Privacy Policy
What Anyura, Inc. collects, why we collect it, and the rules we hold ourselves to, for website visitors, clinic users, and patients of clinics that run on Anyura.
The short version: we never sell personal information, and SMS opt-in data is never shared with anyone for marketing.
Who we are
Anyura, Inc. (“Anyura”, “we”, “us”) builds practice-management software for aesthetic clinics and medical spas, available at app.anyura.com. Clinics use Anyura to run scheduling, patient records, billing, and patient communications.
This policy explains how we handle personal information when you visit our website, use our platform, or receive messages sent through Anyura by a clinic you do business with. If anything is unclear, write to support@anyura.com and a human will answer.
Who this policy covers
This policy applies to three groups of people:
- Visitors: anyone browsing anyura.com.
- Clinic users: owners, providers, and staff who sign in to the Anyura platform for work.
- Patients: clients of those clinics whose information is managed in Anyura and who receive appointment communications through it.
For patient clinical records, the clinic is the data controller and Anyura acts as its service provider under a Business Associate Agreement (see section 9). Your clinic’s own privacy notice also applies to your care.
What we collect
You or your clinic provide: name, email address, mailing address, and phone number; appointment and scheduling details; intake forms, consents, and clinical documentation entered by your clinic; billing and payment records; and messages exchanged with your clinic through the platform.
Collected automatically: device and browser type, IP address, pages viewed, and usage events. We collect this to keep the service secure, diagnose problems, and understand what to improve. We do not use it to build advertising profiles.
Never collected: we do not buy data about you from brokers, and we do not scrape third-party sources to enrich patient records.
How we use information
We use personal information only to operate and improve the service:
- Scheduling, confirming, and reminding you about appointments
- Sending account notifications and verification codes
- Processing payments and generating receipts
- Providing customer support and responding to requests
- Securing accounts, preventing fraud and abuse, and auditing access
- Complying with legal obligations, including HIPAA where applicable
We do not use your personal information to train advertising models, and we do not serve third-party ads anywhere in the product.
SMS & text messaging
With your consent, including when you provide your phone number to a clinic for appointment purposes, we send text messages such as appointment confirmations, reminders, reschedule notices, and account verification codes. Patients who separately opt in may also receive occasional promotional messages from their clinic.
SMS program disclosures. Message frequency varies. Message and data rates may apply. Reply STOP to any message to opt out immediately; reply HELP for help, or contact support@anyura.com.
Opting out of texts never affects your medical care or your ability to book by phone or online.
Email communications
Transactional email (confirmations, receipts, account notices) is sent through HIPAA-capable infrastructure. Marketing email is sent only with consent and always includes an unsubscribe link and a preference center; transactional email cannot be unsubscribed because it is part of operating your account.
Appointment emails are deliberately written to be PHI-free: details live behind a secure portal link rather than in the message body.
Security & HIPAA
We protect personal information with industry-standard safeguards: encryption in transit and at rest, role-based access controls, tenant isolation between clinics, audit logging of access to records, and routine security review.
Where Anyura processes protected health information (PHI) on behalf of a clinic, it does so as a business associate under a Business Associate Agreement (BAA) in accordance with HIPAA. Messaging and email carrying PHI are routed through HIPAA-capable providers under BAAs of their own.
Data retention
We retain information for as long as needed to provide the service and to meet legal and clinical record-keeping requirements. Medical records are retained according to your clinic’s obligations under state law. When data is no longer required, it is deleted or de-identified.
Clinics can export their data at any time; when a clinic leaves Anyura, its data is exported and then scheduled for deletion.
Your rights & choices
- Texts: reply STOP to any message to stop receiving texts.
- Email: use the unsubscribe link or preference center in any marketing email.
- Access & correction: ask your clinic, or email us, to access or correct information held about you.
- Deletion: request deletion of information we hold, subject to medical record-keeping laws your clinic must follow.
If you are a resident of California or another state with a comprehensive privacy law, you may also have rights to know, delete, correct, and to not be discriminated against for exercising them. We honor these requests regardless of state. To exercise any right, email support@anyura.com, and we respond within the time required by law.
Children's privacy
Our website and platform are not directed to children under 13, and we do not knowingly collect personal information from them. Records of minor patients are managed by their clinic with parental or guardian consent as required by law.
Changes to this policy
We may update this policy as the product and the law evolve. The latest version always lives at this URL with the effective date at the top. For material changes, we notify clinics in-product or by email before the change takes effect.
Contact
Privacy questions, access requests, or complaints: support@anyura.com. Anyura, Inc., United States. We read everything.