Effective Date: July 17, 2026
Mitali Health LLC (“Mitali,” “we,” “us,” or “our”) provides AI voice companions for people living with serious health conditions and for the families, caregivers, and organizations that support them — including Mitali Heart, Mitali Memory, and Mitali Glucose, and related services (together, the “Service”). This Privacy Policy explains what information we collect, how we use and protect it, when we disclose it, and the choices and rights available to you.
This Privacy Policy applies to personal information we collect through the Service, our websites, applications, voice experiences, customer support, account tools, and related communications. Depending on how the Service is provided, different privacy laws may apply. For example, when Mitali processes protected health information on behalf of a covered healthcare provider, health plan, healthcare facility, or another business associate under a written agreement, Mitali may act as a business associate or subcontractor under HIPAA. In direct-to-consumer uses, HIPAA may not apply to all information, but we still protect sensitive health and caregiving information as described in this Policy and as required by applicable consumer privacy, health privacy, security, and breach-notification laws.
For purposes of this Policy, “personal information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an individual or household. “Sensitive information” may include health information, condition details, medication and allergy information, dementia-related information, voice transcripts, uploaded photos, caregiving notes, precise location if collected, biometric information if ever used for identification, and other information treated as sensitive under applicable law.
We collect information you provide when you create or use an account, including name, email address, password or authentication credentials managed by our authentication provider, optional phone number, subscription status, billing metadata, communication preferences, and support communications.
You may choose to provide health and caregiving information so the Service can personalize interactions and maintain continuity. This may include date of birth, condition details, care setting, surgery dates, dementia diagnosis information, medications, allergies, symptoms, preferences, routines, family relationships, caregiver notes, and your relationship to the person receiving care. You control how much information you provide, subject to any applicable facility or caregiver workflow.
We collect text conversations and transcripts of voice conversations with the Service. When you use voice features, audio may be streamed to our speech-processing provider to convert speech to text and text to speech in real time. Unless we tell you otherwise in the product, we do not store raw audio recordings after processing, but we may store the text transcript so the Service can remember context, provide continuity, and support safety and account functions. You should not use voice features unless you consent to this processing and have authority or permission for any other person whose voice or information may be captured.
Family members, caregivers, or users may upload photos, stories, memories, and related content to support reminiscence and personalization features. Photos may contain sensitive information about the person depicted, family members, household members, locations, assistive devices, or health context. You should upload information about others only if you have permission or another lawful basis to do so. We strip common location and device metadata (EXIF) from photos on upload where technically feasible. We do not use uploaded photos for advertising or AI model training, and we do not use facial recognition, biometric identification, or voiceprint identification unless we provide a separate notice and obtain any legally required consent.
We collect limited usage and technical information to operate, secure, and improve the Service. This may include feature usage, session events, device and browser information, error logs, authentication events, and security logs. Product analytics are designed to exclude names, conversation content, photos, and health information. Where we describe analytics as de-identified or aggregated, we maintain controls intended to prevent re-identification and do not attempt to re-identify the information.
We do not sell, rent, or trade your personal information. We do not use your conversations, transcripts, photos, or health information for targeted advertising. We do not share personal information with data brokers. We do not use conversations, transcripts, photos, or health information to train AI models unless we first provide a separate notice and obtain any consent required by law.
We use service providers to host, process, secure, and support the Service. These providers may process information only on our behalf and subject to contractual restrictions, including privacy, security, confidentiality, retention, breach-notification, and AI-training restrictions where applicable. Where a provider receives protected health information in a HIPAA context, we require a Business Associate Agreement or other required contractual safeguard.
We may update our service providers over time. We will maintain internal records of providers that process personal information and will provide notice of material changes where required by law, contract, or this Policy.
When Mitali is deployed by or on behalf of a healthcare provider, health plan, memory care community, assisted living facility, or other organization, that organization’s privacy notice, consent process, facility agreement, and any Business Associate Agreement may also apply. In those cases, we process information as instructed by the organization and as permitted by applicable law and contract. If this Policy conflicts with a facility agreement or applicable HIPAA obligation for information processed on behalf of a covered entity or business associate, the facility agreement or applicable legal obligation may control for that information.
If you are using the Service through a facility, healthcare organization, employer, plan, or other sponsor, please review that organization’s privacy notices and contact that organization for requests involving records it controls. You may also contact us, and we will route or support requests as appropriate.
Because the Service is designed for health and caregiving use, we may collect sensitive information only as needed for disclosed purposes, with your consent where required by law, or as otherwise permitted by applicable law. You may withdraw consent or request deletion through account settings or by contacting us, subject to legal, security, facility, contractual, backup, and record-retention exceptions. If you provide information about another person, you represent that you have authority, permission, or another lawful basis to provide that information.
Where a family member, caregiver, legal representative, or facility sets up or manages the Service for a person living with dementia, cognitive impairment, serious illness, or another condition, we may require a consent or authority process. The person receiving care should participate in the consent process where they are able. If a surrogate, caregiver, or representative provides consent, that person must confirm that they have authority to do so. We may log consent, authority, revocation, and account-management events. If authority is disputed, changed, or revoked, we may suspend access, request additional verification, or follow the instructions of the facility or legally authorized representative as appropriate.
We use administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit, encryption at rest, access controls, authentication, audit logging, session controls, vendor security review, incident response procedures, and role-based access. No system can be guaranteed to be completely secure, but we work to protect sensitive information consistent with applicable law, contractual obligations, and the nature of the information.
We retain personal information for as long as reasonably necessary to provide the Service, maintain continuity of memory, operate accounts, comply with law, meet contractual and facility obligations, resolve disputes, enforce agreements, maintain security, and support legitimate business purposes described in this Policy. Retention periods may vary by data category, product configuration, facility agreement, and legal context.
When you delete your account or request deletion, we will delete or de-identify personal information from active production systems within a reasonable period, subject to exceptions for backups, legal holds, security logs, fraud prevention, dispute resolution, facility records, business associate obligations, and other legal or contractual requirements. Backup copies are deleted or overwritten according to our backup lifecycle. De-identified or aggregated information may be retained if it cannot reasonably be linked back to you and we maintain controls against re-identification.
Depending on where you live and how you use the Service, you may have rights to access, confirm, correct, delete, obtain a copy of, or port personal information; opt out of certain processing such as sale, sharing, targeted advertising, or profiling where applicable; limit or withdraw consent for sensitive information where applicable; and appeal a decision regarding a privacy request. We do not sell personal information or share it for targeted advertising as those terms are commonly used in state privacy laws.
You may exercise available rights through account settings or by contacting us at privacy@mitalihealth.com. We may verify your identity before fulfilling a request and may request information necessary to confirm your authority if you are acting as a caregiver, surrogate, authorized agent, facility representative, or legal representative. We will respond within the period required by applicable law. If we deny a request, you may appeal by replying to our decision or contacting us with “Privacy Appeal” in the subject line.
You may opt out of SMS reminders by replying STOP. You may unsubscribe from marketing emails by using the unsubscribe link in those emails. Transactional, account, safety, security, and legal notices may still be sent where permitted by law.
If we discover a security incident or breach involving personal information, health information, protected health information, or unsecured personal health record information, we will investigate and provide notices to affected individuals, covered entities, business partners, regulators, the media, or others as required by applicable law and contract. Depending on the context, this may include obligations under HIPAA breach notification rules, the FTC Health Breach Notification Rule, state breach notification laws, or facility agreements.
The Service is intended for adults and is not directed to children under 18. We do not knowingly collect personal information directly from children. If a caregiver uploads a photo, story, or other content involving a minor, the caregiver is responsible for having permission or another lawful basis to provide that information. If you believe a child has provided information directly to us or that information about a minor should be removed, contact us at privacy@mitalihealth.com.
The Service is currently intended for use in the United States unless we state otherwise. If you access the Service from outside the United States, your information may be processed in the United States or other locations where we or our service providers operate. We will use safeguards required by applicable law for international transfers where required.
We may update this Privacy Policy from time to time. We will post the updated Policy and revise the effective date. If we make material changes to how we collect, use, disclose, or otherwise process sensitive information, we will provide notice and obtain consent where required by law before the changes take effect.
Questions, requests, or appeals may be sent to privacy@mitalihealth.com or by calling 1-833-400-3596.