Privacy & security at Averyn
You're trusting us with sensitive information about your family. This page explains — in plain English — how we handle it, who can see it, and what you control.
For the full legal text, see our Privacy Policy and Terms of Use.
About this page: this is a plain-English summary. The Privacy Policy, Terms of Use, and any applicable signed agreement govern if there is a conflict or if more detail is needed.
At a glance
- We do not sell personal information — not to advertisers, data brokers, or anyone else.
- We never contact providers without your authorization.
- Averyn acts at your family's direction — not at the direction of providers, insurers, or payers.
- We use enterprise infrastructure and vendor configurations selected and managed to support HIPAA-aligned safeguards for sensitive health-related information.
- AI-assisted tools use HIPAA-compliant models that don't train on your data.
- All Averyn employees are bound by confidentiality and non-disclosure agreements.
- Material coordination activity and outcomes are documented in Averyn's systems.
- You can add, remove, or revoke access for any family member or caregiver — at any time, from the app.
How access works
Three steps — each one is deliberate, documented, and under your control.
You sign releases or grant access. We don't freeload on the system — every provider relationship starts with a documented authorization that you approve.
We set up official portal access (a separate login tied to your authorization) so nothing depends on sharing your personal password. This is the cleanest, most auditable approach.
If a portal doesn't support delegate access and you explicitly authorize it, we store credentials in an encrypted, per-customer vault — accessible only to your assigned staff, purgeable when the engagement ends.
Proxy email — the authorized people see what arrives
- Where the provider or portal supports it, we set up a separate administrative proxy address for each Supported Person; where a shared system can't, we may use one household address.
- Portal notices and email-based verification codes are routed to your Care Continuity Partner and the authorized recipient for your household. For a minor, that's the Primary Contact (a parent or legal guardian); for an adult, it follows the household's permissions.
- An Averyn administrative email doesn't replace your clinical or emergency contact info with a provider.
The end state: your records consolidated, organized, and portable. Your Care Continuity Partner uses access only to do the authorized administrative work — checking messages, downloading records, confirming appointments — never to modify clinical records or impersonate you.
How we protect data
Three layers: people, process, and technology.
- Confidentiality bound — all employees sign confidentiality and non-disclosure agreements covering client information
- Background checks via third-party screening before any account access
- OIG LEIE exclusion check — screening for healthcare fraud and abuse
- SAM.gov debarment check — federal exclusion screening
- Least-privilege access — staff only access the accounts they're assigned to
- Authorization before action — documented releases before any provider contact
- Audit trail — material coordination activity is documented in Averyn's systems and surfaced to your household according to your visibility settings
- Revoking access — you can pause or revoke at any time; credential vaults are purged on exit
- Escalation rules — clear boundaries between administrative and clinical work
- AWS + Azure hosting — managed, enterprise-grade cloud infrastructure; all health-related data stored in US data centers
- Encryption — data in transit and sensitive data at rest
- Enterprise password management — per-customer vaults, generated passwords, staff-only access
- Disk encryption on all company-owned workstations; minimal-rights posture
- No self-hosted servers — zero-trust, fully managed infrastructure
A note on HIPAA
Averyn is not a HIPAA covered entity (we are not a health plan, provider, or clearinghouse), and we are not contracted as a Business Associate. That said, we deliberately build on HIPAA-compliant architectures — every vendor we depend on offers BAAs to covered entities and operates at that standard. We do this because it's the right way to handle sensitive health-related information, regardless of whether the law technically requires it of us.
If something goes wrong
No system guarantees absolute security. If a material security incident affects your information, Averyn will provide notice as required by applicable law and its incident-response obligations.
Communication choices
You choose how we communicate with your household. Nothing is forced.
- App messaging — the primary channel; persistent, shared with the whole household
- Phone and video — your Care Continuity Partner is a call away
- Email and text — when that's what works best for you
- App is optional — we can communicate entirely outside the app if you prefer
- We don't send marketing messages unless you opt in
- SMS consent information is not shared with third parties for their own marketing or promotional purposes
- You can opt out of non-essential SMS at any time (reply STOP, END, CANCEL, UNSUBSCRIBE, or QUIT)
- Operational messages (appointment reminders, coordination updates) are tied to your active service
Payment processing
- All payments are processed through Stripe, a PCI-compliant payment processor
- Your card information goes directly to Stripe — Averyn never sees or stores complete payment card numbers
- We do not handle PCI-regulated data
- Averyn is a private-pay service — we do not submit claims to Medicare, Medicaid, or commercial insurers
- This keeps the service free from payer restrictions and focused entirely on your household's priorities
- The cardholder can be the Primary Contact, the Supported Person, or another family member
AI-assisted tools
We use AI to help your Care Continuity Partner process the volume of documentation that comes with complex care. Here's what that looks like — and what it doesn't.
- Standardizing documentation — converting PDFs and imaging reports from portals into structured, consistent formats
- Identifying changes over time — highlighting what's different in your providers' reports so your Care Continuity Partner can surface what matters
- Plain-language summaries — turning dense medical documentation into readable overviews your family can actually use
- Call note-taking — most navigator calls are recorded (announced at the start) to support accurate notes and quality assurance. Original recordings are not retained long-term; de-identified transcripts may be used to improve internal tools and workflows. Some providers or vendors may request we discontinue recording during their calls, and we comply
- HIPAA-compliant models — we use enterprise AI services (Azure OpenAI) that operate under BAA-grade security
- The enterprise models we use do not train on identifiable household data — our enterprise AI providers do not use our prompts, completions, or uploaded information to train their foundation models. Averyn may separately use lawfully de-identified or aggregated data to improve its own tools and Services, as described in our Privacy Policy.
- Human review — AI outputs are reviewed by your Care Continuity Partner before anything is shared with your family or providers
Our summaries are not clinical interpretation or advice. They're administrative plain-language overviews based on your providers' reports. Your Record Vault always includes the full, original documentation from your providers — the summaries make it usable, not replace it.
We'd rather be transparent about using AI tools than pretend everything is done manually. The Care Continuity Partners do the thinking; the tools help with the processing.
Your controls
What you can do at any time — no waiting period, no hoops.
Control who's in your household account
The Primary Contact decides who has access. You can invite family members, caregivers, or anyone else who needs to be in the loop — and suspend or remove them at any time from the app. This is vastly more controlled than sharing portal passwords, managing a group text, or hoping everyone checks a shared Google Calendar.
Choose your communication channels
Tell us how you want to communicate — app, phone, email, text, video — and we'll use that. The app is optional. You can change preferences anytime.
Decide whether we store portal credentials
If delegate/proxy access isn't available for a particular portal, we'll ask your explicit permission before storing credentials. You can decline — we'll use permitted alternatives where reasonably available, though access-dependent work may narrow if none exists. If you authorize it, credentials are encrypted in a dedicated vault, and purged when you say so or the engagement ends.
Can I revoke access or end Services?
You may pause or revoke Averyn's portal, proxy, or credential authority at any time — you remain the decision-maker. Ending paid Services, the effective cancellation date, and any remaining fee obligations are governed by your signed agreement or selected plan. Revoking access may limit access-dependent work and does not by itself cancel billing or waive a commitment. If Services end, Averyn removes reusable credentials from active storage and handles retained records according to the Privacy Policy.
What happens to my Record Vault if I cancel?
Your Record Vault remains accessible for up to 36 months after cancellation of service or the conclusion of your Record Vault engagement — long enough to allow for vault refreshes or the reactivation of a Continuity Plan without starting over.
At any point during that window, you can request a full digital download of your Record Vault as an organized ZIP file with supporting index documents. You can also request that we remove your records at any time.
If you return to services after your records have been removed, a new Record Vault project may be required.
Some contractual, authorization, billing, audit, backup, security, fraud-prevention, or legal-hold records may be retained beyond 36 months, by category and for the periods described in our Privacy Policy. Once information has been lawfully de-identified, Averyn may be unable to isolate an individual contribution to remove it.
Request deletion of your information
You can request deletion of eligible information at any time. We'll comply to the extent required by law, subject to exceptions including legal compliance, billing or documentation needs, fraud prevention, legitimate business interests, and information that has already been de-identified.
To the extent data qualifies as de-identified under applicable law, it is generally excluded from personal-information rights under that law and may no longer be reasonably locatable or removable in response to an individual request; it may be used for analytics, operational modeling, internal tool improvement, and other purposes described in our Privacy Policy.
To request deletion, contact l e g a l [d o t] n o t i c e [ a t ] a v e r y n c a r e [d o t] c o m.
Questions?
If anything on this page is unclear, ask. We'd rather answer directly than leave you guessing.