Privacy Policy
Last updated: July 8, 2026
1. Who We Are
TheraJunction ("TheraJunction," "we," "us," or "our") provides an AI clinical partner platform for speech-language pathologists and clinical practices. This Privacy Policy explains how we collect, use, disclose, and protect information in connection with our website and Service.
2. This Policy and HIPAA
This Privacy Policy describes our general privacy practices. Because TheraJunction may create, receive, maintain, or transmit protected health information ("PHI") on behalf of our clinician and practice customers, we act as a Business Associate under HIPAA. Our handling of PHI is governed primarily by our Business Associate Agreement with each customer and by applicable law, and is summarized in our HIPAA Notice. Where this Policy and our HIPAA obligations differ with respect to PHI, the more stringent HIPAA/BAA requirements control.
3. Information We Collect
We collect the following categories of information:
- Account information: name, email address, practice name, and role details you provide when you sign up or request a demo.
- Billing information: payment and subscription details processed through our payment providers.
- Usage and technical data: device, browser, access logs, and interaction data that help us operate and secure the Service.
- Customer Data, including PHI: clinical notes, schedules, messages, telehealth records, and other content you and your authorized users submit to the Service on behalf of your patients.
4. How We Use Information
We use information to:
- provide, maintain, and improve the Service;
- process transactions and manage subscriptions;
- provide customer support and respond to inquiries;
- monitor, secure, and troubleshoot the Service;
- comply with legal obligations; and
- communicate with you about updates and the Service.
5. Permitted Uses and Disclosures of PHI
We use and disclose PHI only as permitted or required by HIPAA and our Business Associate Agreement—typically to perform functions on behalf of our covered-entity customers for treatment, payment, and healthcare operations. We do not market PHI, and we do not sell PHI. Any other use or disclosure of PHI requires patient authorization or is otherwise permitted by law.
6. Cookies & Similar Technologies
Our website uses cookies and similar technologies to operate the Service, remember preferences, and understand how the site is used. You can control cookies through your browser settings; disabling them may affect some functionality.
7. Analytics
We may use analytics tools to understand usage and improve the Service. Where these tools process personal information, we configure them to limit collection where possible and require appropriate safeguards. We do not permit analytics providers to use PHI for their own purposes.
8. Information Sharing & Recipients
We share information only as described in this Policy, as necessary to provide the Service, or as required by law. Recipients may include:
- Service providers and subprocessors: hosting, infrastructure, and support vendors that act on our behalf, subject to appropriate agreements—including Business Associate Agreements where they may access PHI.
- Your organization: Customer Data is made available to the authorized users within your practice.
- Legal authorities: where required by law, court order, or to protect rights and safety.
We do not sell personal information to third parties.
9. International Data Transfers
The Service and its providers may process data in the United States and other countries. Where information is transferred across borders, we rely on appropriate safeguards consistent with applicable law.
10. Data Security
We use technical, administrative, and physical safeguards designed to protect information, including encryption in transit and at rest, access controls, audit logging, and workforce training. No method of transmission or storage is completely secure, but we work to protect your information using reasonable industry practices.
11. Data Retention
We retain Customer Data for as long as your account is active and as needed to provide the Service, and afterward for a limited period to permit export, comply with legal obligations, resolve disputes, and enforce agreements, after which it is deleted or de-identified.
12. Your Privacy Rights
Our direct customers can manage much of their account information through the Service and may request access to, correction of, or deletion of certain personal data by contacting us. If you are a patient: TheraJunction does not provide healthcare directly; requests about your PHI, including access, amendment, or an accounting of disclosures, should be directed to your healthcare provider (the covered entity), which is responsible for your record and your HIPAA rights. We will cooperate with covered-entity customers to help them fulfill such requests.
13. Children's Privacy
The Service is intended for use by clinicians and practices. We do not knowingly collect personal information from children except as Patient Data submitted by authorized clinicians in the course of care. If you believe a child's information has been submitted in error, please contact us.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will indicate the "Last updated" date above and provide notice of material changes through the Service or by other reasonable means.
15. Contact
For privacy questions or requests, contact us at contact@therajunction.com. See also our HIPAA Notice and Terms of Service.