Privacy
There are two different groups of people here and they deserve separate answers: practices who use the portal, and patients who talk to the concierge. Patient information is handled under a Business Associate Agreement with the practice — see the HIPAA page for the detail.
If you are a patient
Your practice gave you access to their app. Avren builds and runs that app for them; your practice decides what goes in it and what happens to your information.
What is held about you
- The name and email address your practice already had on file
- Everything you type into the app, and everything the assistant replies
- Which practice and which of its locations you belong to
Who can see it
Your practice’s staff, and only after they have signed in with a second factor. No other practice can see it — that is enforced in the database rather than by our application code.
If your practice hides a conversation from their own view, it stays visible to you. Your record of what you asked and what you were told is not theirs to remove from your screen.
What the assistant will not do
It will not give medical advice or tell you whether a treatment is right for you. Those questions are routed to a human every time, and that cannot be switched off by your practice. It will not invent a price, and it will not tell you something your practice has not recorded — if it does not know, it says so and offers to check.
Asking for your information, or its deletion
Contact your practice. They hold the relationship and the record; we act on their instruction. We can destroy conversation content on their request, and doing so is logged.
If you are a practice
What we hold
- Your practice details, locations, opening hours and policies as you enter them
- Your treatment menu and your team
- Staff accounts: name, email and role
- Your patients’ conversations, as described above
What we do not do with it
We do not sell it, rent it, or share it with other practices. We do not use one practice’s data to answer another practice’s patients — every answer comes from that practice’s own knowledge base and nothing else. There is no advertising on any surface of this product and no advertising or analytics tracker in the portal.
Subprocessors
Supabase (database and authentication, AWS US East), Vercel (application hosting, United States), Anthropic (the language model), and Cloudflare (domain name resolution only — Cloudflare is not in the traffic path and receives no request content). The full table, with what each one receives, is on the HIPAA page.
This website
This marketing site loads fonts from Google Fonts, which means Google receives the IP address of anyone who visits it. That applies to this site only. The Avren portal and the patient app load no third-party resources at all — no fonts, no scripts, no trackers — so nobody outside the subprocessors above sees that traffic.
We do not use cookies on this site for advertising or analytics. The portal sets a session cookie, which is what keeps you signed in.
Contact
To be completed before launch: a privacy contact address, the registered legal entity name, and the postal address that a data subject request should be sent to. These are facts about the business rather than the software, and this page will not invent them.