Legal

Privacy Policy

Plain language about what we collect, why, and what we will never do with it.

Effective date: September 1, 2026
Supersedes the separate policies dated August 6, 2026 (branzinohealth.com) and August 12, 2026 (Branzino Health EMR).

Who we are

Branzino Health ("Branzino", "we", "our", "us") makes an electronic health record system for small practices. The legal entity behind it is Nexus Tech LLC, a Texas limited liability company doing business as Branzino Health and Branzino Health EMR.

This policy covers:

  • the branzinohealth.com website
  • the Branzino Health EMR web application
  • the Branzino Patient Portal mobile app for Android and iOS, application ID com.branzinohealth.portal, published under the developer name Branzino Health

Three situations, kept separate

Most of the confusion in privacy policies comes from mixing these up, so we won't.

1. You, dealing with us as a business. When you browse our site, start a trial, or email us, we decide how that information is used. This policy is the full story.

2. A practice's patient information inside Branzino. That data belongs to the practice. The practice is the HIPAA covered entity. We act as its business associate under a signed Business Associate Agreement (BAA), and we only handle patient information on the practice's instructions. If you are a patient, your practice — not us — controls your record.

3. A practice's own third-party accounts. If a practice connects something it already owns, such as its Google Business Profile, we act on that practice's behalf and only within what it authorized. See Google Business Profile and Google user data below.

What we collect

On the website

  • Trial and demo requests — name, practice name and email address you submit through our forms.
  • Chat messages — if you use the chat bubble, we keep the conversation and a random identifier stored in your browser so the thread stays connected.
  • Email — anything you send us, so we can reply.
  • Server logs — standard technical logs (IP address, pages requested, timestamps) used for security and abuse prevention, such as rate-limiting our signup form.

We do not run advertising trackers on this site, and we do not buy visitor data from anyone. We do use two analytics tools on the public website only, described below.

Website analytics

To understand which pages are read and where people give up on the way to a trial, the public marketing pages (this site, not the Branzino application or the patient app) use:

  • Google Analytics 4 — page views and clicks on buttons such as "Start free trial", with IP anonymization on. We send no names, email addresses or form contents to Google.
  • Microsoft Clarity — session replays and heatmaps of how the pages are used, if enabled. Clarity masks text typed into forms by default.

Neither runs inside the EHR or the patient app, and neither ever sees patient information. If your browser sends a Global Privacy Control or Do Not Track signal, we load neither tool. You can also block them with any content blocker without affecting the site.

From practices using Branzino

  • Account information — names, emails and roles of the staff a practice adds.
  • Billing details for the subscription.
  • Usage information — how staff interact with the system, including login times and features used.

Patient information inside the service

Patient records a practice creates or imports, including personal details, health information, insurance information, and documents or images uploaded to the chart. This is protected health information (PHI). We store and process it solely to provide the service to that practice, under the BAA.

From the patient mobile app

  • Device and notification information — a push-notification token and your notification preferences, if you turn reminders on. You can deny or revoke notification permission in your device settings.
  • Documents and photos — files and images you choose to upload and share with your provider.
  • Payment information — balances, payment status, receipts and transaction history. Card details are entered on Stripe-hosted pages and are never collected or stored by the app or by us.

App permissions, specifically:

  • Biometric unlock — if you opt in, your phone does the authentication. We receive only whether it succeeded. We never receive, store or transmit your fingerprint, face image or biometric template.
  • Notifications — delivered through Firebase Cloud Messaging for appointment reminders, practice messages, telehealth alerts, check-ins, assessments and payment receipts, according to your preferences.
  • Camera and microphone — requested only for a video visit or its device check. Audio and video are transmitted to support the visit and are not recorded by the app.
  • Files and photos — accessed only when you pick a document or image to send to your provider.

How we use information

  • To provide, secure and support the service — including backups, audit logging and abuse prevention.
  • To process appointments and support the delivery of care.
  • To respond when you contact us, and to send emails you asked for.
  • To meet legal obligations, including HIPAA's requirements for us as a business associate.

We never sell any of this. We do not use patient information for advertising, and we do not use it to train AI models. Features that use AI — such as the CareRAG chart assistant — operate on the practice's own records to answer the practice's own questions, inside the same access controls as the rest of the system.

Google Business Profile and Google user data

Branzino has an optional Reputation feature. A practice can connect its own Google Business Profile so it can see and answer its Google reviews without leaving Branzino.

Two things to be clear about up front: only practice staff use this, and no patient information is ever sent to Google.

How we get access. A practice user signs in with their own Google account, through Google's own consent screen. We never see or store a Google password. We ask for one permission — https://www.googleapis.com/auth/business.manage — which lets us read the business locations that user manages, read the reviews on the locations they choose, post replies their staff have written, and be notified when a new review arrives. It applies only to the locations they select.

What we do with it. We read the connected location's name, address and place identifier, and the reviews on it: star rating, review text, reviewer display name and dates. We use that to show the practice its reviews, alert it to new or low-rated ones, and send replies its staff compose. That is all we use it for. We do not use Google data to train or improve AI models, we do not use it for advertising, and we do not sell it or pass it to anyone else for their own purposes. Replies are always written by a person at the practice — we never generate or auto-post them.

How long we keep it. Access tokens are encrypted and kept only while the connection is active. Review content pulled from Google is cached for at most 30 days to keep the feature fast, in line with Google's Business Profile API policies, then deleted and re-fetched when needed. We separately keep our own records — that a review invitation went out, that a link was opened, what a staff member wrote — because those are the practice's own activity, not content from Google. We also keep the running counts we calculate, so a practice can see its own trend over time.

Who can see it. Only authorized staff at the practice that connected the profile. Never another practice, never patients, and never pooled across practices.

Reviews and patients. Google reviews are anonymous to us — we cannot tell whether a reviewer is a patient. If Branzino suggests a review might relate to an invitation the practice sent, that stays inside the practice's own account. It is never sent to Google and never published.

Turning it off. A practice can disconnect at any time from Reputation settings in Branzino, or revoke us directly at myaccount.google.com/permissions. We delete the tokens straight away, and any cached Google content within 30 days.

Limited Use. Branzino Health's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Where data lives, and who else touches it

Branzino runs on Google Cloud infrastructure in the United States, using only services covered by Google's HIPAA implementation and Google's own BAA with us. Google Cloud's SOC 2 and ISO 27001 certifications for that infrastructure are publicly verifiable. Details of our own controls are on our Security page.

The service providers that handle information on our behalf are:

  • Google Cloud — hosting and infrastructure
  • Google Firebase — authentication and push notification delivery
  • Stripe — hosted payment processing
  • Twilio — telehealth video
  • Our email provider — trial invites and system email
  • Google Analytics and Microsoft Clarity — website usage analytics on the public marketing site only

Each processes information on our behalf under contractual and security obligations appropriate to the service. We use no other categories of subprocessor without updating this policy.

If a practice chooses to connect an integration — Zapier, Zoho, its own Google Business Profile — data flows to that provider only for the workflows the practice sets up, under that provider's terms. The practice controls which fields each integration can touch and can disconnect it at any time.

We do not sell personal or health information, and we do not use it for targeted advertising.

Cookies and local storage

The site and app use what they need to function: a session for logged-in users, and a chat identifier if you use the chat bubble. The public website also sets the analytics cookies used by Google Analytics and Microsoft Clarity (see "Website analytics" above) unless your browser sends a Global Privacy Control or Do Not Track signal. No advertising cookies, no cross-site tracking.

Security

  • Encryption of data in transit and at rest
  • Role-based access controls and authentication
  • Audit logging
  • Regular security assessments and updates
  • Employee training on data protection

Retention and deletion

We keep information only as long as it is needed for the purposes above, or as long as the law requires.

  • Website leads — trial requests are kept while we work with you, and deleted on request.
  • Health and medical records — retained for the period required of your healthcare provider by applicable federal and state medical-records retention laws. These periods vary by state and by record type, and for records of patients who were minors they generally run until some years after the patient reaches the age of majority. We keep them for at least the legally required minimum and delete them once no retention obligation remains.
  • Practice data — kept while the practice subscribes. When a practice leaves it can export everything in portable formats, and we delete or return PHI as the BAA directs, keeping only what law requires.
  • Account and profile information — kept while your account is active. If you delete your account or ask us to, we remove this within 30 days, except where we must keep it as part of a medical record.
  • Authentication and usage logs — kept up to 12 months for security, auditing and fraud prevention, then deleted.
  • Google Business Profile data — access tokens are kept only while the connection is active and deleted the moment a practice disconnects. Review content pulled from Google is cached for no more than 30 days.
  • Encrypted backups — deleted data may persist in encrypted backups for up to 90 days, after which those backups are purged on a rolling basis.

When a retention period ends, we delete the information or irreversibly de-identify it. To request deletion, email info@branzinohealth.com.

Your choices and rights

  • Email us to access, correct or delete information we hold about you as a website visitor or business contact.
  • Patients: your medical records are controlled by your practice. Requests to see or amend your chart go to them, as HIPAA provides, and we support the practice in fulfilling them.
  • Opt out of communications you have subscribed to.
  • Practice users with a connected Google Business Profile: disconnect at any time from Reputation settings, or revoke access at myaccount.google.com/permissions.
  • File a complaint if you believe your privacy rights have been violated.

Depending on where you live you may have additional rights under state privacy laws. We honor verified requests regardless of which statute they cite.

HIPAA and our role

Branzino is built to comply with HIPAA and other applicable healthcare privacy laws. We sign a BAA with every practice, and within that relationship the practice is the covered entity and we are the business associate. We maintain administrative, physical and technical safeguards appropriate to that role.

If something goes wrong

If a security incident affects PHI, we notify the affected practices without unreasonable delay and in accordance with the BAA and the HIPAA Breach Notification Rule, and we help them meet their own notification duties.

To report a suspected security issue, email security@branzinohealth.com.

Children

This website and our sign-up flows are for practices, not children. Pediatric patient records inside the service are handled under the practice's direction and the BAA, like all other PHI.

Changes to this policy

If we change this policy we will update the date at the top and note material changes here. We won't quietly weaken it.

Contact

Questions about privacy, this policy, a BAA, or a suspected security issue: security@branzinohealth.com

Anything else, including sales and support: info@branzinohealth.com

Nexus Tech LLC, a Texas limited liability company doing business as Branzino Health
Attn: Privacy Officer

Our YouTube channel

We publish our own videos to our own YouTube channel, @branzino-health. To post them, we use a small internal tool that connects to YouTube API Services through the YouTube Data API. Two things up front: only we use this tool, and no patient information and no website-visitor information is ever sent to YouTube.

How we get access. The channel owner signs in once with our own Google account, through Google's own consent screen. We never see or store a Google password. We ask for two permissions — https://www.googleapis.com/auth/youtube.upload and https://www.googleapis.com/auth/youtube — which let the tool upload a video to our channel and set its title, description, tags and thumbnail.

What we do with it. The tool takes a finished video we made and uploads it to our channel, then sets that video's details. That is all it does. It does not read, collect, or store data about viewers, other users, or other channels. It does not search or display anyone else's content, and it runs no analytics on other channels. We do not use anything received from Google or YouTube to train or improve AI models, we do not use it for advertising, and we do not sell it or share it for anyone else's purposes.

How long we keep it. The sign-in token is encrypted and kept only while the connection is active. There is no viewer data or third-party YouTube data to retain, because we never request any.

Turning it off. We can revoke the tool's access at any time at myaccount.google.com/permissions. The token stops working immediately.

The rules we follow. Our use of YouTube API Services is subject to the YouTube Terms of Service and the Google Privacy Policy. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Listed on Capterra GetApp Software Advice G2