Privacy Policy

Effective September 11, 2026

This Privacy Policy explains how Synapse Digital, Inc. (“Synapse Digital,” “we,” “us”) handles information in connection with our web platform at app.synapsedigital.ai and our mobile application, Ensync Mobile (together, the “Services”). Our Services are built for home health and hospice agencies and the licensed clinicians and staff they authorize. They are professional tools, not consumer health apps, and are not offered for individual sign-up.

Our role, and who controls the data

Most of the information handled through the Services is entered or accessed by an agency’s own workforce in the course of caring for patients. For that information — including protected health information (“PHI”) as defined by HIPAA — the agency is the covered entity and the party that controls how the information is used. Synapse Digital acts as a business associate, processing that information only on the agency’s behalf and only as permitted by a written Business Associate Agreement and the agency’s instructions. If you are a patient or a member of the public, requests about your health information should go to your provider; we will support them in responding.

Information we handle

Depending on how the Services are used, this includes:

  • Account information — the name, work email address, agency, and role of the users an agency authorizes, used to sign them in and control what they can see.
  • Health and patient information— the patient identifiers and clinical information an agency’s users enter or view to do their work: for example, a patient’s name and Medicare identifiers, a care profile, and the contents of a visit note. In Ensync Mobile, this is the information a clinician documents during a visit.
  • Technical information needed to operate and secure the Services — for example, the IP address a request comes from and security and audit logs recording sign-ins and key actions.

We do not use advertising identifiers, and we do not include third-party analytics or advertising software-development kits in Ensync Mobile.

How we use information

We use information only to provide, secure, support, and improve the Services — specifically to:

  • authenticate users and enforce access controls, including two-factor authentication;
  • deliver the features an agency and its users ask for, such as composing and finalizing a visit note;
  • keep the Services secure, detect and investigate misuse, and maintain audit trails; and
  • meet our legal and contractual obligations to the agencies we serve.

What we do not do

  • We do not sell personal or health information.
  • We do not use it for advertising, and we do not track users across other apps or websites.
  • We do not use PHI for our own purposes — only to provide the Services to the agency it belongs to.

How information is shared

We share information only as needed to run the Services or as required by law. We rely on vetted service providers (subprocessors) who are bound by written agreements to protect the information and use it only for us — including Microsoft Azure, which hosts the Services in data centers in the United States, and providers that support specific features such as secure email delivery, Medicare eligibility checks, and AI-assisted document processing. A current list of subprocessors is available to agency customers on request. We may also disclose information when required by law or to protect the safety and integrity of the Services.

How we protect information

We encrypt information in transit using TLS and apply administrative, technical, and physical safeguards designed to meet HIPAA’s requirements — including role-based access controls, mandatory two-factor authentication, audit logging, and on-screen and export masking of patient identifiers where an agency enables it. Ensync Mobile stores its sign-in credentials in the device’s secure keystore. No system can be guaranteed perfectly secure, and we work with our agency customers to respond to security events as our agreements and the law require.

How long we keep information

We retain information for as long as needed to provide the Services to the agency and to meet our legal, contractual, and recordkeeping obligations — for example, security and audit records are kept for the periods HIPAA and our agreements require. When information is no longer needed for those purposes, we delete or de-identify it.

Your choices and rights

Because agencies control the health information in the Services, patients and other individuals should direct requests to access, correct, or delete their health information to the agency that provides their care; we assist agencies in fulfilling those requests. If you are an authorized user of the Services, you can update your account information or ask your agency administrator, or contact us at the address below.

The Ensync Mobile app

Ensync Mobile requires an account provisioned by a subscribing agency; it has no public sign-up. It handles the same categories of information described above, solely to let a clinician document patient visits, and transmits them over an encrypted connection to the platform. It contains no advertising or third-party analytics software, and it does not track you.

Children

The Services are workplace tools for healthcare professionals and are not directed to children, and we do not knowingly collect information from children through them. (This does not refer to a patient’s clinical record, which an agency maintains as part of care.)

Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the effective date above and, where appropriate, notify the agencies we serve.

Contact us

Questions about this policy or our privacy practices can be sent to privacy@synapsedigital.ai or through our contact form. Synapse Digital, Inc.