Privacy Policy
Effective date: August 18, 2026
Vene Health, Inc. (“Vene,” “we,” “us,” or “our”) builds a health assistant that navigates healthcare for patients over text messages and phone calls. This Privacy Policy explains what we collect, how we use it, and the choices you have. It applies to our conversational assistant, the browser pages we provide for tasks like enrollment and payment, our web dashboard for sponsoring organizations, our website, and our backend services (collectively, the “Service”).
1. Information We Collect
Account information. Your name and phone number. Your account is tied to your phone number; patients do not create passwords. Organization staff who use our dashboard sign in with their work email and password or through their organization’s connected electronic health record login, and we hold names and email addresses for people who have been invited but not yet enrolled.
Conversation data. Audio from voice conversations with Vene is processed in real time and is not recorded or stored. Written transcripts of each conversation are created and retained so future conversations stay in context. If you text with Vene over iMessage, those messages are retained the same way.
Errand and call data. When Vene works an errand for a patient, we create a brief describing the task and the information approved for sharing, and we keep transcripts and outcomes of the calls Vene places to third parties such as pharmacies, provider offices, health plans, billing offices, medical equipment suppliers, and diagnostic centers. Call audio is not recorded. These transcripts can include information about the people Vene speaks with, such as a staff member’s name and what they said. If a third party calls a patient’s dedicated care line, we collect the caller’s number, who they say they are, and their message.
Personal context and memory. Information you choose to share so Vene can be specific to you: family names, routines, preferences, goals, and care context. Vene maintains a long term memory of this context, including summaries of past conversations and facts learned while working errands.
Tracker and care data. Trackers configured by the patient or someone authorized to help with their care, the readings and assessments Vene records against them from conversations, escalation flags, check-ins, reach-out plans, notes, and errand history.
Medical and insurance records. If a patient or their authorized caregiver connects a health plan or healthcare provider portal, Vene uses that authorized portal session to import health and insurance records such as conditions, medications, allergies, immunizations, lab results, visit history, coverage details, member IDs, claims, and explanations of benefits. Records are imported only after the patient or their authorized caregiver signs in and consents. If a healthcare organization sponsors a patient’s care, we may also receive patient chart information, such as demographics, from that organization’s electronic health record system.
Patient, family, caregiver, and organization data. Names, contact details, and roles of family members, caregivers, and other people authorized to help with a patient’s care. If an organization sponsors care, the enrollment information it provides, including names, phone numbers, and email addresses of invited patients and caregivers. When you accept our Terms and this policy during enrollment, we record the acceptance, including the document versions accepted, the time, your IP address, and your browser’s user agent.
Billing information. Subscription status and billing history. Payments are processed by Stripe; we receive a payment reference and never store full card numbers.
Website data. If you request early access, the name, email address, care needs, and how you heard about us that you submit, verified with Google reCAPTCHA. With your choice, Google Analytics and PostHog measure how visitors use the website and move through onboarding. Meta measures selected marketing visits and enrollment milestones, including checkout, trial start, and the first paid subscription invoice. We do not send form answers or health details to website analytics. If you decline cookies, Google Analytics and Meta stay off, and PostHog uses cookieless measurement.
2. How We Use Information
- Conversations. Powering Vene’s conversations with you over text messages and voice, including listening, speaking, and remembering context across conversations.
- Proactive outreach. Planning when Vene should reach out, based on your trackers, your connected records, recent conversations, and your requests.
- Watching your records. Reviewing newly imported health plan and provider records for changes that need attention, such as new results, claims, coverage changes, and care that is due.
- Trackers and escalations. Recording what fits a tracker from your conversations and flagging responses that match the escalation criteria configured in that tracker for the care team’s review.
- Errands. Carrying out the tasks you approve, including calling third parties on your behalf and sharing the information you approved for the task.
- Account and billing. Managing enrollment, subscriptions, and payments through Stripe, and sending invitations and secure task links.
- Quality and safety monitoring. Reviewing AI prompts and responses, including conversational context, through observability tooling so we can debug problems, evaluate quality, and keep the agent safe.
- Service improvement. Improving Vene’s judgment and reliability using aggregated and de-identified data. We do not sell personal data and we do not use your conversations to train third party foundation models.
3. Service Providers
We work with a small set of service providers to operate Vene. Each is bound by data protection terms and processes data only as needed to provide their portion of the Service.
- Photon. Delivery of Vene’s text conversations over iMessage.
- LiveKit. Real time audio infrastructure for voice conversations and for the telephone connection when Vene places or receives phone calls.
- Deepgram. Speech to text for voice conversations with patients.
- Cartesia. Text to speech for voice conversations with patients.
- ElevenLabs. Speech to text and text to speech for the phone calls Vene places to third parties on your behalf.
- Microsoft Azure. Azure AI services provide one of the language model systems that can generate Vene’s responses.
- Railway. Hosting for Vene’s application services and databases.
- Groq. Additional language model infrastructure used for some of Vene’s responses.
- Zep. Hosted long term memory that stores personal context, conversation summaries, and the knowledge Vene builds up about your care.
- Electronic health record systems. If a healthcare organization sponsors your care, we connect to that organization’s EHR system, such as NextGen, to read the chart information needed to support you.
- Twilio. Phone numbers for patient care lines and the telephone network connection that carries Vene’s calls.
- Stripe. Payment processing and subscription billing.
- Resend. Email delivery for account emails, such as enrollment and caregiver invitations, staff invitations, and billing messages.
- PostHog. Observability for our AI systems, which receives prompts and responses, including conversational context, for quality and safety monitoring; and consent-aware website, onboarding, trial, and subscription analytics that excludes form answers and health details.
- Meta. With your choice, Meta Pixel and Conversions API measure selected marketing visits and enrollment milestones, including accepted early-access signups, checkout, trial start, and the first paid subscription invoice. Meta receives its browser and ad-click identifiers, purchase amount and currency, and technical request data, but not your name, email address, form answers, or health details.
- Exa. Web search Vene performs to bring current information into a conversation. Exa receives only the search query, never your account information, and we screen queries to keep personal identifiers out of them, though a query may reflect a topic raised in conversation.
- Google. Analytics to measure how visitors use our website, reCAPTCHA to protect our forms, Sheets to store early access signups, and sign-in for organization staff and our own team.
Separately from service providers, Vene discloses information to third parties at your direction when working errands, and to authorized family members, caregivers, clinicians, and sponsoring organizations, as described in Section 8 and in our Consumer Health Data Privacy Policy.
4. Data Security
We use industry standard practices to keep information safe.
- TLS encryption for data in transit.
- AES 256 encryption for data at rest.
- Access controls that limit personal data to the employees who need it to operate the Service.
- Credentials for connected records are encrypted, invitation and enrollment tokens are stored hashed, and sensitive values are kept out of URLs.
- Redaction of personal identifiers, such as phone numbers, contact details, and credentials, from our operational logs. Conversation content is shared with our quality and safety tooling as described in Section 3.
Vene is HIPAA compliant. Our administrative, physical, and technical safeguards meet the requirements of the HIPAA Security Rule. Vanta is our compliance partner and continuously monitors the controls, policies, documents, and tests behind that program. Review Vene’s current compliance status in our public Trust Center.
When a healthcare organization provides Vene under a written agreement, including a business associate agreement, Vene handles the protected health information covered by that agreement in accordance with HIPAA and the agreement’s terms. Direct consumer use is governed by this Privacy Policy and applicable consumer health privacy laws rather than a business associate agreement with a healthcare organization. We protect that information with the same security safeguards that support our HIPAA program.
If a breach of security affects unsecured, identifiable health information, we will notify affected users, the Federal Trade Commission, and, where required, state regulators and the media, as required by the FTC Health Breach Notification Rule and applicable state law, without unreasonable delay and within the timelines those laws set.
5. Conversation and Call Data
Call audio, whether a voice conversation with a patient or a call Vene places to a third party, is processed in real time and is not recorded or stored. Written transcripts of conversations and calls, including text conversations over iMessage, are stored in our database and with our memory provider so future conversations stay in context. People authorized to see an errand can see its status and call outcomes. You may request deletion of any stored conversation at any time by contacting us at team@venehealth.com. We do not sell conversation data and we do not use it to train third party foundation models.
6. Memory Data
Vene stores personal context such as names, routines, and preferences so each conversation feels familiar, and adds to that memory as it works: summaries of conversations, facts confirmed on calls, and care details it learns along the way. You can ask us to correct or delete specific memories, or to clear memory entirely, at any time by contacting us at team@venehealth.com. Clearing memory does not affect other categories of data unless you also request that.
7. Your Rights
You have the right to:
- Access. Request a copy of your personal data.
- Delete. Request deletion of your personal data and account information at any time. Shared patient records may remain available to other authorized people as described below.
- Correct. Ask us to fix personal data that is inaccurate.
- Withdraw consent. Stop further data collection, disconnect a records connection, or tell Vene to stop contacting you, at any time.
- Portability. Receive your data in a structured, commonly used format.
To exercise any of these rights, contact us at team@venehealth.com. We respond to access and portability requests within forty five days. We will never discriminate against you for exercising your rights, and you may use an authorized agent to submit a request on your behalf.
8. Sharing with Family, Caregivers, and Organizations
Vene lets patients involve family members, caregivers, and clinicians who support them. These authorized people can see the patient information their role allows, which may include conversations with Vene about shared care, tracker readings and escalations, errand status and call outcomes, and connected records.
If an organization sponsors a patient’s access, what it sees depends on its role. Employer sponsors see enrollment information, such as who has been invited and enrolled, and aggregate program statistics; they do not see patient health information. Healthcare organizations that participate in a patient’s care may access the individual care information needed for that care, such as tracker escalations and errand outcomes, through our dashboard or their electronic health record system.
When Vene works an errand a patient has approved, it discloses the information approved for that task to the third parties involved, such as a pharmacy, provider office, health plan, billing office, medical equipment supplier, or diagnostic center. This sharing happens at your direction and within the scope you approve, as described in our Terms of Service.
9. Your California Privacy Rights
If you live in California, the California Consumer Privacy Act gives you specific rights over your personal information. The categories we collect are identifiers such as name and phone number, commercial information such as subscription status, audio and electronic information such as conversation and call transcripts, health information, including medical records, insurance and claims information, and tracker readings, which California treats as sensitive personal information, and inferences such as wellbeing signals drawn from conversations. We collect them from you, authorized family members, caregivers, sponsoring organizations, connected health plans and providers, the third parties Vene speaks with on your behalf, and your use of the Service, for the purposes described in Section 2. We disclose them to the service providers listed in Section 3, to the authorized people and organizations described in Section 8, and to third parties at your direction when working errands.
We do not sell personal information and we do not share it for cross context behavioral advertising, and we have not done either in the preceding twelve months. We use sensitive personal information only to provide the Service, so there is no sale or sharing to opt out of. If that ever changes, we will update this policy, provide a clear opt out, and honor universal opt out signals such as Global Privacy Control.
You may exercise your California rights to know, access, delete, correct, and limit the use of sensitive personal information by contacting us at team@venehealth.com.
10. Consumer Health Data
Some states, including Washington, Nevada, and Connecticut, give consumers specific rights over consumer health data. Those laws work alongside HIPAA and apply based on how the data is collected and used. Vene collects consumer health data such as medical and insurance records a patient connects, health conditions and medications shared in conversation, tracker readings, and wellbeing signals inferred from conversations, and uses it only to provide the Service as described in this policy. We publish a separate Consumer Health Data Privacy Policy describes this data, the sources it comes from, who it is shared with, and how to exercise your rights, including how to appeal a decision we make about a request.
11. AI and Automated Processing
Vene is artificial intelligence, not a human, and will never claim otherwise. Conversations, whether by voice or by text, are generated by language models run through the providers listed in Section 3, and transcripts are analyzed by language models to maintain memory, record tracker readings, flag responses that match configured escalation criteria, plan outreach, and prepare care summaries. Vene also acts autonomously within limits you set: it initiates check-ins on its own schedule, and it places and handles calls to complete errands within the scope the patient approved, asking first before going beyond that scope. Escalation flags go to the care team for human review; Vene does not independently assess clinical urgency or severity, and we do not make decisions with legal or similarly significant effects about you by automated means alone.
If a conversation suggests a risk of suicide or self harm, automated safety screening keeps the agent from engaging harmfully and the agent is designed to encourage you to speak with a real person and share crisis support resources. Our Terms of Service describe this safety protocol in more detail.
12. Users in the EEA and UK
Vene is operated from the United States and your data is processed there. If you use the Service from the European Economic Area or the United Kingdom, we process personal data to perform our contract with you, with your consent for health data and other special categories, and for our legitimate interests in operating and improving the Service. You have the rights to access, rectify, erase, restrict, and port your personal data, to object to processing, to withdraw consent at any time, and to lodge a complaint with your local supervisory authority. To exercise these rights, contact us at team@venehealth.com.
13. Data Retention
We retain personal data only as long as it is useful to provide the Service or as required by law. Conversation transcripts, memory, tracker and errand history, and imported medical and insurance records are kept while the relevant Vene account or patient profile remains open. Disconnecting a records connection stops further syncing; records already imported are retained so your history stays intact until you request their deletion. Canceling a paid subscription does not close your account or start deletion. When you close your account or request deletion, we delete or anonymize your account data and personal identifiers within thirty days, except where retention is required by law or reasonably necessary to resolve disputes, enforce our Terms, or maintain the security of the Service. Shared patient records may remain available to other authorized people after your account is closed; the patient or another authorized person may request deletion of the patient profile and its shared records as described in our Terms of Service.
14. Children’s Privacy
Vene is intended for adults eighteen and older. We do not knowingly collect personal information from children under thirteen. If we learn that we have collected information from a child under thirteen, we will delete it promptly.
15. Changes to This Policy
We may update this Privacy Policy as the Service evolves. We will note material changes by updating the effective date at the top of this page and, where appropriate, by notifying you through the Service. Continued use of the Service after a change constitutes acceptance.
16. Contact Us
If you have any questions about this Privacy Policy or our data practices, contact us at:
Vene Health, Inc.
10702 Lighthouse Peak, Richmond, TX 77406
team@venehealth.com