Vasl
Features AI Model Peer Groups Teletherapy Outcomes Get started
Legal

Privacy Policy

📅 Effective: March 1, 2026 🔄 Last updated: March 1, 2026 📋 Version 1.0

🔔 The short version: Vasl collects the minimum data necessary to provide emotional health support. We never sell your data. We never show AI-generated signals to members. Raw conversation text is never stored. You can delete your data at any time.

Also read: Terms of Service →

Table of Contents

  1. Who We Are
  2. Who This Policy Covers
  3. Information We Collect
  4. How We Use Your Information
  5. How Our AI Works & What It Sees
  6. Information We Never Collect or Share
  7. Who We Share Your Information With
  8. Data Retention
  9. Your Rights & Choices
  10. Security
  11. HIPAA
  12. Children & Minors
  13. Cookies & Tracking
  14. Changes to This Policy
  15. Contact Us

1. Who We Are

Vasl Health, Inc. (“Vasl,” “we,” “us,” or “our”) is an emotional health technology company headquartered in Los Angeles, California. We operate a digital emotional health platform that serves individuals, partner organizations (including universities, YMCAs, and community-based organizations), licensed therapists, and certified coaches.

For purposes of HIPAA, Vasl functions as a Business Associate to partner organizations that are Covered Entities. We also act as a Covered Entity in certain direct-care relationships where we employ or supervise licensed clinical staff.

Contact us at: privacy@gotovasl.com

2. Who This Policy Covers

This Privacy Policy applies to:

  • Members: Individuals who access Vasl through a partner organization subscription
  • Clinical Staff: Licensed therapists and certified coaches on the Vasl platform
  • Partner Org Admins: Administrators at partner organizations
  • Website Visitors: Anyone who visits gotovasl.com or our subdomains

If you are under 18, additional protections apply. See Section 12 (Children & Minors).

3. Information We Collect

Information you provide directly

  • Account information: Name, email address, date of birth (for age verification), and password when you create an account
  • Profile information: Demographic information you voluntarily share, including racial or ethnic identity, gender identity, and sexual orientation — used solely to match you with culturally-appropriate peer groups and clinical staff
  • Health information: Responses to clinical assessments (PHQ-8, GAD-7, ACEs), mood check-ins, and information shared in coaching or therapy sessions
  • Peer group content: Posts, comments, and messages you share within peer support groups
  • Communications: Messages you send to coaches, therapists, or the Vasl support team

Information collected automatically

  • Usage data: Features you interact with, pages you visit, session duration, and in-app actions
  • Device information: Device type, operating system, browser type, and IP address
  • Log data: Server logs including access timestamps and error reports

Information from partner organizations

Partner organizations may share your name and email address with us to provision your account. They do not have access to your individual session content, assessment results, or any AI-generated signals about you.

4. How We Use Your Information

  • To provide the service: Connecting you to peer groups, coaches, and therapists; delivering your wellbeing assessments; scheduling sessions
  • Clinical care: Sharing appropriate clinical information with your assigned therapist or coach to support your care
  • Safety: Identifying potential crisis situations and routing appropriate human support — see Section 5 for how our AI works
  • Platform improvement: Analyzing aggregate, anonymized usage patterns to improve features and clinical effectiveness
  • Communications: Sending you session reminders, platform updates, and (with your consent) wellbeing check-ins
  • Legal compliance: Meeting our obligations under HIPAA, FERPA, and applicable state mental health laws

We do not use your information for advertising, sell it to third parties, or use it to train AI models without your explicit written consent.

5. How Our AI Works & What It Sees

🧠 Critical to understand: Our AI Language Analysis Platform (VLAP) analyzes text you share on the platform to help clinical staff identify when someone may need support. Members never see AI scores, flags, or signals about themselves. The AI is a tool for clinicians, not for you.

What the AI analyzes

VLAP processes text from peer group posts, mood journal entries, and coach chat messages. It is trained to recognize culturally-specific distress signals — language patterns that may indicate psychological distress, isolation, or crisis — particularly in BIPOC, LGBTQIA+, and underserved youth communities.

What the AI does NOT do

  • It does not diagnose any medical or mental health condition
  • It does not take any automated action without human review
  • It does not show results to you or to your family members
  • It does not store your raw text — text is processed in-memory and immediately discarded after analysis

What is stored

Only structured output is retained: a risk tier (low, moderate, high, or crisis), a list of signal codes that fired, and SHAP attribution spans (short text fragments, maximum 5 words, used to explain the AI output to clinicians). No complete sentences or paragraphs of your writing are stored by the AI system.

Human review requirement

Every high-risk or crisis-tier AI flag requires review by a licensed clinician within 24 hours (high-risk) or 90 minutes (crisis). No AI flag alone results in any action being taken. A human always decides what happens next.

Your consent

AI analysis requires your active consent, which you provide during onboarding. You may withdraw this consent at any time. If you do, all AI-generated data about you is deleted within 24 hours, and your text is no longer analyzed. This does not affect your access to peer groups, coaching, or therapy.

6. Information We Never Collect or Share

  • We do not sell your personal information or health data to any third party, ever
  • We do not share your individual data with your partner organization (they receive only anonymized, aggregate population-level reports)
  • We do not share your data with family members without your explicit consent, regardless of age
  • We do not store raw conversation text after AI processing is complete
  • We do not use your health information for advertising or marketing purposes
  • We do not use your demographic information (race, gender identity, sexual orientation) for any purpose other than service delivery and cultural matching
  • We do not train AI models on your data without separate, explicit written consent

7. Who We Share Your Information With

Your care team

Your assigned therapist and coach have access to your assessment results, session notes, and AI-generated clinical signals relevant to your care. This is necessary to provide you with appropriate support.

Service providers

We use trusted third-party vendors to operate the platform. These vendors are bound by Business Associate Agreements (BAAs) or Data Processing Agreements and are only permitted to process your data as directed by us:

  • Amazon Web Services (cloud hosting and data storage — HIPAA BAA in place)
  • Video session technology providers (teletherapy delivery — HIPAA BAA in place)
  • Secure messaging providers (coach communications)

Legal requirements

We may disclose your information if required by law, court order, or to comply with mandatory reporting obligations under state mental health laws (e.g., duty to warn, duty to report). We will notify you of such disclosures to the extent permitted by law.

Safety emergencies

If a clinician determines that you are in imminent danger of harming yourself or others, we may share necessary information with emergency services. This is a clinical decision made by a licensed human professional, not an automated AI action.

Partner organizations

Your partner organization (e.g., your university or YMCA) receives only aggregate, anonymized population-level reports. They never see your individual records, conversation content, session notes, or AI signals.

8. Data Retention

We retain different types of data for different periods based on clinical necessity and legal requirements:

  • Raw conversation text: Not retained — processed in-memory and discarded immediately after AI analysis
  • AI inference output (risk scores, signal codes): 90 days, or shorter if you withdraw consent
  • Clinical session notes: 7 years from last session (required by most state licensing boards)
  • Assessment results (PHQ-8, GAD-7): Duration of your enrollment plus 7 years
  • Account information: Until you request deletion, then deleted within 30 days
  • Audit logs (no PHI content, only event records): 6 years (HIPAA requirement)

You may request deletion of your account and personal data at any time (see Section 9). Clinical records may be subject to minimum retention requirements under state law even after you request deletion; we will inform you if this applies.

9. Your Rights & Choices

Access

You have the right to request a copy of the personal information we hold about you. Submit requests to privacy@gotovasl.com. We will respond within 30 days.

Correction

You may update your profile information at any time through the app. To correct clinical records, contact your assigned therapist or email us.

Deletion

You may request deletion of your account and associated personal data. Clinical records may be subject to minimum retention requirements under state law. We will inform you of any records we are legally required to retain.

Withdrawal of AI consent

You may withdraw consent for AI analysis at any time through Privacy Settings in the app. All AI-generated data about you will be deleted within 24 hours. Your access to the platform is not affected.

Data portability

You may request a machine-readable copy of your personal data. We will provide this within 30 days of your request.

California residents (CCPA)

California residents have additional rights under the California Consumer Privacy Act, including the right to know, the right to delete, and the right to opt out of sale. We do not sell personal information. To exercise your rights, contact privacy@gotovasl.com.

How to submit a request

Email privacy@gotovasl.com with the subject line “Privacy Request” and your request type. We will verify your identity before processing the request.

10. Security

We implement industry-standard security measures appropriate for a HIPAA-regulated healthcare platform:

  • Encryption in transit: TLS 1.3 on all connections
  • Encryption at rest: AES-256 on all databases and storage
  • Access controls: Role-based access with multi-factor authentication for all clinical and administrative staff
  • Network security: Private cloud environment with no public access to systems handling health data
  • Auditing: Immutable audit logs of all data access events, retained for 6 years
  • Third-party audits: Annual SOC 2 Type II security audit by independent auditors

No system is perfectly secure. In the event of a data breach affecting your information, we will notify you as required by HIPAA (within 60 days of discovery) and applicable state breach notification laws.

11. HIPAA

Vasl is committed to full compliance with the Health Insurance Portability and Accountability Act (HIPAA). Your health information constitutes Protected Health Information (PHI) under HIPAA and is handled accordingly.

Your HIPAA rights include:

  • The right to access your health records
  • The right to request corrections to your health records
  • The right to receive an accounting of disclosures of your PHI
  • The right to request restrictions on how your PHI is used or shared
  • The right to receive communications about your PHI by alternative means or at alternative locations
  • The right to receive a paper copy of this Notice of Privacy Practices

To exercise these rights, contact our Privacy Officer at privacy@gotovasl.com.

You have the right to file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights if you believe your HIPAA rights have been violated. We will not retaliate against you for filing a complaint.

HHS OCR complaint portal: hhs.gov/hipaa/filing-a-complaint

12. Children & Minors

🔔 Vasl serves teenagers (ages 13+) through partner organizations. If you are under 18, special protections apply to your data.

Vasl does not directly enroll children under 13. Members aged 13–17 are enrolled through partner organizations (schools, YMCAs, community programs) which have obtained appropriate parental or institutional consent as required by law, including COPPA and FERPA where applicable.

For members under 18:

  • We do not share your individual records with your parents or guardians without your consent, except where required by law or in genuine safety emergencies
  • Partner organizations receive only anonymized aggregate data and never your individual records
  • AI analysis requires consent from both the member and the enrolling organization
  • Mandatory reporting obligations (child abuse, imminent harm) may require disclosure as required by state law; licensed clinical staff follow applicable mandatory reporting requirements

If you believe a child has been enrolled without appropriate consent, contact privacy@gotovasl.com immediately.

13. Cookies & Tracking

We use a minimal set of cookies necessary to operate the platform:

  • Session cookies: Required to keep you logged in during your session. Deleted when you close your browser.
  • Security cookies: Used to detect and prevent fraudulent access. Expire after 30 days.
  • Preference cookies: Remembering your accessibility and notification preferences. Expire after 1 year.

We do not use advertising cookies, tracking pixels, or third-party analytics that share your data with advertisers. We do not use Google Analytics on pages where you are logged in to the platform.

You may disable cookies in your browser settings. Disabling session cookies will prevent you from logging in.

14. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:

  • Post the updated policy at gotovasl.com/privacy with a new “Last Updated” date
  • Send you an email notification at least 30 days before material changes take effect
  • Display an in-app notice when you next log in

Your continued use of Vasl after the effective date of the revised policy constitutes your acceptance of the changes. If you do not agree, you may close your account before the effective date.

15. Contact Us

Privacy questions & requests

Vasl Health Privacy Office
Email: privacy@gotovasl.com
Response time: within 5 business days for general inquiries; within 30 days for formal privacy requests

For urgent safety concerns: safety@gotovasl.com
For HIPAA-specific complaints: hipaa@gotovasl.com

Read our Terms of Service →
Vasl Health
🔒 HIPAA Compliant · SOC 2 Type II

Mental health support built for the communities that need it most. AI-powered, human-centered, culturally grounded.

Platform
  • Features
  • AI Model
  • Peer Groups
  • Teletherapy
  • Outcomes
  • ▶ Live Prototype
Company
  • About us
  • Mission
  • Careers
  • Press
  • Blog
Support
  • Help center
  • Documentation
  • Contact
  • Privacy
  • Terms
© 2026 Vasl Health, Inc. All rights reserved.
Privacy Policy Terms of Service BAA Accessibility