1. Summary
Ojasya Health, Inc. ("Ojasya", "we") provides an online platform that connects members with licensed clinicians and dispenses medications prescribed by those clinicians. To do that, we collect health information from you, share relevant information with your treating clinician and pharmacy, and protect what we hold under HIPAA and state health-privacy laws.
We do not sell your personal information. We do not share your protected health information (PHI) with advertisers. We use commercial partners only where required to deliver the service you asked for.
2. Information we collect
We collect information you provide directly, information created by your use of the service, and limited information from partners when it is necessary to deliver care.
Provided by you
- Identifying information (name, date of birth, address, phone, email)
- Health history, symptoms, and goals provided in the intake
- Government identification for clinician verification
- Payment information (processed by our PCI-compliant processor)
Generated by use
- Clinical notes authored by your treating clinician
- Messages you exchange with your clinician
- Device and session metadata required to keep the service secure
3. How we use it
We use information for the purposes for which you provided it: to deliver care, manage your account, fulfill prescriptions, and improve the service under appropriate safeguards. We do not use PHI for advertising or marketing beyond the communications you explicitly subscribe to.
4. HIPAA and PHI
The treating clinicians you are matched with through Ojasya are HIPAA-covered entities. Ojasya operates as a business associate to those clinicians and has signed a Business Associate Agreement with each. Your PHI is protected accordingly.
5. Sharing and disclosure
We share information only where necessary:
- With your treating clinician
- With the pharmacy fulfilling your prescription
- With our laboratory partner when you order a panel
- With service providers under confidentiality agreements
- Where legally required — in response to lawful process, subpoena, or a regulator
6. Cookies and tracking
We use a minimal set of essential cookies to keep you signed in and the service secure. Analytics cookies are opt-in and are never connected to PHI. You can manage preferences in your account settings.
7. Your rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict the use of your information. To exercise any of these rights, contact us at privacy@ojasya.health. We'll verify your identity before acting on the request.
8. Data retention
We retain medical records for the period required by the applicable state medical board (typically 7 years from last treatment, 10 years for minors). Account metadata is retained while your account is active plus a limited reconciliation window.
9. Children's privacy
Ojasya does not provide services to individuals under 18. We do not knowingly collect information from minors. If you believe a minor has provided us information, contact us and we will delete it.
10. International users
Ojasya operates in the United States. Our services are not directed to users outside the US and may not be available where you are.
11. Changes
We will notify you by email of any material change to this policy at least 30 days before it takes effect.
12. Contact
Privacy questions: privacy@ojasya.health
Data Protection Officer: Meena Raghavan, MD
Postal: Ojasya Health, Inc., 2600 El Camino Real, Suite 410, Palo Alto, CA 94306