Privacy Policy
How Tend handles personal information and protected health information, and our role as a Business Associate under HIPAA.
Last updated July 1, 2026
Overview
This Privacy Policy explains how Tend Health, Inc. ("Tend", "we") handles information. It covers two very different kinds of data, and treats them differently: the personal information of visitors and account holders on our website, and the protected health information (PHI) of patients that we process on behalf of our healthcare customers.
For patient PHI, our customer is the covered entity and Tend acts as a Business Associate. Our handling of that PHI is governed first by our Business Associate Agreement with the customer and by HIPAA, and second by this policy.
Protected health information (PHI) and our role as a Business Associate
When a healthcare customer uses Tend to make follow-up calls, we receive and create PHI, such as a patient's name, contact number, procedure, and what they say on a call. We use that information only to provide the service: to make the call, to check on recovery, to write a summary, and to flag concerns to the care team.
We do not sell PHI. We do not use PHI to build profiles or for advertising. We use it only for the permitted purposes set out in the Business Associate Agreement, and we apply the minimum-necessary principle.
Under our Business Associate Agreement, we commit to:
- Use and disclose PHI only as permitted by the agreement and by law.
- Safeguard PHI with administrative, physical, and technical controls, including encryption in transit and at rest.
- Report any breach of unsecured PHI to the customer without unreasonable delay.
- Make PHI available for the customer to fulfill patient access and amendment rights.
- Return or delete PHI at the end of the engagement, where feasible.
Information we collect on our website
When you visit tendcareai.com, create an account, or contact us, we collect information you provide and a limited set of technical data:
- Account information: your name, work email, and password (stored only as a secure hash).
- Messages you send us through forms, such as a demo request or a support ticket.
- Basic usage and device information needed to run the site securely.
The sample patients in the free workspace are illustrative and contain no real patient data.
How we use website information
We use the information you give us to create and secure your account, to respond to you, to run the free workspace, and to improve the product. We do not sell your personal information.
Security
We protect information with encryption, least-privilege access, audit logging, and isolation by customer. No system is perfectly secure, but security is a first-class part of how we build. You can read more on our Security page.
Data retention and deletion
We keep account information for as long as your account is active, and we delete it on request. Retention of patient PHI is set in the Business Associate Agreement with each customer, and we return or delete it at the end of the engagement where feasible.
Your choices and rights
You can access, correct, or delete your account information by writing to us. Patients whose PHI we process on behalf of a provider should contact that provider to exercise their access, amendment, and other rights, and we support the provider in fulfilling them.
Contact us
Questions about this policy, or about how we handle PHI, can go to privacy@tendcareai.com. For security and Business Associate Agreement matters, write to security@tendcareai.com.