coyacoya

Privacy Policy

version 2026-07-18 · effective July 18, 2026

This policy describes how COYA handles information. Two regimes apply: protected health information (PHI) handled on behalf of practices is governed by HIPAA and the Business Associate Agreement — not by this policy; practice-account and website information is governed by this policy.

1. Protected health information

PHI processed on behalf of a practice (caller identities, intake submissions, insurance details, call transcripts) is used only as permitted by the BAA: to provide the service to that practice. Architecturally, PHI is segregated in an isolated, audited vault; the operational application database stores routing and workflow data without patient identities.

Patients: COYA works for your healthcare practice. For questions about your health information — including access, amendment, or restriction requests — contact your practice; COYA supports practices in fulfilling those rights per the BAA and the practice's instructions.

2. Practice-account information

We collect account details (name, work email, practice name, configuration), billing information (processed by Stripe; we do not store card numbers), and product usage data (features used, aggregate call/messaging volumes) to operate, secure, and improve the service.

3. Subprocessors

We use vetted subprocessors to provide the service, under agreements consistent with our obligations (including BAAs where they touch PHI): cloud infrastructure (AWS — PHI vault; Vercel — application hosting; Supabase — operational database), AI processing (OpenAI), telephony and messaging (Retell, Twilio, Telnyx), payments (Stripe), and email (Resend). A current list is available on request.

4. Zero-sale policy

We never sell, rent, trade, or share practice data or patients' personal information with third-party marketers, advertisers, or data brokers. Your data is your asset; we treat it accordingly.

5. Security

Controls include encryption in transit (TLS 1.2+) and at rest (AES-256), mandatory two-factor authentication for workspace access, role-based access, tenant isolation enforced at the database layer, structural PHI segregation in a dedicated audited vault, and audit logging of every PHI access. PHI is never placed in URLs or browser storage.

6. Retention and deletion

PHI is retained per the practice's instructions and applicable law, and returned or destroyed at termination per the BAA where feasible. Operational records and audit logs are retained per our data-retention schedule (see the practice-facing retention documentation), including HIPAA's six-year requirement for compliance documentation. Practices may request export or deletion of their data at any time.

7. Cookies and analytics

The application uses minimal, functional cookies required for authentication and session management. We do not use advertising cookies, tracking pixels, or third-party analytics platforms that profile visitors. We may collect anonymous, aggregated usage metrics to improve the service.

8. Contact

Privacy questions: privacy@getcoya.ai. Security reports: security@getcoya.ai. We respond to privacy inquiries within five (5) business days.