Privacy Policy
This document has no effective date yet — see the notice above.
Information we collect
When a practice signs up, we collect account and practice details (name, contact information, billing details). When a practice uses Alcove to run their business, they enter information about their clients — including protected health information — on the practice's own instructions. We also collect usage data (log-in activity, audit events) needed to operate and secure the service.
How we use information
- To provide and operate the service (booking, telehealth, documentation, billing).
- To secure accounts and detect misuse, including audit logging.
- To communicate with practices about their account and the service.
- To meet legal and contractual obligations.
How information is shared
We share information with the subprocessors listed on our Subprocessors page, each bound by its own data protection terms, and only as needed to operate the service. We do not sell personal information or client data.
Data security
Data is encrypted in transit and at rest. Access to client data is scoped by organization and role — see our Security page for the technical controls in place.
Retention and deletion
Practices can configure retention periods per resource type (notes, recordings, transcripts, messages, documents), subject to any applicable legal hold. Requests for export or deletion are handled through the practice's own compliance tools, or by contacting us directly.
Your rights
Depending on your jurisdiction, you may have rights to access, correct, or request deletion of your personal information. If you are a client of a practice using Alcove, please contact that practice directly, as they control your record.
Changes to this policy
We will post any changes to this page and update the effective date once this document has completed legal review.
Contact us
Questions about this policy can be sent to our contact page.