Privacy Policy
Effective May 12, 2026
This Privacy Policy describes how Vane Health, Inc. (“Vane,” “we,” “us,” or “our”) collects, uses, shares, and protects personal information when you visit vanehealth.com, create a Vane account, or otherwise use the Vane platform (the “Service”). It applies to information collected in our role as platform operator. By using the Service you confirm that you have read and understood this Privacy Policy.
Health information and HIPAA.
Vane is not itself a covered entity under the Health Insurance Portability and Accountability Act (HIPAA). It acts as a business associate of the affiliated medical group (OpenLoop Healthcare Partners, P.C.and its state-affiliated professional corporations, the “Medical Group”) and of partner pharmacies when handling protected health information (PHI) on their behalf. PHI generated in the course of clinical care by the Medical Group and partner pharmacies is governed by the Notice of Privacy Practices of the relevant covered entity, not solely by this Privacy Policy. This Policy describes Vane’s own handling of personal information, including information that may overlap with PHI handled on behalf of those covered entities under written business associate agreements.
1. Information We Collect
Information you provide directly. When you create an account or use the Service we collect identifiers (name, email, phone number, date of birth, mailing address, government identification where required for prescribing), health questionnaire responses, medical history, current and prior medications, symptoms, goals, photographs you choose to upload, secure messages, and any other information you submit. We collect payment card details through our payment processor; we do not store full card numbers on our servers.
Information collected automatically. When you interact with the Service we collect device and usage data including IP address, device identifiers, browser type, operating system, referring and exit pages, dates and times of access, and interactions with features. We use cookies and similar technologies as described below.
Information from third parties. We receive laboratory results from CLIA-certified reference laboratories, clinical notes and prescription information from the Medical Group (OpenLoop Healthcare Partners, P.C. and its state-affiliated professional corporations), fulfillment and shipping data from partner pharmacies, payment confirmations from our payment processor, and information from analytics and advertising partners about your interactions with our marketing.
2. Sensitive Personal Information
We collect categories of sensitive personal information that include health information, government identification numbers, and account credentials. We collect and use this information only as needed to operate the Service, deliver care through affiliated clinicians and partner pharmacies, comply with law, and protect against fraud or harm. We do not sell sensitive personal information, and we do not use or disclose it to infer characteristics about you for purposes other than those above.
3. How We Use Information
We use personal information to:
- Operate, maintain, and improve the Service;
- Match you with affiliated independent clinicians and coordinate care, including arranging laboratory orders and prescription fulfillment by partner pharmacies;
- Process payments and manage subscriptions;
- Communicate with you about your account, your clinical engagement, billing, customer support, security, and changes to the Service;
- Send you marketing communications where you have not opted out and applicable law permits;
- Provide AI-assisted educational content and product features. We do not use personal health information to train third-party generative AI models;
- Conduct analytics, research, and product development, using aggregated or de-identified information where feasible;
- Detect, prevent, and respond to fraud, abuse, security incidents, and harm to you, other users, or the Service;
- Comply with legal obligations and respond to lawful requests.
6. Security
We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, alteration, disclosure, or destruction. These include encryption in transit and at rest for sensitive information, access controls, employee training, and audit logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We will notify you of a security incident affecting your information when required by law.
7. Retention
We retain personal information for as long as your account is active and as needed to provide the Service. After account closure we retain information for legitimate business purposes including legal, regulatory, tax, and accounting requirements. Medical records and other protected health information are retained by the affiliated clinicians and partner pharmacies under their own retention policies, which typically follow state-mandated minimums of at least seven years.
8. Your Rights
Depending on where you live you may have rights with respect to your personal information, including the right to access, correct, delete, port, or restrict processing of your information, and to withdraw consent where processing is based on consent. To exercise these rights, contact us at privacy@vanehealth.com. We will respond within the timeframes required by applicable law. We may need to verify your identity before fulfilling a request, and certain information may be retained where law or legitimate business needs require.
9. California Privacy Rights
If you are a California resident the California Consumer Privacy Act and California Privacy Rights Act (collectively, the CCPA) give you the following rights:
- Right to know. The categories and specific pieces of personal information we have collected about you, the categories of sources, the business or commercial purposes for collection, and the categories of third parties to whom we disclosed it.
- Right to delete. The deletion of personal information we have collected from you, subject to exceptions permitted by law.
- Right to correct. Correction of inaccurate personal information.
- Right to opt out of selling and sharing. The right to direct us not to “sell” or “share” your personal information as those terms are defined under CCPA.
- Right to limit use of sensitive personal information. The right to limit our use and disclosure of sensitive personal information to purposes specified by law.
- Right to non-discrimination. We will not discriminate against you for exercising your privacy rights.
To exercise these rights, email privacy@vanehealth.com. You may also authorize an agent to make a request on your behalf. We will require reasonable verification before responding. We honor Global Privacy Control (GPC) signals as a valid opt-out of selling and sharing.
Categories collected. In the prior twelve months we have collected the following categories of personal information under CCPA: identifiers, customer records, characteristics of protected classifications (where you provide them), commercial information, internet activity, geolocation (approximate), audio and visual data (photos where you upload them), professional or employment-related information (where provided), inferences drawn from the foregoing, and sensitive personal information including health information and government identification numbers.
10. Other State Privacy Rights
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, and other states with comprehensive privacy laws may have rights similar to those above, including the right to access, correct, delete, and port their personal information, and to opt out of certain processing activities. Exercise these rights by contacting privacy@vanehealth.com. You may appeal a denial by replying to our response and requesting reconsideration; we will respond to appeals within the timeframes required by applicable law.
11. Children’s Privacy
The Service is intended for adults aged eighteen (18) and older. We do not knowingly collect personal information from individuals under thirteen (13) years old. If we learn we have collected personal information from a child under thirteen without verified parental consent, we will delete it. Parents or guardians who believe their child has provided us with personal information should contact privacy@vanehealth.com.
12. International Users
The Service is intended for United States residents and is operated from the United States. If you access the Service from outside the United States, information we collect may be transferred to, stored in, and processed in the United States, where data protection laws may differ from those in your jurisdiction.
13. AI and Automated Decision-Making
The Service includes AI-assisted features such as an educational health coach and tools that surface relevant content. These features are informational and are not used to make decisions that produce legal or similarly significant effects on you. Clinical decisions, including whether to prescribe medication, are made by independent licensed clinicians applying professional judgment.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we do we will revise the effective date above and, for material changes, will notify you by email or in-product notice before the changes take effect. Continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
15. Contact
Questions about this Privacy Policy or our handling of your personal information may be directed to:
Vane Health, Inc.
Attn: Privacy
1266 Treat Avenue
San Francisco, CA 94110
privacy@vanehealth.com