Gleam Health

Privacy Policy

Last updated: August 4, 2026

1. Introduction

Prelude LLC dba Gleam Health (“Gleam Health,” “we,” “us,” or “our”) provides an online appointment scheduling platform on behalf of healthcare providers (“Providers”). This Privacy Policy covers both our online appointment scheduling service (the “Service”) and our separate public Gleam marketing website (“Marketing Website”). The Marketing Website does not handle patient scheduling data. This Privacy Policy describes how we collect, use, and protect your information when you use the Service or Marketing Website.

By using the Service, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Service.

2. Information We Collect

We collect the following categories of information:

Information you provide directly:

  • Name (first and last)
  • Date of birth
  • Appointment preferences (type, date, time, provider)
  • Comments or special requests you submit during booking

Information collected automatically:

  • Browser type and device information
  • Pages visited and actions taken within the Service
  • Date and time of access

We do not collect Social Security numbers, financial account information, or insurance information through the scheduling Service.

3. How We Use Your Information

We use the information we collect to:

  • Process and manage your appointment bookings on behalf of your Provider
  • Verify your identity as an existing patient of the Provider
  • Send appointment-related communications, including confirmations, reminders, and scheduling updates
  • Improve and maintain the performance and security of the Service
  • Comply with legal obligations

We do not sell your personal information to third parties. We do not use patient or scheduling information collected through the Service for marketing purposes unrelated to your appointment.

4. Marketing Website Analytics and Advertising Measurement

This section applies to our public marketing website and is separate from the patient scheduling Service. We use limited campaign measurement to understand campaign effectiveness and campaign attribution. Campaign attribution uses strict UTM source, UTM medium, UTM campaign, and UTM content values, along with the page path and a random tab-scoped campaign session ID.

  • Vercel Web Analytics supplies anonymous, cookie-free pageview corroboration. Our current Hobby reporting window is one month, and Vercel's visitor hash resets and is discarded after 24 hours.
  • PostHog receives only two canonical campaign events: the campaign landing event marketing_ad_landing and the Book 1:1 click event marketing_book_1on1_clicked. Normal campaign analytics persistence is disabled: PostHog sets no campaign analytics cookie or sessionStorage, creates no persistent anonymous identity, and uses no identify, alias, or group methods. If a visitor denies measurement after the SDK exists, PostHog retains one narrowly scoped localStorage opt-out preference named __ph_opt_in_out_<project token> so the vendor stays opted out. Gleam also retains its site-level denial preference. These preferences record denial or consent choices and are not analytics identifiers or profiles. For this integration, autocapture is disabled, session recording is disabled, and no personal data is sent to PostHog. PostHog receives no full URL or referrer, no oppref, and no PHI or personal identifiers. The shared PostHog project's current event retention setting is 84 months.
  • OpenAI Ads Pixel measures the page_viewedevent and the exact book_1on1_clicked Book CTA event for ad attribution when permitted. The SDK may also automatically send initialization or diagnostic events necessary for operation. It may set a first-party __oppref attribution cookie and a first-party__obref browser-identifier cookie, plus an oaiq_cs:<Pixel ID> sessionStorage marker or state. When oaiq("consent", false) runs after the SDK loads, the SDK may also store oaiq_consent in localStorage and set a first-party __oaiq_consent cookie. These values preserve consent or denial state and are not event or profile payloads. OpenAI receives source and referrer metadata reduced to origin and path (not arbitrary or free-text query values), browser/device metadata, event/time metadata, and the opaque oppref attribution value where present. Gleam sends no user object and configures automatic advanced matching off. Our opt_out: true setting requests the SDK's opt-out-from-personalization behavior; it does not disable SDK transport or storage. Vendor-side retention follows OpenAI's then-current Ads terms, data processing addendum (DPA), and privacy controls.

Campaign measurement honors a site-level stored denial, Global Privacy Control, and Do Not Track. When measurement is blocked, blocked events are not replayed later.

For this B2B marketing campaign, patient booking information is not used. The campaign integration is configured not to send names, email addresses, phone numbers, PHI, patient booking data, free-text URL query values, or Cal.com form data in these campaign events.

The purpose of this measurement is campaign effectiveness and attribution. No separate session-level export remains after the 48-hour reconciliation, although aggregate experiment reporting may be retained.

Contact support@usegleamhealth.com with privacy questions or to exercise your privacy rights.

5. HIPAA and Protected Health Information

When we handle your health-related information on behalf of a Provider, we do so as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”). This means:

  • We maintain a Business Associate Agreement (BAA) with each Provider that governs how we handle Protected Health Information (PHI)
  • We use PHI only as permitted by our BAA and applicable law — specifically to provide the scheduling Service on behalf of the Provider
  • We implement administrative, physical, and technical safeguards to protect PHI as required by the HIPAA Security Rule

Your Provider remains the Covered Entity responsible for their own HIPAA Notice of Privacy Practices, which governs how the Provider uses and discloses your health information more broadly.

6. How We Share Your Information

We share your information only in the following limited circumstances:

  • With your Provider: We share your scheduling information with the healthcare provider whose booking page you are using, as necessary to process and manage your appointment.
  • Service providers: We may use third-party service providers (such as hosting and infrastructure providers) who process data on our behalf and are contractually obligated to protect your information.
  • Legal requirements: We may disclose your information if required to do so by law, regulation, legal process, or enforceable governmental request.

7. Data Security

We implement reasonable technical and organizational measures to protect your information against unauthorized access, alteration, disclosure, or destruction. These measures include encryption of data in transit, access controls, and regular security assessments.

However, no method of electronic transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

8. Data Retention

We retain your information only as long as necessary to provide the Service, fulfill the purposes described in this Privacy Policy, and comply with our legal obligations. When your information is no longer needed, we will securely delete or de-identify it.

9. Your Rights

You may request access to, correction of, or deletion of your personal information by contacting us at the address below. We will respond to your request within a reasonable timeframe and in accordance with applicable law.

For requests related to health information held by your Provider, please contact your Provider's office directly, as they are the Covered Entity responsible for responding to HIPAA-related requests.

10. Children's Privacy

The Service is not intended for use by individuals under the age of 18 without the involvement of a parent or guardian. We do not knowingly collect personal information from children under 13. If we learn that we have collected information from a child under 13, we will take steps to delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the “Last updated” date at the top of this page. Your continued use of the Service after any changes constitutes your acceptance of the revised Privacy Policy.

12. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us at:

Prelude LLC dba Gleam Health
Email: support@usegleamhealth.com