Medical disclaimer — please read.

  • 1.Not insurance.

    The membership is not health insurance, not a substitute for health insurance, and not a minimum essential coverage plan under the Affordable Care Act.

  • 2.No emergencies.

    The membership does not cover emergency care. For true emergencies call 911 or go to the nearest emergency room.

  • 3.No specialty or hospital care on the base plan.

    Specialty visits and hospitalization are not included unless you have added the catastrophic coverage add-on ($49/month, covering ER, hospitalization, surgery coordination, and emergency imaging).

  • 4.AI navigator is not medical advice.

    Suggestions from the AI patient navigator, draft messages, and routing recommendations are tools, not medical advice. Clinical decisions are made by your licensed physician.

Privacy policy

How we handle your information at Blue Line Health.

Plain-English summary of what we collect, who we share it with, the rights you have over your data, and how we keep it safe. Effective for members joining in 2026.

Last updated: 2026-07-28

1. What this policy covers

This Privacy Policy describes how Blue Line Health collects, uses, and protects information about you when you visit our website, sign up for a membership, schedule a visit, send us a secure message, or join our newsletter. It applies to the Blue Line Health website (blueline-health.polsia.app and successor domains) and to all communications initiated through those surfaces.

If you have signed up for a membership, additional protections for your health information apply under HIPAA. We treat HIPAA-protected clinical information with the rules in this policy as a baseline and apply stricter controls where HIPAA requires.

2. Information we collect

The categories below describe what we collect about you, why we collect it, and how it powers the membership. We collect only what is necessary for clinical care, billing, and operating the membership — and we never sell your data.

Account & billing information

Your name, email, phone number, mailing address, payment-method details (handled by our payment processor Stripe — full card numbers are never stored on our servers), and your membership plan selection.

Used to power billing, fraud prevention, and member support.

Intake answers

The structured medical-history, lifestyle, symptoms, and goals fields you complete during signup and at each renewal — the same medical history you provide, intake answers, and visit notes described in your member onboarding.

Used to power AI features (the AI patient navigator builds its context off these answers) and clinical coordination (your physician reads them before each visit).

Document uploads

Files you upload to your member dashboard: lab reports, imaging CDs, prior records, and specialist letters.

Used for clinical coordination and your physician’s review; stored as part of your medical record.

Health Data

Health information you upload or transmit through the member dashboard — including insurance-card images, prior lab results, and intake notes — is governed by this Privacy Policy along with HIPAA. It is encrypted at rest, accessible only to members of your care team whose role requires it, never sold, and never used for advertising or marketing.

Prescriptions

Your current and historical medications, dosing, prescriber, pharmacy choice, and refill events.

Used for medication safety review, prescription routing, and refill coordination with your pharmacy of choice.

Navigator chat messages

Every message you send through the AI patient navigator. Messages are stored as part of your medical record.

Used to power the AI navigator itself: the AI runs against these messages to produce suggestions, follow-ups, and routing drafts for your clinician’s review. Messages are not used to train external third-party models and are never sold; the navigator is an AI tool that operates inside the membership.

Communications

Emails, secure messages, and phone calls. Secure messages are stored as part of your medical record. Phone calls are not recorded.

Used for care coordination and follow-up; never used for marketing.

Website analytics

Coarse, anonymized page views and referrer data so we can understand which articles and pages help potential members.

Used to improve the website and our documentation. We do not use third-party advertising cookies and we never sell behavioral data.

3. How we use your information

To provide the membership: scheduling, clinical care, prescription routing, lab orders, follow-ups, and care coordination with specialists you have explicitly authorized.

To operate the business: billing, fraud prevention, customer support, and product improvements. Aggregated, de-identified statistics may be used internally to evaluate the program.

To communicate with you: appointment reminders, plan changes, billing notices, and — only if you opt in — occasional updates from our care team.

We never use your information to advertise third-party products to you. We never sell your data.

4. When we share information

With you: always, on request. You can download a copy of your records from the member dashboard at any time.

With providers you have authorized: a specialist, hospital, or imaging center that you have explicitly asked us to coordinate with. We share only what is necessary for that visit.

With our service providers: Stripe for billing, our hosting and storage providers for infrastructure, and our pharmacy and lab partners for orders. Each provider is contractually bound to protect your information.

When required by law: we comply with valid legal process. If we receive a subpoena or law-enforcement request, we will notify you before disclosing unless we are specifically prohibited from doing so.

In a clinical emergency: if our medical team determines that disclosure is necessary to prevent imminent harm, we will share the minimum information necessary with emergency responders or treating clinicians.

5. Cookies, analytics, and third-party scripts

We use a small set of strictly necessary cookies that keep you signed in and protect against fraud. Optional analytics cookies (if enabled) collect only anonymized, aggregated page-view counts and IP-truncated location at the country level.

We do not embed Facebook pixel, Google Ads, or any other third-party advertising or remarketing tags on the membership site.

6. Your rights

Access: request a copy of your records at any time.

Correction: ask us to fix anything in your record that is wrong.

Deletion: ask us to delete your account and de-identified clinical records. Note that we are required to retain billing records for the applicable statutory tax and audit window, and HIPAA mandates retention floors for clinical records — see Section 7.

Portability (Export): download your records in a standard format (PDF for the patient-facing summary; FHIR JSON for clinical data on request).

Opt out of marketing: unsubscribe from care-team updates at any time using the link in any email.

Contact us at the email below to exercise any of these rights. We acknowledge within one business day and resolve within thirty days.

7. Retention

Billing records: retained for the applicable statutory tax and audit period. We are unable to delete billing records during that window even on a deletion request, because doing so would break our own tax and audit obligations.

Clinical records (intake answers, document uploads, prescriptions, navigator chat messages, and visit notes): retained for at least the period mandated by applicable state and federal law governing medical records. After that minimum period, clinical records are deleted or fully de-identified on a rolling schedule.

De-identified, aggregated analytics: may be retained indefinitely because they no longer identify you.

Account deletion: on request we delete your account and de-identified clinical records consistent with Section 6 above. Billing records and any clinical records still inside their legally required retention window are kept for that window only and then purged. We will not promise "all data is deleted on request" because HIPAA and state record-retention rules take precedence.

8. Data security

We protect your information with TLS in transit, encryption at rest for clinical records, role-based access controls for staff, and audit logging on every clinical record access. Access to production systems is limited to a small number of named clinical and engineering staff who are bound by confidentiality obligations.

If we ever experience a security incident that affects your information, we will notify you by email within 72 hours of discovery, in line with applicable breach-notification laws.

9. Children

The Blue Line Health website is not directed at children under 13, and we do not knowingly collect information from them. Minor dependents are added to a parent or guardian’s membership rather than holding their own account. Within a Family plan, Virtual Primary Care is available to adult members only, and Psychiatry is available to members 14 and older. Children in a Family plan are enrolled under the parent or guardian’s account and do not hold their own record.

10. Changes to this policy

If we make material changes, we will email active members at least 30 days before the changes take effect and update the “Effective” date below. Continued use of your membership after the effective date constitutes acceptance.

11. Contact

Questions about this policy, a request to exercise your rights, or a privacy complaint: write to us at blueline-health@polsia.app. We read every message ourselves; a member of our care team will reply within one business day.