‹ AnneavaPrivacy Policy
Last updated: July 14, 2026
1. Who we are
Anneava, Inc. operates a coordination platform for individualized-therapy programs. This policy explains what we collect from visitors and account holders and how we handle it. Where health information is involved, Section 4 (HIPAA) controls.
2. What we collect
Account data: your name, work email, password (stored only as a bcrypt hash), organization name, and role. Program data your organization enters:de-identified program codes, indications, party names (labs, CDMOs, sponsors), workflow status, custody events, uploaded documents, and payment records. Operational data: audit-trail entries (who accessed or changed what, when), notification records, and coarse rate-limiting counters (e.g. login attempt counts keyed by email or IP). We do not run third-party advertising or analytics trackers.
3. How we use it
To provide the Service: enforcing per-organization data isolation, maintaining the audit trail HIPAA requires, sending workflow notifications your team has a role in, processing reimbursements through our payment facilitator, and securing the platform (rate limiting, abuse prevention). We do not sell personal information, and we do not use your organization's data to train models or for any purpose other than operating the Service.
4. Health information (HIPAA)
When an organization's use involves protected health information, Anneava acts as a Business Associate under a Business Associate Agreement with that organization (the Covered Entity or upstream Business Associate). PHI is used and disclosed only as the BAA and HIPAA permit: to provide the Service, as required by law, and as directed by your organization. The platform is designed to minimize PHI (programs are tracked by de-identified codes), and every access and disclosure is written to an audit trail your organization can export. Individuals seeking access to or amendment of their health records should contact the treating clinic or program sponsor, who controls those records; we support their compliance on request.
5. Service providers (subprocessors)
We use a small set of infrastructure providers, each bound by contract (and where PHI is involved, a BAA): Vercel (application hosting), Supabase (database hosting), Stripe (payment facilitation; Stripe receives payment details directly and we never see card numbers), and Resend (transactional email, when enabled by your organization). We will update this list here before adding a provider that handles customer data.
6. Security
Tenant isolation is enforced in the database itself with row-level security; access is role-based; every read and write of program records is audited; passwords are hashed with bcrypt; reset and share tokens are stored only as SHA-256 hashes; traffic is TLS-encrypted; and authentication endpoints are rate-limited. No system is perfectly secure. If we learn of a breach affecting your data we will notify your organization without undue delay and as the BAA and applicable law require.
7. Retention
Account and program data are retained while your organization has an account and for 60 days after termination for export. Audit-trail and chain-of-custody records are retained at least six years, as HIPAA requires. Rate-limiting counters are transient and expire with their windows.
8. Your choices and rights
Organization owners can export all org data from the Reports page, correct records in the app, and delete their organization by contacting us. Depending on your location you may have additional rights (access, deletion, portability); contact us and we will honor what applicable law provides. We do not respond to Do Not Track signals because we do not track visitors across other sites.
9. Cookies
We use only the cookies the Service needs to function: a session cookie for sign-in and a cookie remembering your active organization. No advertising or cross-site cookies.
10. Changes and contact
Changes will be posted here with an updated date; material changes will be notified to organization owners. Contact:
privacy@anneava.com.
See also our Terms of Service.