Last updated: August 4, 2026
Prelude LLC dba Gleam Health (“Gleam Health,” “we,” “us,” or “our”) provides an online appointment scheduling platform on behalf of healthcare providers (“Providers”). This Privacy Policy covers both our online appointment scheduling service (the “Service”) and our separate public Gleam marketing website (“Marketing Website”). The Marketing Website does not handle patient scheduling data. This Privacy Policy describes how we collect, use, and protect your information when you use the Service or Marketing Website.
By using the Service, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Service.
We collect the following categories of information:
Information you provide directly:
Information collected automatically:
We do not collect Social Security numbers, financial account information, or insurance information through the scheduling Service.
We use the information we collect to:
We do not sell your personal information to third parties. We do not use patient or scheduling information collected through the Service for marketing purposes unrelated to your appointment.
This section applies to our public marketing website and is separate from the patient scheduling Service. We use limited campaign measurement to understand campaign effectiveness and campaign attribution. Campaign attribution uses strict UTM source, UTM medium, UTM campaign, and UTM content values, along with the page path and a random tab-scoped campaign session ID.
marketing_ad_landing and the Book 1:1 click event marketing_book_1on1_clicked. Normal campaign analytics persistence is disabled: PostHog sets no campaign analytics cookie or sessionStorage, creates no persistent anonymous identity, and uses no identify, alias, or group methods. If a visitor denies measurement after the SDK exists, PostHog retains one narrowly scoped localStorage opt-out preference named __ph_opt_in_out_<project token> so the vendor stays opted out. Gleam also retains its site-level denial preference. These preferences record denial or consent choices and are not analytics identifiers or profiles. For this integration, autocapture is disabled, session recording is disabled, and no personal data is sent to PostHog. PostHog receives no full URL or referrer, no oppref, and no PHI or personal identifiers. The shared PostHog project's current event retention setting is 84 months.page_viewedevent and the exact book_1on1_clicked Book CTA event for ad attribution when permitted. The SDK may also automatically send initialization or diagnostic events necessary for operation. It may set a first-party __oppref attribution cookie and a first-party__obref browser-identifier cookie, plus an oaiq_cs:<Pixel ID> sessionStorage marker or state. When oaiq("consent", false) runs after the SDK loads, the SDK may also store oaiq_consent in localStorage and set a first-party __oaiq_consent cookie. These values preserve consent or denial state and are not event or profile payloads. OpenAI receives source and referrer metadata reduced to origin and path (not arbitrary or free-text query values), browser/device metadata, event/time metadata, and the opaque oppref attribution value where present. Gleam sends no user object and configures automatic advanced matching off. Our opt_out: true setting requests the SDK's opt-out-from-personalization behavior; it does not disable SDK transport or storage. Vendor-side retention follows OpenAI's then-current Ads terms, data processing addendum (DPA), and privacy controls.Campaign measurement honors a site-level stored denial, Global Privacy Control, and Do Not Track. When measurement is blocked, blocked events are not replayed later.
For this B2B marketing campaign, patient booking information is not used. The campaign integration is configured not to send names, email addresses, phone numbers, PHI, patient booking data, free-text URL query values, or Cal.com form data in these campaign events.
The purpose of this measurement is campaign effectiveness and attribution. No separate session-level export remains after the 48-hour reconciliation, although aggregate experiment reporting may be retained.
Contact support@usegleamhealth.com with privacy questions or to exercise your privacy rights.
When we handle your health-related information on behalf of a Provider, we do so as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”). This means:
Your Provider remains the Covered Entity responsible for their own HIPAA Notice of Privacy Practices, which governs how the Provider uses and discloses your health information more broadly.
We share your information only in the following limited circumstances:
We implement reasonable technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction. These measures include encryption of data in transit, access controls, and regular security assessments.
However, no method of electronic transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
We retain your information only as long as necessary to provide the Service, fulfill the purposes described in this Privacy Policy, and comply with our legal obligations. When your information is no longer needed, we will securely delete or de-identify it.
You may request access to, correction of, or deletion of your personal information by contacting us at the address below. We will respond to your request within a reasonable timeframe and in accordance with applicable law.
For requests related to health information held by your Provider, please contact your Provider's office directly, as they are the Covered Entity responsible for responding to HIPAA-related requests.
The Service is not intended for use by individuals under the age of 18 without the involvement of a parent or guardian. We do not knowingly collect personal information from children under 13. If we learn that we have collected information from a child under 13, we will take steps to delete it promptly.
We may update this Privacy Policy from time to time. If we make material changes, we will update the “Last updated” date at the top of this page. Your continued use of the Service after any changes constitutes your acceptance of the revised Privacy Policy.
If you have questions about this Privacy Policy or our data practices, please contact us at:
Prelude LLC dba Gleam Health
Email: support@usegleamhealth.com