Legal · United States

Privacy Policy

How August Labs Inc. collects, uses, and protects your personal information.

Last Modified: May 29, 2026

Our Privacy Commitments

We use data to operate, improve, and develop August, including our AI systems, while placing clear limits on sale, advertising, and third-party model training.

  • We do not sell your health information.
  • We do not use your health information for third-party targeted advertising.
  • We do not allow third-party AI providers to use your identifiable health information to train their own general-purpose models without your consent.
  • We may use information, including de-identified, aggregated, pseudonymized, derived, or synthetic data, to improve, evaluate, develop, train, and fine-tune August's services and AI systems as described in this Policy.
  • Clinical services are provided by independent clinicians or clinical partners. August provides technology, coordination, and support services.

1. Who We Are and Scope of This Policy

August Labs Inc.is a Delaware corporation that provides AI-enabled health information, navigation, support, intake, and care-coordination technology through August's websites, mobile applications, chat products, and related services (the “Services”).

This Privacy Policy explains how August Labs Inc. collects, uses, discloses, retains, and protects personal information when you use the Services. It applies to US residents using August's consumer-facing services.

This Policy should be read together with our Terms & Conditions, any telehealth informed consent presented to you, any applicable Notice of Privacy Practices provided by a clinical partner, and any separate Consumer Health Data Privacy Notice we make available.

Contact: You can reach us about privacy questions or requests at [email protected] or at August Labs Inc., 131 Continental Drive, Suite 301, Newark, DE 19713-4323.

2. Clinical Partners and Telehealth Services

August is not, by itself, a telehealth provider, medical practice, pharmacy, or health plan. Some clinical services available through August may be provided by independent licensed clinicians, medical groups, or clinical partners, including MD Integrations or another partner identified to you before the service is provided.

When you request a telehealth or clinical service, the treating clinician or clinical partner is responsible for clinical decisions, including diagnosis, treatment, prescribing, follow-up, and medical-record obligations. August provides technology, intake, coordination, administrative support, AI-assisted summarization, and related services that help facilitate your interaction with the clinical partner.

If a clinical partner provides a Notice of Privacy Practices, that notice governs the partner's use and disclosure of protected health information for treatment, payment, and healthcare operations. If there is a conflict between this Policy and an applicable Notice of Privacy Practices for protected health information, the Notice of Privacy Practices controls for that protected health information.

Clinical Independence

Independent clinicians and clinical partners exercise their own medical judgment. August does not control or direct a clinician's diagnosis, treatment, prescribing, or other clinical decision-making.

3. Information We Collect

Information You Provide

  • Account information: name, email address, phone number, date of birth, state of residence, login credentials, account preferences, and other registration details.
  • Health conversations and content: symptoms, conditions, diagnoses, medications, allergies, labs, vitals, lifestyle information, care questions, goals, photos, documents, messages, and other information you enter into August.
  • Telehealth intake information: chief complaint, symptom history, medication and allergy information, medical history, consent acknowledgments, preferred pharmacy, and other information needed to facilitate a clinical service.
  • Insurance, payment, and cost information: insurance plan details, member ID, explanation-of-benefits documents, medical bills, cost documents, payment status, and transaction metadata. Payment card details may be processed by our payment processors and may not be stored directly by August.
  • Support and feedback: support requests, survey responses, ratings, product feedback, bug reports, and communications with us.

Information from Clinical Partners and Third Parties

  • Clinical partners: information related to a telehealth request, clinical encounter, prescription, referral, care plan, or follow-up, where provided by or through a clinical partner.
  • Pharmacy and prescription infrastructure: prescription-routing, pharmacy-selection, medication, or prescription-status information where available and relevant to the service you requested.
  • User-authorized sources: medical records, EHR exports, wearable data, lab reports, pharmacy information, identity verification results, or other information you authorize us to receive.
  • Service providers and partners: fraud-prevention signals, analytics, attribution, communications, identity verification, payment, or operational information needed to provide and secure the Services.

Information Collected Automatically

  • Device identifiers, IP address, browser type, operating system, app version, approximate location inferred from IP address, language, and time zone.
  • Usage information, including pages viewed, features used, session duration, referral source, clicks, errors, crash logs, diagnostic logs, and security events.
  • Cookies, pixels, local storage, SDKs, and similar technologies used for authentication, security, analytics, performance, preferences, and service operations.
  • Bot-mitigation: Cloudflare Turnstile verifies human visitors on signup, login, and contact forms. It sets short-lived security cookies (cf_clearance, _cf_bm) and receives IP address, HTTP headers, and browser/device characteristics; it does not receive account content or health information. See the Cloudflare Turnstile privacy notice.

4. How We Use Information

We use personal information for the following purposes:

  • Provide and personalize the Services: answer health questions, generate summaries, maintain context, personalize responses, support care navigation, review bills or cost documents, and provide other requested features.
  • Facilitate clinical services: collect intake information, share relevant information with the applicable clinical partner or treating clinician, support scheduling or follow-up, and help route prescriptions or pharmacy information where applicable.
  • Operate and secure the Services: authenticate users, prevent fraud and abuse, troubleshoot bugs, monitor performance, protect against security incidents, and maintain service reliability.
  • Communicate with you: send account messages, service updates, reminders, support responses, administrative notices, and other communications related to the Services.
  • Improve, evaluate, develop, train, and fine-tune August: analyze usage, measure quality, evaluate safety, improve clinical reasoning and summarization, develop new features, build synthetic and de-identified datasets, conduct quality assurance, and improve our AI systems as described in Section 5.
  • Comply with law and enforce our rights: respond to lawful requests, comply with legal obligations, enforce our Terms, resolve disputes, and protect the rights, safety, and property of August, users, clinicians, partners, or others.

Advertising and Sale Limits

We do not sell your health information. We do not use your health information for third-party targeted advertising or cross-context behavioral advertising.

5. AI Processing and Product Improvement

August is an AI-enabled service. We use information to operate, monitor, evaluate, improve, develop, train, and fine-tune our Services and AI systems, subject to this Policy and applicable law.

How August Uses Data to Improve AI Systems

  • Improve response quality, personalization, clinical reasoning, summarization, routing, retrieval, and safety systems.
  • Evaluate model performance, safety, hallucination risk, refusal behavior, escalation behavior, benchmark performance, and clinical consistency.
  • Develop and test prompts, classifiers, guardrails, triage logic, synthetic patient actors, simulated conversations, evaluation datasets, and other model-improvement workflows.
  • Review conversations, feedback, logs, and outcomes for quality assurance, debugging, safety monitoring, and product development.
  • Create and use de-identified, aggregated, pseudonymized, derived, or synthetic data for analytics, research, development, model training, model fine-tuning, and service improvement.

De-identified, Aggregated, Derived, and Synthetic Data

We may de-identify, aggregate, pseudonymize, transform, derive, or synthesize data from information collected through the Services. We may use and disclose such data for lawful purposes, including analytics, research, product development, safety evaluation, AI model training, model fine-tuning, publications, and business operations.

Where information is protected health information under HIPAA, we treat it as de-identified only when it has been de-identified in a manner permitted by HIPAA or applicable law. De-identified, aggregated, derived, and synthetic data may be retained indefinitely unless applicable law requires otherwise.

Third-Party AI Providers and Subprocessors

We may use third-party AI providers, cloud providers, analytics providers, infrastructure providers, security vendors, and other service providers to process information on our behalf. These providers may process information only to provide services to August, subject to contractual restrictions.

We do not allow third-party AI providers to use your identifiable health information to train their own general-purpose models without your consent. This does not limit August's ability to use information, including de-identified, aggregated, pseudonymized, derived, or synthetic data, to improve, evaluate, develop, train, and fine-tune August's own Services and AI systems as described in this Policy.

Human Review

Authorized August personnel, contractors, reviewers, clinicians, or service providers may review information where needed to provide support, improve the Services, evaluate quality and safety, debug systems, investigate abuse, comply with law, or operate the Services. We limit access based on role and business need.

6. How We Share Information

We share personal information as described below:

Clinical and Telehealth-Related Sharing

  • Clinical partners and treating clinicians: We share intake, health, account, and related information with the applicable clinical partner or treating clinician to facilitate the clinical service you request.
  • Pharmacies and prescription networks: If a treating clinician prescribes medication, information may be shared with prescription-routing networks, pharmacies, and related service providers to transmit or support the prescription.
  • Labs, referrals, or other care partners: Where available and requested or authorized, information may be shared to support referrals, lab orders, follow-up, or other care coordination.

Operational Sharing

  • Service providers: cloud hosting, database infrastructure, AI processing, analytics, customer support, payment processing, identity verification, communications, security, fraud prevention, and product operations.
  • User-directed sharing: people or organizations you ask us to share with, such as a caregiver, family member, clinician, health plan, employer, attorney, or other third party.
  • Business transfers: in connection with a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, subject to appropriate confidentiality or privacy protections.
  • Legal, safety, and compliance: where we believe disclosure is required or permitted by law, legal process, regulation, professional obligations, or is necessary to protect rights, safety, security, or prevent serious harm.
  • De-identified or aggregated data: data that does not identify you may be shared for analytics, research, product development, benchmarking, publication, or other lawful purposes.

Government and Law-Enforcement Requests

We do not voluntarily disclose health information to government or law-enforcement agencies except as described in this Policy, when required or permitted by law, or where necessary to prevent serious harm. Where appropriate and legally permitted, we may seek to narrow or challenge overbroad requests.

7. HIPAA, Protected Health Information, and Clinical Records

Not all information collected by August is protected health information under HIPAA. For example, information you provide directly to August outside of a covered healthcare relationship may be governed by this Privacy Policy and applicable consumer privacy or consumer health data laws rather than HIPAA.

When August processes protected health information on behalf of a HIPAA-covered clinical partner, August may act as a business associate and will handle that protected health information in accordance with the applicable business associate agreement, HIPAA, and the clinical partner's Notice of Privacy Practices.

For telehealth or clinical services, clinical records, diagnoses, prescriptions, treatment notes, and related information may be maintained by the treating clinician or clinical partner. You may have rights to access or amend those records through the applicable clinical partner or as otherwise required by law.

Practical Rule

If information is created or used for a clinical service provided by an independent clinician or clinical partner, the clinical partner's privacy practices and medical-record obligations may also apply.

8. Your Privacy Rights and Choices

Depending on where you live and the type of information involved, you may have rights to access, correct, delete, obtain a copy of, or restrict certain uses of your personal information. You may also have the right to appeal a denied request, designate an authorized agent, or withdraw consent where processing is based on consent.

Rights Available to Many Users

  • Access: request a copy of personal information we maintain about you.
  • Correction: ask us to correct inaccurate personal information.
  • Deletion: ask us to delete personal information, subject to legal, clinical, security, fraud-prevention, backup, dispute-resolution, and operational exceptions.
  • Portability: request a copy of certain information in a portable format where required by law.
  • Opt-out: opt out of sale, sharing, targeted advertising, or certain profiling where those rights apply. August does not sell health information or use health information for third-party targeted advertising.
  • Limit or withdraw consent: limit use of certain sensitive information or withdraw consent where applicable law gives you that right.

How to Exercise Your Rights

  • In-app: Account Settings → Privacy → Manage My Data, where available.
  • Email: [email protected]. Include your account email and the request type.
  • We may need to verify your identity before completing a request.
  • We will not discriminate against you for exercising privacy rights required by applicable law.

California and Other State Privacy Rights

Residents of California and other states may have additional rights under state privacy laws, including rights to know, access, correct, delete, port, opt out of certain processing, limit certain uses of sensitive personal information, or appeal a decision. We honor these rights where required by applicable law.

California residents may designate an authorized agent to submit requests on their behalf. We may require proof of authorization and identity verification.

9. Data Retention and Deletion

We retain personal information for as long as reasonably necessary to provide the Services, maintain your account, improve and secure our systems, comply with legal and clinical obligations, resolve disputes, enforce agreements, and support legitimate business purposes.

Data CategoryGeneral Retention Approach
Account and profile informationRetained while your account is active and for a reasonable period after closure, unless longer retention is required or permitted by law.
Health conversations and user-provided contentRetained as needed to provide continuity, personalization, safety, support, quality assurance, product improvement, legal compliance, and dispute resolution.
Telehealth and clinical recordsRetained by the applicable clinical partner, and by August where applicable, as required by medical-record, HIPAA, contractual, and other legal obligations.
Payment, tax, and transaction recordsRetained as required for accounting, tax, audit, payment, chargeback, and compliance purposes.
Security, diagnostic, and usage logsRetained for security, debugging, analytics, fraud prevention, service reliability, and operational purposes, generally for a limited period unless needed longer.
De-identified, aggregated, derived, or synthetic dataMay be retained indefinitely and used for lawful purposes, including analytics, research, product development, AI training, and model improvement.

When you request deletion, we will delete or de-identify personal information as required by applicable law. We may retain information where needed for legal, clinical, security, fraud-prevention, backup, dispute-resolution, tax, accounting, or compliance purposes. Deletion requests do not require us to delete de-identified, aggregated, derived, or synthetic data that no longer identifies you.

10. Consumer Health Data Notice

Some state laws regulate “consumer health data” or similar categories of health-related personal information. Depending on where you live and how you use the Services, information we collect may include consumer health data such as symptoms, conditions, diagnoses, medications, allergies, lab values, vitals, reproductive or sexual health information, mental health information, substance-use information, gender-affirming care information, disability-related information, biometric or genetic information if provided, health-related inferences, and information about healthcare services you request.

We collect and use consumer health data for the purposes described in this Policy, including providing the Services, facilitating clinical services you request, communicating with you, operating and securing the Services, complying with law, and improving, evaluating, developing, training, and fine-tuning August's services and AI systems.

Where required by law, we will provide a separate Consumer Health Data Privacy Notice that describes consumer health data categories, purposes of collection, sources, disclosures, and applicable rights. If that notice applies to you and conflicts with this Policy, the more specific notice controls for consumer health data covered by that law.

11. Children and Minors

The Services are intended for users who are 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If we learn that a person under 18 has provided personal information through the Services, we will take appropriate steps to delete the information or account, unless retention is required by law. If you believe a minor has provided us with information, contact [email protected].

12. Data Security

We use administrative, technical, and organizational safeguards designed to protect personal information, including health-related information. These safeguards may include encryption in transit and at rest, access controls, authentication controls, bot-mitigation on pre-authentication surfaces, logging, monitoring, vendor review, confidentiality obligations, and security testing.

No system is perfectly secure. You are responsible for maintaining the confidentiality of your login credentials and for using secure devices and networks when accessing the Services.

13. Security Incidents and Breach Notification

If we discover a security incident that requires notice under applicable law, we will notify affected users, regulators, clinical partners, service providers, and other parties as required by law. The timing, content, and recipients of notice may vary depending on the type of information involved, the applicable law, and the circumstances of the incident.

We will provide public, substitute, or media notice only where required by applicable law.

14. International Processing

August is based in the United States, and information may be processed in the United States and other countries where August, its affiliates, personnel, contractors, service providers, or partners operate. These countries may have privacy laws that differ from the laws where you live. We use contractual, technical, and organizational safeguards where required by applicable law.

15. Changes to This Policy

We may update this Policy from time to time. If we make material changes, we will provide notice through the Services, by email, or by another legally sufficient method. The updated Policy will be effective as of the date stated at the top of the Policy unless otherwise stated. Where required by law, we will obtain consent before applying material changes to certain existing data uses.

16. Contact Us

If you have any questions, please contact us:

Privacy Requests

[email protected]

Company

August Labs Inc.

Mailing Address

131 Continental Drive, Suite 301
Newark, DE 19713-4323

If you have concerns about our privacy practices, you may contact us at the email above. You may also have the right to contact your state Attorney General, state privacy regulator, the Federal Trade Commission, or another regulator depending on where you live and the type of information involved.

Your health journey starts with a single question

Download August today. No appointments. Just answers you can trust.

Hand reaching for August Health app icon