PropPilot Get Started
๐Ÿ”’ Legal

Privacy Policy

HIPAA-aligned privacy disclosure for the PropPilot GLP-1 telehealth platform.

Contents

  1. 1. Overview
  2. 2. Data We Collect on the Assessment
  3. 3. Abandoned-Funnel Captures (partial_lead rows)
  4. 4. Consult Requests (consult_requests rows)
  5. 5. Third-Party Processors & Sub-Contractors
  6. 6. Your Rights as a Patient
  7. 7. Contact

1. Overview

PropPilot Health, P.C. (d/b/a PropPilot) operates a healthcare marketplace that connects patients with independently licensed healthcare providers for GLP-1 weight-loss treatment. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our website at proppilot-13.polsia.app and related services (collectively, the "Service"). We design privacy practices to comply with HIPAA, HITECH, applicable state telehealth privacy laws, and where applicable, the California Consumer Privacy Act (CCPA).

By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.

We take privacy seriously โ€” especially health information. We do not sell your personal data. Ever.

2. Data We Collect on the Assessment

When you complete the patient eligibility assessment, the following fields are collected and written to the `patient_assessments` table at submission time. Each row is also stamped with a server-side `submitted_at` timestamp and assigned the lifecycle status `pending_review`.

  • Identity & contact: first_name, last_name, email, phone
  • Demographics: date_of_birth, state (state of residence for licensing verification)
  • Health metrics: current_weight_lbs, goal_weight_lbs, height_feet, height_inches, bmi
  • Medical history: conditions (JSON array of condition keys โ€” e.g. history of pancreatitis, thyroid conditions, personal or family history of medullary thyroid carcinoma or Multiple Endocrine Neoplasia syndrome type 2)
  • GLP-1 experience: previous_glp1 (boolean), previous_glp1_medication, previous_glp1_stop_reason
  • Treatment goals: primary_motivation, timeline_expectation
  • Telehealth consent: telehealth_consent (boolean โ€” explicit consent to receive care via telehealth)
  • Lifecycle metadata: submitted_at (server-set timestamp), status (server-set to `pending_review` โ€” transitions to `consult_requested` / `booked` / `archived` as the patient moves through the funnel)

3. Abandoned-Funnel Captures (partial_lead rows)

If you start the assessment and stop before completing it but provide your email address (for example, to receive the lead-magnet guide or to be reminded to finish), we write a single row to `patient_assessments` with only the email populated and lifecycle status set to `partial_lead`. All other assessment columns โ€” first_name, last_name, telehealth_consent, etc. โ€” are stored as NULL on the partial row.

Partial rows are governed by a partial unique index on lower-cased email where status = `partial_lead`. If you submit the same email again as a partial capture within 30 days, we refresh the `submitted_at` timestamp rather than creating a duplicate row. Completing the full assessment inserts a new pending_review row for the same email โ€” partial and complete rows coexist for the same address.

4. Consult Requests (consult_requests rows)

When you request a consultation with a matched provider through the platform, we write a row to the `consult_requests` table that links back to your assessment record. The row is stored with the following columns and is used to coordinate contact between you, the provider, and our support team.

  • assessment_id: foreign key reference to patient_assessments.id (links the consult request back to your submitted assessment)
  • provider_id: foreign key reference to provider_directory.id (the matched, board-certified physician)
  • preferred_contact_window: a short string you select (e.g. "morning", "afternoon", "evening") โ€” used by the provider to schedule outreach
  • timezone: IANA timezone string (e.g. "America/Los_Angeles") so the provider can call at a sensible local time
  • notes: optional free-text field for context you want to share with the provider ahead of the consult
  • status: lifecycle column defaulting to `pending` at creation; transitions to `in_progress` / `completed` / `cancelled` as outreach progresses
  • created_at: server-set timestamptz marking when the request was submitted

5. Third-Party Processors & Sub-Contractors

We share Protected Health Information only with sub-processors that have executed a Business Associate Agreement (BAA) with us and that agree to handle PHI in compliance with the HIPAA Security Rule. Our current sub-processors are:

  • Polsia Email Proxy (notifications & drip delivery): Used to deliver assessment-submission notifications to PropPilot staff and the 5-step patient nurture drip sequence. Endpoint: https://polsia.com/api/proxy/email. Inbound PHI (assessment metadata) is scoped to the minimum necessary to fulfil the delivery, and the proxy is operated under our BAA.
  • HIPAA-compliant object storage (clinical attachments, if used): If you or your provider upload clinical attachments (lab results, prior imaging, photographs relevant to the consult), those files are stored in HIPAA-compliant object storage delivered by a sub-processor operating under a signed BAA. Attachments are encrypted at rest and scoped per-assessment; they are not used for any purpose other than supporting your care.

We do not engage third-party advertising networks, retargeting pixels, data brokers, or third-party analytics vendors that receive PHI. Meta Pixel and Google Analytics are loaded only on public marketing pages and are explicitly excluded from the assessment funnel.

6. Your Rights as a Patient

You have the following rights with respect to your personal information and Protected Health Information. To exercise any of these rights, contact us at the email address in Section 7 and we will respond within 30 days. We may require identity verification before processing requests to protect your information from unauthorized access.

  • Access: Request a copy of the personal information we hold about you, including a copy of any row in `patient_assessments` associated with your email and any `consult_requests` linked to those rows.
  • Correct: Request correction of inaccurate or incomplete information. Update requests for assessment fields (name, contact details, health metrics) are applied directly to the underlying `patient_assessments` row.
  • Delete: Request deletion of your personal information. Deletion requests for assessment, partial_lead, and consult_requests rows are honoured subject to HIPAA record-retention requirements (45 CFR ยง164.530(j)) and state healthcare recordkeeping standards. We will inform you of any applicable retention exception when responding to your request.
  • Portability: Request transfer of your information to another service provider in a machine-readable format. We will provide an export of the fields described in Sections 2โ€“4 (and any attachments stored under Section 5) at your request.
  • Restriction: Request that we restrict processing of your information in certain circumstances (for example, pausing nurture-drip emails without deleting the underlying row โ€” which is also available at any time via the unsubscribe link in every drip email).

California residents have additional rights under the CCPA, including the right to know, delete, and opt out of the sale of personal information. We do not sell personal information. Requests submitted under the CCPA follow the same contact path and verification process described above.

7. Contact

For questions, concerns, or requests regarding this Privacy Policy or our privacy practices, contact our Privacy Team at the email address below. For HIPAA-specific inquiries โ€” including requests to access or amend your PHI, requests for an accounting of disclosures, or complaints about the use or disclosure of your health information โ€” please contact our Privacy Officer directly at the same address.

Email: support@proppilot-13.polsia.app ยท Phone: +1 (415) 555-0136

Last updated: 2026-07-28  ยท  Effective: 2026-07-28

Regulatory & Business Disclosures

This telehealth service is operated by PropPilot Health, P.C. (d/b/a PropPilot), a Professional Medical Corporation.

Business Identity & Contact

Mailing address: 548 Market St, PMB 871234, San Francisco, CA 94104
Website: https://proppilot-13.polsia.app
Patient support: support@proppilot-13.polsia.app ยท +1 (415) 555-0136

Applicable License & Registration References

PropPilot facilitates telehealth consultations and prescribing of FDA-approved GLP-1 medications through board-certified physicians. The entity and its prescribing physicians hold the following registrations:

  • State medical board: Medical Board of California โ€” CA Professional Medical Corporation โ€” License #pending-issuance
  • Federal controlled-substance prescribing: Drug Enforcement Administration (DEA) โ€” DEA registration on file with prescribing physicians
  • Federation of State Medical Boards (FSMB) โ€” Physician Data Center
  • National Provider Identifier (NPI) Registry

Complaint & Appeals Procedure

If you have a concern about the care you received, the platform, your privacy, or any advertising or billing practice, follow the steps below. We respond to every written complaint within 5 business days.

  1. Step 1 โ€” Contact PropPilot Patient Support. Email or call us first so we can try to resolve your concern directly. We log every complaint and respond in writing within the response window below.
  2. Step 2 โ€” Escalate to our Compliance Officer. If Patient Support cannot resolve the issue, your concern is automatically escalated to our Compliance Officer, who will conduct a formal review and respond with a written determination.
  3. Step 3 โ€” File with the State Medical Board. You may file a complaint about the care you received โ€” or about the prescribing physician โ€” directly with the state medical board listed above, regardless of whether you first contacted us.
  4. Step 4 โ€” File with federal or consumer-protection channels. For concerns about advertising, billing, or HIPAA privacy you may also file with the FTC, HHS Office for Civil Rights, or your state Attorney General using the links below.

Appeals. If you are not satisfied with our determination, reply to your complaint ticket within 30 days and request escalation. Your appeal is reviewed by a senior officer who was not involved in the original decision, and we will issue a final written response within 10 business days of receiving the appeal request.

Regulator Complaint Channels

In addition to (or instead of) contacting us, you may file a complaint directly with the following regulators:

  • Medical Board of California โ€” File a Complaint ยท +1 (800) 633-2322
  • HHS Office for Civil Rights โ€” HIPAA Complaints ยท +1 (877) 696-6775
  • Federal Trade Commission โ€” Report Fraud ยท +1 (877) 382-4357
  • National Association of Boards of Pharmacy (NABP)

Patient Privacy & HIPAA Disclosures

For full details on what personal and health information PropPilot collects during the assessment, how it is stored, the sub-processors we engage under Business Associate Agreements, and your patient rights (access, correction, deletion, portability, restriction of processing), see our full Privacy Policy. To request any of those rights, contact us at the support email above.

Disclosure footer last updated 2026-07-23. This information is provided to satisfy LegitScript healthcare-advertiser transparency standards.

Cookie preferences

PropPilot

Doctor-led weight loss with verified providers, personalized GLP-1 treatment, and integrated lifestyle coaching.

Platform

  • How It Works
  • Pricing
  • FAQ

Legal

  • Privacy Policy
  • Cookie preferences
  • Terms of Service
  • HIPAA Notice
  • Refund Policy
  • Telehealth Consent

Contact

  • support@proppilot-13.polsia.app
© 2026 PropPilot. All rights reserved. Built with Polsia
PropPilot is a healthcare marketplace connecting patients with independently licensed healthcare providers. Prescriptions are issued only after consultation with a licensed physician who determines medical appropriateness. This site does not provide medical advice โ€” consult your physician before starting any treatment.
We value your privacy

We use essential cookies to make PropPilot work and, with your permission, analytics cookies to improve it. You can accept all, reject non-essential, or choose your preferences.

Cookie preferences

Choose which categories of cookies PropPilot may set on this browser. Your selection is stored locally and can be changed any time from the footer.