Legal
Privacy Policy
June 23, 2026
MotherCode Corp ("MotherCode," "we," "us," or "our") is committed to protecting the privacy of the individuals who interact with us, whether as visitors to our website (https://meet.tellus.health/) and any other websites we operate (collectively, the "Website"), as users of our TellUs platform and related services (the "Platform"), as healthcare providers and their patients, or individuals who apply for employment with us. This privacy policy ("Privacy Policy") describes how we collect, use, disclose, and protect personal information in connection with our Website, our Platform, and our employee recruitment activities.
This Privacy Policy does not apply to information that is subject to a Business Associate Agreement ("BAA") between MotherCode and a healthcare provider customer to the extent such information is governed by the Health Insurance Portability and Accountability Act of 1996, as amended ("HIPAA"), the Health Information Technology for Economic and Clinical Health Act (the "HITECH Act"), and the regulations promulgated thereunder (collectively, the "HIPAA Rules"). The use, disclosure, and safeguarding of protected health information ("PHI") by MotherCode in its capacity as a business associate is governed by the applicable BAA and the HIPAA Rules, not this Privacy Policy.
Your access to and use of the Website is governed by MotherCode's Terms of Use, which are incorporated herein by reference. Your access to and use of the Platform is governed by MotherCode's Terms of Service, which are incorporated herein by reference. In the event of any conflict between this Privacy Policy and the Terms of Use or Terms of Service with respect to matters other than the collection, use, and disclosure of personal information, the Terms of Use or Terms of Service (as applicable) shall control. To the extent you are a healthcare provider customer, your use of the Platform is additionally governed by the services agreement and any applicable Business Associate Agreement between you and MotherCode.
By accessing the Website, using the Platform, or submitting information to us, you acknowledge that you have read and understand this Privacy Policy.
Information We Collect
We collect personal information in several contexts, as described below.
Information You Provide Directly
Website Visitors
When you visit our Website, you may provide us with information voluntarily, including:
- Contact information (such as your name, email address, phone number, and organization name) when you complete a contact form, request a demo, or subscribe to our communications;
- Any other information you choose to provide in free-text fields or through correspondence with us.
Healthcare Provider Customers
When a healthcare provider organization enters into a services agreement with MotherCode to use the Platform, we collect information necessary to establish and maintain the customer relationship, including:
- Business contact information of the organization's representatives (such as name, title, email address, and phone number);
- Billing and payment information;
- Account credentials and authentication information for authorized users of the Platform.
Patients
When patients interact with the TellUs pre-visit intake experience at the direction of their healthcare provider, the information patients provide is collected on behalf of, and under the direction of, the healthcare provider. This may include:
- Identifying information (such as name, date of birth, and contact information);
- Health and medical information (such as health history, current symptoms, concerns, and other information the patient wishes to communicate to their provider);
- Insurance and billing-related information.
Important: MotherCode collects and processes patient information solely as a service provider (business associate) to the healthcare provider (covered entity). The healthcare provider is the controller of patient data and is responsible for providing patients with its own Notice of Privacy Practices under HIPAA. MotherCode does not use patient health information for its own independent purposes except as permitted by the applicable BAA and the HIPAA Rules.
Job Applicants
When you apply for a position with MotherCode, we collect information that you submit in connection with your application, including:
- Contact information (such as name, email address, phone number, and mailing address);
- Professional and educational background (such as resume or curriculum vitae, cover letter, work history, education, certifications, and professional licenses);
- Information from references you provide or authorize us to contact;
- Any other information you voluntarily include in your application materials (such as portfolio samples, writing samples, or links to professional profiles);
- Information necessary to verify your eligibility to work in the United States.
We may also collect information about applicants from publicly available sources (such as LinkedIn or professional directories) and from third-party recruiting platforms through which you submit your application.
Information Collected Automatically
When you visit our Website or use the Platform, we may automatically collect certain technical and usage information, including:
- Device and Browser Information: Device type, operating system, browser type and version, screen resolution, and language preferences;
- Log Data: Internet Protocol (IP) address, access times, pages viewed, referring URL, and actions taken on the Website;
- Cookies and Similar Technologies: We use cookies, pixel tags, and similar technologies to facilitate Website functionality, analyze usage trends, and improve the user experience. See the Cookies and Tracking Technologies section below for more information.
Information from Third Parties
We may receive information about healthcare provider customers from our integration partners, including electronic medical records (EMR) platforms such as athenahealth, to the extent necessary to facilitate the integration of our Platform with the customer's existing systems. This information is used solely to provide and support the Platform. The mobile opt-in data is not shared or sold for marketing.
How We Use Information
We use the information we collect for the following purposes:
Website Visitors
- To respond to inquiries, demo requests, and other communications;
- To send informational and marketing communications about our products and services (you may opt out at any time);
- To operate, maintain, and improve the Website;
- To analyze Website usage trends and user behavior to improve the user experience;
- To detect, prevent, and address technical issues, fraud, or security concerns.
Healthcare Provider Customers and Platform Users
- To provide, operate, maintain, and support the Platform and related services;
- To authenticate authorized users and manage accounts;
- To process billing and payments;
- To communicate with customers regarding their accounts, service updates, and technical support;
- To improve the Platform, develop new features, and conduct internal analytics;
- To create de-identified or aggregated data in accordance with 45 C.F.R. § 164.514 for product improvement, analytics, benchmarking, and research purposes (such de-identified data is not subject to this Privacy Policy or the HIPAA Rules);
- To comply with legal obligations and enforce our agreements.
Patients
- To process and transmit patient-provided information to the patient's healthcare provider through the Platform, including pre-visit intake responses, health history, symptoms, and related clinical information;
- To generate clinical documentation signals, billing code support, and other outputs for the healthcare provider;
- To operate and maintain the Platform;
- As otherwise permitted or required by the applicable BAA and the HIPAA Rules.
Job Applicants
- To evaluate your qualifications and candidacy for employment;
- To communicate with you regarding your application, including scheduling interviews and providing status updates;
- To verify information you have provided, including contacting references;
- To comply with applicable employment laws and regulations;
- To maintain records of our recruiting activities and improve our hiring processes.
If you are offered and accept employment with MotherCode, the information collected during the application process may become part of your employment record and will be used in accordance with our internal employee privacy practices.
How We Share Information
We do not sell your personal information. We do not engage in cross-context behavioral advertising. We share personal information only in the following limited circumstances:
Service Providers
We share information with third-party service providers who perform services on our behalf, such as cloud hosting and infrastructure (e.g., Amazon Web Services), payment processing, email delivery, analytics, and customer support. These service providers are contractually obligated to use personal information only as necessary to provide services to us and to maintain appropriate confidentiality and security measures. To the extent any service provider accesses PHI, we maintain a business associate agreement or sub-business associate agreement with such provider as required by the HIPAA Rules.
Healthcare Providers
Patient information collected through the Platform is transmitted to the applicable healthcare provider in connection with the patient's care. MotherCode processes this information as a business associate of the healthcare provider.
EMR Platform Partners
To the extent necessary to facilitate the integration of our Platform with a healthcare provider's EMR system (such as the athenaOne platform provided by athenahealth), we may exchange data with the EMR platform partner in accordance with the authorizations and consents provided by the healthcare provider customer.
Legal and Regulatory Disclosures
We may disclose personal information if we believe in good faith that such disclosure is necessary to: (a) comply with applicable law, regulation, legal process, or governmental request; (b) enforce our agreements and policies; (c) protect our rights, property, or safety, or the rights, property, or safety of our users or others; or (d) detect, prevent, or address fraud, security, or technical issues.
Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or other similar transaction involving MotherCode, personal information may be transferred as part of that transaction. We will provide notice of any such transfer and any choices you may have regarding your information.
With Your Consent
We may share information with third parties when you have given us your explicit consent to do so.
Data Retention
We retain personal information for as long as reasonably necessary to fulfill the purposes for which it was collected, as described in this Privacy Policy, unless a longer retention period is required or permitted by law.
- Website visitor information is retained for as long as needed to respond to inquiries and, for marketing contacts, until you opt out or request deletion.
- Healthcare provider customer information is retained for the duration of the customer relationship and for a reasonable period thereafter as necessary to comply with our legal and contractual obligations, resolve disputes, and enforce our agreements. PHI is retained and disposed of in accordance with the applicable BAA and the HIPAA Rules.
- Patient information is retained in accordance with the applicable BAA and the HIPAA Rules and is returned or destroyed as provided therein upon termination of the customer relationship, unless retention is required by law or return/destruction is infeasible.
- Job applicant information is retained for a reasonable period following the conclusion of the recruiting process (typically no longer than two (2) years), unless you are hired, in which case the information becomes part of your employment record. We may retain de-identified aggregate recruiting data for longer periods for analytics purposes.
Data Security
We implement and maintain reasonable and appropriate administrative, physical, and technical safeguards designed to protect personal information from unauthorized access, use, disclosure, alteration, or destruction. However, no method of transmission over the internet or method of electronic storage is 100% secure. While we strive to use commercially reasonable means to protect personal information, we cannot guarantee its absolute security.
Cookies and Tracking Technologies
Types of Cookies We Use
We use the following categories of cookies and similar technologies on our Website:
- Strictly Necessary Cookies: These are essential for the operation of the Website and enable core functionality such as security, network management, and accessibility. You cannot opt out of these cookies.
- Analytics Cookies: These help us understand how visitors interact with the Website by collecting information about pages visited, time spent on pages, and other usage metrics. We use this information to improve the Website and user experience.
- Functional Cookies: These enable enhanced functionality and personalization, such as remembering your preferences and settings.
What We Do Not Do
We do not use cookies or tracking technologies for cross-context behavioral advertising. We do not serve targeted advertisements based on your browsing activity across third-party websites. We do not sell data collected through cookies or tracking technologies.
Managing Cookies
Most web browsers allow you to manage cookie preferences through browser settings. You can set your browser to refuse cookies or to alert you when cookies are being sent. Please note that disabling certain cookies may affect the functionality of the Website.
Children's Privacy
Our Website and Platform are not directed to children under the age of 13, and we do not knowingly collect personal information from children under the age of 13. To the extent patient information relating to minors is collected through the Platform, such information is collected on behalf of, and at the direction of, the healthcare provider in its capacity as a covered entity under HIPAA, and such collection is governed by the applicable BAA, the HIPAA Rules, and applicable state law.
If we learn that we have inadvertently collected personal information from a child under 13 outside of the healthcare provider context, we will take steps to delete such information promptly. If you believe we have collected information from a child under 13, please contact us at the address provided below.
Third-Party Links
Our Website may contain links to third-party websites, applications, or services that are not operated or controlled by MotherCode. This Privacy Policy does not apply to any third-party websites or services. We encourage you to review the privacy policies of any third-party websites you visit.
Job Applicant Disclosures
Sources of Applicant Information
We collect applicant information directly from you when you submit an application, as well as from the following sources:
- Third-party recruiting platforms (e.g., job boards, applicant tracking systems) through which you apply;
- Publicly available professional profiles (e.g., LinkedIn);
- References you have provided or authorized us to contact;
- Background check providers, if applicable and to the extent permitted by law, following a conditional offer of employment.
How We Use Applicant Information
We use applicant information solely for recruitment and employment-related purposes as described above. We do not use applicant information for marketing or any other purpose unrelated to the evaluation of your candidacy.
Sharing of Applicant Information
We may share applicant information with:
- Our internal hiring team and relevant personnel involved in the evaluation of your application;
- Third-party service providers who assist us with recruiting operations (e.g., applicant tracking system providers, background check providers); or
- As required by applicable law.
We do not sell applicant information.
Applicant Rights
You may request access to the personal information we hold about you in connection with your application, request correction of inaccurate information, or request deletion of your information, subject to our legal obligations to retain certain records. To submit a request, please contact us at the address provided in the Contact Us section below.
Your Choices and Rights
Marketing Communications
If you receive marketing or promotional communications from us, you may opt out at any time by following the unsubscribe instructions included in each communication or by contacting us at the address below. Please note that even if you opt out of marketing communications, we may continue to send you transactional or service-related communications.
Cookies
You may manage your cookie preferences through your browser settings, as described in the Cookies section above.
Access, Correction, and Deletion
You may contact us to request access to, correction of, or deletion of your personal information. We will respond to such requests within a reasonable timeframe and in accordance with applicable law. Please note that certain information may be exempt from such requests under applicable law (for example, information we are required to retain for legal or compliance purposes).
Patient Rights
Patients who wish to access, amend, or obtain information about the use and disclosure of their health information should contact their healthcare provider directly. As a business associate, MotherCode processes PHI under the direction of the healthcare provider, and individual rights requests under HIPAA are fulfilled by the healthcare provider as the covered entity.
State-Specific Privacy Notices and Rights
Depending on where you reside, you may have certain rights under applicable state privacy laws, such as the California Consumer Privacy Act (as amended by the California Privacy Rights Act), the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, and similar laws in other states. These rights may include the right to know what personal information we collect, the right to request deletion of your personal information, the right to correct inaccurate personal information, the right to opt out of certain processing activities, and the right to obtain a copy of your personal information in a portable format. To exercise any rights that may be available to you under applicable state law, or if you have questions about your rights, please contact us using the information provided in the Contact Us section below. We will respond to your request in accordance with applicable law.
Automated Decision-Making
We may use automated tools and technologies, including algorithms and machine learning, to help us provide and improve our Services. For example, our Platform uses automated processes to generate clinical documentation signals and billing code suggestions based on patient-provided intake information. These automated outputs are provided to healthcare providers as decision-support tools and are not used to make final determinations regarding patient care, diagnosis, treatment, or billing without human review and oversight by the healthcare provider.
We do not use automated decision-making, including profiling, to make decisions that produce legal or similarly significant effects on individuals without human involvement. If you have questions about our use of automated tools, please contact us using the information provided in the Contact Us section below.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will update the "Last Updated" date at the top of this Privacy Policy and, where appropriate, provide additional notice (such as by posting a notice on our Website or sending a notification to affected individuals). We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information.
Text Messaging (SMS)
For clinics using the TellUs platform, patients who opt in receive appointment and care-related text messages. Message frequency varies. Message and data rates may apply. Mobile opt-in information and consent are not shared with third parties or sold, and are not used for marketing purposes. Reply STOP to unsubscribe or HELP for help at any time.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at:
MotherCode CorpAttn: Privacy Inquiries
6909 Laurel Ave 5954
Takoma Park, MD 20913
Email: privacy@tellus.health
For questions about the privacy of patient health information processed through the Platform, please contact your healthcare provider directly.