Last updated: September 2026
Heerio LLC (“Heerio,” “we,” “us,” or “our”) provides a client check-in platform for therapy, medical, and legal practices. This Privacy Policy describes how we collect, use, disclose, and protect information when you use our mobile applications, web applications, and related services (collectively, the “Services”).
By using our Services, you agree to the collection and use of information as described in this Privacy Policy.
Heerio serves three types of users:
| User Type | Description |
|---|---|
| Practice Owners | Healthcare, therapy, or legal professionals who sign up and manage a practice on Heerio |
| Providers | Staff members (therapists, doctors, attorneys, etc.) invited by a Practice Owner to receive check-in notifications |
| Clients/Patients | Individuals who check in at a practice using a kiosk, mobile app, or client code. Clients do not create accounts. |
When you create an account or are invited to join a practice, we collect:
Heerio is designed to collect the minimum information necessary for a check-in. When a client checks in, we collect only:
We do not collect: full patient names, dates of birth, Social Security numbers, diagnoses, treatment information, insurance information, or any other clinical or medical records.
| Purpose | Data Used |
|---|---|
| Provide the check-in service | Client initials, check-in type, timestamp, provider selection |
| Send real-time notifications to providers | Check-in event data (generic notification — no patient information is included in the push notification) |
| Account management | Email, name, password, practice information |
| Billing and subscription management | Practice ID, subscription status (no health information is shared with payment processors) |
| Security and fraud prevention | IP address, API logs, audit trail |
| Customer support | Email, name, practice information |
| Service improvements | Aggregated, de-identified usage data |
Heerio may be considered a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA) when providing services to healthcare practices. In this capacity:
For practices that are covered entities under HIPAA, our handling of PHI is governed by the terms of the Business Associate Agreement between Heerio and the practice.
We do not sell your personal information or PHI. We share information only in the following circumstances:
We use third-party service providers to operate our platform. These providers process data on our behalf and are contractually obligated to protect it:
| Provider | Purpose | Data Shared |
|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure (servers, database, storage) | All application data is hosted on AWS. BAA in place. |
| Stripe | Payment processing | Practice ID and subscription data only. No health information. |
| Firebase (Google) | Push notifications and web hosting | Generic notification messages only (e.g., “New arrival”). No patient information in notifications. |
| Resend | Transactional email (invites, password resets) | Email addresses only. No health information. |
| RevenueCat | In-app purchase management | Anonymous user IDs only. No health information. |
We may disclose information if required to do so by law, such as in response to:
If Heerio is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify affected users before their information becomes subject to a different privacy policy.
We implement industry-standard security measures to protect your information:
| Measure | Details |
|---|---|
| Encryption at rest | All database data is encrypted using AES-256 |
| Encryption in transit | All data transmitted between your device and our servers is encrypted using TLS 1.2+ |
| Password security | Passwords are hashed using bcrypt and are never stored in plain text |
| Access controls | Role-based access controls ensure users can only access data within their own practice |
| Audit logging | All system access is logged for security monitoring |
| Infrastructure security | Database servers are isolated in private networks and are not directly accessible from the internet |
While we take reasonable measures to protect your information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
| Data Type | Retention |
|---|---|
| Active check-ins | Cleared by the provider after the client is seen |
| Check-in history (initials + timestamps) | Retained while account is active. Deleted on account deletion. |
| Account information | Retained while the account is active. Deleted upon account deletion request. |
| Audit logs | 90 days in the database, 6 years in S3 Glacier (WORM) |
| Provider photos | Retained while the provider is active. Deleted upon provider removal. |
You have the right to:
To exercise these rights, contact us at support@heerio.app.
If you are a patient of a healthcare practice that uses Heerio, your rights regarding your protected health information are governed by HIPAA and the privacy practices of your healthcare provider (the practice), not Heerio directly. Please contact your healthcare provider to exercise your HIPAA rights, including:
If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect and the right to request deletion. Note that health information governed by HIPAA is exempt from CCPA. To exercise your CCPA rights, contact us at support@heerio.app.
Heerio is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete that information promptly. If you believe a child under 13 has provided us with personal information, please contact us at support@heerio.app.
Heerio sends push notifications to providers when a client checks in. These notifications are intentionally generic (e.g., “New arrival at your practice”) and do not contain any patient information, names, initials, or health data. You can disable push notifications at any time through your device settings.
The Heerio web applications may use essential cookies for authentication and session management. We do not use third-party advertising cookies or tracking pixels. We do not track you across other websites.
Heerio’s services are hosted in the United States (AWS us-east-1 region). If you access our Services from outside the United States, your information will be transferred to and processed in the United States. By using our Services, you consent to this transfer.
We may update this Privacy Policy from time to time. When we make changes, we will update the “Last updated” date at the top of this page. If we make material changes that affect how we handle your information, we will notify you through the Services or by email.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
If you have questions about this Privacy Policy or our privacy practices, contact us at:
Heerio LLC
Email: support@heerio.app