Privacy policy
What the Haventri platform and clinician app collect, how we use and protect it, and how HIPAA roles apply. Written to be read, not skimmed past.
Last updated: July 16, 2026
Haventri LLC ("Haventri," "we," "us") provides a home-health operations platform and the Haventri clinician companion mobile app (the "App"). This policy explains what information the App and platform collect, how we use it, and how we protect it.
Read this first — who our users are. Haventri is a business-to-business service. The App is used by authorized staff of home-health agencies that license our platform (clinicians, schedulers, and administrators). It is not a consumer product and is not directed to the general public or to patients.
1. Our role, and how patient health information is handled
Many Haventri customers are HIPAA covered entities or business associates. When Haventri creates, receives, maintains, or transmits protected health information ("PHI") on behalf of a customer subject to HIPAA, Haventri acts as that customer's business associate (or subcontractor business associate) under an applicable business associate agreement (BAA).
- The licensing agency controls the patient information processed through Haventri and determines how and why it is used. Haventri processes that information only to provide services to the agency and as permitted by the applicable agreement and law. Its collection, use, and a patient's rights over it are governed by that agency's notice of privacy practices and applicable law — not by this policy.
- A patient seeking to access, amend, or restrict their health information should contact the home-health agency providing their care.
- The remainder of this policy describes the information of App users (agency staff) and how Haventri operates the service.
2. Information we collect from App users
We collect only what the service needs to function:
- Account and identity. Name, work email, role, and agency affiliation — for sign-in, authorization, and audit.
- Authentication data. Password (stored only as a salted hash) and two-factor codes. On-device biometric unlock (Face ID / fingerprint) never leaves your device and is never sent to us — we only receive a yes/no unlock result from the operating system.
- Employment and work data. Schedule, timesheets, mileage, and visit assignments — the core operational features.
- Location. A single location point, captured only after you initiate a feature that requires it (for example, verifying a visit or attaching a location point to a message). The App requests a current location point, transmits it to your agency, and stops accessing location when the action completes. We do not continuously monitor location, and we collect no location while the App is closed or not in use.
- Camera images. Photos you capture with the in-app camera feature (for example, a document or insurance card), used only to attach the item to the relevant record. The App does not request or access your photo library.
- Messages. Secure messages you send within the App, for team communication.
- Push-notification and app-installation data. Push-notification registration tokens, platform, and app-installation identifiers used to deliver notifications. Depending on the operating system and notification service, the notification service provider (Firebase Cloud Messaging / Apple Push Notification service) may also automatically process technical app and device information — such as application version, operating-system version, device model, language, and time zone — to deliver notifications and manage subscriptions. Haventri itself retains only the registration token and platform. None of it is used for advertising or profiling.
- Log and security data. Sign-in events, IP address, and security-relevant actions — for security, audit, and fraud prevention.
- Patient information (PHI). Patient data you are authorized to view for your work, processed on behalf of your agency under a BAA (see section 1).
What we do not collect or do: no advertising, no ad identifiers, no tracking across apps or websites, no third-party analytics or behavioral-profiling SDKs. We do not sell or rent personal information — ever.
3. How we use information
- Provide and operate the platform (scheduling, visits, timesheets, messaging, visit verification).
- Authenticate users and enforce role-based access.
- Secure the service, maintain audit trails, and prevent misuse.
- Provide customer support and service communications.
- Comply with legal and regulatory obligations (including HIPAA, on behalf of agencies).
We do not use your information for advertising or for any purpose unrelated to operating the service for your agency.
4. How information is shared
- With your agency. Your employer/agency administers your account and can view work data associated with it.
- Infrastructure service providers (subprocessors) that host and operate the service on our behalf, under contract — and, before any PHI reaches a provider, under an executed business associate agreement with that provider. Our current providers are identified on our subprocessor list, which we keep up to date as infrastructure changes.
- Push delivery (Firebase Cloud Messaging / Apple Push Notification service): push messages are PHI-free by design (generic prompts such as "You have a new message — open the app to read it"). Message content and patient information are never placed in a push notification.
- Legal and safety. When required by law, valid legal process, or to protect rights and safety.
- Business transfers. If Haventri is involved in a merger or acquisition, information may transfer subject to this policy.
We do not share information with advertisers, data brokers, or third-party trackers.
5. How we protect information
- Encryption in transit (TLS) and at rest, including encrypted off-site backups.
- Multi-factor authentication (TOTP), with enforced MFA available for administrator roles.
- Role-based access control — users see only what their role permits.
- Tenant isolation — each agency's data is logically separated from every other's.
- Audit logging of security-relevant events; sensitive changes are recorded as the fact that a change occurred, without logging the underlying values.
- Haventri configures its application and logging systems to prevent passwords, authentication secrets, notification tokens, PHI values, and other sensitive content from being included in application logs.
No system is perfectly secure, but we design the platform to minimize exposure by default. More detail is on our security page.
6. Data retention
We retain information for as long as needed to provide the service and to meet the legal, clinical, and contractual obligations of the agencies we serve. Because health and employment records are subject to regulatory retention requirements, retention of patient and work records is controlled by your agency. Account data is deleted or de-identified when it is no longer needed and no obligation requires keeping it.
7. Your choices and rights
- App permissions. You control location and camera access through your device Account settings; the App requests them only for the features described above and never uses background location. If you decline a permission, the related feature is unavailable but the rest of the App continues to work.
- Notifications. You may disable push notifications entirely through your device Account settings — when device notifications are disabled, Haventri cannot deliver push notifications to that device, though alerts and messages remain available when you open the App. The App also offers an in-app mute window for routine notifications; while muted, your agency may configure urgent operational alerts to still be delivered within the App's notifications — an in-app setting, which never overrides your device-level choice.
- Account creation and deletion. Haventri accounts are created and administered by your agency; the App does not offer public or consumer account registration. You may request deletion of your Haventri user account through the App or on our account deletion page. Account deletion removes your login credentials, active sessions, notification registrations, and direct access to the service, and we delete or de-identify personal account information that is not required to be retained. Associated agency records — work, visit, EVV, clinical, payroll, messaging, compliance, security, and audit records — remain under your agency's control and may be retained as your agency directs or as required for legal, regulatory, contractual, security, or fraud-prevention purposes.
- Access and correction requests. Because your agency administers your account, you may direct requests to access or correct your information to your agency administrator, or contact us at the address below and we will work with your agency.
- Patient (PHI) rights are handled by the home-health agency as described in section 1.
8. Children
The App is a professional tool for authorized agency staff and is not directed to children. We do not knowingly collect personal information from children.
9. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by a new "Last updated" date and, where appropriate, communicated through the App or to agency administrators.
10. Contact us
Haventri LLC
2222 W. Grand River Ave Ste A, Okemos, MI 48864, US
Privacy: privacy@haventri.com ·
Support: support@haventri.com
This policy describes App-user data handling and Haventri's role as a service provider. It does not replace or modify any business associate agreement between Haventri and a home-health agency, nor any agency's notice of privacy practices.