Privacy Policy
Contents
- Who we are and what this policy covers
- Information we collect on willowbridge.app
- How we use marketing-site information
- Cookies and analytics
- How we share information
- Patients and protected health information (PHI), including the mobile apps, Apple Health and Health Connect data, and deleting your app account
- Security
- Data retention
- Your rights and choices
- Children
- International users
- Changes to this policy
- How to contact us
1. Who we are and what this policy covers
Willowcare LLC ("Willowcare", "we", "us") is the developer and operator of the WillowBridge software-as-a-service platform for Medicare care management. This Privacy Policy describes how we collect, use, and share information when you:
- visit the public marketing website at willowbridge.app, www.willowbridge.app, or related pages we operate;
- contact us to request a demo or otherwise communicate with us;
- use the WillowBridge software platform as an authorized user of a healthcare-provider customer that has signed an agreement with us;
- use the Willowbridge or Willowbridge Care mobile apps, or register as a patient's family member or caregiver through an invite from the Willowbridge app (Sections 6.4–6.6); or
- are a patient whose health information is processed by WillowBridge on behalf of your healthcare provider.
2. Information we collect on willowbridge.app
The marketing website collects only limited information:
2.1 Information you give us directly
If you fill out the "Book a 20-min demo" form, click an email link, or otherwise contact us, you provide whatever information you choose to share — typically your name, work email, practice name, role, and the message body. The current "Book a demo" form opens your email client and sends the message directly to us (drnick@willowbridge.app); no separate database stores this submission unless we reply and thread the conversation.
2.2 Information collected automatically
Our static-site host (Cloudflare Pages) records standard server logs for every page request: IP address, request URL, user-agent string, referrer, and timestamp. Cloudflare uses this information to defend the site against abuse, deliver content from the nearest edge, and produce aggregate traffic statistics. We do not run third-party analytics scripts (Google Analytics, Mixpanel, Segment, etc.) on the marketing site as of the date of this policy.
3. How we use marketing-site information
We use the information described in Section 2 to:
- respond to your inquiry or demo request;
- operate, defend, and improve the marketing website;
- understand aggregate traffic (how many people visit, what pages they read);
- comply with legal obligations and respond to lawful requests; and
- where you have given permission, send you product updates or sales follow-ups.
We do not sell your personal information. We do not share it with third parties for their own marketing purposes.
4. Cookies and analytics
The marketing website does not set any first-party cookies as of the date of this policy. We may add a privacy-respecting analytics tool in the future (for example, Plausible or Fathom) to count visits and identify which content is useful; if we do, we will update this policy and limit it to aggregate, non-personally identifying data.
The WillowBridge application (the authenticated product at app.willowbridge.app or your practice's production host) sets a session cookie that holds an opaque session identifier. That cookie is HTTP-only, Secure, SameSite=Lax, and is used only to keep you signed in. It expires with your session.
5. How we share information
We share marketing-site information only with the following categories of recipients:
- Service providers that help us run the marketing site and respond to inquiries. Today this is Cloudflare, Inc. (CDN and hosting for the public site), and the email provider that delivers your inquiry to us. These providers receive only the information they need to do their job and are bound by contractual confidentiality.
- Law-enforcement or government authorities when we are required to share information by law, subpoena, or court order, or when we believe in good faith that disclosure is necessary to protect rights, safety, or property.
- Successors in interest if Willowcare is acquired, merged, or sells substantially all of its assets; information may transfer to the acquirer subject to this Privacy Policy.
6. Patients and protected health information (PHI)
6.1 What this means for you, the patient
- To request access to your records, ask your provider. Under 45 CFR § 164.524 you have the right to a copy of your records — but you exercise that right with the provider, not with us. Your provider can produce the records using WillowBridge's USCDI v3 FHIR Bundle export, C-CDA, or PDF tools.
- To correct an error, ask your provider. Amendments to your record are made by the provider; WillowBridge applies the changes the provider directs.
- To file a HIPAA complaint, you may contact your provider or the U.S. Department of Health and Human Services, Office for Civil Rights, at hhs.gov/hipaa/filing-a-complaint.
6.2 What WillowBridge does with PHI
For each healthcare-provider customer, Willowcare processes the categories of PHI necessary to provide the WillowBridge platform: demographics, identifiers (MRN, Medicare beneficiary identifier, NPI of treating clinicians), clinical data captured during care management (problems, medications, vital signs, observations, care-plan content, time spent, interactive communications), billing data, and ancillary documents (consents, advance directives, signed billing notes). The full list and the safeguards we apply are described in our HIPAA Security Plan and summarized in Schedule B of our standard Business Associate Agreement.
6.3 Subprocessors that may process PHI
Willowcare engages a small set of subprocessors that may process PHI on our behalf. The current list is published in our standard Business Associate Agreement (Schedule A). Aptible (hosting), Amazon Web Services (storing documents, consent signatures, and reports), and Sentry (error monitoring) process PHI under written BAAs with us. DirectTrust clinical messaging (MaxMD or Updox) and SMS / voice / video services (Twilio, disabled by default) are used for PHI only once a BAA is in place. Our email provider (SendGrid) is not used for patient health information. We give our healthcare-provider customers 30 days' advance notice before adding or replacing a subprocessor that materially handles PHI.
The Willowbridge mobile apps also use Expo (which relays push notifications and delivers app updates) and Apple's and Google's push-notification services. These services are not given your health records; what they receive is described in Section 6.4.
6.4 The Willowbridge mobile apps
Willowcare LLC publishes two mobile apps: Willowbridge, the patient app ("Willowbridge" on Google Play, "Willowbridge Patient" on the Apple App Store), and Willowbridge Care, for practice staff. Both link to this policy, and everything in this Section 6 applies in them. Some patient app features below, such as "Stop sharing" and "Sign out", need app version 1.0.2 or later.
- Signing in. Neither app lets you create an account. Staff use their practice login with two-factor authentication. Patients get a registration link or QR code from their care team, choose a 4-digit PIN, and enter their date of birth, which WillowBridge checks against the practice's record. The PIN is stored only in hashed form.
- What the patient app collects. The app sends what you enter: messages to your care team, call requests, check-ins, family invites, and consents, which are recorded with their wording, the time, your IP address, and device information. If you turn it on, it also sends your continuous glucose monitor (CGM) readings (Section 6.5). WillowBridge receives your IP address and device information whenever the app connects, and your practice's audit log records many of your actions in the app for security and compliance.
- What Willowbridge Care collects. The staff member's login, the patient information they view or record, and their messages to patients or Willowcare support. Signatures patients give on a staff member's screen are stored encrypted at Amazon Web Services, not on the phone. Signed advance directives open in the phone's browser, which may keep a copy.
- On your phone. The apps load health information over encrypted (TLS) connections, tell the phone not to keep a copy, and do not save it to iCloud. Sign-in items and security keys are stored encrypted with the phone's secure keystore and erased when you sign out or remove your access.
- Phone features. With Face ID or a fingerprint set up, both apps open locked and lock again after about a minute in the background. No biometric data leaves the phone. The patient app uses the camera only to scan your registration QR code, and saves or sends no images. Neither app records audio, uploads photos or files, or accesses your location, contacts, or calendar.
- Notifications. WillowBridge sends notifications through Expo, which passes them to Apple or Google (Firebase Cloud Messaging). These services receive a push token, an app installation identifier, and the notification text. The patient app registers your phone for notifications when you sign in, even if notifications are off. Patient notifications never include your name, messages, or readings. Some can show that you are in a care program or recently left a hospital ("Welcome home. Your care team is here for you"). You can turn them off in your phone's settings.
- Updates and crash reports. At each start, the apps ask Expo for updates, sending an installation identifier, version details, and any crash error message. Both apps also send crash reports, app-session details, and performance data from about 5% of app use to Sentry, our error-monitoring subprocessor (Section 6.3). These include a random installation identifier, device model, software versions, and the WillowBridge web addresses the app called. In Willowbridge Care, those addresses can include record identifiers or search terms. Screenshots and the contents of messages, readings, and charts are not included. Sentry works under a Business Associate Agreement and deletes reports within 90 days.
- No advertising or tracking. The apps show no ads, contain no advertising or tracking tools, and do not use your advertising identifier. Besides WillowBridge and its Amazon Web Services storage, they connect only to Expo, Apple, Google, and Sentry, each of which can see your IP address. We give Expo, Apple, and Google only the information described above, and only to deliver notifications and updates. Nothing is sold.
- Family and caregiver invites. The patient app can show a single-use invite QR code, valid for 72 hours or until your access is removed or reset. Whoever scans it sees only your first name, and enters their name, relationship, and email or phone on a WillowBridge web page that records their IP address and browser. These details join your record but give them no access to your health information. To remove someone, ask your care team.
6.5 Health data from Apple Health and Health Connect
If you choose, the Willowbridge patient app reads blood glucose readings from Apple Health (HealthKit) on iPhone or Health Connect on Android, for one purpose: to share your continuous glucose monitor (CGM) readings with your care team at your practice.
- What is read. The app asks your phone for blood glucose only, read-only, and never writes to or changes Apple Health or Health Connect. To find your CGM readings, it reads all blood glucose readings saved there for the period below, from any app.
- Off unless you turn it on. Nothing is read until, on Share my CGM, you agree to your practice's CGM sharing consent (if not already on file), turn sharing on, and allow access when your phone asks. On Android, sharing stays off if you decline. On iPhone, Apple does not tell apps your choice, so your consent and sharing are recorded anyway, and if you declined, the app finds no readings.
- When. The app reads and uploads readings only while you are signed in and it is open and unlocked on your screen: when you open or return to it (at most every 15 minutes), open Share my CGM, or tap "Share now". It never reads in the background. Each upload covers the last 14 days, or 30 days each time you turn sharing on, including readings saved while sharing was off. This is not emergency monitoring: readings are reviewed later, so keep using your CGM's alerts and call 911 in an emergency.
- What is shared. Only readings saved by a CGM app on Willowbridge's supported list (Share my CGM names the ones known to save readings to your phone). Readings from glucose meter apps or other apps are not shared, nor are readings marked as entered by hand or (on Android) as fingerstick samples. For each shared reading, the app sends the value (mg/dL), date and time, its Apple Health or Health Connect record identifier, the identifier of the app that saved it, and, if recorded, whether it was entered by hand (iPhone) or how it was recorded and its sample type (Android).
- Where it goes. Readings travel encrypted (TLS) only to WillowBridge, which rechecks each one and stores none that do not qualify (older app versions send all readings), recording only how many, why, and which apps saved them. Shared readings are stored in the United States in your practice's WillowBridge account as part of your medical record. The app keeps no copy. Readings are never sent to Expo or Sentry or shown in notifications.
- Who sees it and how it is used. You see a 14-day summary in the app. Practice staff whose role covers your care or billing see your readings and trends, and automated checks flag some for review, such as frequent lows. Your clinician can sign a CGM interpretation report (summary statistics and a glucose chart), added to your practice's electronic health record if connected. Your practice may bill your insurance for the review; the bill lists the service, not your readings, though the insurer may ask for the report.
- Willowcare staff. Willowcare personnel can technically access practice records but, by policy, do not view your glucose readings or anything made from them, except with your explicit permission (for example, to check a problem you report), when necessary for security, such as investigating abuse, or to comply with the law.
- What we never do. Willowcare and its service providers never sell Apple Health or Health Connect data, or anything made from it, and never give it to advertising platforms, data brokers, or information resellers. They never use it for advertising or marketing, to decide eligibility for credit, loans, insurance, or employment, to train artificial-intelligence or machine-learning models, for research, or for any purpose unrelated to your care. These limits also apply to de-identified or aggregated data.
- Who receives it. Willowcare transfers your readings, and reports made from them, only to your practice (as you agree when you turn sharing on), including its electronic health record, and to service providers processing them for us under Business Associate Agreements. The only other transfers are when necessary for security or required by law. Your practice uses and discloses your medical record only as HIPAA allows.
-
How to stop. Anytime, without affecting your other
care:
- In the app: on Share my CGM, tap "Stop sharing". Reading stops, your enrollment with your practice ends, your care team is told, and this phone's daily reminder is cancelled. Your consent stays on file, and the phone permission stays on until you turn it off.
- On your phone: turn off Willowbridge's blood glucose access in Health Connect (App permissions) or the iPhone Health app (tap your profile picture, then Apps). The app then cannot read new readings, but your care team is not told and you stay enrolled (the app may still show "Sharing on") until you also tap "Stop sharing" or ask your care team.
- Through your care team: ask them to end your enrollment or withdraw your CGM consent. The app stops at its next check.
- Readings already shared. Stopping, removing access, or deleting the app does not delete uploaded readings. They stay in your medical record, which your practice controls and must generally keep for a period set by law (Section 6.1).
The use and transfer of information that the Willowbridge app receives from Health Connect adhere to Google Play's Health Connect by Android Permissions policy, including its Limited Use requirements. Data from Apple Health is handled under the same limits and Apple's HealthKit requirements.
6.6 Deleting your Willowbridge account and data
Your account in Willowbridge, the patient app published by Willowcare LLC, is your sign-in: your registration link and PIN. In the app, deleting it is called "Remove my access". Deleting it does not delete your medical record, which your practice keeps as its custodian.
- In the app. At the bottom of the Home screen, tap "Remove my access" and confirm. This immediately deletes your PIN, disables every registration link issued to you, and signs you out on every device. It also removes every phone's notification registration, cancels unused family invites and this phone's daily reminder, and tells your care team. Deleting the app alone does not remove your access.
- Without the app. Ask your care team to remove your access, or email privacy@willowbridge.app with the subject "Delete my Willowbridge account", your name, and your practice. We will confirm your identity with your practice, have your sign-in deleted, pass any record request to your practice, and tell you it is done within 30 days.
- Glucose sharing. After you remove access, the app cannot read or send readings, but your CGM consent and enrollment stay on file. If you later sign in again with the phone permission still on, sharing starts again. To prevent that, tap "Stop sharing" first or ask your care team. Removing access also does not turn off the phone permission or remove family members already added (ask your care team).
- What is kept. Your practice keeps your medical record, including your name, date of birth, messages, check-ins, consents, and shared readings (with the app that saved each one), for as long as the law requires. Also kept: the practice's audit log, including IP addresses and device information, for at least 7 years (Section 8), and Sentry crash and diagnostics reports, which do not include your name, for up to 90 days.
- Signing out. "Sign out" on the Home screen erases the sign-in on that phone, cancels its daily reminder, and stops glucose reading there. It does not delete your account. If your sign-in has timed out, or the phone can't reach WillowBridge, the phone stays registered and may still receive notifications until your care team resets your access or you email us.
- Staff accounts. Willowbridge Care accounts are closed by the practice administrator.
7. Security
Willowcare implements administrative, physical, and technical safeguards designed to protect personal information against loss, misuse, and unauthorized access, disclosure, alteration, and destruction. A summary of the safeguards applied to PHI is published as Schedule B of our standard Business Associate Agreement. Highlights include: AES-256 encryption at rest; TLS 1.2 or higher in transit (TLS 1.3 where the device supports it); Argon2id password hashing; mandatory TOTP multi-factor authentication for the workforce; Postgres row-level security and per-tenant data isolation; tamper-evident SHA-256 hash-chained audit logs with Ed25519-signed exports; 35-day Postgres point-in-time recovery; 30-day advance notice for new subprocessors.
No method of transmission or storage is one-hundred-percent secure. If we become aware of a Breach of Unsecured PHI, we will notify the affected healthcare-provider customer without unreasonable delay and in no case later than 30 days after discovery, in accordance with our BAA and 45 CFR §§ 164.400–414.
8. Data retention
We retain personal information for as long as it is needed for the purposes described in this policy and as required by law.
- Marketing inquiries are retained in our email for as long as the inquiry is active and for a reasonable period thereafter (typically 24 months) for follow-up.
- PHI processed under a BAA is retained for as long as the underlying provider–customer relationship is active. On termination of the customer's services agreement, the customer has a 90-day extraction window, after which we return or destroy the PHI and certify destruction. Immutable backups expire on the Aptible 35-day point-in-time recovery schedule. State-specific clinical-record retention requirements (for example, a state-mandated 7-year minimum) can be configured per customer.
- Audit logs are retained for at least 7 years from the date of the event, as required for HIPAA and Medicare audit defense.
- Mobile app data. A patient's PIN, sign-in sessions, and notification registrations are deleted when the patient uses "Remove my access" or the practice resets their access. Crash and diagnostics reports sent to Sentry are deleted within 90 days. What the practice keeps is described in Section 6.6.
9. Your rights and choices
9.1 Marketing data
You may ask us to access, correct, or delete the marketing-site information you have provided to us, or to stop sending you product updates. Email privacy@willowbridge.app and we will respond within 30 days.
9.2 PHI
As explained in Section 6, rights to access, amend, and account for disclosures of your PHI are exercised with your healthcare provider, not directly with Willowcare. Your provider can use the WillowBridge platform to fulfil those requests.
9.3 California, Virginia, and other U.S. state privacy laws
The California Consumer Privacy Act, as amended by the CPRA, and similar state laws give residents of certain states rights with respect to personal information that is not regulated by HIPAA. To the extent any information we hold about you is governed by those laws, you may request access, correction, or deletion by emailing privacy@willowbridge.app. We do not sell personal information, and we do not share it for cross-context behavioral advertising.
10. Children
The Willowbridge marketing site is not directed to children under 13, and we do not knowingly collect personal information from children under 13. The WillowBridge platform is a B2B platform used by healthcare providers; if a pediatric record is processed on a provider's behalf, the provider is responsible for the applicable legal posture (HIPAA, COPPA, FERPA where relevant). The Willowbridge patient app is intended for adults (18 and over) whose care team invites them.
11. International users
Willowcare is based in the United States, and the WillowBridge platform is hosted in the United States (Aptible — US East). The WillowBridge platform is intended for use by U.S. healthcare providers serving U.S. patients. If you access the marketing site from outside the United States, you understand that any information you provide will be transferred to and processed in the United States.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version at this URL and update the "Last updated" date. For material changes that affect how we handle personal information, we will provide additional notice (for example, by email to active customers, or by a banner on the marketing site) before the change takes effect.
13. How to contact us
For privacy questions or requests:
- Email — privacy@willowbridge.app
- Postal — Willowcare LLC, 128 Paul Bradley Drive, Murray, KY 42071
- If you are a patient and your concern relates to your health record, please contact your healthcare provider; they are the legal custodian of your record under HIPAA and we will work with them to resolve your request.