Privacy
Privacy Policy
Last updated October 9, 2026. Panaceum is an AI app and website builder for healthcare teams, run by Health Council Inc. (“we”, “us”). This policy explains what we collect when you visit panaceum.app, join the waitlist or use Panaceum with an account, why we collect it, who helps us, and the choices you have.
Health information in the apps you build
This policy doesn’t cover patient health information in the apps you publish with Panaceum. That information is governed by the Business Associate Agreement (BAA) your organization accepts before it publishes a HIPAA app, and by the notices you give your own patients. We handle it only as the BAA allows.
The builder, its previews and its chat are for synthetic data only. Never enter real patient information there.
What we collect
When you visit panaceum.app
If you accept analytics in the banner on our home page: the pages you view, the links and buttons you click (not the text on them), the site that sent you, your browser and device type, and your approximate location from your IP address (see Analytics). If you decline or don’t answer, PostHog doesn’t run and our servers keep only their service logs of your visit. Your browser still keeps how you first found us and, once you answer, a cookie that remembers your answer; if you had accepted before, PostHog also keeps a note that you declined (see Analytics).
When you join the waitlist
Your name, email address and organization, and what you’d like to build if you tell us. We screen that note for patient information before we keep it; please don’t include any. We also keep how you found us (such as the campaign tags in the link you followed, the site that sent you and the first page you visited), your product email choice and the country you were in, as far as we could tell.
When you have an account
- Your email address and name, and your password, which our sign-in provider keeps; we never store it ourselves.
- If you choose Continue with Google, which the sign-in dialog offers when it’s available: Google confirms your email address and sends us your name and your Google account ID. We ask Google only for your basic profile and email address, never for your contacts, files or anything else, and we never see your Google password.
- Your workspaces, their members and roles, the classification you declare for each workspace (such as HIPAA covered entity or business associate) and whether your organization receives HHS federal financial assistance, and settings such as your language.
- What you describe and say in the builder, the files you attach, and the apps it builds for you. When you build a HIPAA app, we screen your prompts and files for patient information before we keep them.
- Whether you want product emails, with a record of each choice (see Product email), and how you found us, saved once when you sign up.
- If you buy a plan: your billing name and email, your plan and invoices. Our payment processor, Stripe, collects your card details; we never see your full card number.
- A cookie that keeps you signed in, and service logs of which part of the service a request reached and whether it worked. Our logs don’t record what you typed or built.
How we use it
- To run Panaceum: sign you in, build, host and publish your apps, and keep your work.
- To bill you for your plans.
- To keep Panaceum safe and to investigate problems.
- To send you service emails, such as sign-in codes and notices about your account or your apps.
- To send you product updates and tips, if you’re enrolled (see Product email).
- To understand how people find and use our public pages, so we can improve them.
- To answer you when you contact us.
We don’t sell your personal information, we don’t show you ads, and we don’t use what you create to train AI models.
Product email
Besides service emails, we send occasional product updates and tips.
- In most countries, creating an account or joining the waitlist enrols you, and the form says so. In the European Economic Area, the United Kingdom, Switzerland and Canada, we email you only if you tick an unticked box. If we can’t tell where you are, we ask with the box.
- Accounts made before October 9, 2026 aren’t enrolled; Panaceum asks you once whether you’d like these emails.
- Every product email has a link to a page where one click unsubscribes you, and you can turn Product emails off in your settings at any time. Service emails about your account continue.
- We keep a record of each choice: when and how you made it, the version of this policy, and, for the choice you made when you signed up or joined the waitlist, the country you were in, as far as we could tell.
Analytics on our public pages
We use PostHog to understand how people use panaceum.app’s public pages. It runs only after you accept analytics in the banner on our home page, only on our public pages and only while you’re signed out: never on the signed-in screens where you build and manage apps, and not at all if we can’t tell whether you’re signed in.
- Its code is part of our own site, and what it records goes through our own web address to PostHog in the United States.
- Once you accept, PostHog keeps an ID for your browser in a cookie and in your browser. A cookie remembers your answer for 180 days, and Change preference in the banner changes it.
- If you decline after accepting, PostHog stops and removes its cookie and the ID it kept. Your browser keeps only PostHog’s note of your answer and, until you close the tab, a note about that tab. If you never accept, PostHog doesn’t start and keeps nothing.
- If your browser sends Do Not Track or Global Privacy Control, analytics don’t run.
- We don’t record your screen or your sessions (no session replay), PostHog doesn’t record the text on our pages, and we never send PostHog your name, your email address or anything you build.
- Separately from PostHog, your browser keeps how and when you first arrived on panaceum.app (the campaign tags in the link you followed, the site that sent you and the first page you visited) for 30 days, whatever you choose about analytics. It doesn’t leave your browser on its own: it goes with your waitlist entry or your sign-up, as how you found us.
- Also separately from the banner, our servers tell PostHog when an account or a waitlist entry reaches certain steps, such as joining the waitlist, creating an account, a first build or publish, or a plan upgrade. Each of these events carries a random ID for the account or entry, the product and plan, whether it belongs to our own team and, for a plan change, its billing period and whether it’s a trial; never your name, your email address or anything you build.
Who helps us run Panaceum
We share information only with the companies that run parts of Panaceum for us, only what they need, and only to provide the service:
- Amazon Web Services (United States), our hosting provider: hosting, storage, databases, sign-in, email, and the AI models that build your apps.
- Anthropic: where we have enabled it, Anthropic runs those models for us directly. For HIPAA apps, it receives your prompts and files only after we screen them for patient information.
- OpenAI: images for your Standard apps, made from descriptions written from your prompts.
- Stripe: payments.
- PostHog (United States): analytics on our public pages, only after you accept, and the account and waitlist events described under Analytics.
- Google: our company email, for messages you send us and email we send you, and Continue with Google, if you use it.
We may also disclose information when the law requires it, to protect the rights and safety of our users or the public, or as part of a merger or sale of our business, in which case this policy continues to apply to it.
Your choices and rights
- You can change your settings in Panaceum. You can delete a Standard app yourself if you can publish in its workspace; HIPAA apps are deleted through support, which keeps the records the BAA requires.
- You can stop product emails with the unsubscribe link in any of them, or by turning Product emails off in your settings.
- You can decline analytics in our banner, or turn on Global Privacy Control or Do Not Track in your browser.
- To get a copy of your information, correct it, or delete your account, email privacy@panaceum.app. We’ll confirm it’s you before acting, and reply within 30 days.
- Depending on where you live (for example California, the European Economic Area or the United Kingdom), you may have further rights, such as to object to or restrict how we use your information, or to complain to your data protection authority.
Keeping, protecting and changing
- We keep your account and your work while you have an account, service logs for up to a year, and billing records as long as tax and accounting law requires. We keep your product email choices for as long as we may need to show what you agreed to.
- We encrypt your data in transit and at rest, keep each customer’s data separate, limit which of our people can reach it, and keep logs of access. If a breach affects your information, we’ll tell you as the law requires.
- Panaceum runs in the United States. If you use it from elsewhere, your information is transferred to and stored in the United States.
- Panaceum is for organizations and adults. It isn’t meant for anyone under 18, and we don’t knowingly collect information from children.
- If we change this policy, we’ll update the date above, and for significant changes we’ll tell you by email or in Panaceum before they take effect.
Contact
Health Council Inc.. Email privacy@panaceum.app.
What would you build first?
Panaceum is in early access. Join the waitlist and we’ll send you an access key.