This policy covers visitors to this website. It is not a Notice of Privacy Practices — patient health information is held by the independent practices that deliver care, under their own notices.
Effective: September 1, 2026 · Last updated: September 1, 2026
This website is operated by Corevia Health, LLC, a California limited liability company ("Corevia", "we", "us"). Our business address is:
Corevia Health, LLCOur privacy contact is legal@coreviahealth.com.
This policy describes what happens to ordinary website visitor information — the data created when someone browses these pages, and what people choose to send us when they email us or ask for a demo. That is the entire scope of this document.
It does not cover protected health information. It is important to be precise about why.
Corevia is a business associate, not a covered entity. Corevia provides technology, administrative and business-support services. Medical care is delivered exclusively by independent, physician-owned professional practices. Those practices are the covered entities under HIPAA; they hold the patient relationship and the patient record.
Protected health information that Corevia processes is governed by HIPAA, each practice's own Notice of Privacy Practices, and the Business Associate Agreement between Corevia and that practice — not by this page. This policy cannot and does not change any of those. If you are a patient asking how your health information is handled, the answer is in the Notice of Privacy Practices published by the healthcare brand or practice you enrolled with, not here.
We keep this deliberately small. There are three categories.
If you email us, request a demo or ask for materials, we receive whatever you put in that message — typically your name, your email address, your company, your role, and whatever you chose to write. We did not ask you for anything else, and we do not enrich it from outside sources.
Our demo request page asks a short series of questions about what you are building. Your answers stay in your browser while you work through them and are transmitted only when you send them at the end. It is a business enquiry form: please do not enter patient information into it.
Every request to any web server produces a record of the request. Ours are no different: IP address, browser type and user agent, the pages and files requested, timestamps, and the referring page if your browser sends one. This is a byproduct of serving the site, and we use it to operate and secure it.
See section 4 below, which states exactly what is and is not in use today.
This site uses no advertising, marketing or session-recording technology of any kind. There is no Google Analytics, no advertising pixel, no heatmap or session-replay tool, no chat widget and no social media tag. We do not sell or share personal information, and nothing on this site follows you to another website.
We use one measurement tool, and it is a deliberately limited one. Cloudflare Web Analytics tells us how many people visited a page and roughly where in the world they came from. It sets no cookies, writes nothing to your browser's storage, does not fingerprint your device and does not track you across sites. Because it stores no identifier, it cannot follow an individual visitor from one page to the next, and we cannot use it to single you out. That is a real limitation for us and the reason we chose it.
The only cookies that may be set are those strictly necessary to serve the site and keep it functioning, together with a single local record of your own cookie preferences if you set them.
| Tool | Purpose | Data collected | Retention |
|---|---|---|---|
| Cloudflare Web Analytics | Aggregate page-view and performance measurement | Page URL, referrer, approximate country, browser and device type, page load timings. No cookies, no client-side storage, no cross-site identifier. | Aggregated; retained by Cloudflare per its published retention for this product |
Why the list is this short. The California Invasion of Privacy Act has produced an active wave of litigation against website operators over trackers, session recording, chat widgets and third-party pixels deployed without clear disclosure and consent. Healthcare-adjacent sites have drawn a disproportionate share of it. We chose a cookieless, storage-free measurement tool specifically so that this page could stay short and accurate.
If an analytics, advertising, chat or session-recording tool is ever added here, this section and the subprocessors page will be updated before it is deployed, not after.
We use the information described above to:
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We do not run advertising on this site and we do not build advertising profiles from it.
We share information in three narrow circumstances:
That is the complete list. We do not sell personal information to anyone.
Business correspondence — the emails and demo requests described in section 3(a) — is retained for as long as needed for the relationship it relates to, plus a reasonable period afterwards for record-keeping and legal purposes: ordinarily up to three years after our last substantive contact with you, and up to seven years where a tax, accounting or contractual record-keeping obligation applies to the correspondence.
Server and technical logs described in section 3(b) are kept for a short operational period and then discarded: ordinarily 30 days, and in no case more than 90 days, except where a specific log is preserved longer as part of an active security investigation.
Aggregate analytics described in section 4 contain no identifier for you and are not subject to a per-person retention period; they are retained in aggregate form by Cloudflare under its published retention for that product.
Where we are required by law or contract to retain something longer, we do.
We describe our technical and organizational safeguards on the security page. Those controls apply to the Corevia platform; this marketing website is a static site with a much smaller surface.
This website is not a channel for protected health information. Do not send patient information, medical records or any other sensitive personal information to us by email or through this site. Ordinary email is not a secure channel, we do not want to receive clinical data here, and if you send it we will delete it. If you are a patient, contact the healthcare brand you enrolled with through the channel it provides.
You can ask us to access, correct or delete the information you sent us. Email legal@coreviahealth.com and tell us what you would like done. We will verify that the request comes from you — in practice, that usually means replying from the address the information came from — and respond within the time the applicable law allows.
If you receive a marketing email from us, you can unsubscribe using the link in that email or by replying and asking. We will still send you operational replies to messages you send us.
These requests concern information held by Corevia about you as a website visitor. Requests about patient records must go to the practice that holds them.
The California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, "CCPA/CPRA"), gives California residents specific rights. Those rights are:
To exercise any of these rights, email legal@coreviahealth.com. An authorized agent may submit a request on your behalf with proof of authorization. We do not use or disclose sensitive personal information for purposes that would require a "limit the use of my sensitive personal information" link.
Applicability to be confirmed by counsel. CCPA/CPRA obligations attach to businesses above statutory thresholds for revenue, consumer volume, or share of revenue derived from selling or sharing personal information. Corevia may well sit below those thresholds today. This section is included as good practice and because buyers ask for it, not as a concession that the statute applies — counsel should confirm current applicability and adjust the wording accordingly.
This website is intended for a business audience and is not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child has sent us information, email legal@coreviahealth.com and we will delete it.
This website, Corevia's platform and the care delivered through it are intended for the United States. We do not offer goods or services to residents of the European Union or the United Kingdom and do not monitor their behavior. If you access this site from outside the United States, you do so on your own initiative, and you understand that any information you send us is transferred to and processed in the United States, where privacy law differs from the law where you live.
We may update this policy from time to time. The "last updated" date at the top will change, and the updated version applies from the date it is posted. Where a change is material — most obviously, adding any tracking technology — we will update this page before the change takes effect rather than after.
Privacy questions and requests: legal@coreviahealth.com
General enquiries: hello@coreviahealth.com