Primary Square

Privacy policy.

Effective date: August 19, 2026

Primary Square, Inc. ("Primary Square," "we," "us") operates a health technology platform: an electronic health record system used by independent medical practices, a member application, and a personal health record we call the Vault. This policy explains what information we collect, how we handle it — with particular care for health information — and the choices and rights you have. It applies to primarysquare.com and to our applications and services.

One idea organizes everything below: your health information is used to support your care, and for no other reason. We do not sell it. We do not use it for advertising. We do not use it to train artificial-intelligence models.

Who we are — and who your medical providers are

Primary Square is a technology company. We do not practice medicine. Medical care is provided by independent medical practices and clinicians ("providers") who use our platform. When a provider treats you, your medical record with that provider is governed by the federal Health Insurance Portability and Accountability Act ("HIPAA") and by that provider's own Notice of Privacy Practices, which the provider gives you directly. In that relationship, Primary Square acts as the provider's "business associate" under HIPAA: we handle your health information on the provider's behalf, under written agreements that bind us to HIPAA's safeguards.

The information we collect

Account and profile information: your name, contact details, date of birth, identity-verification information, and login credentials.

Health information you give us: answers to health questionnaires, documents and records you upload, and information you enter in the Vault.

Health records you direct us to retrieve: at your request and with your verified identity, we can help you collect copies of your own medical records from other healthcare organizations — for example through national health information networks and patient portals you connect. These records go into your Vault because you asked for them; you control them.

Health records retrieved for your treatment: when you are a patient of a provider on our platform, that provider may retrieve your medical history through national health information networks so your care is based on your complete record. These retrievals occur only within a documented treatment relationship with your provider.

Payment information: when you pay for memberships or services, payments are processed by us or our payment processors; card numbers are handled by the processor, not stored by us.

Technical information: device, browser, and usage information that keeps the service secure and working. We do not use advertising trackers on pages where you handle health information.

How we use health information

To provide your care experience: assembling your records in the Vault, organizing and summarizing your history so you and your care team can use it, supporting appointments, lab orders and results, care plans, and ongoing care-related alerts to your care team.

To operate the service on behalf of your providers: the uses HIPAA permits a business associate — supporting treatment, running the record system, and meeting legal obligations.

With artificial intelligence, carefully: our AI features organize, summarize, and present your information to support your care. AI outputs that inform clinical decisions are reviewed by licensed clinicians. Your health records are used by AI only to serve you in the moment — we do not use health records retrieved from health information networks, or your medical records generally, to train, tune, or develop AI models.

What we never do with your health information

We do not sell your health information, and we do not license it to third parties. We do not use it for advertising or marketing. We do not use records retrieved from health information networks for analytics unrelated to your care, for provider recruitment, or for AI model training. We do not aggregate or de-identify network-retrieved records for our own commercial purposes.

How we share information

With your providers and care team, for your treatment. With service providers (such as hosting, identity-verification, payment, and interoperability vendors) who work under contracts that limit their use of your information to providing services to us and, where health information is involved, bind them to HIPAA-level safeguards. With health information networks, only as described above and subject to network rules — and when your provider's practice responds to a lawful network request from another treating provider, only records originated by that practice are shared, with legally protected categories (such as substance-use-disorder treatment records) withheld as the law requires. As required by law, such as in response to lawful process. In a corporate transaction, where the recipient must honor this policy's commitments for previously collected information.

Two legal regimes, one standard of care

Some information we hold is protected by HIPAA (records we maintain as a business associate of your providers). Other information — such as records you direct into your own Vault before you have a provider on the platform — sits outside HIPAA and is protected instead by federal consumer-protection law (including the FTC Health Breach Notification Rule) and state privacy laws. We apply the same safeguards to both: HIPAA-grade administrative, technical, and physical protections for all health information on our platform, regardless of which law technically governs it.

Security

We protect information with encryption in transit and at rest, role-based access controls, audit logging of access to health records (including a log of every network record retrieval, its purpose, and the requesting clinician), employee training, and continuous monitoring. No system is perfectly secure; if a breach affects your unsecured health information, we will notify you and regulators as the law requires.

Your rights and choices

Your Vault is yours: you can view, download, correct, and delete the information you keep in it, and you can disconnect any source you connected. For records that are part of a provider's medical record, HIPAA gives you rights of access, amendment, and an accounting of certain disclosures — exercise those with your provider, and we support the provider in honoring them. Depending on your state, you may have additional rights (such as access, correction, deletion, and portability) under state privacy law, including for Virginia residents under the Virginia Consumer Data Protection Act; we honor verified requests as those laws require. Deleting your account deletes your Vault, subject to records we must retain for a provider's medical record or as required by law.

Children

Our services are for adults. We do not knowingly collect information from anyone under 18 except within a provider's care of a minor patient with parental or guardian involvement, or as otherwise permitted by law.

Changes to this policy

We will post any changes here with a new effective date, and for material changes affecting health information we will notify you in the app or by email before they take effect. We will never weaken the "never" commitments above for information already collected without your consent.

Contact us

Questions, requests, or concerns: [email protected]. You may also write to Primary Square, Inc., Attn: Privacy, 5850 T.G. Lee Blvd., Suite 460, Orlando, FL 32822. If you believe your HIPAA rights have been violated, you may also file a complaint with your provider or with the U.S. Department of Health and Human Services Office for Civil Rights.