Imria Health Privacy Policy
Effective Date: 8/17/2025
Last Updated: 8/17/2025
This Privacy Policy explains how Imria Health, LLC (“Imria,” “we,” “our,” or “us”) collects, uses, discloses, and protects your personal information when you use our website, mobile application, or related services (collectively, the “Services”). This policy is designed to comply with applicable privacy laws and to ensure you understand your rights and choices.
By using the Services, you acknowledge and agree to the terms of this Privacy Policy. If you are accessing the Services on behalf of another individual or entity, you represent that you are authorized to do so and consent on their behalf.
Information We Collect
We collect information to operate, maintain, and improve our Services, as well as to support lawful purposes such as compliance, security, and communication. Information we collect includes:
- Information you provide directly, such as your name, email address, phone number, health status, or questions you submit to the platform. This may occur when you register, use features, or communicate with us.
- Payment information, which is handled by secure third-party processors. We do not store your payment card details, but we may receive information related to transaction confirmations for recordkeeping purposes.
- Automatically collected data, including IP address, device type, browser version, session activity, general location (if enabled), and usage metrics. We use cookies and similar technologies to support site functionality and analytics.
Use of Information
We use the information we collect to:
- Provide, operate, and improve the Services
- Personalize user experience and content
- Facilitate optional physician consultations and care navigation tools
- Communicate with users about account activity, features, and updates
- Conduct internal research and analytics
- Comply with legal obligations and protect our users and infrastructure
We may also use de-identified or aggregated data for research, trend analysis, product development, or publication. This information does not identify individuals and may be retained indefinitely.
Protection Health Information and HIPAA Compliance
Imria Health, LLC is not a HIPAA-covered entity. However, our physician consultation feature is designed to comply with HIPAA requirements. When you use this feature, your personal health information is handled in accordance with applicable privacy and security standards under HIPAA.
We work with licensed healthcare professionals who are themselves subject to HIPAA, and with third-party service providers (such as secure video, document storage, or messaging platforms) that are contractually obligated to comply with HIPAA as Business Associates. We implement administrative, physical, and technical safeguards to ensure your protected health information (PHI) is stored and transmitted securely when using this part of the platform.
Use of other features within the Imria platform—such as educational content, visit preparation tools, AI-powered guidance—does not involve the collection of PHI and is not governed by HIPAA. Nonetheless, we take the privacy of all user information seriously across all services.
Sharing of Information
We do not sell your personal information. We may share your data only in the following circumstances:
- With third-party service providers under contract who help us operate the platform, such as hosting services, analytics providers, or customer support systems
- With payment processors who securely manage billing transactions
- With legal authorities or regulatory agencies, when required by law, subpoena, or to protect the rights, safety, or security of Imria, its users, or others
- As part of a business transaction such as a merger, acquisition, or asset transfer, where user data is considered part of the transferred assets
- With other parties only with your explicit consent
All third parties that receive your information from us are required to protect it under applicable privacy laws and contractual obligations.
Your Rights and Choices
You may access, correct, or delete certain personal information by logging into your account or contacting us directly. You may also:
- Opt out of promotional emails by using the unsubscribe link or notifying us
- Adjust browser or device settings to manage cookies or limit location tracking
- Request deletion of your account, subject to legal and operational constraints
Please note that certain data may be retained as required by law, for fraud prevention, or for audit and compliance purposes.
Data Retention and Security
We retain personal information only as long as necessary to fulfill the purposes outlined in this policy or as required by applicable law. This includes maintaining records of user interactions, payments, and regulatory reporting.
Please note that certain data may be retained as required by law, for fraud prevention, or for audit and compliance purposes.
We implement commercially reasonable safeguards to protect your data, including encryption, access control, and secure storage systems. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
If we become aware of a security breach that affects your information, we will notify you as required by law.
Use by Children
The Services are not intended for use by children under 13 years of age, and we do not knowingly collect personal data from individuals in this age group. If we learn that such information has been collected, we will promptly delete it.
International Users
The Services are operated in the United States. If you access them from another country, you consent to the transfer, processing, and storage of your information in the United States or other jurisdictions, which may have different data protection laws from your country of residence.
U.S. State Privacy Rights
If you are a resident of California, you may have additional rights under the California Consumer Privacy Act (CCPA) or similar laws. These may include: the right to request access to personal data we hold about you, the right to request deletion of certain data, and the right to opt out of data sharing for direct marketing purposes. To exercise these rights, please contact us using the information below. We will verify your request in accordance with applicable law.
In addition to California residents, individuals in other U.S. states—including but not limited to Virginia, Colorado, Connecticut, Utah, and Texas—may have specific rights regarding their personal information under applicable state privacy laws. These may include the right to access, correct, delete, or restrict the processing of certain data, and to opt out of targeted advertising or data sales. If you are a resident of one of these states and wish to exercise your rights, please contact us using the information below. We will verify your identity and respond as required by applicable law.
Changes to This Policy
We may update this Privacy Policy from time to time. Any material changes will be communicated through our Services or via direct notice. The effective date at the top of this document will reflect the latest version. Your continued use of the Services constitutes your agreement to the updated policy.
Contact Us
For questions about this Privacy Policy or to submit a request regarding your personal information, please contact support@imriahealth.com.