Ava

CardioOptimizer

Privacy Policy

Last updated: August 1, 2026

This is the CardioOptimizer privacy policy (“CardioOptimizer,” “we,” “us”). This policy describes what personal information we collect when you use CardioOptimizer, how we use it, and the choices you have.

We built CardioOptimizer to serve cardiovascular service line leaders. We collect only what we need to give you a decision-grade readiness assessment and to keep the service running responsibly.

What we collect

When you interact with Ava (our AI advisor), we may collect:

  • Profile information you provide: your name, organization, role, program size, and the cardiovascular challenges you tell us about.
  • Assessment responses: the questions Ava asks and the answers you give during a readiness assessment.
  • Email address, if you enter one to receive your assessment report or to request an introduction to a partner.
  • Session metadata: a randomly-generated session ID, timestamps, and a visitor-identifier cookie so we can continue your conversation if you return.
  • Basic technical data automatically sent by your browser: IP address, browser type, and pages viewed. We use this for security, abuse prevention, and service reliability.

We do not knowingly collect information from anyone under 18. CardioOptimizer is intended for healthcare professionals.

We do not intentionally collect protected health information (PHI) about identifiable patients. If you share patient-identifying details during a conversation, please avoid doing so — Ava is a strategy tool, not a clinical system, and is not a HIPAA-covered business associate.

How we use it

  • To generate your readiness assessment and recommendations.
  • To improve the quality of Ava’s advice through internal review.
  • To route introductions to partner vendors when you request them by clicking the “Ask Ava to introduce you” call to action on a partner card.
  • To respond to your questions and provide customer support.
  • To detect and prevent abuse, security incidents, and service disruptions.

Who we share it with

We use third-party providers to run the service. Each provider processes only what’s needed to perform its function. Current providers:

  • Anthropic — powers Ava’s conversation and analysis.
  • OpenAI — content moderation and semantic search embeddings.
  • Pinecone — vector database for our cardiovascular knowledge base.
  • Supabase — database and account authentication.
  • Vercel — hosting, edge network, and platform security.
  • Resend — transactional email delivery (assessment reports, partner introductions).
  • Sentry — error monitoring so we can detect and fix issues quickly.

When you request an introduction to a partner vendor, we send that partner your email address and a short context snippet — specifically, the last two things you typed to Ava, capped at 600 characters. Your transcript, your scores, your recommendations, and the rest of your conversation stay private. You are in control of that action: no vendor receives anything about you until you click “Ask Ava to introduce you” on a partner card.

We do not sell personal information. We do not share it with advertisers.

We may disclose information if required by law, to protect our rights, or if we’re involved in a merger, acquisition, or asset sale (in which case we’ll give notice before your information becomes subject to a different policy).

How long we keep it

We retain assessment sessions and associated conversation records for up to 24 months from the date of your last activity, so we can continue to serve you if you return and so we can improve Ava’s recommendations. You can ask us to delete your data sooner (see “Your choices” below).

Error logs and technical telemetry are retained for shorter windows (typically 30 to 90 days) sufficient to diagnose incidents.

How we protect it

  • All data in transit is encrypted (TLS 1.2 or higher).
  • Database credentials are stored in a secrets manager, not in code.
  • Admin dashboards are behind authentication; access is limited to CardioOptimizer personnel.
  • Session identifiers are randomly generated with high-entropy UUIDs (not sequential), making URLs non-guessable.
  • Rate limits and abuse protections run on every request.

Cookies

We use only cookies that are strictly necessary to operate the service — chiefly, to keep you signed in and to remember your session so a returning visitor can pick up where they left off. We do not use advertising cookies. We do not use third-party analytics that profile you across sites.

Your choices

You have the right to know what personal information we hold about you, to correct it, to request deletion, and to opt out of communications. To exercise any of these rights, email us at privacy@cardiooptimizer.com. We respond within 30 days.

California residents: under the CCPA/CPRA, you have specific rights, including the right to know, delete, correct, and limit use. We do not sell or share personal information as defined by the CCPA.

Changes to this policy

When we make material changes, we update the “Last updated” date at the top of this page and, where appropriate, notify you by email. Continued use of CardioOptimizer after changes means you accept the updated policy.

Contact

Questions or requests: privacy@cardiooptimizer.com

CardioOptimizer
(Address available on request)