Health Exam Privacy Policy
Effective Date: August 5, 2026
This Privacy Policy explains how Health Exam Inc. ("Health Exam," "Company," "we," "our," or "us") collects, uses, discloses, and safeguards information when you use the Health Exam websites, mobile applications, APIs, and services, including Aya AI, our AI health assistant and clinical decision support assistant (collectively, the "Services").
We do not sell your questions or conversations. We do not train AI models on Protected Health Information. We secure processed data using safeguards consistent with HIPAA where HIPAA applies.
1. Introduction and Scope
This Privacy Policy applies to all websites, applications, APIs, and services operated by Health Exam Inc., including https://www.healthexam.com and https://www.healthexam.ai.
It applies to:
- Consumer Services — the public Aya AI assistant and general health education tools
- Professional Services — features intended for licensed healthcare professionals and authorized trainees
- Enterprise customers — subject to any applicable Business Associate Agreement (BAA), which controls with respect to Protected Health Information
This Policy does not apply to third-party websites, applications, or services that maintain their own privacy policies, or to information practices of your employer, healthcare organization, or identity provider.
By using the Services, you acknowledge the practices described in this Policy. Where consent is required by law, we obtain it separately.
2. What Constitutes Personal Information
"Personal Information" means any information or data that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, to a particular identifiable natural person or household, or that constitutes "personal information," "personal data," or "personally identifiable information" under applicable data protection laws.
An identifiable natural person, or "Data Subject," is one who can be identified, directly or indirectly, by reference to an identifier such as a name, an identification number, location information, an online identifier, or one or more factors specific to their physical, physiological, genetic, mental, economic, cultural, or social identity.
"Protected Health Information" or "PHI" means individually identifiable health information as defined under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations ("HIPAA").
"De-identified information" and "aggregated information" are not Personal Information, and we may use and disclose them for any lawful purpose.
3. Information We Collect
Information You Provide
| Context | Types of Information | Primary Purpose |
|---|---|---|
| Account registration | Name, email address, password or one-time codes, postal or ZIP code, and account preferences | To create and administer your account and authenticate you |
| Professional credentials | Occupation, professional background, specialty, National Provider Identifier (NPI), state license number, board certifications, school name and graduation year | To verify eligibility for Professional Services and tailor clinical content |
| Conversations and prompts | Questions, symptoms, follow-up answers, uploaded text, documents, and files submitted to Aya AI | To generate responses and operate the Services |
| Feedback | Thumbs up or down ratings, written feedback, copied or shared responses, and support requests | To evaluate and improve response quality and to respond to you |
| Communications | Email correspondence, marketing preferences, and communication settings | To respond to inquiries and send communications you have requested |
| Billing information | Where paid Services apply, billing contact and payment details processed by our payment processor | To process payments and maintain records |
| Research participation | Survey responses and any information you choose to provide when participating in voluntary research | To conduct research you have consented to participate in |
We do not require an account to use the public Aya AI assistant.
Information Collected Automatically
| Context | Types of Information | Primary Purpose |
|---|---|---|
| Usage information | Pages and features viewed, queries submitted, session length, interaction patterns, conversation counts, and daily usage limits | To operate, secure, measure, and improve the Services |
| Device and technical information | IP address, general location derived from IP, browser type and version, operating system, device identifiers, language, referring URL, and time zone | For security, fraud prevention, compatibility, and analytics |
| Cookies and similar technologies | Cookie identifiers, local storage values (such as session tokens and conversation counters), and analytics identifiers | To keep you signed in, enforce usage limits, and understand aggregate usage |
| Log and security data | Server logs, error reports, request metadata, and abuse signals | To detect, investigate, and prevent security incidents and misuse |
Information from Third Parties
- Identity providers — if you sign in with Google or Apple, or through our authentication application, we receive your email address, a provider identifier, and authentication tokens. We never receive your password.
- Credential verification providers — we may receive or verify NPI numbers, licensure status, and related professional data.
- Analytics and infrastructure providers — aggregated technical and usage data.
- Enterprise administrators — where your organization provisions access, we may receive your name, role, and organizational identifiers.
Sensitive Information
Health information you voluntarily submit to Aya AI may be considered sensitive Personal Information under some laws. We process it only to provide the Services, to maintain safety and quality, and as otherwise described in this Policy. Please avoid submitting more identifying detail than necessary, and avoid submitting information about other individuals unless you have their authorization.
4. How We Collect Your Personal Information
We collect Personal Information:
- Directly from you — when you register, sign in, submit prompts, provide feedback, contact support, or complete a form or survey;
- Automatically — through cookies, local storage, and server logs as you interact with the Services;
- From third parties — identity providers, credential verification services, analytics providers, and enterprise administrators; and
- From your organization — where your access is provisioned under an enterprise agreement or BAA.
5. How We Use Information
We use information to:
- Provide, operate, personalize, and maintain the Services, including generating Aya AI responses
- Authenticate you, maintain your session, and enforce usage limits
- Verify professional credentials and eligibility for Professional Services
- Evaluate, test, and improve the accuracy, safety, and clinical quality of our AI systems
- Monitor for unsafe, abusive, fraudulent, or prohibited use, including emergency-related safety signals
- Diagnose and fix technical problems and improve performance and reliability
- Communicate with you about the Services, including service updates and security notices
- Send marketing communications where permitted, subject to your opt-out rights
- Conduct research and analytics using de-identified or aggregated data
- Comply with legal, regulatory, professional, and contractual obligations
- Establish, exercise, or defend legal claims
- Evaluate or complete a corporate transaction, such as a merger, financing, or sale of assets
We do not use your conversations to make automated decisions that produce legal or similarly significant effects about you, and we do not use them for credit, insurance, or employment decisions.
6. Protected Health Information and HIPAA
Health Exam is not a covered entity with respect to Consumer Services, and information you submit as a consumer is generally not PHI subject to HIPAA.
Where we process PHI on behalf of a covered entity or another business associate, we do so as a business associate under an executed BAA. In that case, the BAA governs our permitted uses and disclosures of PHI and supersedes any conflicting provision of this Policy.
We do not train or fine-tune AI models on PHI. Where technically feasible, we minimize, mask, or de-identify identifiers before any quality or model-improvement review.
View the Business Associate Agreement
7. AI Processing and Model Improvement
Aya AI responses are generated using large language models operated by us or by trusted AI infrastructure providers acting on our instructions under contractual confidentiality and security obligations.
- Prompts and responses may be transmitted to those providers solely to generate a response and to maintain safety.
- Our AI providers are contractually restricted from using your content to train their own general-purpose models.
- Aya AI conversations may be reviewed by authorized personnel or automated systems to evaluate safety, accuracy, and quality, and to improve our models. Where a BAA applies, that agreement controls.
- Model outputs are probabilistic and may be inaccurate. Outputs are not a medical record and are not medical advice.
You can reduce the information available for review by avoiding identifying details in your prompts.
8. Safety and Abuse Monitoring
We use automated and manual review to detect prohibited or unsafe use, including attempts to bypass usage limits, automated scraping, credential abuse, harmful content, and messages suggesting an imminent medical emergency. Aya AI is not a monitoring or emergency service and cannot summon help; in an emergency you must call your local emergency services.
9. Cookies and Tracking Technologies
We use cookies, browser local storage, and similar technologies for the following purposes:
- Strictly necessary — authentication, session continuity, security, load balancing, and enforcement of daily conversation limits. These cannot be disabled without breaking the Services.
- Functional — remembering preferences such as language and interface settings.
- Analytics — understanding aggregate usage so we can improve the Services.
We do not use cookies to build cross-site advertising profiles of consumer health interests, and we do not sell or share conversation content for cross-context behavioral advertising.
You can control cookies through your browser settings and can clear local storage at any time, which will reset stored preferences and usage counters. Some browsers offer a Global Privacy Control (GPC) signal, which we honor where required by law. We do not currently respond to "Do Not Track" browser signals, as no common standard exists.
10. Sharing Your Information with Third Parties
We do not sell your Personal Information, and we do not share your questions or conversations for advertising purposes. We disclose information only as follows:
- Service providers and processors — cloud hosting, AI model providers, authentication, analytics, email delivery, payment processing, and customer support vendors, each bound by contract to use information only to provide services to us.
- Your organization — where your access is provisioned by an employer or institution, to the extent permitted by the applicable agreement and BAA.
- Professional verification partners — to confirm licensure and credentials.
- Legal and safety disclosures — to comply with law, subpoenas, court orders, or regulatory requests; to enforce our Terms; to protect the rights, property, or safety of Health Exam, our users, or the public; and to investigate fraud or security incidents.
- Corporate transactions — in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to this Policy or a successor policy with comparable protections.
- With your consent or at your direction — including when you choose to share a response.
- De-identified and aggregated information — which may be disclosed for research, benchmarking, publication, and business purposes.
11. Security of Information
We maintain administrative, technical, and physical safeguards designed to protect Personal Information, including:
- Encryption of data in transit using TLS and encryption of data at rest
- Access controls, least-privilege permissions, and authentication requirements for personnel
- Network segmentation, logging, and monitoring for anomalous activity
- Vendor security review and contractual security obligations
- Personnel confidentiality obligations and security training
- Incident response procedures and, where required, breach notification
No method of transmission or storage is completely secure. You are responsible for safeguarding your credentials and for notifying us at privacy@healthexam.ai of any suspected compromise.
12. Data Retention
We retain information only as long as necessary for the purposes described in this Policy, and then delete or de-identify it.
- Consumer Aya AI conversations are not retained as a persistent, user-accessible conversation history. Transient copies may exist briefly in processing and security logs.
- Account and credential information is retained while your account is active and for a limited period afterward for legal, security, and audit purposes.
- Security and audit logs are retained for a limited period appropriate to their purpose.
- Feedback and quality-review records are retained in de-identified or minimized form where practicable.
- PHI is retained and returned or destroyed in accordance with the applicable BAA.
- Information may be retained longer where required by law or to resolve disputes and enforce agreements.
13. Choice and Control
You can:
- Use the public Aya AI assistant without creating an account
- Choose what information to include in your prompts
- Update your account and professional information in account settings
- Opt out of marketing emails using the unsubscribe link or by contacting us
- Clear browser local storage to remove stored preferences and counters
- Sign out of all sessions using the log-out control, and request account deletion
Some communications, such as security, legal, and transactional notices, are necessary to the Services and cannot be opted out of while your account is active.
14. Your Privacy Rights
Depending on where you live, you may have the right to:
- Know or access the Personal Information we hold about you and how we process it
- Correct inaccurate Personal Information
- Delete Personal Information, subject to legal exceptions
- Portability — receive a copy in a portable format
- Opt out of sale, sharing for cross-context behavioral advertising, or certain profiling — we do not engage in these activities
- Limit the use of sensitive Personal Information
- Withdraw consent where processing is based on consent
- Non-discrimination for exercising your rights
- Appeal a denial of a rights request, where applicable law provides an appeal right
To exercise a right, email privacy@healthexam.ai with your request and enough information for us to verify your identity. We will respond within the time required by applicable law and will not discriminate against you for making a request. An authorized agent may submit a request on your behalf with proof of authorization.
If your information is held by us as a business associate on behalf of a healthcare organization, we will direct your request to that organization, which controls the information.
15. Supplemental U.S. State Privacy Notice
Residents of California, Colorado, Connecticut, Virginia, Texas, and other states with comprehensive privacy laws have the rights described in Section 14.
Categories of Personal Information collected — identifiers; internet or network activity; geolocation derived from IP address; professional or employment-related information; education information; commercial information for paid Services; and health-related information you choose to submit.
Sources — you, your device, your organization, identity providers, and verification and analytics vendors.
Business purposes — as described in Section 5.
Categories disclosed for a business purpose — identifiers, internet activity, and professional information, disclosed to the service-provider categories in Section 10.
Sale or sharing — we do not sell Personal Information and do not share it for cross-context behavioral advertising. We honor GPC signals where required.
Sensitive Personal Information — used only for permitted purposes such as providing the Services, ensuring security and integrity, and quality assurance.
Retention — as described in Section 12.
California residents may also request information under California's "Shine the Light" law by contacting privacy@healthexam.ai.
16. Supplemental European and UK Privacy Notice
Controller — Health Exam Inc., contactable at privacy@healthexam.ai.
Legal bases for processing — performance of a contract (providing the Services and administering accounts); consent (marketing, non-essential cookies, research participation, and any processing of health data where required); legitimate interests (security, fraud prevention, service improvement, and analytics, balanced against your rights); and compliance with legal obligations.
Your rights — access, rectification, erasure, restriction, objection, portability, and withdrawal of consent, plus the right to lodge a complaint with your supervisory authority or, in the UK, the Information Commissioner's Office.
Automated decision-making — we do not carry out solely automated decision-making producing legal or similarly significant effects.
International transfers — the Services are operated from the United States, and information will be transferred to and processed in the United States and other countries where we or our providers operate. Where required, we use appropriate transfer mechanisms such as the European Commission's Standard Contractual Clauses together with supplementary technical and organizational measures.
17. Children's Privacy
The Services are intended for individuals eighteen (18) years of age or older, or the age of majority where they reside. We do not knowingly collect Personal Information from children. If we learn that we have collected information from a child, we will delete it. A parent or guardian who believes a child has provided information should contact privacy@healthexam.ai.
18. International Users
If you access the Services from outside the United States, you understand that your information will be processed in the United States, where data protection laws may differ from those in your jurisdiction. Where local law requires additional protections, we apply them.
19. Third-Party Websites and Services
The Services may link to third-party websites, publications, and applications, and may rely on third-party identity providers. This Policy does not cover their practices. Please review the privacy policies of any third party before providing information to it.
20. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the Effective Date above, and the updated version becomes effective when posted. Where changes are material, we will provide additional notice through the Services or by email. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy.
21. Contact Us
Health Exam Inc.
Website: https://www.healthexam.ai
Privacy inquiries: privacy@healthexam.ai
Legal inquiries: legal@healthexam.ai
Related policies: Terms of Use · Business Associate Agreement
By using Health Exam, including Aya AI and any Professional Services, you acknowledge that you have read and understand this Privacy Policy.
