Privacy Policy
The short version
- We never sell your information. We never use or share your health information for advertising. The text line and its web pages use no ad pixels, ad trackers, or analytics.
- Caspia is an AI, not a doctor. It does not diagnose and never tells you to stop or change a medication.
- Your conversation is deleted automatically after 30 days. Photos and PDFs you send are deleted right after we read them, and we don't keep copies of photos or medical records you share unless you ask us to. Our service providers keep their own copies for limited periods, described under "How long we keep it".
- Connecting MyChart or Apple Health is always your choice. Text
DISCONNECTto remove connected records. - Text
DELETEto erase everything tied to your number. TextSTOPto stop texts. - Texts and photos are not encrypted on the way to us. Ask for a private upload link if you would rather not text a photo.
Who we are
Caspia is a health AI text line operated by Pro-Patient Tech, Inc., "we" or "us". You can reach us at privacy@propatienttech.com or by mail at 114 Upper State St, North Haven, CT 06473.
Caspia is offered directly to you. It is not run for your doctor, clinic, hospital, or health plan, even if you found the number on a poster or prescription pad in a clinician's office. This policy, not your doctor's privacy notice, covers what we do with your information.
How Caspia works
Your phone number is your identity. There is no account to create and nothing to install. When Caspia sends you a link, it opens in your phone's web browser.
You text a health or lifestyle question and an AI model (Claude, made by Anthropic) writes the reply. You are talking to software, not a person. AI answers can be incomplete or wrong, so check anything important with your clinician. Medication questions always end with "Bring this to your doctor." In an emergency call 911. In a mental health crisis call or text 988.
What we collect
| Information | When and how |
|---|---|
| Your phone number and your confirmation that you are 18 or older | When you first text Caspia |
| Your consent choices, with the date and time you made them | When you continue the chat after the first reply (which confirms you are 18 or older), when you agree to sending a photo, and when you text STOP. Your START, DISCONNECT, and DELETE texts are kept, with their date and time, as part of your messages. |
| What you text us and what Caspia texts back, which may include health goals, symptoms, conditions, and medications | Whenever you text |
| Results you choose to send: a photo, screenshot, or PDF (for example a lab report or medication list) | Only if you send one, by text or through a private one-time upload link |
| Records from MyChart: medications, conditions, lab results, allergies, and vital signs | Only if you connect MyChart through a link we text you and approve it on MyChart's own page |
| Apple Health readings: daily steps, sleep, resting heart rate, and workouts | Only if you add our Apple Shortcut, which sends them from your phone to Caspia over a secure (HTTPS) connection, or by text |
| Usage and cost records: how many AI "tokens" each reply used | Automatically. These do not contain what you or Caspia said. |
| A short topic label for each question (for example "sleep" or "cholesterol") | Automatically, to improve answers. Stored with no phone number or other detail that identifies you. |
| Website: what you type into the clinician order form or contact form on propatienttech.com | Only if you submit one of those forms |
We never ask for your MyChart password or any other password by text. If a message asks you for one, it is not from us.
How we use it
- To answer your questions and tailor answers to the goals, conditions, medications, results, and activity you share or connect.
- To run the line: sending replies, confirming you are 18 or older, honoring
STOP,START,HELP,DISCONNECT, andDELETE, and keeping a record of your consent. - To improve answers, using only the topic labels described above.
- To track our costs, using only token counts.
- To fill clinician orders and answer requests sent through propatienttech.com.
What we never do
- Sell your information, or share it for advertising.
- Use your health information to advertise to you or anyone else.
- Use ad pixels or ad trackers, or let any analytics or advertising tool receive your messages or health information.
- Share your phone number or your consent to receive texts with anyone for their marketing.
- Let Anthropic train its AI models on your messages.
Who we share it with
Only these service providers, and only so they can run Caspia for us:
| Provider | What it does | What it receives |
|---|---|---|
| Twilio | Carries texts and photos between your phone and us | Your phone number and the texts and photos you exchange with Caspia |
| Anthropic | Its AI model, Claude, writes Caspia's replies | Message content and any health details needed to answer, under commercial terms that do not allow Anthropic to train on our data |
| Amazon Web Services | Hosts the Caspia service and its web pages | Information passing through the service |
| Supabase | Stores our database, encrypted at rest | The information we keep, as described below |
| Epic and your health system | Run MyChart. Only if you choose to connect it. | Your approval request. You sign in on MyChart's own page, and MyChart sends us the records you approve. |
Apple is not one of our service providers. If you add our Apple Shortcut, it reads readings from the Health app on your own phone and sends them to us over a secure (HTTPS) connection, or by text, when they are needed to answer you, or once a day if you ask Caspia to keep them handy. Apple's own privacy policy covers the Health app.
On the website only, the propatienttech.com contact form is handled by HubSpot, and clinician order details are stored in our Supabase database.
We share your information with anyone else only with your express consent, or when the law requires it (for example a valid court order).
How long we keep it
| Information | How long |
|---|---|
| Your phone number and the consent dates above | Until you text DELETE |
| Conversation messages | 30 days, then deleted automatically |
| Photo, screenshot, and PDF originals | Read once, then deleted from our systems and from Twilio right after reading (a photo you send before agreeing to photos is deleted unread). We never store the file in our own database. |
| Results we read from what you send (for example a lab name, value, unit, and date) | Not stored unless you ask. We read them only to answer you. If you ask Caspia to keep them handy, they are kept until you text DISCONNECT or DELETE. What Caspia says about them in a reply is part of your conversation messages, above. |
| MyChart records | Not stored unless you ask. We read them from MyChart when needed to answer you. If you ask Caspia to keep them handy, they are kept until you text DISCONNECT or DELETE. Otherwise we keep only the connection itself, until you text DISCONNECT or DELETE. |
| Apple Health readings your Shortcut sends (steps, sleep, resting heart rate, workouts) | Not stored unless you ask. We read them only to answer you. If you ask Caspia to keep them handy, they are kept until you text DISCONNECT or DELETE. |
| One-time upload and connect links | Expire 30 minutes after we send them |
| Topic labels (no phone number or identifying detail) | Kept to improve answers |
| Usage and cost records (token counts, no message content) | Kept for our records |
Opt-out record (your number and the date you texted STOP) | Kept so we keep honoring your opt-out, even after DELETE |
| Under-18 record (your number and the fact you said you are under 18, nothing else) | Kept so the line stays closed to you, even after DELETE |
| Twilio's message records (texts sent and received, with phone numbers) | Kept by Twilio under its own data retention policy. When you text DELETE we also ask Twilio to delete your message records. |
| What Anthropic receives to write a reply | Kept by Anthropic only for the limited period set in its commercial terms, never used to train its models |
Deleted data can remain in our database provider's routine encrypted backups for a limited time, until those backups are overwritten.
Security
Our database is encrypted at rest, and our upload and connect pages use HTTPS. Regular texts and MMS photos are not encrypted while they travel over phone carrier networks, so others could see them in transit. That is how texting works. Before your first photo, Caspia warns you and offers a private upload link (HTTPS) instead.
Your choices and rights
- Stop texts: text
STOP. TextSTARTto come back. - Remove connected records: text
DISCONNECT. This removes your MyChart and Apple Health connections and everything we read from them or from results you sent. Your recent chat stays until it expires. - Erase everything: text
DELETE. This erases everything tied to your number: messages, results, and connections. If you text again, you start fresh. - Ask what we have, get a copy, correct something, or withdraw consent: email privacy@propatienttech.com from any address and include the phone number you use with Caspia. That is how we find your information.
We answer emailed requests within 45 days, and tell you if we need up to 45 more. If we decline a request, you can appeal by replying to our decision. If we deny your appeal, you can contact your state attorney general. We do not treat you differently for using any of these rights. We honor them for everyone, wherever you live.
Consumer health data (Washington and other states)
This section is our consumer health data privacy policy under Washington's My Health My Data Act and similar laws in other states, such as Nevada and Connecticut.
- What we collect: health goals, symptoms, conditions, medications, lab and other results, allergies, vital signs, and activity readings (steps, sleep, resting heart rate, workouts), plus anything you tell Caspia about your health.
- Where it comes from: you (your texts and the results you send), MyChart if you connect it, and your own Apple Shortcut if you add it.
- Why: only to provide the answers you ask for and to run the line, as described in "How we use it."
- Who receives it: only the service providers listed in "Who we share it with" (Twilio, Anthropic, Amazon Web Services, Supabase, and Epic and your health system if you connect MyChart), so they can run Caspia for us. Anyone else only with your express consent or when the law requires it.
- Selling: we do not sell consumer health data.
- Location: we do not track your device's location and do not use geofencing.
- Your rights: to confirm whether we have your consumer health data, see it and the list of everyone it was shared with, have it deleted, and withdraw your consent. Use the steps in "Your choices and rights" above.
If something goes wrong
We follow the Federal Trade Commission's Health Breach Notification Rule. If your health information is accessed or shared without your permission, we will tell you by text or email without unreasonable delay and no later than 60 calendar days after we discover it. We will also notify the FTC, and the media where the rule requires.
Adults only
Caspia is only for adults 18 and older. Caspia's first reply says so, and continuing the chat confirms you are 18 or older. If you tell us you are under 18, the chat ends and we delete it. If we learn someone under 18 is using Caspia, we delete their information.
HIPAA
Caspia is a consumer service offered directly to you, not on behalf of a doctor, hospital, or health plan. The federal health privacy law HIPAA generally does not apply to it. The commitments in this policy, the FTC's rules, and state health data laws do.
Not medical care
Caspia shares general health and lifestyle information. It is not a doctor, does not diagnose, and never tells anyone to stop or change a medication. We do not promise any health result. Always talk with your clinician before changing your care.
Changes to this policy
We will update the "Last updated" date when this policy changes. We will not use or share health information you already gave us in a materially different way without asking you first.
Contact
Pro-Patient Tech, Inc., 114 Upper State St, North Haven, CT 06473. Privacy questions and requests: privacy@propatienttech.com. Text line terms: propatienttech.com/sms-terms.