1Who we are
Heal-X is a clinical decision-support platform that helps licensed practitioners build safety-checked, data-driven wellness plans from patient conversations, assessments, and labs. Heal-X is provided to you by Heal-X, LLC (the “Practice”) operating on the Heal-X platform.
2Information we collect
From patients — through the Heal-X conversation, assessments, and lab uploads:
- Identifiers: name, email, date of birth, and the patient link you used to start the conversation.
- Health information: symptoms, medications, lifestyle, diet, and uploaded lab reports (PHI).
- Consent records: when you acknowledged the consent and data-privacy gate before starting.
- Conversation transcript and the generated plan, patterns, and follow-up assessments.
From clinicians — to operate your account:
- Account: name, email, role, and practice settings (store subdomain, branding, discipline).
- Practice data: clinician profile, saved plans, patient links you create, and EHR push history.
Automatically — when you use the app:
- Usage analytics (aggregate, non-identifying) and technical logs needed for reliability.
- Decision-ledger entries that record which decision was made and when — no PHI in the ledger itself.
3How we use it
- To generate your wellness plan, pattern analysis, and follow-up recommendations.
- To let your treating clinician review, edit, and finalize the plan, and to push it to their EHR when you consent.
- To build product links (supplements, peptides) from the clinician’s store so you can fulfill the plan — store resolution happens after the plan is sealed and uses no pricing or inventory data in the clinical record.
- To schedule re-checks and follow-up assessments, and to chart progress over time.
- To operate, secure, and improve the platform, and to meet legal obligations.
4How we share it
- Your treating clinician and their practice — the clinician of record owns every clinical decision and the plan sent to you.
- EHR partners (e.g. Practice Better, Healthie, Cerbo, Charm) — only when your clinician initiates a push and only the plan and relevant chart data.
- Fulfillment vendors (NutriDyn, NorthStar, and other supplement/peptide vendors) — only the product link and order needed to fulfill; never your clinical data or plan.
- Subprocessors that host or secure the platform under Business Associate Agreements (BAA) — see Security below.
- As required by law — to respond to legal process, protect rights/safety, or as HIPAA permits.
5Data retention
Conversation and plan data is retained for the life of your patient relationship with the Practice, plus the period required by law or the Practice’s records policy. You may request deletion of your data at any time (see Your rights); clinical records the Practice is legally required to keep may be retained in a restricted archive.
6Security
- Encryption in transit (TLS) and at rest for all PHI and account data.
- Role-based access: patients see only their own records; clinicians see their patients; admins manage the workspace. Row-level security enforces this at the data layer.
- PHI is masked before any AI/analytics step; decision-support outputs are framed as patterns and signals, not diagnoses.
- Subprocessors handling PHI operate under BAA; access is logged and reviewed.
7Your rights
You have the right to:
- Access the personal and health information we hold about you.
- Request correction or amendment of inaccurate records.
- Revoke consent for the conversation, EHR push, or product fulfillment at any time.
- Request deletion of your data (subject to the Practice’s legal record-keeping duties).
- Receive a copy of your data in a portable format.
To exercise any of these rights, contact the Practice’s privacy contact at jake@heal-x.chat. We respond within 30 days.
8Clinician responsibilities
Clinicians using Heal-X are responsible for obtaining patient consent before starting a conversation, before pushing a plan to an EHR, and before sending any plan to a patient. The credentialed clinician of record owns every clinical decision. Heal-X outputs are decision-support — not a diagnosis and not a substitute for professional medical judgment. Supplement statements are structure/function and have not been evaluated to diagnose, treat, cure, or prevent any disease; peptide content is clinician-gated decision-support only.
9Changes to this policy
We may update this policy as the platform evolves. Material changes will be posted here with a new effective date; we will notify active patients and clinicians of significant changes affecting PHI handling.