Privacy Policy
Privacy at a glance
- We collect account, professional, service-use, transaction, and support information. Client-facing features may also process sensitive health and care information.
- When a provider or organization directs our processing of Client Data, that Customer generally controls the data and Habit of Care acts as its service provider or business associate.
- We do not sell personal information, use Client health information for targeted advertising, or authorize third-party AI providers to train general-purpose models on identifiable Client Data.
- Privacy rights for Client Data may need to be handled through the Client User's provider or organization. Requests about data Habit of Care controls can be sent to privacy@habitofcare.com.
- Our separate Consumer Health Data Privacy Policy describes consumer-health categories, sources, purposes, recipients, consent, and state-law rights.
1. Scope and our role
Camus LLC, doing business as Habit of Care ("Habit of Care," "we," "us," or "our"), provides websites, provider software, client-facing applications and portals, communications, support, and related services (collectively, the "Services"). This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when providers, practices, organizations, team members, website visitors, prospective customers, and invited clients use the Services. Our separate Consumer Health Data Privacy Policy supplements this policy for consumer health data regulated by applicable state law.
This policy applies to information we control for our own business purposes and to information we process for a provider, practice, or organization (a "Customer"). It does not replace a Customer's privacy notice, informed-consent documents, Notice of Privacy Practices, or professional duties.
When a Customer controls Client Data
For journals, assessments, messages, activities, care plans, progress information, and other information submitted through a Customer relationship ("Client Data"), the Customer generally decides why the information is processed, who may access it, and how long it must be kept. In that context, Habit of Care acts as a processor, service provider, or business associate on the Customer's instructions. The Customer's privacy notice and agreement with Habit of Care also apply. Client Users should usually direct requests about Client Data to their provider or organization so that clinical, legal, guardian, and record-integrity requirements can be addressed correctly.
When Habit of Care controls information
Habit of Care independently determines how to process website enquiries, marketing preferences, business contacts, account security records, billing and transaction records, product telemetry, fraud-prevention information, and support or legal records used for our own operations. Requests concerning this information may be directed to us using the contact details below.
This Privacy Policy is not a HIPAA Notice of Privacy Practices. Whether HIPAA applies depends on the entity, relationship, data, and signed agreements involved.
2. Information we collect
The information collected depends on the User, enabled features, Customer configuration, and interaction with the Services. We may collect:
- Account and identity information: name, email address, telephone number, mailing address, organization, username, account identifiers, authentication factors, role, team membership, invitation status, and account preferences. Passwords are stored in protected form, not as readable text.
- Professional and organization information: practice information, professional type, credentials, license details and status, qualifications, jurisdiction, supervision or team relationships, service preferences, and information needed to verify eligibility for a feature or program.
- Client and care information: provider-client connections, assignments, journals, mood and habit entries, goals, assessments, care-plan or homework information, messages, notes, progress information, safety-related entries, sharing choices, and other health or care-related content a User chooses to submit.
- Files, media, and communications: documents, images, audio, voice messages, transcripts, visualizations, feedback, support messages, survey responses, demo or meeting information, and the date, participants, and content of communications. We do not use voice or image content for biometric identification unless we first provide any notice and obtain any consent required by law.
- Subscription, payment, and payout information: plan, subscription status, invoices, payment status, transaction and processor identifiers, refund or dispute information, payout readiness, transfers, and related accounting records. We may retain historical redemption and fulfillment records from discontinued programs where required for support, accounting, disputes, or legal compliance. Payment card numbers and bank, tax, or identity-verification information are generally entered directly with our payment provider; we receive limited status, identifiers, and transaction details rather than full card or bank credentials.
- Device, network, and use information: IP address, approximate location derived from IP, device and browser type, operating system, language, referral page, pages and features used, clicks, timestamps, session information, error and performance data, security events, and pseudonymous audit identifiers. We do not intentionally collect precise geolocation unless an enabled feature clearly requests it.
- Website, sales, and support information: contact forms, business correspondence, requested products, demo activity, marketing preferences, support history, complaint information, and information needed to investigate or resolve a request.
- AI inputs, output, and derived information: prompts, selected source content, transcripts, generated drafts, summaries, recommendations, classifications, patterns, and other inferences created by enabled analytics or AI-assisted features.
- Integration information: identifiers, authorization tokens, connection status, and information exchanged with services a Customer or User chooses to connect, subject to the integration's permissions.
- Compliance and investigation information: records needed to document consent, authorization, privacy requests, legal holds, security incidents, access reviews, fraud reviews, disputes, and compliance with applicable agreements or law.
Some of this information may be considered sensitive personal information, consumer health data, PHI, or another specially protected category. We ask Users and Customers not to submit sensitive information outside fields and features designated for it.
3. Sources of information
We collect information:
- Directly from Users, Customers, and representatives when they create an account, accept an invitation, complete an activity, send a message, upload content, make a purchase, request support, or communicate with us.
- From connected parties when a provider, organization administrator, Client User, guardian, or authorized team member creates a connection, assigns content, changes permissions, submits information, or otherwise uses a shared workflow.
- Automatically from browsers, devices, servers, cookies, local storage, logs, and security tools when someone visits or uses the Services.
- From service providers and integrations such as payment and payout providers, communications providers, cloud hosts, identity or credential-verification services, and services a User chooses to connect.
- From public and professional sources when reasonably necessary to verify publicly available professional or business information.
- By creation or inference when the Services calculate metrics, organize entries, generate audit records, or produce analytics or AI-assisted output from other information.
4. How we use information
We use personal information as reasonably necessary to:
- provide, configure, personalize, and support accounts, provider-client connections, activities, journals, messages, dashboards, visualizations, AI-assisted tools, and other requested features;
- authenticate Users, enforce roles and sharing settings, maintain audit trails, detect unauthorized activity, prevent fraud and abuse, protect safety, and secure the Services;
- process subscriptions, invoices, payments, payouts, credits, refunds, disputes, and related tax or accounting records;
- send invitations, reminders, confirmations, security alerts, service notices, support responses, and other communications requested by a User or Customer;
- operate support, investigate errors, test availability, restore service, manage vendors, and maintain business continuity;
- develop and improve the Services using operational data and, for Client Data, de-identified or aggregated information unless an applicable agreement and law expressly authorize another use;
- evaluate eligibility, usage, service quality, program integrity, and feature performance without treating engagement alone as proof of a clinical outcome;
- comply with signed agreements, Customer instructions, legal process, tax and accounting obligations, privacy and security duties, regulatory requests, and record-retention requirements; and
- establish, exercise, or defend legal claims and protect the rights, property, safety, and integrity of Habit of Care, our Users, Customers, and others.
Where a law requires a legal basis, we rely as appropriate on performance of a contract, compliance with legal obligations, protection of vital interests, legitimate interests that are not overridden by individual rights, and consent. Consent can be withdrawn for future processing, but withdrawal does not affect processing already lawfully completed or processing supported by another legal basis.
5. Health information, HIPAA, and specially protected records
Health-related information is not automatically covered by HIPAA. HIPAA applies only to covered entities, business associates, and PHI within the scope of the law. When we process PHI for a covered Customer under an executed BAA, we use and disclose that PHI as permitted by the BAA, the Customer's documented instructions, and applicable law. We support the Customer in responding to individual-rights requests as the BAA requires.
The Customer remains responsible for its Notice of Privacy Practices, informed consent, authorizations, minimum-necessary decisions, professional records, and responses to Clients. If a Client User asks us to access, correct, amend, restrict, account for, or delete PHI controlled by a Customer, we may refer or forward the request to that Customer. We will not disclose whether someone is a Client User before reasonably verifying identity and authority.
Some records may be subject to stricter rules, including 42 C.F.R. Part 2 substance-use-disorder record protections, state mental-health confidentiality laws, psychotherapy-note rules, minor-consent rules, privilege, or legal-proceeding restrictions. Customers must not submit such records unless the use is authorized and appropriate contracts and controls are in place. Where Part 2 applies, the Customer is responsible for identifying the data and ensuring that consent, notice, redisclosure, legal-process, and other requirements are satisfied; Habit of Care will follow the applicable signed agreement and approved configuration.
For consumer health data outside HIPAA, we collect and use the information to provide the health-related feature requested by the User or Customer, maintain security, comply with law, and for other purposes disclosed at collection with any consent required by law. We do not sell consumer health data or use it for targeted advertising. We do not use geofencing to identify or target people seeking in-person health care services.
6. AI-assisted features
Enabled AI-assisted features may send a prompt and selected information to an approved AI service provider to generate a response. Depending on the feature, this information may include Client Data. PHI may be sent only when the Customer has authorized the feature and the required BAA, vendor agreement, retention configuration, and product controls are in place.
We do not use identifiable Client Data to train public or general-purpose AI models, and we do not authorize third-party AI providers to do so. We may use de-identified or aggregated information to evaluate quality and improve the Services, subject to applicable agreements and law. AI inputs and output may be stored in the Customer account, included in audit records, and visible to Users with appropriate permissions.
AI output may be inaccurate or incomplete and requires human review. We do not use AI to make solely automated decisions that produce legal or similarly significant effects about a person. Providers, not Habit of Care or an AI system, are responsible for clinical interpretation and decisions.
7. How we disclose information
We disclose personal information only as described in this policy, at a User's or Customer's direction, or as permitted by law:
- Customers and authorized account Users: We disclose information within a Customer account according to roles, provider-client connections, sharing choices, and Customer instructions. Organization administrators may have account-level access consistent with assigned permissions.
- Service providers and subprocessors: Vendors may provide cloud hosting and storage, database and backup services, AI processing, communications, payment and payout processing, security, error monitoring, support, credential verification, and professional services. We provide only information reasonably needed for the service and use contracts and configuration requirements appropriate to the risk.
- Integrations: We exchange information with a third-party service when a Customer or User enables and authorizes the connection.
- Payment and payout recipients: Payment processors, financial institutions, and tax or accounting providers receive information necessary to complete a transaction, prevent fraud, resolve a dispute, or comply with law. Clinical details should not be included in payment or payout metadata.
- Legal, safety, and security recipients: We may disclose information to courts, law enforcement, regulators, government authorities, security researchers, or affected parties when we reasonably believe disclosure is required by law or necessary to protect rights, safety, funds, data, or the integrity of the Services. Specialized health-record restrictions may limit these disclosures.
- Professional advisers: Lawyers, auditors, insurers, accountants, and consultants may receive information subject to professional duties or confidentiality restrictions.
- Corporate transactions: Information may be reviewed or transferred in a financing, merger, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality and any legally required notice.
- With direction or consent: We may disclose information for another clearly described purpose when the authorized person directs us or provides consent.
- De-identified information: We may disclose information that has been de-identified or aggregated so it is not reasonably linkable to an individual. We require recipients not to attempt re-identification where appropriate or required.
We do not disclose Client Data to affiliates for their independent marketing. We do not place clinical content in ordinary email subjects, payment metadata, advertising systems, or public areas. Users remain responsible for content they intentionally share or publish.
8. No sale, targeted advertising, or unrelated profiling
We do not sell personal information for money. We also do not share personal information for cross-context behavioral advertising, use Client Data for targeted advertising, or profile Client Users in furtherance of decisions that produce legal or similarly significant effects. We have not engaged in these activities during the preceding 12 months.
Some state laws define a "sale" or "sharing" broadly. If our practices change, we will update this policy and provide any required opt-out mechanism before the new practice begins. Because we do not currently sell or share personal information for targeted advertising, a browser-based opt-out signal does not change those practices. Where legally required, we will treat a recognized Global Privacy Control signal as a request to opt out for the browser or device sending it.
10. Retention, account closure, and deletion
We retain information for the shortest period reasonably necessary for the purposes described in this policy, subject to Customer instructions and legal, clinical, contractual, security, tax, accounting, dispute, backup, and legal-hold requirements. The period depends on the type of information, the Customer relationship, whether the account is active, sensitivity, risk, and applicable law.
Closing an account or ending a provider-client connection does not necessarily delete all information immediately. A Customer may be required to retain a clinical record; transaction and compliance records may need to be preserved; an investigation or legal hold may prevent deletion; and restricted backup copies may remain until they expire under the backup schedule. We isolate or restrict retained information where appropriate and delete or de-identify it when the applicable requirements end.
Temporary privacy exports are encrypted, delivered through an approved method, and scheduled for secure disposal after the request and any applicable review period are complete. We may retain de-identified information for research, analytics, security, and product improvement for as long as it remains de-identified, and we will not attempt to re-identify it except to test or validate de-identification as permitted by law.
11. Security and incident notice
We use administrative, technical, and physical safeguards designed for the nature and sensitivity of the information. Depending on the service and deployment, safeguards may include encryption in transit and at rest, multi-factor authentication, role-based access, session controls, audit logging, private storage, vulnerability and change management, vendor review, workforce policies, incident response, backups, and recovery testing.
No system is completely secure. Users also play an important role: use unique credentials, protect devices, enable multi-factor authentication, verify recipients, avoid shared accounts, and promptly report suspicious activity. Do not send sensitive clinical information through ordinary support or unencrypted email unless instructed to use an approved secure method.
If an incident creates a notification duty, we will notify affected Customers, individuals, regulators, or others as required by the applicable law and agreement. Depending on the data and relationship, this may include HIPAA breach duties, the FTC Health Breach Notification Rule, state breach laws, or contractual requirements.
12. Privacy rights and requests
Consumer-health rights, including withdrawal of consent and recipient-list requests, are described in our Consumer Health Data Privacy Policy.
Depending on the law and our role, an individual may have a right to:
- confirm whether personal information is processed and access or obtain a copy of it;
- correct inaccurate information or request an amendment to an eligible record;
- delete information, subject to legal, clinical, contractual, security, and record-integrity exceptions;
- obtain portable information in a usable format where required and technically feasible;
- restrict, object to, or withdraw consent for certain processing;
- opt out of sale, targeted advertising, or certain profiling, although we do not currently conduct those activities;
- receive information about categories of information, sources, purposes, and recipients;
- appeal a denied privacy request and contact the appropriate regulator; and
- exercise rights without unlawful discrimination or retaliation.
Requests involving Client Data
Contact the provider or organization shown in the Client account first. The Customer is generally responsible for evaluating identity, authority, clinical-record rules, amendment procedures, guardian rights, restrictions, and applicable deadlines. We will assist the Customer as required by our agreement. A request to delete Client Data cannot override a Customer's lawful record-retention duty, legal hold, or another applicable exception.
Requests involving information Habit of Care controls
Email privacy@habitofcare.com with the subject "Privacy Request" and describe the request. We will verify identity and authority in a manner proportionate to the sensitivity of the information. An authorized agent may submit a request, but we may require proof of authorization and direct identity confirmation. We will respond within the period required by applicable law and explain any denial and available appeal process.
We will not ask for more identity information than reasonably necessary, and we will not disclose whether a person has a provider relationship before verification. If a request concerns data controlled by a Customer, we may forward the request to that Customer and tell the requester how to contact it.
13. Account, sharing, and communication choices
- Client sharing: Where available, Client Users can adjust which categories of information are shared with a connected provider. Certain information already received by a provider or required for account, safety, audit, or legal purposes may not be removed by changing a setting.
- Connections and access: A User may end an available provider-client connection or ask the Customer to do so. Ending a connection affects future access but does not necessarily delete existing records.
- Account information: Users can update certain contact, security, and preference information through account settings or support.
- Marketing: Recipients can unsubscribe through the link in a marketing email or contact us. We may still send security, transaction, legal, and service messages that are necessary for an account or relationship.
- Notifications: Users can use available application and device settings to manage reminders and notification previews. Customers should consider shared-device and lock-screen privacy before enabling sensitive notifications.
14. Minors
The Services are not marketed directly to children under 13, and a child under 13 may not create an account independently. A provider or organization may invite a minor to a client-facing feature only when the Customer has determined that the use is appropriate and lawful and has completed any required parent or guardian notice, verifiable consent, authorization, assent, or institutional process.
Information about a minor may be subject to rules that give the minor confidentiality or consent rights even when a parent or guardian is involved. The Customer is responsible for determining and configuring appropriate access. We do not use a minor's Client Data for targeted advertising or authorize it for general-purpose AI training.
If you believe a child has used the Services without required authorization, contact privacy@habitofcare.com. We will investigate, coordinate with the appropriate Customer where necessary, and delete or restrict information as required by law.
15. International use and data transfers
Habit of Care is based in the United States, and the Services are designed primarily for U.S. use. Information may be processed in the United States and in other locations where approved service providers operate. Those locations may have privacy laws different from the User's jurisdiction.
If we approve use in a jurisdiction that requires a transfer mechanism, we will use an appropriate contractual or legal safeguard. A Customer must not make the Services available in another jurisdiction without confirming with us that the required agreement, hosting, notice, consent, and transfer arrangements are in place.
16. External services and public content
The Services may link to external websites or allow a User to enable a third-party integration. An external provider's privacy policy applies to its independent processing, and we are not responsible for its practices. Review the provider's terms and permissions before connecting it.
Do not place Client Data or confidential information in testimonials, public comments, social media, community areas, or other public fields. Information intentionally made public can be copied, indexed, or redistributed by others and may not be fully removable.
17. Changes to this policy and contact
We may update this policy to reflect changes in the Services, vendors, law, or our practices. We will post the revised policy and update the date above. If a change materially affects how we use previously collected information, we will provide additional notice or obtain consent when required by law or contract. Changes apply prospectively from their effective date.
Questions, complaints, privacy requests, and suspected privacy or security incidents may be sent to:
Habit of Care Privacy Team / Camus LLC1141 N. Martin Luther King Jr. Drive
Milwaukee, WI 53203
USA
Email: privacy@habitofcare.com
If you are not satisfied with our response, you may have the right to appeal to us and complain to your state attorney general, data protection authority, the U.S. Department of Health and Human Services Office for Civil Rights, the Federal Trade Commission, or another regulator with jurisdiction.