Legal
Privacy Policy
This policy explains what we collect from website visitors and platform users, how protected health information is handled only under a BAA, and the real vendors we rely on — stated plainly, with nothing invented.
Last updated: July 14, 2026
This policy is being finalized; contact privacy@neuroltc.com with questions.
1. Scope of this policy
This Privacy Policy explains how NeuroLTC, Inc. ("NeuroLTC," "we," "us," or "our") handles personal information. It covers three audiences, which are treated differently:
- Website visitors — people who browse neuroltc.com and submit the pilot-request form;
- Platform users — facility staff with accounts on the NeuroLTC application; and
- Resident / clinical data (PHI) — protected health information a customer processes through the platform, which is governed by the Business Associate Agreement (BAA) rather than by this policy.
Today the platform operates on demonstration and synthetic data; PHI is processed only for customers under a signed BAA.
2. Information we collect
We collect only what we need for the audience in question:
- Pilot-request form: your name, work email, facility name, and the optional message you send us.
- Account data: the name, work email, and role of provisioned platform users, plus authentication data.
- Usage and technical data: basic, essential logs needed to operate and secure the Service — for example request logs and audit-log entries recording access and changes within the platform.
- Customer clinical data: data a facility enters or connects. When this is PHI, it is customer-controlled and governed by the BAA, not this policy.
3. How we use information
We use the information above to:
- respond to pilot requests and communicate with you about them;
- create and administer accounts, and provide, secure, and support the Service;
- maintain audit logs and detect, prevent, and investigate security or integrity issues; and
- comply with legal obligations.
We do not use pilot-form submissions for advertising, and we do not add them to third-party mailing lists.
4. Protected health information and HIPAA
When a facility processes PHI through the platform, the facility is the covered entity (or a business associate of one) and NeuroLTC acts as a business associate under HIPAA. A signed BAA is required before any PHI is entered, and the BAA — not this policy — governs the permitted uses, disclosures, and safeguards for that PHI.
Until a BAA is in place, the platform runs on synthetic demonstration data, and we ask customers not to enter PHI into demonstration environments. Where AI features are enabled, inputs are PHI-minimized: internal identifiers, never resident names.
5. Cookies and tracking
This marketing site is a static Next.js site backed by a Convex-hosted form. We use only cookies and storage that are strictly necessary to deliver the site and operate the platform (for example, keeping you signed in). We do not set advertising cookies, and we do not use cross-site or third-party ad-tracking technologies.
6. Subprocessors we rely on
We rely on a small set of vendors ("subprocessors") to run the site and platform. We name only those we actually use:
- Vercel — Hosting and content delivery for the site and application. Data: website and application content; request metadata.
- Convex — Application backend and data storage — database, server functions, and file storage. Data: account data, pilot-form submissions, and (under a baa) customer clinical data.
- OpenRouter (LLM provider) — Routing to a large-language-model provider for AI drafting — only when AI features are enabled. Data: phi-minimized inputs (internal identifiers, never resident names).
- PointClickCare — Customer-initiated, read-only EHR / FHIR integration — only when a facility connects it. Data: medications, conditions, and demographics read from the customer's chart.
In addition, the platform uses public CMS Care Compare data — a public U.S. government dataset — as reference content within the product; this is public data, not personal information you provide to us.
7. How we share information
We do not sell personal information. We share it only:
- with the subprocessors above, to provide the Service under appropriate contractual protections;
- when required to comply with law, respond to lawful requests, or protect the rights, safety, and security of NeuroLTC, our customers, or the public; and
- in connection with a corporate transaction such as a merger or acquisition, subject to this policy.
Sharing of PHI is governed by the BAA.
8. Data retention
We keep personal information only as long as needed for the purposes described here — for example, pilot-form submissions for as long as we are in contact about your request, and account data for the life of the account. When information is no longer needed, we delete or de-identify it in the ordinary course. Retention and deletion of PHI follow the terms of the BAA and the customer's instructions.
9. Security measures
We protect information with encryption in transit and at rest through our infrastructure providers, facility-scoped and role-based access controls, function-level authorization on every data path, and comprehensive audit logging of access and changes. Our architecture is HIPAA-minded; we do not claim to be "HIPAA certified," and SOC 2 Type II is in preparation rather than held. No system is perfectly secure, but security is designed in from the ground up — see our security posture.
10. Your privacy choices and rights
You may ask us to access, correct, or delete the contact information you submitted through the pilot form or that is associated with your account. Email privacy@neuroltc.com and we will respond within a reasonable time. Requests to access, correct, or delete resident PHI are handled by the facility as the covered entity, under the BAA and applicable law; direct those requests to the facility.
11. Where we operate
NeuroLTC operates in the United States, and the Service is intended for facilities and users in the United States. If you access the site from outside the U.S., understand that your information will be processed in the United States.
12. Children's privacy
The Service is intended for facility staff and is not directed to children under 18, and residents are not "users." We do not knowingly collect personal information directly from children through the website. Resident information a facility processes through the platform is PHI governed by the BAA.
13. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the "last updated" date above and, where appropriate, provide additional notice. Your continued use of the site or Service after changes take effect constitutes acceptance of the updated policy.
14. How to reach us
Questions about this policy or your information can go to privacy@neuroltc.com. For the terms that govern use of the Service — including the BAA requirement before any PHI is processed — see our Terms of Service.