Privacy

Last updated 30 July 2026

There are two different groups of people here and they deserve separate answers: practices who use the portal, and patients who talk to the concierge. Patient information is handled under a Business Associate Agreement with the practice — see the HIPAA page for the detail.

If you are a patient

Your practice gave you access to their app. Avren builds and runs that app for them; your practice decides what goes in it and what happens to your information.

What is held about you

Who can see it

Your practice’s staff, and only after they have signed in with a second factor. No other practice can see it — that is enforced in the database rather than by our application code.

If your practice hides a conversation from their own view, it stays visible to you. Your record of what you asked and what you were told is not theirs to remove from your screen.

What the assistant will not do

It will not give medical advice or tell you whether a treatment is right for you. Those questions are routed to a human every time, and that cannot be switched off by your practice. It will not invent a price, and it will not tell you something your practice has not recorded — if it does not know, it says so and offers to check.

Asking for your information, or its deletion

Contact your practice. They hold the relationship and the record; we act on their instruction. We can destroy conversation content on their request, and doing so is logged.

If you are a practice

What we hold

What we do not do with it

We do not sell it, rent it, or share it with other practices. We do not use one practice’s data to answer another practice’s patients — every answer comes from that practice’s own knowledge base and nothing else. There is no advertising on any surface of this product and no advertising or analytics tracker in the portal.

Subprocessors

Supabase (database and authentication, AWS US East), Vercel (application hosting, United States), Anthropic (the language model), and Cloudflare (domain name resolution only — Cloudflare is not in the traffic path and receives no request content). The full table, with what each one receives, is on the HIPAA page.

This website

This marketing site loads fonts from Google Fonts, which means Google receives the IP address of anyone who visits it. That applies to this site only. The Avren portal and the patient app load no third-party resources at all — no fonts, no scripts, no trackers — so nobody outside the subprocessors above sees that traffic.

We do not use cookies on this site for advertising or analytics. The portal sets a session cookie, which is what keeps you signed in.

Contact

To be completed before launch: a privacy contact address, the registered legal entity name, and the postal address that a data subject request should be sent to. These are facts about the business rather than the software, and this page will not invent them.