Privacy Policy
Last updated: September 18, 2026
This Privacy Policy explains how Hootcare Inc ("we", "us"), the company that operates the Hootcare platform (the "Service"), handles information. Hootcare is software used by speech-language pathology practices and the families they serve — between-session speech practice for kids, assigned and overseen by their SLP.
Our role with health information
For the clinical and child information processed through the Service, the clinical practice is the data controller (and, under U.S. health-privacy law, the "Covered Entity"). Hootcare Inc acts as that practice's service provider — a HIPAA Business Associate and, where applicable, a GDPR processor — and processes Protected Health Information ("PHI") only on the practice's documented instructions and under a Business Associate Agreement (BAA). The practice's own privacy notice governs how that PHI is used in care. This Policy describes Hootcare Inc's own practices and our public website.
Information we collect
From website visitors. When you browse hootcare.io or request a demo, we collect what you submit (e.g., name, email, practice name) and basic, privacy-respecting analytics. We do not use third-party advertising or cross-site tracking cookies.
From platform users, on behalf of practices. To provide the Service we process: clinician and parent account details (name, email, and — for providers — SLP credentials such as an NPI, state license, or ASHA number, which we may check against public registries like NPPES); child profile and clinical information that the practice enters or that families provide (intake, practice assignments and results, clinical notes and progress summaries, messages, voice recordings captured during speech practice where consent has been given, and interactions with Hoot, the kid-facing AI companion); device push tokens for mobile notifications; and audit/usage logs. This information is provided to us by the practice and the families it invites, and is processed under the practice's instructions and the BAA.
How we use information
We use information solely to provide, secure, maintain, and improve the Service for the practice; to provide support; to process AI features (practice-activity generation, speech-practice feedback and transcription, draft session notes and progress digests, and Hoot's voice conversations); for billing to the practice; and to meet legal obligations. We do not sell personal information, and we do not use PHI or children's information for advertising or to train AI models for unrelated purposes.
Children's privacy (COPPA)
Hootcare's kid-facing surfaces are used in a clinical context. Child information is collected and used only at the direction of the clinical practice and the child's parent/guardian, who provide the required consent through the practice. We minimize the data collected from children, do not use it for advertising, and provide tools for the practice and parents to access or delete it. To request deletion of a child's data, a parent/guardian can email support@hootcare.io from the address on their account (or ask the child's practice), and we will erase the child's records and recordings; deleting the parent's own account in-app removes the family space it owns. Questions about a child's data should be directed to the child's practice or to us at support@hootcare.io.
A child's voice during speech practice. When a child practices, Hoot briefly listens each time the child says a practice word so it can transcribe that one word and check whether it was heard. This momentary capture happens on every practice turn, and on its own nothing is saved: the audio is used only for that check and then discarded — even before a grown-up has finished the in-app "Set up practice" step. A child's short practice clips are kept only with the verifiable consent of that child's own parent/guardian, given by the adult in the app (or by the treating clinician on the web) for that specific child; without it the server keeps nothing. Kept clips are automatically deleted after 90 days and are never used for advertising or to train AI models for unrelated purposes. A child's voice is processed by Google's Vertex AI under a HIPAA business-associate agreement (BAA), not by any consumer AI service. Consent can be withdrawn at any time in the app's Settings.
How we share information — subprocessors
We share information only with vendors that help us run the Service, under contracts that restrict their use of it (and a BAA where they may handle PHI). Our current subprocessors include Google Cloud (hosting, database, storage, and Vertex AI for AI features — covered by the Google Cloud BAA), WorkOS (clinician sign-in),Apple (App Store in-app subscription billing), SendGrid/Twilio (transactional email), Expo (mobile push notification delivery), and Cloudflare (network/security). We do not sell data and disclose it otherwise only when required by law or to protect rights and safety.
Cookies & tracking
We use only the cookies needed to sign you in and keep the Service secure. No third-party advertising or cross-site tracking cookies are used.
Data retention
We retain information for as long as needed to provide the Service to the practice and as the practice instructs, and as required by law. As a data-minimization measure, the most sensitive raw data (consent-retained child speech-practice recordings and raw AI conversation turns) is automatically purged after 90 days by a nightly job that deletes the stored audio and then its record, while clinical records are retained per the practice's record-keeping obligations. Audit logs are retained for at least six years.
Security
We encrypt data in transit and at rest, isolate each practice's data at the database layer, enforce role-based access controls, hash credentials, keep an append-only audit log of PHI access, and route all AI processing through BAA-eligible infrastructure. No method of transmission or storage is perfectly secure, but we hold ourselves to recognized safeguards for health data.
Your choices & rights
Individuals have rights to access, correct, and delete their personal information. For clinical/child information, these requests are fulfilled through the clinical practice (the controller); Hootcare Inc assists the practice and provides data-export and erasure tooling. For website/marketing information, contact us at support@hootcare.io to access or delete your data or to opt out of communications.
Where data is processed
The Service is operated from the United States, and information is processed and stored in the United States. We do not currently offer the Service to controllers processing the personal data of individuals located in the EU/EEA/UK.
Changes to this Policy
We may update this Policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, by notice to affected practices.
Contact us
Hootcare Inc — privacy questions: support@hootcare.io. If you are a patient/parent, you may also contact your clinical practice, which controls your health information.