Privacy Policy
Effective date: June 12, 2026
This Privacy Policy describes how BlueMint IQ, Inc. (“CareIQ,” “we,” “us”) collects, uses, discloses, and protects information in connection with our websites, applications, and care-management platform (the “Services”).
1. Information We Collect
Information you provide
- Patients: account and profile details (name, date of birth, contact information), device readings, symptom and wellness check-ins, messages to your care team, and other health information you submit through the patient applications. This information is generally PHI processed on behalf of your provider.
- Healthcare professionals: name, role, work contact details, credentials, and the content you create in the platform (notes, care plans, messages).
- Website visitors: information you submit when you contact us, request a demo, or sign up for communications.
Information collected automatically
- Device and usage data such as IP address, browser type, pages viewed, and interactions with the Services, collected via logs and similar technologies, used for security, troubleshooting, and improving the Services.
- Connected-device data (for example, blood-pressure or glucose readings) transmitted to the platform as part of a monitoring program in which you are enrolled.
2. How We Use Information
- To provide, operate, secure, and support the Services, including delivering readings, messages, reminders, and educational content between patients and their care teams;
- To support program operations for healthcare organizations, including documentation, care coordination, and billing workflows;
- To power AI-assisted features that summarize, draft, and surface information for review — always grounded in the relevant clinic's data and subject to the safeguards described in our Terms of Service;
- To communicate with you about the Services, respond to inquiries, and — with the required consent — send SMS messages as described in our SMS Consent Terms;
- To meet legal, regulatory, audit, and compliance obligations, including maintaining audit logs required for healthcare operations;
- To analyze and improve the Services, using de-identified or aggregated data where feasible. We de-identify PHI only as permitted by HIPAA and our BAAs.
We do not sell personal information, and we do not use PHI for advertising or marketing.
3. How We Share Information
- With your healthcare provider and care team — patient information submitted through the Services is shared with the organization providing your care;
- With service providers (subprocessors) that host, process, or transmit data on our behalf (for example, cloud infrastructure, messaging delivery, email). Subprocessors that handle PHI are bound by BAAs and may use the data only to provide services to us;
- For legal reasons — when required by law, legal process, or to protect the rights, safety, and security of patients, users, or the public;
- In a business transaction — in connection with a merger, acquisition, or sale of assets, subject to obligations at least as protective as those in this Policy and applicable BAAs.
4. SMS and Communications
With your consent, we send care-related text messages on behalf of your healthcare provider. Mobile numbers and SMS opt-in status are used solely to deliver those messages and are never sold or shared with third parties for their own marketing. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. See our SMS Consent Terms for opt-in, opt-out (reply STOP), and help (reply HELP) details.
5. Security
We maintain administrative, physical, and technical safeguards designed to protect personal information and PHI, including:
- Encryption of data in transit and at rest;
- Role-based access controls and least-privilege design;
- Immutable audit logging of state-changing actions;
- Security controls aligned with our SOC 2 attestation, with continuous monitoring and independent examination.
No system is perfectly secure; if we learn of a breach affecting your information, we will notify affected parties and regulators as required by HIPAA and applicable breach-notification laws.
6. Data Retention
We retain personal information for as long as needed to provide the Services and meet legal, regulatory, and contractual obligations. PHI is retained and returned or destroyed in accordance with our BAAs and applicable healthcare record-keeping requirements, which often mandate multi-year retention.
7. Your Rights and Choices
- PHI: to access, amend, or obtain an accounting of disclosures of your health records, contact your healthcare provider — HIPAA routes those rights through the covered entity. We support providers in fulfilling these requests.
- Other personal information: depending on your state of residence, you may have rights to access, correct, delete, or obtain a copy of personal information we hold about you outside the provider relationship. Submit requests to [email protected]; we will verify and respond as required by law and will not discriminate against you for exercising your rights.
- Communications: reply STOP to opt out of SMS; use unsubscribe links in marketing emails. Service and transactional communications essential to your care programs are managed through your provider.
8. Children
Our websites are not directed to children under 13, and we do not knowingly collect personal information from children outside of care programs. Where a minor is enrolled in a care program by their provider, the minor's information is handled as PHI under the provider relationship and applicable law, with consent managed by a parent, guardian, or authorized representative.
9. Changes to This Policy
We may update this Policy from time to time. We will post the revised version with an updated effective date and, for material changes, provide additional notice through the Services or by other reasonable means.
10. Contact Us
For privacy questions or requests, contact us at [email protected].