Privacy Policy
- Effective Date:
- July 30, 2026
- Last Updated:
- July 30, 2026
Elrond Health Inc., doing business as Rivendell and, in California, as Rivendell Insurance & Administration Services ("Rivendell," "we," "us," or "our"), provides websites, portals, mobile applications, insurance producer and administration services, and member support (collectively, the "Services").
This Privacy Policy explains how Rivendell collects, uses, discloses, and retains personal information when Rivendell determines the purposes and means of processing. It also explains your choices.
This policy applies to:
- visitors to rivendell.health and other pages that link to it
- prospects and people requesting plan information or a quote
- employers, plan sponsors, brokers, and their representatives
- members, dependents, parents, guardians, and authorized representatives
- users of Rivendell's web portals, mobile apps, support, and communication channels
The California Privacy Supplement provides additional California notices. The Terms of Service govern use of the Services.
1. Health-plan information and HIPAA
A group health plan is generally the HIPAA covered entity for protected health information maintained for that plan. Rivendell may process that information as the plan's business associate, administrator, or agent under a contract. The applicable plan's Notice of Privacy Practices explains the plan's uses and disclosures of protected health information, your HIPAA rights, and how to submit a HIPAA request or complaint.
This general Privacy Policy does not replace a plan's Notice of Privacy Practices and does not give Rivendell independent authority to use plan protected health information. If this policy conflicts with a plan notice or Rivendell's business associate agreement, the plan notice and agreement control for that information.
Rivendell may separately control information collected from a public-site visitor, prospect, business contact, or user outside a covered plan function. This policy applies to that processing.
California's Confidentiality of Medical Information Act ("CMIA") protects medical information maintained through Rivendell's consumer health application even when HIPAA does not apply to the same activity. We maintain the confidentiality of that medical information. We disclose it to contracted service providers as permitted by Civil Code section 56.10(c)(3), with a valid authorization when one is required, or as otherwise required or permitted by law. The California Privacy Supplement explains this further.
2. Information we collect
The categories below describe information Rivendell may have collected during the prior 12 months. The exact information depends on your relationship with us and the features you use.
| Category | Examples |
|---|---|
| Identity and contact | name, date of birth, mailing and email address, phone number, signature, account identifier, government-issued identifier, Social Security number where required, and identity-verification results |
| Employer, broker, and professional | employer, job title, work location, employment status, broker relationships, producer information, authority, group and plan identifiers, and business communications |
| Enrollment, eligibility, and household | census data, hire and termination dates, coverage election, effective date, qualifying event, dependent and beneficiary information, relationship, guardianship, and enrollment status |
| Health and medical | conditions, medications, major care history, accessibility needs, lab data, and service or CPT information contained in an invoice or other record you submit |
| Plan, reimbursements, and benefits | plan selection, coverage, deductible and out-of-pocket activity, member-submitted bills and reimbursement requests, benefit explanations and appeals, allowed amount, member responsibility, and payment status |
| Financial and transaction | bank-linking tokens and account details, account ownership, routing information where required, premium, copay, ACH, card, HSA, balance, merchant, authorization, settlement, reversal, dispute, and fraud information |
| Files and content | census files, plan documents, invoices, receipts, lab reports, images, messages, prompts, assistant conversations, form entries, feedback, and electronic signatures |
| Mobile permissions and device features | approximate or precise location if enabled, camera and photo or document scans, selected calendar events, push-notification token, Face ID authentication result, and wallet or payment-pass provisioning status |
| Communications and support | secure messages, email, SMS, MMS, iMessage, phone contact records, support requests, notification preferences, and correspondence |
| Device, usage, and security | IP address, cookie or device identifier, browser, operating system, app version, pages and features used, referring source, timestamps, crash and performance data, access logs, authentication events, and suspected fraud |
| Derived information | document extraction, summaries, assistant responses, risk or security signals, service recommendations, and other inferences created from the information above |
We do not require every category from every person. Please do not provide information that a form or authorized support representative has not requested.
3. Sources
We collect information:
- directly from you
- from a parent, guardian, dependent, beneficiary, or authorized representative
- from an employer, plan sponsor, group health plan, broker, producer, administrator, or insurer
- from health care providers, laboratories, plan administrators, care partners, and records you authorize
- from banks, card partners, HSA custodians, payment processors, and transaction networks
- automatically from browsers, devices, apps, cookies, SDKs, logs, and security systems
- from government, licensing, sanctions, address, and other permitted reference sources
- from service providers that perform a requested function
- by deriving or combining information as described in this policy
If you provide another person's information, you represent that you are authorized to do so and will provide any notice or obtain any permission required by law.
4. Why we use information
We use personal information to:
- provide public plan information, respond to inquiries, prepare quotes, and support licensed producer services
- establish and secure accounts and verify identity, authority, and eligibility
- operate enrollment, eligibility, billing, administration, reimbursements, appeals, and plan support
- display plan, benefit, balance, reimbursement, provider, payment, card, and HSA information
- process authorized premium, copay, reimbursement, card, HSA, and bank transactions
- receive, store, extract, validate, and route documents
- provide support, concierge, provider-search, scheduling, and communication features
- provide an assistant and other automated features with the disclosures and permissions described below
- deliver legal, plan, security, transaction, service, and consented marketing communications
- maintain, debug, secure, measure, and improve the Services
- prevent fraud, misuse, security incidents, and harm
- meet plan, contractual, tax, accounting, insurance, financial, regulatory, litigation, and legal obligations
- exercise or defend legal rights and complete a corporate transaction
We use sensitive information only for the requested service, security, legal compliance, or another purpose allowed by law. We do not use health or financial information for unrelated advertising.
5. Artificial intelligence and automated processing
Some features use third-party artificial-intelligence or document-processing providers. Before a mobile feature sends personal information to a third-party AI provider, Rivendell identifies the provider, the information sent, and the purpose, then requests explicit permission. Acceptance of this policy is not that permission. We use contracted vendors to perform services on Rivendell's behalf as permitted by CMIA. If a disclosure instead requires a CMIA authorization, we obtain that separate authorization.
| Provider | Current or proposed function | Information that may be sent |
|---|---|---|
| Anthropic | member assistant, medical-history normalization, lab extraction, and provider-review summaries | prompts, assistant history, relevant plan, reimbursement, appointment, lab, medical-history, and member context needed to answer, extract, or summarize |
| Reducto | invoice and receipt extraction | the submitted invoice or receipt and the minimum account or reimbursement context needed to return extracted fields |
| OpenAI | public plan-information assistant | public plan facts and the prompt; authenticated member or health data is not intentionally provided to this feature |
Rivendell uses AI output to assist users and staff. Automated output can be incomplete or wrong. Users and authorized staff should review extracted values and material actions. Rivendell does not authorize a provider to use personal information sent for these features to train a provider's general model.
You may withdraw permission for future optional AI transfers through the feature or by contacting privacy@rivendell.health. Withdrawal does not undo processing that occurred while permission was valid. A non-AI method will be offered where legally required or reasonably available. Some optional features may not function after permission is declined.
Rivendell does not use an automated system as the sole basis for a final adverse eligibility, coverage, reimbursement, or other plan decision when law requires human review.
6. When we disclose information
We disclose the minimum information reasonably needed for the permitted purpose to:
Employers, plans, and authorized representatives
We disclose enrollment, eligibility, plan, reimbursement, payment, and administrative information to the employer, plan sponsor, group health plan, fiduciary, broker, administrator, parent, guardian, or other representative authorized to receive it. Access is limited by plan rules, law, role, and contract. An employer does not receive protected health information merely because it sponsors a plan.
Health care and plan operations
We disclose information to providers, laboratories, care-navigation partners, plan administrators, stop-loss partners, and other parties involved in an authorized plan or care-support function. The applicable Plan Documents and NPP govern protected health information.
Financial and transaction partners
We disclose information to Increase, Stripe Financial Connections, HSA custodians, banks, card networks, payment processors, fraud providers, and their regulated partners as needed to link an account, issue or service a card, move funds, settle or reverse transactions, prevent fraud, and comply with financial law. Their agreements and privacy notices also apply.
When the Gramm-Leach-Bliley Act, Regulation P, or the California Financial Information Privacy Act governs financial information, the applicable financial institution's own privacy notice explains its collection, disclosure, choices, and security duties. Rivendell provides or links to that notice at the point required for the financial service.
Technology and operations providers
We use providers for hosting and file storage, document processing, AI, email and push delivery, communications, identity and security, analytics, diagnostics, support, professional advice, and similar operations. Current integrations include Cloudflare, Anthropic, Reducto, OpenAI, Resend, Apple, PostHog, Sentry, Increase, Stripe, and Google for sign-in and location search.
Providers may use information only for contracted services and legal obligations. Where required, they sign a business associate agreement or another data-protection agreement.
At your direction
We disclose information when you direct us, connect a service, request that we send a record, or give valid permission. A receiving party's own privacy policy applies after it receives information as an independent party.
Legal, safety, and rights
We may disclose information when required or permitted by applicable law to respond to valid legal process, protect a person, prevent fraud or security harm, enforce an agreement, respond to a regulator, or establish or defend legal claims. Health, plan, and insurance information remains subject to any stricter limits that apply. California law imposes special restrictions on some requests involving abortion, contraception, gender-affirming care, sensitive services, or immigration enforcement.
Corporate transactions
Information may be reviewed or transferred as part of financing, due diligence, merger, acquisition, reorganization, bankruptcy, or sale of all or part of the business. Recipients must protect it consistently with law and applicable contracts.
We do not disclose personal information to data brokers. We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising.
7. Cookies, analytics, and tracking choices
Our websites and web views use:
- essential storage for authentication, security, preferences, and requested features
- measurement tools to understand performance and feature use
- diagnostics to identify errors and security events
We configure analytics and diagnostics to avoid collecting the content of health, reimbursement, financial, and assistant fields.
You can control nonessential cookies through our cookie control where offered and through your browser. Blocking essential storage can prevent sign-in or other requested functions.
We honor a valid Global Privacy Control signal as an opt-out request where the CCPA applies and the signal is required for the processing at issue. Because there is no uniform Do Not Track standard, our Services do not otherwise respond to browser DNT signals. We do not permit third parties to collect personally identifiable information across unaffiliated websites through our authenticated member Services for their own advertising.
8. Mobile permissions
The app requests a device permission only when a related feature needs it:
- Location: to search for nearby care or support location-dependent plan functions
- Camera or photos: to scan or upload a document, invoice, receipt, card, or other selected image
- Calendar: to add or help manage a selected appointment
- Notifications: to send plan, reimbursement, card, transaction, appointment, support, security, and other enabled updates
- Face ID: to protect local access on a supported device
- Wallet: to provision an eligible payment pass
You can decline or revoke a permission in device settings. The related feature may stop working, but unrelated features will remain available where practical.
9. Communications
We send service and legal communications needed for your account, plan, transaction, or security. You may control optional notifications in the app or device settings. You can unsubscribe from marketing email through the message link.
SMS, MMS, and iMessage can pass through systems Rivendell does not control and may not be end-to-end encrypted. Do not send sensitive health, identity, or financial details through an ordinary message. The Mobile App Terms explain messaging consent, charges, STOP, and HELP.
10. Retention and deletion
We retain information only while reasonably needed for the purpose collected, an active service, security, dispute, or a legal, plan, insurance, tax, accounting, or financial obligation. We consider the data's sensitivity, the risk of harm, available deletion controls, and whether a purpose can be met with less information.
Our retention criteria are:
| Record | Period or criterion |
|---|---|
| Public-site analytics | while needed to measure and secure the site, then deleted or aggregated under the applicable analytics configuration |
| Account profile and preferences | while the account is active, then deleted or de-identified after account closure unless another row applies |
| Assistant conversation | until the user deletes it or after 365 days of inactivity, subject to a legal hold and processor deletion lag |
| Support communication | while needed to resolve and document the request, then according to any plan, insurance, dispute, or legal requirement |
| Quote and prospect record | while the quote or business relationship is active, then for the applicable insurance, contract, dispute, or legal period |
| Enrollment, eligibility, plan, reimbursement, appeal, and HIPAA record | as instructed by the applicable plan and required by ERISA, HIPAA, insurance, tax, litigation, and contract rules |
| Bank, ACH, card, HSA, premium, and accounting record | while needed for the account or transaction and for the period required by financial, tax, anti-fraud, and accounting law |
| Legal acceptance and notice-delivery evidence | while the agreement or notice may be enforced or audited |
| Security and access log | while reasonably needed to secure the Services, investigate an incident, or satisfy a legal hold |
| Backups | removed through a rolling backup cycle after deletion from active systems |
Closing an account removes access but may not delete records held for a plan, transaction, fraud prevention, legal hold, or legal obligation. When a required period ends, we delete, aggregate, or de-identify information. We require processors to delete or return information as their contracts and law require.
11. Security and incidents
We use administrative, technical, and physical safeguards designed for the nature of the information, including encryption in transit and at rest, access control, audit logging, secure development, vendor review, backups, workforce training, incident response, and risk assessment.
No electronic system is completely secure. Protect your credentials and devices, and contact privacy@rivendell.health if you suspect unauthorized access. We investigate incidents and give notices required by applicable health, insurance, financial, consumer, and breach-notification law.
12. Your choices and requests
Depending on the information and law, you may be able to:
- access or obtain a copy
- correct inaccurate information
- request deletion
- restrict or object to certain processing
- withdraw consent for future processing
- opt out of sale, sharing, or targeted advertising
- obtain portability
- appeal a denied privacy request
- request an accounting or other right under a plan NPP
You can update some information in the Services. To make another request, email privacy@rivendell.health, call (646) 600-8840, or use the in-app privacy control. California residents can review the California Privacy Supplement.
We verify identity and authority in proportion to the request and sensitivity. An authorized agent may submit a request where law allows, but we may require proof of authority and direct identity confirmation. We will not discriminate because you exercise a privacy right.
A request may be denied or limited where an exception applies, including when Rivendell holds information only for a plan or another organization. We will explain the basis and any appeal or complaint path.
Account deletion
You may initiate account deletion in the app or contact us. We will:
- verify the request
- explain effects on access and active services
- close the account after any required confirmation
- delete or de-identify information that is not subject to a permitted retention
- identify categories retained and the reason
Account deletion does not cancel health coverage, an employer agreement, a reimbursement request, a benefit appeal, a bank or card agreement, or a legal obligation. Contact the relevant plan, employer, or financial institution for those actions.
13. Children and dependents
The Services are not directed to a child for independent account creation. A parent, guardian, employer, or plan may provide information about a covered minor dependent, and Rivendell knowingly processes that information for enrollment, eligibility, reimbursements, plan administration, and authorized support.
A person submitting minor information must have legal authority. We apply role-based access and the applicable plan, HIPAA, and state rules to that information. A parent or guardian can contact us about a child's information, subject to identity, authority, plan rules, and exceptions that protect a minor's confidential care.
If a child created an account without authorization, contact privacy@rivendell.health.
14. Processing locations
Rivendell operates the Services for people and organizations in the United States. Rivendell and its providers may process information in the United States and in other countries where a provider operates. Where required, we use contractual and other safeguards for a cross-border transfer.
15. Changes
We may update this policy prospectively. We will post the new version and effective date. If a change is material, we will provide additional notice and obtain consent where required. We will not use plan protected health information in a newly incompatible way unless the plan documents, notice, contract, and law permit it.
Archived policy versions will remain available through Rivendell's legal library.
16. Contact
Privacy Officer, Elrond Health Inc., 895 Broadway, Floor 5, New York, NY 10003, privacy@rivendell.health, (646) 600-8840
California insurance privacy requests may also be sent to:
Rivendell Insurance & Administration Services, 156 2nd St, Unit 310, San Francisco, CA 94105, privacy@rivendell.health, (646) 600-8840
For a HIPAA request or complaint, use the contact in your plan's Notice of Privacy Practices. You may also complain to the U.S. Department of Health and Human Services Office for Civil Rights when HIPAA applies. We will not retaliate for a good-faith complaint.