TellUs

Legal

Privacy Policy

Effective Date: July 27, 2026

MotherCode Corp dba TellUs Health ("TellUs Health," "we," "us," or "our") is committed to protecting the privacy of the individuals who interact with us, whether as visitors to our website (https://meet.tellus.health/) (the "Website"), users of our TellUs platform and related services (the "Platform"), or individuals who apply for employment with us. This privacy policy ("Privacy Policy") describes how we collect, use, disclose, and protect personal information in connection with our Website, our Platform, and our employee recruitment activities.

This Privacy Policy does not apply to information that is subject to a Business Associate Agreement ("BAA") between TellUs Health and a healthcare provider customer to the extent such information is governed by the Health Insurance Portability and Accountability Act of 1996, as amended ("HIPAA"), the Health Information Technology for Economic and Clinical Health Act (the "HITECH Act"), and the regulations promulgated thereunder (collectively, the "HIPAA Rules"). The use, disclosure, and safeguarding of protected health information ("PHI") by TellUs Health in its capacity as a business associate is governed by the applicable BAA and the HIPAA Rules, not this Privacy Policy.

Your access to and use of the Website is governed by our Terms of Use, which are incorporated into this Privacy Policy by reference as applicable.

Your access to and use of the Platform is governed by our Terms of Service, which are also incorporated into this Privacy Policy by reference as applicable.

In the event of any conflict between this Privacy Policy and the Terms of Use or Terms of Service with respect to matters other than the collection, use, and disclosure of personal information, the Terms of Use or Terms of Service (as applicable) shall control. To the extent you are a healthcare provider customer of the Platform, your use of the Platform is additionally governed by the services agreement and any applicable Business Associate Agreement between you and us.

By accessing the Website, using the Platform, or submitting information to us, you acknowledge that you have read and understand this Privacy Policy.

Information We Collect

We collect personal information in several contexts, as described below.

Information You Provide Directly

Website Visitors

When you visit our Website, you may provide us with information voluntarily, including:

Healthcare Provider Customers

When a healthcare provider organization enters into a services agreement with TellUs Health to use the Platform, we collect information necessary to establish and maintain the customer relationship, including:

Patients

When patients interact with the TellUs pre-visit intake experience at the direction of their healthcare provider, the information patients provide is collected on behalf of, and under the direction of, the healthcare provider. This may include:



Important: TellUs Health collects and processes patient information solely as a service provider (business associate) to the healthcare provider (covered entity). The healthcare provider is the controller of patient data and is responsible for providing patients with its own Notice of Privacy Practices under HIPAA. TellUs Health does not use patient health information for its own independent purposes, except as permitted by the applicable BAA and the HIPAA Rules.

Job Applicants

When you apply for a position with us, we collect information that you submit in connection with your application, including:



We may also collect information about applicants from publicly available sources (such as LinkedIn or professional directories) and from third-party recruiting platforms through which you submit your application.

Information Collected Automatically

When you visit our Website or use the Platform, we may automatically collect certain technical and usage information, including:

Information from Third Parties

We may receive information about healthcare provider customers from our integration partners, including electronic medical record (EMR) platforms such as athenahealth, to the extent necessary to facilitate the integration of our Platform with the customer's existing systems. This information is used solely to provide and support the Platform.

How We Use Information

We use the information we collect for the following purposes:

Website Visitors

Healthcare Provider Customers and Platform Users

Patients

Job Applicants



If you are offered and accept employment with us, the information collected during the application process may become part of your employment record and will be used in accordance with our internal employee privacy practices.

How We Share Information

We do not sell your personal information. We do not engage in cross-context behavioral advertising. We share personal information only in the following limited circumstances:

Service Providers

We share information with third-party service providers who perform services on our behalf, such as cloud hosting and infrastructure (e.g., Amazon Web Services), payment processing, email delivery, analytics, and customer support. These service providers are contractually obligated to use personal information only as necessary to provide services to us and to maintain appropriate confidentiality and security measures. To the extent any service provider accesses PHI, we maintain a business associate agreement or sub-business associate agreement with such provider as required by the HIPAA Rules.

Healthcare Providers

Patient information collected through the Platform is transmitted to the applicable healthcare provider in connection with the patient's care. We process this information as a business associate of the healthcare provider.

EMR Platform Partners

To the extent necessary to facilitate the integration of our Platform with a healthcare provider's EMR system (such as the athenaOne platform provided by athenahealth), we may exchange data with the EMR platform partner in accordance with the authorizations and consents provided by the healthcare provider customer.

Legal and Regulatory Disclosures

We may disclose personal information if we believe in good faith that such disclosure is necessary to: (a) comply with applicable law, regulation, legal process, or governmental request; (b) enforce our agreements and policies; (c) protect our rights, property, or safety, or the rights, property, or safety of our users or others; or (d) detect, prevent, or address fraud, security, or technical issues.

Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or other similar transaction involving TellUs Health, personal information may be transferred as part of that transaction. We will provide notice of any such transfer and any choices you may have regarding your information.

With Your Consent

We may share information with third parties when you have given us your explicit consent to do so.

Cookies and Tracking Technologies

Types of Cookies We Use

We use the following categories of cookies and similar technologies on our Website:

What We Do Not Do

We do not use cookies or tracking technologies for cross-context behavioral advertising. We do not serve targeted advertisements based on your browsing activity across third-party websites. We do not sell data collected through cookies or tracking technologies.

Managing Cookies

Most web browsers allow you to manage cookie preferences through browser settings. You can set your browser to refuse cookies or to alert you when cookies are being sent. Please note that disabling certain cookies may affect the functionality of the Website.

Do Not Track Signals

Some web browsers may transmit "Do Not Track" signals to websites. Because there is no industry standard for how to respond to such signals, our Website does not currently respond to or take any action based on Do Not Track signals. We will update this disclosure if an industry standard for Do Not Track compliance is established.

Your Choices and Rights

Marketing Communications

If you receive marketing or promotional communications from us, you may opt out at any time by following the unsubscribe instructions included in each communication or by contacting us at the address below. Please note that even if you opt out of marketing communications, we may continue to send you transactional or service-related communications.

Cookies

You may manage your cookie preferences through your browser settings, as described in the Managing Cookies subsection of Section 4 above.

SMS Text Messages

If you are a patient who provides a mobile phone number in connection with your use of the Platform, you may receive SMS text messages from TellUs Health on behalf of your healthcare provider. These messages may include appointment reminders, pre-visit intake prompts, follow-up communications, and other messages related to your care. Message frequency may vary. Message and data rates may apply.



By providing your mobile phone number and agreeing to receive SMS messages, you consent to receive such messages at the number provided. Your consent to receive SMS messages is not a condition of receiving healthcare services from your provider.



You may opt out of receiving SMS messages at any time by replying STOP to any message you receive or by contacting your healthcare provider. After you opt out, you may receive a single confirmation message, but you will not receive further SMS messages from us unless you later re-subscribe. Opting out of SMS messages will not affect your ability to receive care from your healthcare provider or use other features of the Platform.



Please note that SMS is not a fully secure means of communication. We recommend that you do not include sensitive health information in any SMS replies. TellUs Health will not send detailed medical information via SMS.

Access, Correction, and Deletion

You may contact us to request access to, correction of, or deletion of your personal information. We will respond to such requests within a reasonable timeframe and in accordance with applicable law. Certain information may be exempt from such requests under applicable law (for example, information we are required to retain for legal or compliance purposes).

Patient Rights

Patients who wish to access, amend, or obtain information about the use and disclosure of their health information should contact their healthcare provider directly. As a business associate, we process PHI under the direction of the healthcare provider, and individual rights requests under HIPAA are fulfilled by the healthcare provider as the covered entity.

Job Applicant Disclosures

Sources of Applicant Information

We collect applicant information directly from you when you submit an application, as well as from the following sources:

How We Use Applicant Information

We use applicant information solely for recruitment and employment-related purposes as described in the Job Applicants subsection of Section 2 above. We do not use applicant information for marketing or any other purpose unrelated to the evaluation of your candidacy.

Sharing of Applicant Information

We may share applicant information with:

We do not sell applicant information.

Applicant Rights

You may request access to the personal information we hold about you in connection with your application, request correction of inaccurate information, or request deletion of your information, subject to our legal obligations to retain certain records.

To submit a request, please contact us at the address provided in the Contact Us section below.

Data Retention

We retain personal information for as long as reasonably necessary to fulfill the purposes for which it was collected, as described in this Privacy Policy, unless a longer retention period is required or permitted by law.

Website visitor information is retained for as long as needed to respond to inquiries and, for marketing contacts, until you opt out or request deletion.

Healthcare provider customer information is retained for the duration of the customer relationship and for a reasonable period thereafter as necessary to comply with our legal and contractual obligations, resolve disputes, and enforce our agreements. PHI is retained and disposed of in accordance with the applicable BAA and the HIPAA Rules.

Patient information is retained in accordance with the applicable BAA and the HIPAA Rules and is returned or destroyed as provided therein upon termination of the customer relationship, unless retention is required by law or return/destruction is infeasible.

Job applicant information is retained for a reasonable period following the conclusion of the recruiting process (typically no longer than two (2) years), unless you are hired, in which case the information becomes part of your employment record. We may retain de-identified aggregate recruiting data for longer periods for analytics purposes.

Data Security

We implement and maintain reasonable and appropriate administrative, physical, and technical safeguards designed to protect personal information from unauthorized access, use, disclosure, alteration, or destruction. However, no method of transmission over the internet or method of electronic storage is completely secure. While we strive to use commercially reasonable means to protect personal information, we cannot guarantee its absolute security.

In the event of a security incident that results in unauthorized access to, or acquisition of, personal information that we are required by applicable law to report, we will notify affected individuals and, where required, applicable regulatory authorities, in accordance with the timeframes and procedures required by law. For any security incident involving PHI, notification will be provided in accordance with the HIPAA Breach Notification Rule and the applicable BAA.

Children's Privacy

Our Website is not directed to children under the age of 18, and we do not knowingly collect personal information from children under the age of 18. To the extent patient information relating to minors is collected through the Platform, such information is collected on behalf of, and at the direction of, the healthcare provider in its capacity as a covered entity under HIPAA, and such collection is governed by the applicable BAA, the HIPAA Rules, and applicable state law.

If we learn that we have inadvertently collected personal information from a child under 18 outside of the healthcare provider context without receiving verifiable parental consent, we will take steps to delete such information promptly. If you believe we have collected information from a child under 18, please contact us at the address provided below.

Third-Party Links

Our Website may contain links to third-party websites, applications, or services that we do not operate or control. This Privacy Policy does not apply to any third-party websites or services. We encourage you to review the privacy policies of any third-party websites you visit.

State-Specific Privacy Notices and Rights

Depending on where you reside, you may have certain rights under applicable state privacy laws, such as the California Consumer Privacy Act (as amended by the California Privacy Rights Act), the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, and similar laws in other states. These rights may include the right to know what personal information we collect, the right to request deletion of your personal information, the right to correct inaccurate personal information, the right to opt out of certain processing activities, and the right to obtain a copy of your personal information in a portable format. To exercise any rights that may be available to you under applicable state law, or if you have questions about your rights, please contact us using the information provided in the Contact Us section below. We will respond to your request in accordance with applicable law.

International Users

The Website and Platform are intended for use by individuals and organizations located in the United States. TellUs Health is based in the United States, and the personal information we collect is stored and processed in the United States. We do not knowingly collect personal information from individuals outside the United States, and we make no representation that the Website, Platform, or our services are appropriate or available for use in any jurisdiction outside the United States. If you are located outside the United States and choose to access the Website, Platform, or provide information to us, you do so on your own initiative, at your own risk, and are responsible for compliance with applicable local laws. Your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your country of residence.

Artificial Intelligence and Automated Decision-Making

The Platform incorporates artificial intelligence (AI) technologies, including machine learning models and natural language processing, to provide clinical decision-support functionality. Specifically, the Platform uses AI to: (a) analyze patient-provided intake information; (b) generate clinical documentation signals and draft clinical notes; and (c) suggest billing codes based on clinical inputs. All AI-generated outputs are provided to healthcare providers solely as decision-support tools. No AI-generated output constitutes a diagnosis, treatment recommendation, clinical judgment, or billing determination. Healthcare providers are solely responsible for reviewing, validating, and approving all AI-generated content before use in patient care, medical record documentation, or billing submissions.

We do not use AI, automated decision-making, or profiling to: (a) make determinations that produce legal or similarly significant effects on individuals without human involvement; (b) make employment, credit, insurance, or housing decisions; (c) make clinical, diagnostic, or treatment decisions (which are made solely by healthcare providers); or (d) engage in behavioral advertising or targeted marketing based on sensitive health information. The AI functionality in the Platform is limited to clinical decision-support as described above. If you have questions about our use of AI or automated tools, please contact us using the information provided in the Contact Us section below.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will update the "Effective Date" at the top of this Privacy Policy and, where appropriate, provide additional notice (such as by posting a notice on our Website or sending a notification to affected individuals). We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information.

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at:

MotherCode Corp dba TellUs Health
Attn: Privacy Inquiries
6909 Laurel Street Northwest
Takoma Park, MD 20913
Email: privacy@tellus.health

For further questions about the privacy of patient health information processed through the Platform in connection with your healthcare provider, please contact your healthcare provider directly.