Log In Start for free

Privacy Policy

1. Scope and our role

Camus LLC, doing business as Habit of Care ("Habit of Care," "we," "us," or "our"), provides websites, provider software, client-facing applications and portals, communications, support, and related services (collectively, the "Services"). This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when providers, practices, organizations, team members, website visitors, prospective customers, and invited clients use the Services. Our separate Consumer Health Data Privacy Policy supplements this policy for consumer health data regulated by applicable state law.

This policy applies to information we control for our own business purposes and to information we process for a provider, practice, or organization (a "Customer"). It does not replace a Customer's privacy notice, informed-consent documents, Notice of Privacy Practices, or professional duties.

When a Customer controls Client Data

For journals, assessments, messages, activities, care plans, progress information, and other information submitted through a Customer relationship ("Client Data"), the Customer generally decides why the information is processed, who may access it, and how long it must be kept. In that context, Habit of Care acts as a processor, service provider, or business associate on the Customer's instructions. The Customer's privacy notice and agreement with Habit of Care also apply. Client Users should usually direct requests about Client Data to their provider or organization so that clinical, legal, guardian, and record-integrity requirements can be addressed correctly.

When Habit of Care controls information

Habit of Care independently determines how to process website enquiries, marketing preferences, business contacts, account security records, billing and transaction records, product telemetry, fraud-prevention information, and support or legal records used for our own operations. Requests concerning this information may be directed to us using the contact details below.

This Privacy Policy is not a HIPAA Notice of Privacy Practices. Whether HIPAA applies depends on the entity, relationship, data, and signed agreements involved.

2. Information we collect

The information collected depends on the User, enabled features, Customer configuration, and interaction with the Services. We may collect:

Some of this information may be considered sensitive personal information, consumer health data, PHI, or another specially protected category. We ask Users and Customers not to submit sensitive information outside fields and features designated for it.

3. Sources of information

We collect information:

4. How we use information

We use personal information as reasonably necessary to:

Where a law requires a legal basis, we rely as appropriate on performance of a contract, compliance with legal obligations, protection of vital interests, legitimate interests that are not overridden by individual rights, and consent. Consent can be withdrawn for future processing, but withdrawal does not affect processing already lawfully completed or processing supported by another legal basis.

5. Health information, HIPAA, and specially protected records

Health-related information is not automatically covered by HIPAA. HIPAA applies only to covered entities, business associates, and PHI within the scope of the law. When we process PHI for a covered Customer under an executed BAA, we use and disclose that PHI as permitted by the BAA, the Customer's documented instructions, and applicable law. We support the Customer in responding to individual-rights requests as the BAA requires.

The Customer remains responsible for its Notice of Privacy Practices, informed consent, authorizations, minimum-necessary decisions, professional records, and responses to Clients. If a Client User asks us to access, correct, amend, restrict, account for, or delete PHI controlled by a Customer, we may refer or forward the request to that Customer. We will not disclose whether someone is a Client User before reasonably verifying identity and authority.

Some records may be subject to stricter rules, including 42 C.F.R. Part 2 substance-use-disorder record protections, state mental-health confidentiality laws, psychotherapy-note rules, minor-consent rules, privilege, or legal-proceeding restrictions. Customers must not submit such records unless the use is authorized and appropriate contracts and controls are in place. Where Part 2 applies, the Customer is responsible for identifying the data and ensuring that consent, notice, redisclosure, legal-process, and other requirements are satisfied; Habit of Care will follow the applicable signed agreement and approved configuration.

For consumer health data outside HIPAA, we collect and use the information to provide the health-related feature requested by the User or Customer, maintain security, comply with law, and for other purposes disclosed at collection with any consent required by law. We do not sell consumer health data or use it for targeted advertising. We do not use geofencing to identify or target people seeking in-person health care services.

6. AI-assisted features

Enabled AI-assisted features may send a prompt and selected information to an approved AI service provider to generate a response. Depending on the feature, this information may include Client Data. PHI may be sent only when the Customer has authorized the feature and the required BAA, vendor agreement, retention configuration, and product controls are in place.

We do not use identifiable Client Data to train public or general-purpose AI models, and we do not authorize third-party AI providers to do so. We may use de-identified or aggregated information to evaluate quality and improve the Services, subject to applicable agreements and law. AI inputs and output may be stored in the Customer account, included in audit records, and visible to Users with appropriate permissions.

AI output may be inaccurate or incomplete and requires human review. We do not use AI to make solely automated decisions that produce legal or similarly significant effects about a person. Providers, not Habit of Care or an AI system, are responsible for clinical interpretation and decisions.

7. How we disclose information

We disclose personal information only as described in this policy, at a User's or Customer's direction, or as permitted by law:

We do not disclose Client Data to affiliates for their independent marketing. We do not place clinical content in ordinary email subjects, payment metadata, advertising systems, or public areas. Users remain responsible for content they intentionally share or publish.

8. No sale, targeted advertising, or unrelated profiling

We do not sell personal information for money. We also do not share personal information for cross-context behavioral advertising, use Client Data for targeted advertising, or profile Client Users in furtherance of decisions that produce legal or similarly significant effects. We have not engaged in these activities during the preceding 12 months.

Some state laws define a "sale" or "sharing" broadly. If our practices change, we will update this policy and provide any required opt-out mechanism before the new practice begins. Because we do not currently sell or share personal information for targeted advertising, a browser-based opt-out signal does not change those practices. Where legally required, we will treat a recognized Global Privacy Control signal as a request to opt out for the browser or device sending it.

9. Cookies, local storage, and external resources

We use session cookies and similar technologies to keep Users signed in, protect accounts, remember preferences, support navigation, and operate requested features. We also use browser local storage for settings such as themes, dismissed notices, tour progress, display choices, and unsent drafts. Some local storage may remain until the User clears it or the application removes it.

Our public pages may load resources such as fonts, icons, or scripts from service providers. Those providers may receive technical information such as IP address, browser type, and the referring page when the resource loads. The Services are not currently designed to use third-party behavioral advertising cookies. If we introduce optional analytics or advertising technologies, we will provide notice and controls required by law before using them.

Browser settings can block or remove cookies and local storage, but essential account and preference features may not work correctly. Because there is no common standard for "Do Not Track," we do not respond to that signal.

10. Retention, account closure, and deletion

We retain information for the shortest period reasonably necessary for the purposes described in this policy, subject to Customer instructions and legal, clinical, contractual, security, tax, accounting, dispute, backup, and legal-hold requirements. The period depends on the type of information, the Customer relationship, whether the account is active, sensitivity, risk, and applicable law.

Closing an account or ending a provider-client connection does not necessarily delete all information immediately. A Customer may be required to retain a clinical record; transaction and compliance records may need to be preserved; an investigation or legal hold may prevent deletion; and restricted backup copies may remain until they expire under the backup schedule. We isolate or restrict retained information where appropriate and delete or de-identify it when the applicable requirements end.

Temporary privacy exports are encrypted, delivered through an approved method, and scheduled for secure disposal after the request and any applicable review period are complete. We may retain de-identified information for research, analytics, security, and product improvement for as long as it remains de-identified, and we will not attempt to re-identify it except to test or validate de-identification as permitted by law.

11. Security and incident notice

We use administrative, technical, and physical safeguards designed for the nature and sensitivity of the information. Depending on the service and deployment, safeguards may include encryption in transit and at rest, multi-factor authentication, role-based access, session controls, audit logging, private storage, vulnerability and change management, vendor review, workforce policies, incident response, backups, and recovery testing.

No system is completely secure. Users also play an important role: use unique credentials, protect devices, enable multi-factor authentication, verify recipients, avoid shared accounts, and promptly report suspicious activity. Do not send sensitive clinical information through ordinary support or unencrypted email unless instructed to use an approved secure method.

If an incident creates a notification duty, we will notify affected Customers, individuals, regulators, or others as required by the applicable law and agreement. Depending on the data and relationship, this may include HIPAA breach duties, the FTC Health Breach Notification Rule, state breach laws, or contractual requirements.

12. Privacy rights and requests

Consumer-health rights, including withdrawal of consent and recipient-list requests, are described in our Consumer Health Data Privacy Policy.

Depending on the law and our role, an individual may have a right to:

Requests involving Client Data

Contact the provider or organization shown in the Client account first. The Customer is generally responsible for evaluating identity, authority, clinical-record rules, amendment procedures, guardian rights, restrictions, and applicable deadlines. We will assist the Customer as required by our agreement. A request to delete Client Data cannot override a Customer's lawful record-retention duty, legal hold, or another applicable exception.

Requests involving information Habit of Care controls

Email privacy@habitofcare.com with the subject "Privacy Request" and describe the request. We will verify identity and authority in a manner proportionate to the sensitivity of the information. An authorized agent may submit a request, but we may require proof of authorization and direct identity confirmation. We will respond within the period required by applicable law and explain any denial and available appeal process.

We will not ask for more identity information than reasonably necessary, and we will not disclose whether a person has a provider relationship before verification. If a request concerns data controlled by a Customer, we may forward the request to that Customer and tell the requester how to contact it.

13. Account, sharing, and communication choices

14. Minors

The Services are not marketed directly to children under 13, and a child under 13 may not create an account independently. A provider or organization may invite a minor to a client-facing feature only when the Customer has determined that the use is appropriate and lawful and has completed any required parent or guardian notice, verifiable consent, authorization, assent, or institutional process.

Information about a minor may be subject to rules that give the minor confidentiality or consent rights even when a parent or guardian is involved. The Customer is responsible for determining and configuring appropriate access. We do not use a minor's Client Data for targeted advertising or authorize it for general-purpose AI training.

If you believe a child has used the Services without required authorization, contact privacy@habitofcare.com. We will investigate, coordinate with the appropriate Customer where necessary, and delete or restrict information as required by law.

15. International use and data transfers

Habit of Care is based in the United States, and the Services are designed primarily for U.S. use. Information may be processed in the United States and in other locations where approved service providers operate. Those locations may have privacy laws different from the User's jurisdiction.

If we approve use in a jurisdiction that requires a transfer mechanism, we will use an appropriate contractual or legal safeguard. A Customer must not make the Services available in another jurisdiction without confirming with us that the required agreement, hosting, notice, consent, and transfer arrangements are in place.

17. Changes to this policy and contact

We may update this policy to reflect changes in the Services, vendors, law, or our practices. We will post the revised policy and update the date above. If a change materially affects how we use previously collected information, we will provide additional notice or obtain consent when required by law or contract. Changes apply prospectively from their effective date.

Questions, complaints, privacy requests, and suspected privacy or security incidents may be sent to:

Habit of Care Privacy Team / Camus LLC
1141 N. Martin Luther King Jr. Drive
Milwaukee, WI 53203
USA
Email: privacy@habitofcare.com

If you are not satisfied with our response, you may have the right to appeal to us and complain to your state attorney general, data protection authority, the U.S. Department of Health and Human Services Office for Civil Rights, the Federal Trade Commission, or another regulator with jurisdiction.