Please review the below carefully and completely.
EMOTILINK PRIVACY POLICY
Effective Date: September 13, 2026
Last Updated: September 13, 2026
Version: 2.2 (supersedes the May 13, 2024 website version and retires it upon publication)
This Privacy Policy describes how emotilink, LLC (“emotilink,” “we,” “our,” or “us“) collects, uses, stores, shares, and protects information about you when you use our mobile application, website at www.emotilink.com, provider portal, and related services (collectively, the “Platform“).
By registering as a User of the Platform, you consent to the collection, use, and storage of your information as described in this Privacy Policy. If you do not agree with this Policy, please do not use the Platform.
This Policy is the single canonical privacy disclosure for the Platform. Any shorter summary that may appear on our website at www.emotilink.com/privacy-policy is provided for convenience only and is not legally binding; this Policy controls.
QUICK NOTICE
- You must be at least 18 years old to use the Platform.
- emotilink is not for emergencies. If you or someone you know is in crisis, call or text 988 (Suicide and Crisis Lifeline) or dial 9-1-1.
- We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising.
- Real-time session content is encrypted in transit and is not recorded, transcribed, stored, or analyzed by emotilink.
- California, Washington, Colorado, Connecticut, Virginia, Utah, Texas, and Tennessee residents: see Section 11 for your state-specific privacy rights.
- Health-related information is treated as Protected Health Information (“PHI“) under HIPAA where applicable; see Section 9.
1. WHO THIS POLICY APPLIES TO
This Policy applies to:
- Users (clients) who download the Platform, create an account, browse providers, schedule appointments, or conduct sessions.
- Visitors to our website.
- Providers to the extent of the data emotilink collects about them as Platform participants (separate provisions of the Provider Terms of Service govern Provider obligations).
You must be an adult (at least 18 years of age) to use the Platform. We do not knowingly collect personal information from anyone under 18, including children under 13 (or under 16 in California). If you believe we may have inadvertently collected information from a person under 18, contact us at info@emotilink.com and we will promptly delete it.
2. WHAT INFORMATION WE COLLECT
We are designed to collect the minimum information necessary to deliver a secure tele-therapy experience. You can browse providers and download the App without sharing personal information. To schedule an appointment, you must create an account and provide the following:
2.1 Account Information
- Login credentials: username (which is the email address you designate) and password
- Display name: the name you choose to share with providers (which may be a pseudonym if you wish to engage providers anonymously)
2.2 Contact Information
- First and last name
- Mobile phone number (used for security verification and to respond to your inquiries)
- State of residence (used to identify providers licensed in your state)
- Email address (used as your username for login and for the communications described in our Email Policy)
2.3 Payment Information
- Name, billing address, and credit card details (collected and processed by Finix Payments, Inc. through Finix’s secure SDK; see Section 5)
2.4 Emergency Information
- Full name, home address, emergency contact name, and emergency contact telephone number (collected at account creation; disclosed only in emergency situations as described in Section 8)
2.5 Session, Scheduling, and Transaction History
- Records of appointments (date, time, duration, provider, and status)
- Records of payments processed through the Platform
- Records of cancellations and rescheduling activity
2.6 Legal Notices and Authorizations
- Records of your acceptance of Terms of Service, Privacy Policy, Acceptable Use Policy, Email Policy, Session Minimum and Cancellation Policy
- Records of your receipt of each provider’s HIPAA Notice of Privacy Practices and Consent to Treat (attached to appointment confirmation emails)
2.7 Optional User Preferences
- Starred (favorited) providers
- Notification preferences
- Anonymous provider ratings (if you submit any)
- Profile photo (if you choose to upload one)
2.8 Communications
- Records of your emails, the platform-generated transactional and logistical messages we send you (e.g., appointment confirmations, receipts), and your phone or mail communications with emotilink. The Platform does not support direct messaging between Users and Providers, and emotilink does not store any user-to-provider message content because none exists.
2.9 Server Log Files
- Date, time, originating IP address, and a record of the activities performed on the Platform each time you sign in and use your account
- Used for security, performance monitoring, debugging, and improving the Platform
- Stored in encrypted, technical format on our secure servers
- Retained for 13 months; de-identified server logs retained indefinitely
2.10 Location Information
- Your mobile device’s GPS location, which the Platform requests permission to access at account creation
- Accessed only when a provider activates the Platform’s emergency-reporting feature, and only for the purpose described in Section 8
- Not accessed, stored, or transmitted at any other time
2.11 Real-Time Session Content
- Video and audio of your sessions are transmitted over encrypted connections using industry-standard transport encryption
- emotilink does not record, transcribe, store, or analyze the content of your sessions, and does not sell or share session content with third parties. Session content is not used to train any model.
- Transmission metadata necessary to route the connection may be processed by our communications vendor; see Section 5
The categories listed above are the only information we collect about you over the Platform.
3. HOW WE USE YOUR INFORMATION
We use the information we collect to:
- Operate, maintain, and improve the Platform
- Create, authenticate, and secure your account
- Process your appointment requests and payments
- Send you appointment confirmations, reminders, and other transactional emails as authorized in our Email Policy
- Share limited information with providers as described in Section 4
- Respond to your inquiries, complaints, and customer-service requests
- Detect, investigate, and prevent fraud, abuse, security threats, and violations of our Acceptable Use Policy
- Comply with legal obligations, including those imposed by HIPAA and state law on our role as a business associate of your provider
- Generate de-identified, aggregate analytics to understand Platform usage and improve service quality
We do not use your information to:
- Train, fine-tune, validate, or improve artificial intelligence or machine learning systems on identifiable PHI (the Platform may use AI in development and operational contexts that do not touch PHI; see Section 9)
- Market third-party products or services to you
- Sell or share your information for advertising purposes
- Make automated decisions about you that produce legal or similarly significant effects
4. WHAT WE SHARE WITH YOUR PROVIDERS
emotilink shares only the following information with the providers you engage:
- Your display name
- Your state of residence
- Your optional profile photo (if uploaded)
Providers do not automatically have access to your first or last name, login credentials, email address, mobile telephone number, residential or billing addresses, payment instructions, or other preferences. What additional information you share with your provider during your sessions is entirely your choice.
Emergency exception. If a provider activates the Platform’s emergency-reporting feature (Section 8), emotilink will share additional information with the provider necessary to facilitate emergency response.
5. THIRD-PARTY SERVICE PROVIDERS
We use service providers to operate the Platform. We share information with them only as necessary to deliver their services, and they are bound by contractual obligations to safeguard the information.
5.1 Microsoft (Azure)
What: Cloud hosting and infrastructure for the Platform.
Information shared: All information we store, in encrypted form at rest and in transit.
HIPAA posture: Microsoft is a business associate of emotilink. Microsoft has executed a HIPAA Business Associate Agreement with emotilink through the Microsoft Product Terms and Data Protection Addendum, which apply automatically to emotilink’s Azure subscription. The HIPAA-eligible Azure services on which emotilink relies are covered.
5.2 Finix Payments, Inc.
What: Payment processing for session charges.
Information shared: Name, billing address, credit card details, transaction amount, and transaction status. Card details are tokenized and stored by Finix in PCI DSS-compliant format; emotilink does not store card numbers.
HIPAA posture: Finix processes payment-card information rather than Protected Health Information. emotilink takes the position that Finix qualifies for the HIPAA Financial Institution Exception in its role as a payment processor; written confirmation of this posture is in progress with Finix. This Policy will be updated once that confirmation is received.
5.3 Twilio, Inc.
What: Real-time video and audio communication (WebRTC) for tele-therapy sessions.
Information shared: Real-time session content (the audio and video stream) is transmitted through Twilio’s real-time communications infrastructure over encrypted connections (SRTP with DTLS-SRTP key negotiation). To route the stream between participants, Twilio’s media server may transiently decrypt and re-encrypt the stream in memory in the course of forwarding it. Twilio has no functionality enabled on emotilink’s account to record, store, transcribe, or analyze the audio or video stream of your session, and emotilink does not record, store, transcribe, or analyze it. Twilio retains limited operational metadata about the connection (such as room identifier, participant identifiers, and timestamps) consistent with standard telecommunications operation; this metadata is not session content.
HIPAA posture: emotilink is transitioning its Twilio configuration to a peer-to-peer architecture in which real-time session content is transmitted directly between User and provider without traversing Twilio’s media servers. Under that architecture, Twilio operates under the HIPAA Conduit Exception (45 C.F.R. § 160.103) with respect to session content. This Policy will be updated to describe the operative configuration when the transition is complete.
5.4 Apple, Inc. (iOS App Store)
What: App distribution, push notification delivery (if you opt in), in-app purchase processing (if applicable).
Information shared: As governed by Apple’s standard terms.
HIPAA posture: Apple’s terms apply.
5.5 Analytics
We use Google Analytics 4 on our marketing website (www.emotilink.com) to understand visitor behavior in the aggregate. Google Analytics does not have access to information about authenticated Users or session content. See our Cookies & SDK Disclosure for additional detail and for any third-party services in use on the mobile application.
We do not use:
- Advertising trackers or behavioral-advertising SDKs
- Session-replay tools
- Cross-app or cross-site tracking
- Data broker enrichment
6. HOW WE STORE AND SECURE YOUR INFORMATION
Where we store. Your information is stored on encrypted servers maintained by Microsoft Azure. Access to the information is restricted to emotilink personnel who require it to perform their duties and who have signed the appropriate HIPAA and confidentiality undertakings.
Encryption. Information is encrypted both in transit (TLS) and at rest. Real-time session content is encrypted in transit (SRTP with AES-256, DTLS-SRTP key negotiation, HMAC integrity verification); emotilink does not record, store, transcribe, or analyze session content.
Payment information is collected via Finix’s secure SDK embedded in the application and transmitted directly to Finix for tokenized storage. emotilink does not retain card numbers or full payment instructions on our systems.
Even with these measures, no method of electronic transmission or storage is 100% secure. You share and transmit information electronically at your own risk. If you have reason to believe your account has been compromised, contact us immediately at info@emotilink.com.
7. HOW LONG WE KEEP YOUR INFORMATION
We retain information for the following periods:
| Information Category | Retention Period |
|---|---|
| Account credentials and contact information | Active account + 10 years from last provider interaction, if any appointment was scheduled |
| Scheduling and session history (date, time, duration, provider, status) | 10 years from last interaction |
| Payment records | 7 years (for tax recordkeeping and dispute resolution) |
| Server logs (with personal identifiers) | 13 months |
| De-identified server logs | Retained indefinitely |
| Email and other communications with emotilink | 10 years |
| Emergency information | Retained only as part of emergency-response records; governed by HIPAA and applicable state law |
| Records of legal notice acceptance | 10 years |
| De-identified information (data scrubbed to HIPAA standards) | Retained indefinitely; may be used for any purpose |
The 10-year retention from last provider interaction reflects the obligations emotilink assumes under its Business Associate Agreements with providers, which require emotilink to retain certain records to support provider compliance with state mental-health record-retention requirements (typically 6-10 years post-treatment).
After the applicable retention period, your information is securely deleted or de-identified.
8. WHAT WE SHARE IN AN EMERGENCY
Providers have legal and ethical obligations to report when a User poses an imminent danger to themselves or others. To support those obligations, you grant emotilink access to your mobile device’s location services upon account creation.
emotilink does not access, collect, or use your location information unless and until a provider activates the Platform’s emergency-reporting feature.
When a provider activates emergency reporting, emotilink generates an email to the provider containing:
- Your full name
- Home address
- Phone number
- Emergency contact name and telephone number
- Last GPS location recorded by your mobile device
The provider may then use this information to coordinate appropriate emergency response, including by contacting 9-1-1 dispatch or your emergency contact.
9. HIPAA AND HEALTH INFORMATION
Mental and behavioral health information about you is Protected Health Information (“PHI”) under HIPAA when it identifies you (or could reasonably be used to identify you) and relates to your physical or mental health, the provision of health care to you, or payment for that health care.
Your providers are HIPAA-covered entities. Each provider must furnish you with a HIPAA Notice of Privacy Practices (“NPP”) describing how that provider uses and discloses your PHI. emotilink distributes each provider’s NPP to you with your appointment-confirmation email. Your provider’s NPP — not this Privacy Policy — governs your provider’s use of your PHI.
emotilink is a HIPAA business associate of your provider, meaning emotilink processes PHI on behalf of your provider and is subject to the safeguards required by HIPAA. The Business Associate Agreement between emotilink and each provider governs emotilink’s permitted uses of PHI; that BAA is made available to providers during onboarding.
What we treat as PHI: Information that identifies you and relates to your engagement with a provider over the Platform. This includes scheduling records, session history, payment records linked to a provider, and emergency information.
Our position on AI: emotilink does not use PHI to train, fine-tune, validate, or improve any artificial intelligence or machine learning system, except where the PHI has first been de-identified to HIPAA’s de-identification standards (45 C.F.R. § 164.514(a)-(c)), or with explicit written authorization from the provider as the covered entity. AI used in the Platform’s development and operational contexts (such as code generation tools used by emotilink’s engineers) does not have access to PHI.
Reproductive Health Care: Consistent with the 2024 HIPAA Reproductive Health Rule (45 C.F.R. § 164.502(a)(5)(iii)), neither emotilink nor your provider will use or disclose your PHI for the purpose of conducting an investigation into or imposing liability for the mere act of seeking, obtaining, providing, or facilitating reproductive health care that was lawful under the circumstances in which it was provided.
10. WHEN WE CAN DISCLOSE YOUR INFORMATION OUTSIDE THE COMPANY
emotilink does not sell, rent, or loan any of your information to third parties. We do not share your information with third parties except:
- As described in this Policy (for example, with providers under Section 4, with service providers under Section 5, in emergencies under Section 8)
- Where you direct and authorize us in writing
- Where required by law or to comply with legal process, including a court order or subpoena
- In a business transition (acquisition, merger, restructuring), in which case the acquiring entity will be bound to protect your information consistent with this Policy and applicable law
Response to legal process. emotilink will respond to legal process directed at us. When the request relates to PHI of a User and where consistent with HIPAA, emotilink will use reasonable efforts to notify the affected User unless prohibited by law. Where the request potentially relates to Reproductive Health Care, emotilink will require the requesting party to provide a written attestation as required by the 2024 HIPAA Reproductive Health Rule before disclosing.
11. STATE-SPECIFIC PRIVACY RIGHTS
11.1 California Residents (CCPA / CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act. These rights, the categories of personal information we collect, sources, purposes, and recipients, and the process for exercising your rights are described in our separate California Privacy Rights Notice, available at www.emotilink.com/california-privacy-rights and incorporated into this Policy by reference.
In brief: California residents have the right to know, delete, correct, opt-out of sale or sharing, limit use of sensitive personal information, and non-discrimination. emotilink does not sell or share personal information as those terms are defined under CCPA/CPRA.
11.2 Washington Residents (My Health My Data Act)
If you are a Washington resident, the Washington My Health My Data Act (“MHMDA”) provides rights with respect to your “consumer health data.” Tele-therapy information about you constitutes consumer health data under MHMDA.
Under MHMDA, you have the right to:
- Know what consumer health data we collect about you
- Withdraw consent to our collection or sharing of your consumer health data
- Request deletion of your consumer health data
- Appeal a denial of your request
emotilink does not sell consumer health data (the sale of consumer health data requires separate written authorization under MHMDA, which emotilink does not seek or obtain). emotilink does not engage in geofencing of healthcare facilities.
To exercise MHMDA rights, contact info@emotilink.com with the subject line “Washington Privacy Request.”
11.3 Colorado, Connecticut, Virginia, Utah, Texas, Tennessee, and other state privacy laws
If you are a resident of Colorado, Connecticut, Virginia, Utah, Texas (Texas Data Privacy and Security Act), Tennessee, or another state with a comprehensive privacy law that affords similar rights, you have the right to:
- Access the personal information we have about you
- Correct inaccurate personal information
- Delete personal information (subject to exceptions for HIPAA-regulated data, legal obligations, fraud prevention, etc.)
- Opt out of the sale of personal information, opt out of “targeted advertising,” and opt out of certain “profiling” (none of which emotilink engages in)
- Appeal a denial of your request
To exercise your rights, contact info@emotilink.com with the subject line “[State] Privacy Request.”
11.4 HIPAA-PHI exception
Personal information that constitutes Protected Health Information under HIPAA is generally exempt from state comprehensive privacy laws — it is governed instead by HIPAA’s separate access, amendment, and accounting-of-disclosures framework. Where your information is PHI in the hands of your provider, your HIPAA rights are described in your provider’s HIPAA Notice of Privacy Practices and may be exercised through your provider.
11.5 How we respond
We will respond to verifiable state-law privacy requests within the timeframes required by the applicable law (typically 45 days, with one 45-day extension if reasonably necessary). To verify your identity, we may require you to confirm two or more pieces of information we already have on file. For requests involving deletion of sensitive information or to know specific pieces of personal information, we may require a signed declaration under penalty of perjury.
12. INTERNATIONAL USERS
emotilink is operated from the United States and is designed for use by individuals in the United States. If you access the Platform from outside the United States, your information will be transferred to and processed in the United States, which has data-protection laws that may differ from those of your country. By using the Platform, you consent to this transfer.
If you are in the European Economic Area, United Kingdom, or another jurisdiction with comprehensive data-protection requirements (GDPR, UK GDPR, PIPEDA, etc.), you may have additional rights with respect to your personal data. emotilink does not currently target services to users outside the United States, but where these rights apply, contact info@emotilink.com.
13. COOKIES AND TRACKING TECHNOLOGIES
Our use of cookies, software development kits (SDKs), pixels, and other tracking technologies is described in our separate Cookies and SDK Disclosure, available at www.emotilink.com/cookies and incorporated into this Policy by reference.
In brief: we use only the tracking technologies necessary to deliver and secure the Platform and to understand basic Platform performance. We do not use behavioral advertising trackers, session-replay tools, data broker SDKs, or marketing-attribution SDKs that share user-level data with third parties.
14. HOW TO TERMINATE YOUR ACCOUNT AND DELETE YOUR INFORMATION
14.1 Automatic termination
Accounts inactive for 12 consecutive months are terminated automatically.
14.2 Termination on request
You can terminate your account at any time by selecting “Terminate Account” in the App and following the prompts.
14.3 Deletion of information
The extent to which we can delete your information depends on whether you used the Platform to schedule appointments:
- Application downloaders who never created an account: No information to delete.
- Account holders who never scheduled an appointment: Full deletion of your account and associated information within a reasonable time after request.
- Account holders who scheduled appointments: emotilink retains certain information (as described in Section 7) for up to 10 years from last interaction with a provider, in accordance with provider record-retention obligations and applicable law. After this period, your information is securely deleted or de-identified.
De-identified information (scrubbed to HIPAA standards) may be retained indefinitely and used by emotilink for any lawful purpose.
To exercise a deletion request, email info@emotilink.com from the email address associated with your account.
15. CONTACT
Questions, complaints, or requests about this Privacy Policy or our information practices:
emotilink, LLC
222 W Merchandise Mart Plaza, Suite 1230
Chicago, IL 60654
info@emotilink.com
312-554-5812
Correspondence by mail should include the notation “Private and Confidential” where appropriate.
emotilink will not respond to emails or voicemails containing detailed clinical or sensitive health information. For matters involving your clinical care, contact your provider directly.
16. CHANGES TO THIS POLICY
emotilink may update this Policy from time to time. Material changes will be communicated through the Platform or by other reasonable means, and the “Effective Date” and “Last Updated” dates at the top will be revised. The current version is always available at www.emotilink.com/privacy-policy.
