Draft
DRAFT PENDING LEGAL REVIEW -- DO NOT CONSIDER BINDING.
Privacy Policy
Last updated: 2026-06-09 | PURA Health
Data We Collect
- Clinic owner and staff account information (name, email, role)
- Patient names, phone numbers, and contact information entered by clinic staff
- Daily patient check-in data (pain, sleep, energy, stress, functional scores)
- Wearable data synced via patient consent through Junction Health
- AI-generated briefings, message drafts, and approval workflow records
- Clinic practice profile and intake interview responses
- Uploaded documents (care plan templates, philosophy docs, patient letters)
How We Use Data
- Generate daily morning briefings for clinic staff
- Draft personalized outreach messages for DC review and approval
- Compute patient recovery signals (PURA Index)
- Enable RAG-based AI context retrieval from clinic documents
- Provide aggregate analytics to the founder (no PHI, clinic-level summaries only)
Data Isolation
Each clinic's data is isolated via row-level security at the database layer. No clinic can access another clinic's data. PURA staff access is limited to aggregate metrics only. Individual patient records are never accessible to PURA employees.
AI Processing
When generating briefings and message drafts, PURA sends de-identified patient data to Anthropic (Claude Haiku) and Groq (Llama). Patient names, phone numbers, and contact details are never included in AI prompts. Real names are re-inserted server-side after AI processing is complete. OpenAI's embedding API receives anonymized clinic document text for RAG retrieval purposes only.
Subprocessors
- Supabase — database hosting (US-East-2)
- Vercel — application hosting
- Anthropic — briefing generation AI
- OpenAI — document embeddings
- Groq — message draft generation
- Twilio — SMS delivery to patients
- Junction Health — wearable data integration
Patient Rights
Patients may request access to, correction of, or deletion of their data by contacting their clinic directly. Clinics are responsible for honoring patient data requests in compliance with applicable law. PURA will assist clinics in fulfilling data subject requests upon written request.
Contact
Privacy inquiries: privacy@purahealth.app