Privacy
What we do with data — and what we won’t.
This policy covers personal information collected on ignitehealth.ai. Protected Health Information processed by PrefillX on behalf of a covered entity is governed by the Business Associate Agreement between IgniteHealth and that entity — not by this page.
Who we are
IgniteHealth, Inc. (“IgniteHealth,” “we,” “us”) is a Delaware corporation. We build AI-native medication-adherence systems for Medicare Advantage and ACO customers. Privacy contact: admin@ignitehealth.ai.
What we collect on this site
This is the complete list. We do not collect anything else.
- Contact form submissions. Name, work email, organisation, role, the topic you selected, and any message you wrote. Optional fields (members covered, current Stars) are blank unless you fill them in.
- Newsletter subscriptions. If you subscribe, we keep your email address and the date you subscribed.
- Server logs. Standard request logs (timestamp, URL, IP address, user agent, referer) are written by our hosting provider and retained for security and operational debugging. IP addresses are not stored alongside form submissions.
- Privacy-first analytics. We use Plausible Analytics, which is cookieless, GDPR-compliant by default, and does not collect personal data. We see aggregated pageviews and referrer statistics — no per-user profiles.
We do not use Google Analytics, advertising trackers, session replay tools, or third-party marketing pixels.
How we use it
- To respond to your inquiry and route you to the right team member.
- To follow up about IgniteHealth — but only if you ticked a relevant topic or explicitly asked to be contacted. No cold-email follow-ups.
- To improve the marketing site. Aggregated analytics tell us which pages people read; we adjust accordingly.
- To meet legal obligations — taxation, audit, regulatory inquiry.
Protected Health Information (PHI)
When IgniteHealth processes PHI for a customer, we do so as a HIPAA business associate under a signed Business Associate Agreement (BAA) with that customer. The BAA — not this policy — governs that data. We sign a BAA with every covered entity before we touch a single resource.
- We never train foundation models on PHI. Customer data is not used to improve our base models, and is not shared with any third-party model provider for fine-tuning or eval.
- We never sell PHI. Or any derivative of PHI. Or anything close to it.
- We never share PHI with anyone outside the explicit scope permitted by the BAA with the customer.
- De-identified, aggregate statistics may be used to publish methodology updates or to improve the protocol, only where the BAA permits and only after the data has been de-identified to the HIPAA Safe Harbor or Expert Determination standard.
Sharing on the marketing site
We do not sell, rent, or share contact-form data with anyone outside IgniteHealth. The only third-party processors involved on this site are:
- Our cloud hosting provider (AWS) — for the hosting itself. A BAA is in place where applicable.
- Plausible Analytics — for cookieless web analytics. No personal data flows.
- Our transactional-email provider — to deliver replies to your contact-form submission.
Cookies
The marketing site uses essential cookies only — for example, a small session cookie to remember if you have dismissed an announcement. No advertising cookies, no third-party tracking cookies, no fingerprinting.
Data retention
- Contact-form submissions are retained for 24 months after the last interaction, then deleted on a rolling schedule.
- Newsletter subscriber lists are retained until you unsubscribe; unsubscribing removes your email from the active list within 7 days.
- Server logs are retained for 90 days for operational and security purposes.
- PHI retention is governed by the BAA with the covered entity.
Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict the processing of your personal information under laws such as the California Consumer Privacy Act (CCPA/CPRA), the Virginia Consumer Data Protection Act, the EU General Data Protection Regulation (GDPR), or other state and national laws. To exercise any of these rights, email admin@ignitehealth.ai and tell us what you want. We respond within 30 days. We do not require an account or paid subscription to honour these requests.
Children
IgniteHealth’s services are not directed at children under 13 (or under 16 where local law requires that age). We do not knowingly collect personal information from children. If you believe we have done so by mistake, write to admin@ignitehealth.ai and we will delete the data immediately.
Changes to this policy
We will update this page when our practices change. Material changes — anything that affects how we collect or use data — will be flagged at the top of the page for at least 30 days. The “Last updated” date at the bottom always reflects the most recent revision.
Contact
For any privacy question, write to admin@ignitehealth.ai. For general inquiries, the contact page is the right entry point.
Last updated: 2026-05-21