This Privacy Policy explains how TrueYou Healthcare, Inc. ("TrueYou," "we," "us," or "our") collects, uses, discloses, and protects information in connection with our website and the TrueYou platform (collectively, the "Services"). Please read it together with our Terms of Use.
1. Scope of this policy
TrueYou is used by surgical and medical practices ("Clinics") to coordinate communication with their patients, including through our AI assistant, Sophie. Because TrueYou sits between clinics and patients, this policy applies differently depending on who you are:
If you are browsing trueyouapp.com, requesting a demo, or evaluating TrueYou on behalf of a Clinic, TrueYou is the party responsible for your personal information ("controller" under most state privacy laws), and this policy governs directly.
PatientsIf you are a patient who receives a message, call, or chat from Sophie on behalf of your Clinic, your Clinic is responsible for your care and for your protected health information ("PHI"). TrueYou acts as your Clinic's business associate under HIPAA and processes your information only as instructed by your Clinic under a Business Associate Agreement ("BAA"). See Section 10. Your Clinic's own Notice of Privacy Practices governs your PHI; this policy covers the parts of our Services (like our website and account systems) that fall outside that relationship.
Clinic staff usersIf you log in to TrueYou as a Clinic employee or contractor, this policy governs the account and usage information we collect about you, subject to any separate agreement between TrueYou and your Clinic.
2. Summary of key points
- We do not sell personal information, and we do not share it for cross-context behavioral advertising.
- Sophie's responses are generated by OpenAI. See Section 3 for exactly what is shared.
- Patient data and PHI are not used to train general-purpose or foundation AI models. See Section 7.
- Sophie always identifies itself as an AI assistant and can route you to a human at your Clinic. See Section 8.
- We act as a HIPAA business associate to Clinics; PHI is governed by our BAA with each Clinic. See Section 10.
- We use a limited number of subprocessors, listed in Section 9.
- You have rights over your information under state privacy laws, described in Section 13.
3. How Sophie uses OpenAI
TrueYou uses OpenAI to power Sophie's responses. When you chat with Sophie, we send OpenAI only the information needed to write a helpful reply:
- Patient name
- Procedure(s)
- Recovery day
- Surgeon/practice
- Allergies
- Current medications
- Operative report and post-op care instructions
- Recent conversation history
We don't send anything else. OpenAI uses this information only to generate Sophie's response. It does not use it to train its models, and it is contractually required to protect it with safeguards equal to or greater than those described in this policy.
OpenAI is listed with our other subprocessors in Section 9. If you'd rather talk to a person, you can ask your Clinic at any time (see Section 8).
4. Information we collect
Information you give us
- Contact details you provide when requesting a demo or contacting us (name, email, phone, Clinic name)
- Account credentials for Clinic staff users
- Content you submit through forms, email, or support requests
Information your Clinic provides
- Patient contact information and communication preferences
- Clinic-approved clinical and administrative content used to configure Sophie
- Scheduling, intake, and coordination details relevant to your care
Communication content
- The content of messages, chats, and voice conversations with Sophie
- Voice audio and transcripts, where calls are used (see Section 5)
Automatically collected information
- Device and browser information, IP address, and approximate location
- Usage data, such as pages visited and interactions with our website
- Cookies and similar technologies (see Section 14)
5. Voice and message content
Where our Services include voice conversations with Sophie, calls may be recorded and transcribed to provide the Service, support quality review, and maintain a record for your Clinic. We provide notice before recording begins. If you are in a state that requires all-party consent to call recording, continuing the call after the notice constitutes your consent; you may decline by ending the call and contacting your Clinic through another channel. Message and call content is treated as PHI when it relates to your care and is handled under the protections described in Section 10.
6. How we use information
We use information to:
- Provide, operate, and maintain the Services on behalf of Clinics
- Prepare responses and recommendations for review by Clinic staff
- Communicate with you about your care, at your Clinic's direction
- Maintain audit logs of what Sophie recommended and what Clinic staff approved, edited, or escalated
- Secure the Services and detect fraud or abuse
- Improve our Services, using de-identified or aggregated data where we use patient content for improvement at all
- Comply with legal obligations and enforce our agreements
7. AI and model training
TrueYou is built so each Clinic controls what Sophie knows and does. We do not use patient data or PHI to train general-purpose or foundation AI models, whether ours or a third party's. Sophie's responses are generated from Clinic-approved knowledge scoped to that Clinic, and our AI subprocessors are contractually bound to no-training and data-minimization terms for that content. Sophie's conversational responses are generated using OpenAI; see Section 3 for exactly what is shared.
Every recommendation Sophie prepares is subject to your Clinic's review. As described on our website, Clinic staff can approve, edit, escalate, or pause any action, and each decision is logged. We may use de-identified, aggregated information — information that does not identify you — to evaluate and improve the Services generally.
8. AI disclosure and human escalation
Sophie is an AI assistant, not a person and not a healthcare provider. When you communicate with Sophie, we disclose that you are interacting with an AI-generated system, consistent with applicable state disclosure laws. Sophie does not diagnose conditions, prescribe treatment, or make clinical judgments. If you ask to speak with a person, or if your message needs clinical judgment, Sophie will route you to your Clinic's staff. Sophie's communications are not a substitute for professional medical advice, and if you are experiencing a medical emergency, call 911 or go to the nearest emergency room.
9. How we share information
We share information with:
- Your Clinic and its care team, who direct how your information is used
- Service providers (subprocessors), who help us operate the Services under contract, listed below
- Legal and safety recipients, when required by law, to protect rights and safety, or to respond to legal process
- Successors, in connection with a merger, acquisition, or sale of assets, subject to the same protections described here
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.
Current subprocessors
| Subprocessor | Purpose | Data involved |
|---|---|---|
| OpenAI | AI-generated conversational responses (Sophie) | Patient name, procedure(s), recovery day, surgeon/practice, allergies, current medications, operative report and post-op care instructions, recent conversation history |
| ElevenLabs | Conversational voice AI, speech-to-text, and text-to-speech | Voice audio, call transcripts |
| Google Analytics | Website analytics | IP address, device and usage data |
| Google Fonts | Web font delivery | IP address |
10. HIPAA and protected health information
Where TrueYou processes PHI on behalf of a Clinic, we do so as the Clinic's business associate under the Health Insurance Portability and Accountability Act ("HIPAA"), pursuant to a Business Associate Agreement with that Clinic. We use and disclose PHI only as permitted by that BAA and applicable law, apply the minimum necessary standard, and notify the affected Clinic of any breach of unsecured PHI without unreasonable delay and in accordance with the HIPAA Breach Notification Rule.
Because your Clinic is the HIPAA covered entity, requests to access, amend, or receive an accounting of disclosures of your PHI should be directed to your Clinic in accordance with its Notice of Privacy Practices. We will support your Clinic in responding to those requests as required by our BAA.
11. Security
We use administrative, technical, and physical safeguards designed to protect information, including encryption of data in transit and at rest, role-based access controls built on the principle of least privilege, audit logging of access to patient information, and an incident response process. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. Retention
We retain information for as long as necessary to provide the Services, as instructed by the applicable Clinic, and as required by law or our BAAs. When a Clinic directs us to delete data, we do so within the timeframe specified in our agreement with that Clinic, subject to reasonable backup retention cycles and any legal retention obligations.
13. Your privacy rights
Depending on where you live, you may have rights under state privacy laws such as the California Consumer Privacy Act (as amended by the CPRA) and similar laws in states including Colorado, Connecticut, Virginia, Texas, and Utah, including the right to:
- Know what personal information we collect about you and why
- Access a copy of your personal information
- Correct inaccurate personal information
- Delete your personal information, subject to legal exceptions
- Receive your data in a portable format
- Limit the use of sensitive personal information
- Not be discriminated against for exercising these rights
- Appeal a decision we make regarding your request
Where information you provide qualifies as consumer health data under laws like Washington's My Health My Data Act or Nevada's consumer health data law, we extend the additional protections those laws require, including not sharing that data beyond what is necessary to provide the Services without your consent.
To exercise these rights, contact us at privacy@trueyouapp.com. If you are a patient, some requests may need to be routed to your Clinic as described in Section 10. We honor Global Privacy Control signals where required by law and will respond to verifiable requests within the timeframe required by applicable law.
14. Cookies and analytics
Our website uses Google Analytics to understand how visitors use our site, which sets cookies and collects information such as your IP address, browser, and pages viewed. You can opt out using the Google Analytics opt-out browser add-on, your browser's cookie controls, or a Global Privacy Control signal, where supported.
15. Messages and calls (TCPA)
If you receive text messages or calls from Sophie, your Clinic has obtained your consent to be contacted through those channels as part of your care. You can stop text messages at any time by replying STOP, and get help by replying HELP. Message and data rates may apply, and message frequency varies based on your care needs. You may revoke consent to future messages or calls in any reasonable manner, including by contacting your Clinic directly; we will honor revocation requests as soon as practicable.
16. Children's privacy
Our website and account systems are intended for individuals 18 and older. Where a Clinic uses TrueYou to communicate with a minor patient, that communication occurs under the Clinic's direction and consent from the minor's parent or guardian, and is governed by our BAA with that Clinic rather than by direct collection from the minor.
17. Data location
We provide the Services from the United States, and information we collect is stored and processed in the United States.
18. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date above and, where required by law, provide additional notice.
19. Contact us
If you have questions about this Privacy Policy or wish to exercise your rights, contact us at:
Email: privacy@trueyouapp.com or
legal@trueyouapp.com
Address: TrueYou Healthcare, Inc., San Francisco, CA, United States