Legal
Privacy policy
The short version: we collect little, we don't track you, we never sell data, and patient information is handled only under a business associate agreement.
Effective September 28, 2026
Who we are and what this covers
This policy explains how Owed ("Owed", "we", "us") handles personal information on our website, owed.health, when you ask to become a design partner, and when you use the Owed application at app.owed.health.
It does not cover protected health information (PHI) in the remittances our customers send us. We receive PHI as a business associate of the healthcare providers we serve, and we handle it only under a signed business associate agreement and the HIPAA rules. If you are a patient, the provider you saw controls your information; please contact them directly.
What we collect
When you ask to become a design partner
Your work email, name, practice or company, the kind of organization you work for and, if you choose, how many clinicians it has. The form has no free-text field, and we ask you not to send patient information through it.
When you use the Owed application
Your name, email, role, sign-in and security records (such as sign-in times and multi-factor authentication settings), and a record of what you do in the application for the audit trail HIPAA requires.
Automatically
Like any website, our servers record technical information about each request: IP address, browser type, the page requested and the time. We use it to keep the service running and secure, and keep it for up to about thirteen months.
Cookies and tracking
The website sets no cookies and runs no analytics, advertising or third-party scripts. The application uses one strictly necessary cookie to keep you signed in. We don't track you across other sites, and we don't respond differently to Do Not Track or Global Privacy Control signals because there is nothing to turn off.
How we use it
- To reply to your request and talk with you about Owed.
- To provide, secure and support the application, including detecting and preventing abuse.
- To meet legal obligations and enforce our agreements.
We don't sell personal information, share it for targeted advertising, or use customer data to train AI models.
Who we share it with
Only the service providers that help us run Owed, bound by contract to use the information only for us: Amazon Web Services (hosting and email delivery) and our business email provider (for messages you send to an @owed.health address). We may also disclose information when the law requires it, or to a successor if Owed is acquired, subject to this policy.
How long we keep it
- Design-partner requests: until you ask us to delete them, or two years after we last spoke, whichever comes first.
- Application accounts: while the account exists; audit records for at least six years, as HIPAA requires.
- Server request logs: up to about thirteen months.
How we protect it
Encryption in transit and at rest, mandatory multi-factor authentication, least-privilege access and a tamper-evident audit log. The details are on our security page.
Your choices and rights
You can ask us to show you, correct or delete the personal information we hold about you, or to stop contacting you, by writing to privacy@owed.health. Depending on where you live, you may have additional rights under state privacy laws; we honor these requests for everyone, and we won't treat you differently for making one. We may need to confirm your identity first.
Children
Owed is a business service and isn't directed to children. We don't knowingly collect personal information from anyone under 16.
Where data is stored
The Owed application and our customers' data are stored in the United States. Our services are intended for US businesses.
Changes
If we change this policy, we'll post the new version here with a new effective date, and tell customers directly about material changes before they take effect.
Contact
Questions or requests: privacy@owed.health.