Privacy Policy

Last updated: September 2026

1. Introduction

Heerio LLC (“Heerio,” “we,” “us,” or “our”) provides a client check-in platform for therapy, medical, and legal practices. This Privacy Policy describes how we collect, use, disclose, and protect information when you use our mobile applications, web applications, and related services (collectively, the “Services”).

By using our Services, you agree to the collection and use of information as described in this Privacy Policy.

2. Who This Policy Applies To

Heerio serves three types of users:

User TypeDescription
Practice OwnersHealthcare, therapy, or legal professionals who sign up and manage a practice on Heerio
ProvidersStaff members (therapists, doctors, attorneys, etc.) invited by a Practice Owner to receive check-in notifications
Clients/PatientsIndividuals who check in at a practice using a kiosk, mobile app, or client code. Clients do not create accounts.

3. Information We Collect

3.1 Information from Practice Owners and Providers

When you create an account or are invited to join a practice, we collect:

  • Email address
  • Password (stored in hashed form — we cannot see your password)
  • First and last name
  • Practice name and profession category
  • Provider credentials and title (if applicable)
  • Provider photo (if uploaded)
  • Device tokens for push notifications

3.2 Information from Clients/Patients

Heerio is designed to collect the minimum information necessary for a check-in. When a client checks in, we collect only:

  • Client initials (e.g., “J.S.”) — we do not collect full names
  • Check-in type (arrived, late, cancelled)
  • Timestamp of the check-in
  • The provider the client is checking in with

We do not collect: full patient names, dates of birth, Social Security numbers, diagnoses, treatment information, insurance information, or any other clinical or medical records.

3.3 Information Collected Automatically

  • IP address (logged for security and audit purposes)
  • Device type and operating system (for app compatibility)
  • API request logs (endpoint, method, status code, timestamp — for security auditing)

4. How We Use Your Information

PurposeData Used
Provide the check-in serviceClient initials, check-in type, timestamp, provider selection
Send real-time notifications to providersCheck-in event data (generic notification — no patient information is included in the push notification)
Account managementEmail, name, password, practice information
Billing and subscription managementPractice ID, subscription status (no health information is shared with payment processors)
Security and fraud preventionIP address, API logs, audit trail
Customer supportEmail, name, practice information
Service improvementsAggregated, de-identified usage data

5. Protected Health Information (PHI)

Heerio may be considered a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA) when providing services to healthcare practices. In this capacity:

  • We handle only minimal protected health information (PHI): client initials and check-in timestamps
  • We enter into Business Associate Agreements (BAAs) with practices as required
  • We maintain administrative, technical, and physical safeguards to protect PHI
  • We do not use or disclose PHI for marketing, advertising, or any purpose other than providing the Services
  • We do not sell PHI under any circumstances

For practices that are covered entities under HIPAA, our handling of PHI is governed by the terms of the Business Associate Agreement between Heerio and the practice.

6. How We Share Your Information

We do not sell your personal information or PHI. We share information only in the following circumstances:

6.1 Service Providers

We use third-party service providers to operate our platform. These providers process data on our behalf and are contractually obligated to protect it:

ProviderPurposeData Shared
Amazon Web Services (AWS)Cloud infrastructure (servers, database, storage)All application data is hosted on AWS. BAA in place.
StripePayment processingPractice ID and subscription data only. No health information.
Firebase (Google)Push notifications and web hostingGeneric notification messages only (e.g., “New arrival”). No patient information in notifications.
ResendTransactional email (invites, password resets)Email addresses only. No health information.
RevenueCatIn-app purchase managementAnonymous user IDs only. No health information.

6.2 Legal Requirements

We may disclose information if required to do so by law, such as in response to:

  • A court order or subpoena
  • A request from a law enforcement agency
  • To protect the rights, property, or safety of Heerio, our users, or the public

6.3 Business Transfers

If Heerio is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify affected users before their information becomes subject to a different privacy policy.

7. Data Security

We implement industry-standard security measures to protect your information:

MeasureDetails
Encryption at restAll database data is encrypted using AES-256
Encryption in transitAll data transmitted between your device and our servers is encrypted using TLS 1.2+
Password securityPasswords are hashed using bcrypt and are never stored in plain text
Access controlsRole-based access controls ensure users can only access data within their own practice
Audit loggingAll system access is logged for security monitoring
Infrastructure securityDatabase servers are isolated in private networks and are not directly accessible from the internet

While we take reasonable measures to protect your information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.

8. Data Retention

Data TypeRetention
Active check-insCleared by the provider after the client is seen
Check-in history (initials + timestamps)Retained while account is active. Deleted on account deletion.
Account informationRetained while the account is active. Deleted upon account deletion request.
Audit logs90 days in the database, 6 years in S3 Glacier (WORM)
Provider photosRetained while the provider is active. Deleted upon provider removal.

9. Your Rights

9.1 All Users

You have the right to:

  • Request access to the personal information we hold about you
  • Request correction of inaccurate information
  • Request deletion of your account and associated data
  • Opt out of non-essential communications

To exercise these rights, contact us at support@heerio.app.

9.2 HIPAA Rights (for Patients of Covered Entity Practices)

If you are a patient of a healthcare practice that uses Heerio, your rights regarding your protected health information are governed by HIPAA and the privacy practices of your healthcare provider (the practice), not Heerio directly. Please contact your healthcare provider to exercise your HIPAA rights, including:

  • Right to access your health information
  • Right to request corrections
  • Right to an accounting of disclosures
  • Right to request restrictions on uses and disclosures

9.3 California Residents (CCPA)

If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect and the right to request deletion. Note that health information governed by HIPAA is exempt from CCPA. To exercise your CCPA rights, contact us at support@heerio.app.

10. Children’s Privacy

Heerio is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete that information promptly. If you believe a child under 13 has provided us with personal information, please contact us at support@heerio.app.

11. Push Notifications

Heerio sends push notifications to providers when a client checks in. These notifications are intentionally generic (e.g., “New arrival at your practice”) and do not contain any patient information, names, initials, or health data. You can disable push notifications at any time through your device settings.

12. Cookies and Tracking

The Heerio web applications may use essential cookies for authentication and session management. We do not use third-party advertising cookies or tracking pixels. We do not track you across other websites.

13. International Users

Heerio’s services are hosted in the United States (AWS us-east-1 region). If you access our Services from outside the United States, your information will be transferred to and processed in the United States. By using our Services, you consent to this transfer.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make changes, we will update the “Last updated” date at the top of this page. If we make material changes that affect how we handle your information, we will notify you through the Services or by email.

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

15. Contact Us

If you have questions about this Privacy Policy or our privacy practices, contact us at:

Heerio LLC
Email: support@heerio.app