Privacy Policy

Effective October 6, 2026

This policy explains how Refine OS, Inc. (“Refine OS,” “we”) handles information through our website (refineos.app) and our clinical software platform. How the policy applies depends on your relationship with us, so it is organized by who you are.

1. Patients of clinics that use Refine OS

If your clinic uses Refine OS, your clinic controls your health information. We process it on the clinic's behalf as a business associate under HIPAA, under a business associate agreement (BAA) with your clinic. Your clinic's Notice of Privacy Practices describes how your health information is used and your rights over it, such as access, amendment and an accounting of disclosures. Please send those requests to your clinic; we help the clinic respond.

We use and disclose health information only as our agreements with the clinic and HIPAA allow:

  • To provide the platform: your chart, labs, treatment plan, patient portal and messages with your care team.
  • To support your care when your clinician directs it, for example sending orders or prescriptions to a pharmacy or laboratory.
  • To run, secure and support the service, including our subcontractors described in section 5.
  • As required by law.

We may create de-identified information under HIPAA's de-identification standard and use it to improve the platform and produce aggregate insights about which care works. De-identified information does not identify you. We do not sell health information and do not use it for advertising.

2. Clinicians and staff who use the platform

We collect account information (name, work email, phone, role, credentials) and security data such as sign-in records, multi-factor and passkey enrollment, and an audit log of actions taken in the platform. We use it to provide accounts, keep the service secure, meet audit requirements and support customers.

3. Website visitors and self-assessments

Our public pages include optional tools, such as our menopause self-assessment and a sign-up form. If you use them, we collect what you enter: your name, email, phone and age, and any health information you choose to share, such as symptoms, history, height and weight. This is consumer health data. We use it to give you your results and to connect you with the participating clinic you asked to hear from. That clinic receives your submission so it can follow up with you. We do not sell it or use it for targeted advertising, and we share it only as described here, or with your consent.

Cookies: we use only cookies and browser storage that the site needs to work: signing in, security, and remembering your light or dark theme. We do not use advertising or third-party analytics cookies.

4. How we protect information

  • Encryption in transit (TLS) and at rest, including databases and backups.
  • Role-based access, multi-factor authentication and passkeys for clinicians, and automatic sign-out after inactivity.
  • Audit logging of access and changes to patient records.
  • Encrypted backups kept in two geographic regions, with tested restore procedures.
  • Business associate agreements with every vendor that handles health information on our behalf.

No system is perfectly secure. If a breach of unsecured health information occurs, we notify affected clinics as HIPAA and our agreements require, so that notice can reach patients.

5. Service providers

We use a small number of vendors to run the platform. Each handles data only to provide its service to us:

  • Amazon Web Services: hosting, database, storage, backups and transactional email (under a BAA).
  • Anthropic: AI features that help clinicians, such as reading lab reports and drafting summaries for clinician review (under a BAA, with no use of your data to train models).
  • E-prescribing and pharmacy networks (for example Surescripts), pharmacies and laboratories, when a clinician uses these features for your care.
  • Integrations your clinic or you turn on, such as a wearable device account you choose to connect. Data from those services is governed by their own terms as well.

6. Retention

Clinical records are kept for as long as our agreement with your clinic and medical-records law require. When a clinic removes a patient, records go on a retention hold rather than being deleted immediately. Records of our HIPAA compliance are kept for at least six years. Website submissions are kept for as long as needed to respond to you, and you can ask us to delete them at any time.

7. Your choices and rights

  • Patients: make access, correction and other HIPAA requests through your clinic.
  • Website visitors: you can ask to access, correct or delete information you submitted to us, or withdraw consent. Depending on where you live (for example Washington, Nevada, Connecticut or California), you may have additional rights over consumer health data. We will not discriminate against you for using them.

Email support@refineos.app with your request. We will verify it and respond within the time the law requires.

8. Children

Our website and self-assessments are intended for adults. We do not knowingly collect information from children under 13 through the website.

9. Changes

We will post any changes here and update the effective date. If changes are material, we will give additional notice where appropriate.

10. Contact

Refine OS, Inc., Chicago, Illinois · support@refineos.app · (618) 298-8574. See also Contact and About.