Ashlee Health

Legal

Privacy Policy

How Ashlee collects, uses, discloses, and protects personal information, including personal health information.

Effective 2026-08-17 · Last reviewed 2026-08-17 · Reviewed at least annually or when significant changes occur

Who we are

My Beacon AI Inc. (“Ashlee,” “we,” “us”) operates the Ashlee advance care planning platform at beaconcare.ai. Ashlee helps people document what matters to them for their care, in their own words, so clinicians and substitute decision-makers are not left guessing.

Ashlee is clinical decision support. It records and organizes what a person said. It does not diagnose, recommend treatment, give legal advice, or make care decisions.

For personal health information processed in the product, the participating long-term care home, community health organization, or other customer is typically the health information custodian (under Ontario’s Personal Health Information Protection Act, “PHIPA”) or, where HIPAA applies, the covered entity. Ashlee acts as their service provider / agent, and as a business associate when we handle protected health information (PHI) for a HIPAA covered entity. That customer remains accountable for the information. This policy describes Ashlee’s practices when we collect or process information.

Scope

This policy covers personal information we collect through our websites (including beaconcare.ai), the Ashlee Health application, voice and text conversations, related emails, and support channels.

It applies to patients and residents, substitute decision-makers (SDMs), family members who participate, clinical and administrative staff, customer-organization contacts, and visitors to our public pages.

Customer organizations may also have their own privacy notices. Where those notices and this policy both apply to health information, the customer’s notice and the written agreement (including any Data Processing Agreement) govern how that organization directs Ashlee to use the information.

Information we collect

Account and contact information

Depending on your role, we may collect name, preferred name, email address, phone number, date of birth, province, and login credentials (passwords are stored as one-way hashes).

Clinical staff accounts are created by an administrator; staff authenticate with multi-factor authentication. Patients authenticate with email and password.

Health and care-planning information

When you use the product, we collect the information needed to run a values conversation and produce a cited values portrait. That can include health context you or your care team provide (for example health status, primary condition, and referring clinician), the conversation transcript, extracted value statements with source citations, validation and edit history, the values portrait, consent records, and SDM authority details.

Voice sessions are recorded as audio and stored securely, and a written transcript is kept. Session audio is retained for up to 120 days and can be deleted earlier on request. Typed sessions capture no audio.

We may collect identifiers your organization uses to match you to an existing record (for example a health-card or other government health identifier), SDM relationship and authority type, and uploaded authority documents such as a power of attorney.

Website, support, and technical data

If you email us or use public pages (documentation, support, security, status, whistleblower), we collect the contact details and message content you send.

We collect technical logs needed to operate and secure the service, such as IP address, user agent, timestamps, and authentication events. We do not use third-party advertising or analytics cookies on the public site. Session cookies and similar tokens are used to keep you signed in and to protect the service.

How we use personal information

We use personal information to provide, maintain, and improve the Ashlee Health service: creating accounts, running conversations, generating and sharing values portraits, authenticating users, scoping access by organization and role, sending transactional email (for example SDM notices and portrait-share links), providing support, and keeping an audit trail.

We use information to protect the security and integrity of the service, detect and investigate incidents, meet legal and contractual duties, and communicate about the service.

We do not sell personal information. We do not use personal health information for advertising. We do not use conversation content to train generally available foundation models outside the inference required to provide the service.

Health information — uses and disclosures

Treatment, payment, and health care operations

When we process personal health information or PHI on behalf of a customer organization, we use and disclose it only as described in this policy, the customer’s instructions, and the applicable agreement.

Treatment and care involvement: we make values records available to authorized clinicians and staff in the patient’s organization, and we share a values portrait with people the patient (or authorized SDM) directs, including through a time-limited share link.

Payment: we may use limited organizational and account information to bill the customer organization for the service. We do not use patient conversation content to market to patients.

Health care operations: we use information to operate, secure, quality-check, and improve the service for that customer, including troubleshooting, audit logging, and service administration.

Uses and disclosures that need a further opportunity to agree or object (for example involving additional family members) are handled through the product’s consent and sharing flows, or by the customer organization under its own policies.

Other uses and disclosures

We may disclose information to subprocessors who help us run the service, under contracts that require them to protect it (see Subprocessors below).

We may disclose information if required by law, legal process, or a competent authority, or to protect the rights, safety, or security of a person or of Ashlee.

We do not use or disclose personal health information in a manner inconsistent with this notice. Other uses require the individual’s authorization or the customer organization’s documented instruction, except where law requires or permits otherwise.

Sharing

Who can see your information in the product

Clinical staff see residents in their own organization, limited by role. An administrator at one home is not an administrator at another.

A share-link recipient sees only the single values portrait that was shared, without creating a Ashlee login. Share links expire (currently after one year) and can be revoked.

Ashlee workforce access to production data is limited to named operators who need it to run, secure, or support the service.

Subprocessors

Amazon Web Services (AWS) hosts the application, database, object storage, staff identity, email delivery, and related infrastructure. Data at rest is stored in AWS ca-central-1 (Montreal, Canada).

Microsoft Azure Speech, in Canada Central, provides speech-to-text and text-to-speech for voice sessions.

AI inference uses Claude models on Amazon Bedrock. The API endpoint is in Canada, but inference currently routes through AWS regions in the United States. Prompt content can include conversation text and some identifiers (such as a name, and for portraits a date of birth). Storage of records remains in Canada. This cross-border inference path is disclosed to customer organizations in the applicable agreement.

We will notify customers of material subprocessor changes as required by those agreements.

Protection and retention

How we protect information

We use administrative, technical, and organizational measures appropriate to the sensitivity of health information. These include encryption in transit (TLS) for public HTTPS endpoints; encryption at rest for the primary database and object storage; private subnets for application data stores; mandatory multi-factor authentication for clinical staff; organization-scoped authorization, including database row-level security in production; least-privilege cloud and database roles; and an append-only, hash-chained audit log of access and significant events.

A longer summary of these practices is published at https://beaconcare.ai/security/.

Retention

Session audio is retained for 120 days and then expired from object storage, unless deleted earlier by an authorized organization administrator. Deleting audio removes the recording; the transcript, captured values, and values portrait remain part of the record unless separately addressed under the customer’s instructions.

Transcripts, extracted values, values portraits, consent records, and the audit log are retained for the life of the customer relationship and as needed for legal, security, and clinical-record purposes. Audit records are append-only. Specific retention for a site may be set in that site’s agreement.

Database backups are retained for a short operational window (currently seven days).

Your choices and rights

You can ask to access or correct personal information we hold, or to have it deleted, subject to law and to the customer organization’s record-keeping duties. For health information created in a participating organization, start with that organization (your care home or clinic). You may also email support@beaconcare.ai. We will route the request to the responsible customer where they are the custodian or covered entity.

You can ask to have a session audio recording deleted at any time. An organization administrator performs that deletion. A typed session captures no audio.

You can withdraw consent for future processing where consent is the basis we rely on, without affecting processing already completed. Share links can be revoked.

Depending on applicable law (including PIPEDA, PHIPA, and, where HIPAA applies, the Privacy Rule), you may also have rights to an accounting of certain disclosures, to request restrictions, to receive a copy of this notice, and to complain to Ashlee, to the customer organization, to the Office of the Privacy Commissioner of Canada, to Ontario’s Information and Privacy Commissioner, or to the U.S. Department of Health and Human Services, as applicable. Ashlee does not retaliate for a good-faith privacy complaint.

Children

Ashlee is designed for adult care-planning in long-term care and community health settings. We do not knowingly collect personal information from children for marketing. If you believe we have collected a child’s information in error, contact support@beaconcare.ai.

Changes to this policy

We review this privacy policy at least annually, and whenever we make significant changes to how we collect, use, disclose, or protect personal information. The “Last reviewed” date at the top of this page is updated when that review happens.

If we make material changes, we will post the updated policy at this URL and, where required, notify customer organizations or affected individuals. The current version is always at https://beaconcare.ai/privacy/.

Contact

Privacy questions, access or deletion requests, and suspected privacy incidents: support@beaconcare.ai (triaged by engineering and operations; privacy management is owned by the CEO).

Security or vulnerability reports use the same mailbox. Customer DPA and privacy-agreement requests: vatsal.trivedi@beaconcare.ai.

Anonymous reports, including privacy concerns, can be submitted at https://beaconcare.ai/whistleblower/.

Related resources

My Beacon AI Inc. (operating as Ashlee Health) · Privacy Policy · https://beaconcare.ai/privacy/