Privacy Policy

Last updated: July 20, 2026

This Privacy Policy describes how 28labs Inc. ("Company," "we," "us," or "our") collects, uses, and shares information through our website at getbirch.com (the "Site") and our AI-powered patient communication platform, Birch (together with the Site, the "Services"). Please read this Privacy Policy carefully.

Information We Collect

We collect information you provide directly to us, information collected automatically when you use the Services, and information from other sources.

Information You Provide

We collect information you provide directly to us, such as when you create an account, submit information via the Services, communicate with us via third party social media sites, request customer support, or otherwise communicate with us. This information may include:

- Contact details, such as your name, email address, phone number, and mailing address
- Account details, such as your username and password
- Professional information, such as your medical credentials, specialty, and practice information
- Voice recordings and transcripts of calls handled through the Services, including calls answered by our AI agents
- Messages exchanged through the Services via text (SMS), web chat, or email
- Scheduling, insurance, and billing information you provide in the course of an interaction (payment card details are processed by our payment processor and are not stored by us)
- Technical data related to your use of our communication and automation features
- Feedback and correspondence, such as information you provide when you report a problem or communicate with us

Automatically Collected Information

When you access or use our Services, we automatically collect information about you, including:

- Log Information: Information about your use of the Services, such as the type of browser you use, access times, pages viewed, your IP address, and the page you visited before navigating to our Services.
- Device Information: Information about the computer or mobile device you use to access our Services, including the hardware model, operating system and version, device identifiers, and mobile network information.
- Location Information: Your device's GPS signal and information about nearby WiFi networks and cell towers. We collect this data for fraud prevention purposes.
- Usage Information: Information about how you use our Services, such as session frequency and duration.
- Cookies and Analytics: We and our analytics providers (such as Google Analytics) use cookies and similar technologies to understand how visitors use the Site. You can control cookies through your browser settings.

Information from Other Sources

We may obtain information about you from other sources, including through third-party services and organizations to supplement information provided by you. For example, when a healthcare practice uses Birch, we may receive scheduling, insurance, or contact information from that practice's electronic health record (EHR) or practice management system in order to provide the Services. This supplemental information allows us to verify information that you have provided and to enhance our ability to provide accurate, helpful communication. We may also collect information about medical terminology, healthcare workflows, and payer policies from publicly available sources to improve our AI communication capabilities.

Automated (AI) Interactions

Some interactions through the Services — including phone calls, text messages, and chat conversations — are handled by artificial intelligence. Where required by law, and as a matter of practice, our AI identifies itself as an automated assistant at the start of an interaction — consistent with the transparency obligations of the EU AI Act (Article 50), applicable since August 2, 2026, and equivalent U.S. state disclosure laws. Calls and conversations may be recorded and transcribed to provide the Services, for quality assurance, and as described in this Policy; where the law requires, you will be notified of recording. Our AI does not provide medical advice, and you may request a human representative at any time during an interaction. Significant decisions are not made solely by automated means without the involvement of the healthcare practice.

How We Use Information

We use the information we collect for a variety of business purposes such as:

- Provide our Services, including AI-powered voice, text, and chat communication, appointment scheduling, reminders, intake, and billing support
- Improve and optimize our Services, for example by enhancing the accuracy and helpfulness of our AI agents and conversation workflows
- Communicate with you about our Services through emails, messages, push notifications, and other channels
- Enable you to communicate and interact with healthcare professionals for telemedicine services
- Advertise our Services on third party websites and apps
- Provide customer support and respond to requests
- Detect and prevent fraud, abuse, security, incidents, and other harmful activity
- Conduct research and analysis of our Services for improvements
- Create deidentified and/or aggregated data to understand usage trends, improve conversation quality, and refine our AI models
- Enforce compliance with our Terms of Use and as required by law
- Maintain legal and regulatory requirements applicable to our Services
- Establish, exercise, and defend legal rights and claims

Sharing of Information

We disclose information as described below and as described elsewhere in this Privacy Policy. Service Providers. We share information with third party vendors and service providers that perform services on our behalf, such as hosting, analytics, customer service, marketing, and other services. Research and Analytics. We share deidentified and/or aggregated information with third parties, including researchers and analysts, to conduct research, analytics, and measurements of our Services. Advertising Partners. We share information with third party advertising partners to show you ads that we think may interest you. As Required by Law. We will disclose your information if we reasonably believe we are required to do so by law, regulation, subpoena, or other legal process. Business Transfers. Your information may be disclosed and transferred in the event Company is involved in a merger, acquisition, reorganization, bankruptcy, or sale of some or all of its assets or stock. To Protect Rights and Interests. We will disclose your information where we believe it necessary to investigate, prevent, or take action regarding illegal activities, suspected fraud, situations involving potential threats to safety or security of any person, violations of our Terms of Use or this Privacy Policy, or as evidence in litigation. With Your Consent. We will share your personal information in other ways not described in this policy if we notify you and you consent to the sharing.

Subprocessors and Third-Party Services

We use the following third-party services, which may process the categories of information described in this Policy:

  • DigitalOcean (US/EU) — website hosting
  • Google Analytics (US) — website analytics, loaded only after you accept analytics cookies
  • Adobe Fonts (Typekit) (US) — web font delivery
  • Calendly (US) — appointment scheduling on our support page; information you enter there is processed under Calendly's privacy policy
  • Amazon Web Services (US) — infrastructure for processing contact-form submissions

AI subprocessors. When the Birch platform handles conversations on behalf of a healthcare practice, the content of those conversations (including voice audio and message text) is transmitted to AI service providers to generate responses. These providers may include OpenAI (language models), ElevenLabs (voice synthesis), and Twilio (telephony and messaging). Prompts and conversation content therefore leave our servers and are processed by these subprocessors under data processing agreements. We will update this list as our providers change; you may request the current list at any time via support@getbirch.com.

Security

We employ industry-standard security measures designed to protect your information, including end-to-end encryption, secure data storage, and strict access controls. Our systems are designed to meet or exceed HIPAA requirements for the protection of sensitive healthcare information. However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security. You acknowledge and accept that we cannot guarantee the security of your information and that you provide such information at your own risk. We are not responsible for circumvention of any privacy settings or security measures contained on the Service.

US State Privacy Rights

If you are a resident of certain US states, you may have additional privacy rights under state law:

California Residents (CCPA/CPRA):

  • Right to know what personal information is collected, used, shared or sold
  • Right to delete personal information held by us and our service providers
  • Right to opt-out of sale or sharing of personal information
  • Right to non-discrimination for exercising privacy rights
  • Right to correct inaccurate personal information
  • Right to limit use and disclosure of sensitive personal information

To exercise these rights, California residents may contact us at support@getbirch.com. We will verify your request using the information associated with your account.

Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws:

  • Right to access personal data
  • Right to correct inaccuracies in personal data
  • Right to delete personal data
  • Right to obtain a copy of personal data in a portable format
  • Right to opt-out of targeted advertising, sale of personal data, and profiling
Biometric Data

Our Services may process biometric data in the form of voice recordings when providing our voice communication features. We handle biometric data with enhanced security measures:

  • Voice data is processed solely to provide and improve our communication services and is not used for biometric identification
  • Audio recordings are automatically deleted 90 days after processing unless a longer retention period is required by the healthcare practice or applicable law
  • We do not sell, lease, trade, or otherwise profit from your biometric data
  • We obtain consent before collecting biometric data where required by law
  • You may request deletion of your biometric data at any time
Employee and Job Applicant Privacy

If you are an employee or job applicant of 28labs Inc., we collect additional categories of personal information in connection with your employment or application:

  • Professional and employment-related information
  • Education and qualification details
  • Background check information (with consent)
  • Emergency contact information
  • Payroll and benefits information

This information is used solely for employment-related purposes and is retained in accordance with applicable employment laws. Employees may request access to their personnel files in accordance with state law.

Do Not Sell or Share My Personal Information

We do not sell your personal information in the traditional sense. However, we may share certain information with third parties in ways that could be considered a "sale" or "sharing" under certain state privacy laws. You have the right to opt-out of such sharing:

  • Click the "Do Not Sell or Share My Personal Information" link in the footer of our website
  • Email us at support@getbirch.com with your opt-out request

We will honor opt-out preference signals such as the Global Privacy Control where required by law.

Shine the Light Disclosure

California Civil Code Section 1798.83 permits customers who are California residents to request certain information regarding our disclosure of personal information to third parties for their direct marketing purposes. We do not share personal information with third parties for their direct marketing purposes.

Nevada Privacy Rights

Nevada residents have the right to opt-out of the sale of certain personal information to third parties. We do not currently sell personal information as defined under Nevada law. If you are a Nevada resident and would like to make a request pursuant to Nevada law, please contact us at support@getbirch.com.

Your Data Rights and Choices

You have choices regarding our handling and use of your personal data.

- Access / Update Data: You may access, review, and update your data by logging into your account. You must promptly update any changes to your contact information or other information.
- Delete Data: You may request deletion of your personal data by emailing support@getbirch.com. We will respond consistent with applicable laws.
- Opt-Out of Communications: You may opt out of receiving certain communications from us by following the unsubscribe process described in an email communication, or contacting us via email. This does not opt you out of essential communications regarding operation of the Services.
- Disable Location Data: You may disable location data collection in your mobile device settings. However, this may affect use of location-enabled features. If you reside in certain territories, including the EU, you may have additional rights available to you under applicable privacy laws.

Children's Privacy (COPPA)

Our Services are not directed to children under 13 years of age, and we do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13 without verification of parental consent, we will take steps to delete that information as quickly as possible.

For healthcare providers treating minors: While Birch may be used to document pediatric consultations, the healthcare provider remains responsible for obtaining appropriate consent for treatment and ensuring compliance with applicable laws regarding minors' health information. Any pediatric health information processed through our Service is subject to enhanced protections and extended retention periods as required by law.

If you believe we have inadvertently collected information from a child under 13, please contact us immediately at support@getbirch.com.

International Data Transfers

We are headquartered in the United States and have service providers in other countries. Your information may be transferred to the U.S. or other locations where privacy laws may be less stringent. By using our Services or providing information to us, you consent to such transfers.

Changes to this Privacy Policy

We may periodically change this Privacy Policy to keep pace with our business needs and evolving laws. We will notify you of material changes either by posting the revised Privacy Policy on the Site or app, or by contacting you through email or other communication.

Contact Us

If you have any questions about our Privacy Practices or this Policy, please contact us at:

28labs Inc.

support@getbirch.com