures:

9. International Data Transfers & Regional Compliance

In Short: Your data may be processed in countries other than your own, with appropriate safeguards in place.

Data Processing Locations:

Cross-Border Transfer Safeguards: When data is transferred internationally:

Regional Privacy Law Compliance:

10. How Long Do We Keep Your Information?

In Short: We retain your information only as long as necessary for healthcare purposes, with automated deletion protocols.

Data Retention Periods:

Data Type Retention Period
Clinical Health Records (active treatment) Retained while receiving services
Clinical Health Records (post-treatment) 7 years from last interaction (healthcare standard)
Raw Audio Files Deleted only after healthcare provider review and approval
Biometric Templates Updated annually during active use; deleted upon patient request or account termination
Voice Analytics Results Retained as part of health record per healthcare provider discretion
Facial Recognition Data Deleted immediately after mood analysis completion unless flagged by provider
Behavioral Patterns Aggregated data retained based on clinician discretion

Automated Deletion Protocols:

Legal Basis for Retention:

11. Information Security Measures

In Short: We protect your information through comprehensive security measures aligned with healthcare industry standards.

🔒 Security — How We Protect Your Data

Technical Safeguards:

Organizational Safeguards:

However, no method of transmission over the internet or electronic storage is 100% secure. While we implement industry-leading security measures, we cannot guarantee absolute security.

12. Your Privacy Rights & Choices

In Short: You have extensive rights under HIPAA, state privacy laws, and federal regulations to control your health information.

How to Exercise Your Rights:

Request Type Contact
General Privacy Questions privacy@monitorhealth.ai
Biometric Deletion privacy@monitorhealth.ai
Audio File Deletion support@monitorhealth.ai
HIPAA Rights privacy@monitorhealth.ai

Response Timeline: All requests processed within 30 days with confirmation provided. Identity verification may be required for sensitive requests. Most requests are processed at no charge (copies may incur reasonable fees).

Opt-Out Options:

13. Cookies & Tracking Technologies

In Short: We use cookies and similar technologies to improve our services and analyze usage patterns.

Types of Tracking Technologies:

Your Cookie Choices:

Mobile App Tracking:

14. Changes to This Privacy Policy

In Short: We will update this policy as necessary to stay compliant with relevant laws and will inform you of any material changes.

Update Notification Process:

Version Control:

15. Contact Information & Complaints

Privacy-Specific Contacts:

Inquiry Type Contact
General Privacy Questions privacy@monitorhealth.ai
HIPAA Privacy Officer privacy@monitorhealth.ai
Biometric Privacy Concerns privacy@monitorhealth.ai
Audio Data Questions privacy@monitorhealth.ai

Mailing Address:
MonitorHealth.ai Privacy Office
1201 Cold Spring Dr
O'Fallon, MO 63368

Regulatory Complaints:

MonitorHealth.ai is committed to transparency and protecting your privacy rights. This policy is reviewed annually and updated as necessary to reflect changes in technology, regulation, and our services.

© 2026 Monitor Health LLC. All rights reserved.