Privacy Policy

Last updated August 5, 2026

This Policy explains how Echo handles information when a clinic uses our service to run automated patient text check-ins, capture Remote Therapeutic Monitoring (RTM) data and clinical time, and produce chart-ready notes. For patient health information, the clinic is the covered entity and Echo acts as its business associate.

1. Information we collect

  • Account data: clinician name, work email, clinic name, password credentials handled by our authentication provider, and workspace membership/roles.
  • Clinic configuration: practice hours, timezone, clinic mode, messaging cadence settings.
  • Patient records you enter: first and last name, mobile phone number, protocol type, enrollment status, and RTM status.
  • Message content: inbound and outbound SMS text, timestamps, and delivery metadata.
  • Clinical data derived from messages: pain scores, HEP adherence and compliance days, device days, red-flag indicators, and AI-generated summaries.
  • Activity and time data: RTM time log entries, patient detail and note review events, note-copy audit entries with clinician identity and timestamp.
  • Waitlist and support data: information you voluntarily submit in marketing or contact forms.
  • Technical data: log and analytics data such as IP-derived country, device type, pages viewed, and error diagnostics.

2. How we use information

  • To deliver the service: send and receive patient messages, extract structured clinical data, track time, and generate notes and billing summaries.
  • To secure the service: authenticate users, enforce clinic-level access controls, detect abuse, and maintain audit trails.
  • To support you: respond to requests and troubleshoot issues.
  • To improve reliability and usability using aggregated or de-identified usage data.

We do not sell personal information, and we do not use patient health information for advertising or to train third-party AI models for their own purposes.

3. AI processing

Inbound patient replies and the context needed to draft a response or summary are sent to an AI model provider through our gateway for processing. Output is returned to your workspace for clinician review. We work with providers that do not retain this content for model training. AI output is a draft and must be reviewed by a clinician before use.

4. SMS and telephony

Patient phone numbers and message bodies are transmitted through our SMS carrier gateway to deliver texts. Carriers process message metadata to route messages. Automated replies are suppressed outside the practice hours your clinic configures. Patients can reply STOP to opt out, and your clinic is responsible for honoring opt-outs and obtaining consent before enrollment.

5. Sharing and subprocessors

We share information only as needed to run Echo: our cloud database, storage, and authentication provider; our SMS carrier gateway; our AI model gateway and providers; and error and analytics tooling. Each is bound by contract to appropriate confidentiality and security obligations, including a BAA where PHI is involved. We may also disclose information when required by law or to protect rights and safety, and in connection with a merger or acquisition subject to this Policy.

6. Access controls

Data is scoped to your clinic workspace. Row-level security policies restrict every patient record, conversation, time log, and audit entry to members of the owning clinic. Access is authenticated per user, and privileged operations run server-side.

7. Retention

We retain clinic and patient records for as long as your account is active and as needed to provide the service and support your billing and recordkeeping obligations. Audit logs and time logs are retained to preserve the integrity of your documentation. On request we will delete or export your clinic's data, except where retention is required by law or for legitimate dispute resolution.

8. Security

We use encryption in transit, encrypted storage at rest, scoped credentials, server-side secret management, and least-privilege access. No system is perfectly secure; if a breach affecting your data occurs, we will notify affected account owners as required by law and any executed BAA.

9. Your choices and rights

  • Clinicians can update account and clinic settings, remove patients, and adjust cadence and hours at any time.
  • Patients should direct requests about their health information to their treating clinic, which controls the record.
  • Depending on where you live, you may have rights to access, correct, delete, or port personal information; contact us to exercise them.

10. Children

Echo accounts are for clinicians only and are not offered to anyone under 18. Where a clinic enrolls a minor patient, the clinic is responsible for obtaining guardian consent.

11. Changes

We may update this Policy. Material changes will be reflected in the "Last updated" date and communicated to account owners where significant.

12. Contact

Privacy questions, data requests, or BAA requests: support@echo-health.app.

Questions? Email support@echo-health.app.