Reveris Reveris | AI-powered clinic assistant
  • Problem
  • How it works
  • Pricing
  • FAQ
Provider Portal Run a 10-case pilot
Legal

Privacy Policy

Effective date: September 4, 2026 · Last updated: September 4, 2026

Reveris Inc. ("Reveris," "we," "us," or "our") provides a public website at reveris.health and a separate authenticated software platform for clinics and healthcare professionals. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information through the website, the platform, and related communications (collectively, the "Service").

This Policy is separate from our Terms and Conditions. When we process Protected Health Information ("PHI") for a Customer under a Business Associate Agreement ("BAA"), the BAA and applicable healthcare law also apply. The BAA controls if it conflicts with this Policy regarding PHI. This Policy is not a healthcare provider's Notice of Privacy Practices.

1. Our Role

Public website and business relationships. For website visitors, business contacts, and the administrative records of Customer personnel, Reveris determines the purposes and means of processing and acts as a business or controller under applicable privacy law.

Customer Data. For information a Customer submits to the authenticated platform, Reveris processes the information on the Customer's behalf as a service provider or processor. If the Customer is subject to HIPAA and a BAA is in effect, Reveris also acts as a business associate or subcontractor business associate for PHI. The Customer determines the purposes of that processing and is responsible for required notices, permissions, authorizations, and responses concerning its client records.

Requests concerning client records. Individuals should contact the clinic or provider that collected the information. If a person contacts Reveris directly, we may refer the request to the relevant Customer and assist as required by law, contract, and any applicable BAA.

2. Information We Collect

Contact, account, and transaction information. We may collect names, business contact details, professional roles, organization information, account credentials and permissions, login and authentication records, contracts, subscriptions, invoices, payment status, usage information, and support records. Payment providers may process payment information on our behalf; Reveris does not store complete payment-card numbers unless disclosed at collection.

Public website and technical information. We may collect IP address, browser and device information, operating system, cookie and device identifiers, referring and exit pages, pages viewed, interactions, timestamps, approximate location derived from IP address, advertising and campaign information, consent choices, diagnostic data, and security events.

Customer Data. Authorized users may submit intake information, goals, health histories, laboratory results, treatment-related information, case notes, communications, images, documents, workflow materials, and other information used to provide the Service. We also process related inputs, outputs, corrections, approvals, and feedback. Customer Data may include PHI, medical information, and other sensitive personal information.

Communications. We collect information in emails, forms, pilot or demonstration requests, support requests, meetings, surveys, and other communications. If a call or meeting is recorded, we provide notice or obtain consent where required.

Sources. We receive information from individuals, Customers and their authorized users, Customer-directed integrations, service and advertising providers, referral sources, public professional sources, and use of the Service.

3. How We Use Information

We use personal information to provide, configure, secure, maintain, and support the Service; authenticate users and administer accounts; process Customer Data as instructed; prepare workflow outputs; provide demonstrations and support; process billing and contracts; communicate about transactions, security, and policy changes; send permitted business marketing; analyze and improve our website, products, models, and services; measure and optimize advertising on public marketing pages; prevent fraud and misuse; enforce agreements; protect rights and safety; comply with law; and establish or defend legal claims.

When applicable law requires consent, we request it separately. Acceptance of general Terms is not consent when a specific, informed, or opt-in choice is required.

4. How We Disclose Information

Customers and authorized users. Information may be available to the Customer controlling the relevant account and to users the Customer authorizes.

Service providers and subcontractors. We disclose information as needed to providers supporting hosting, storage, AI processing, authentication, security, monitoring, communications, support, payments, invoicing, analytics, advertising, and professional services. They are subject to appropriate contractual, confidentiality, and data-protection obligations. We require a BAA when a provider processes PHI on our behalf and HIPAA requires one.

Advertising and analytics platforms. On public marketing pages, we use Google, Meta, and LinkedIn technologies. These platforms may receive online identifiers, IP address, browser and device information, page URLs, referral or campaign data, and public-site activity for analytics, measurement, attribution, audience matching, campaign optimization, and advertising. Depending on the service and law, these platforms may act as independent or joint controllers under their own terms. Their practices are described in the Google, Meta, and LinkedIn privacy notices linked in Section 5.

Other disclosures. We may disclose information to professional advisers; when required by law, legal process, or a regulator; to investigate unlawful activity or protect rights, property, security, or safety; in connection with financing, investment, merger, acquisition, reorganization, bankruptcy, or sale of assets; and at the direction of the relevant individual or Customer.

5. Public Website Cookies and Advertising

Technologies used. Public marketing pages may use essential cookies and similar technologies, Google Analytics or Google Ads technologies, Meta Pixel or other Meta Business Tools, and the LinkedIn Insight Tag. We use these technologies to operate and secure the website, remember preferences, understand usage, measure advertising, attribute conversions, build business-to-business audiences, limit frequency, and show relevant ads.

Separation from clinical areas. We do not deploy advertising pixels or targeted-advertising technologies within authenticated clinical workflow areas. We do not knowingly send PHI, clinical case data, patient lists, laboratory information, diagnoses, or treatment information to Google, Meta, LinkedIn, or another advertising platform for advertising, audience creation, or profiling.

Consent and opt-out controls. Where required, nonessential technologies are activated only after consent. Visitors can change applicable choices through the "Your Privacy Choices" control in the website footer or through browser settings. Where required by law, we honor a recognized Global Privacy Control signal as an opt-out request for the browser or device sending it. We do not respond to ordinary "Do Not Track" signals because no uniform standard applies.

Sale, sharing, and targeted advertising. We do not sell personal information for money. Disclosing online identifiers and public-site activity to advertising platforms may be considered a "sale," "sharing," or targeted advertising under some state laws. Individuals may exercise applicable opt-out rights through the controls described above. We do not knowingly sell or share personal information of individuals under 18 for targeted advertising.

Platform information: How Google uses information from partner sites; Meta Privacy Policy; and LinkedIn Privacy Policy.

6. Health Information, AI, and De-identified Data

Health information. Reveris supports healthcare organizations that may be subject to HIPAA. Customers subject to HIPAA may contact Reveris to execute a Business Associate Agreement (BAA) for their use of the Service. Where a BAA applies, its terms govern our handling of PHI. Information not subject to HIPAA may still be protected by consumer-health and other privacy laws. Where those laws apply, we process health-related information under the Customer agreement and applicable notice, consent, and rights requirements.

AI processing. Reveris uses one or more contracted AI model and infrastructure providers to process inputs and generate outputs. We permit a subcontractor to create, receive, maintain, or transmit PHI only when appropriate contractual protections, including a subcontractor BAA where required, are in place. Reveris does not authorize third-party AI providers to use PHI to train their general-purpose models. Customer Data may be used to provide, maintain, secure, and improve the Service, including to address reported errors, as permitted by the Terms, Customer agreements, BAAs, and law.

De-identified and aggregated information. Subject to applicable law and applicable agreements, Reveris may create de-identified or aggregated information from information processed through the Service and may use, disclose, license, or otherwise commercialize that information for lawful purposes, including analytics, research, benchmarking, product development, security, and service improvement. Where information originates from PHI, de-identification occurs only as authorized by the applicable BAA and using a method permitted by HIPAA. We maintain legally de-identified information in de-identified form and do not attempt to re-identify it except as permitted by law for validation, security, or compliance purposes.

7. Retention and Security

Retention. We retain personal information only as long as reasonably necessary for the purposes described in this Policy, considering the information's nature and sensitivity, Customer instructions, contracts, BAAs, security needs, legal limitation periods, and regulatory obligations. Following termination, Customer Data is deleted except for encrypted backups purged under our backup-retention schedule and information retained as required by law or an applicable BAA. When retention is no longer necessary, we delete, de-identify, or securely dispose of the information, subject to legal and technical limitations.

Security. Reveris uses administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit and at rest, least-privilege access controls, audit logging, security monitoring, and incident-response procedures. No system is completely secure, and we cannot guarantee that unauthorized access, loss, misuse, or disclosure will never occur.

Incidents. If we become aware of a security incident affecting personal information, we investigate and provide notices required by law, an applicable BAA, and the HIPAA Breach Notification Rule where it applies. Where we process information for a Customer, we notify that Customer as required by the applicable agreement so it can meet its obligations.

8. Privacy Rights and Choices

Depending on residence, applicable law, and any legal threshold or exemption, individuals may have rights to confirm processing; access, correct, delete, or obtain a portable copy of personal information; withdraw consent; obtain information about recipients; opt out of sale, sharing, targeted advertising, or certain profiling; limit certain uses of sensitive personal information; appeal a denied request; and receive equal service without unlawful discrimination for exercising a privacy right.

Requests may be submitted to info@reverisglobal.com with the subject "Privacy Request." An appeal may be submitted to the same address with the subject "Privacy Appeal." We may verify identity and authority before acting. Authorized agents may submit requests where permitted, subject to proof of authority. If we process the relevant information only for a Customer, we may direct the requester to that Customer.

Recipients may unsubscribe from promotional emails using the link in the message or by contacting us. We may continue to send non-promotional account, transaction, support, security, and legal communications.

The public website and authenticated platform are intended for businesses and healthcare professionals and are not directed to children under 13. We do not knowingly collect personal information directly from children under 13 through the public website. Customers may submit information concerning minors only when legally authorized and permitted by the applicable agreement and BAA.

9. International Processing, Updates, and Contact

Personal information may be processed in the United States and other countries where Reveris or its providers operate. Where required, we rely on recognized safeguards such as Standard Contractual Clauses, the UK International Data Transfer Addendum, adequacy decisions, consent, or another lawful mechanism. Individuals may also have rights under applicable international law and may complain to their local supervisory authority.

We may update this Policy to reflect changes in the Service, our practices, or law. We will publish the updated version and revise the "Last updated" date. If required, we will provide additional notice or obtain consent before applying a materially different practice to previously collected information.

Reveris Inc.
2113 Union St, San Francisco, CA 94103
Email: info@reverisglobal.com

If a request concerns information submitted by a Customer, identify the relevant clinic or provider without sending medical records or other sensitive information through ordinary email.

Reveris Inc
info@reverisglobal.com 2113 Union St, San Francisco, CA 94103 © 2026 Reveris Inc. All rights reserved.
How it works Pricing FAQ Terms Privacy Your Privacy Choices LinkedIn Provider Portal