Privacy policy

Last updated 13 September 2026

This is the privacy policy of Fenna Health LLC. We sell software to addiction treatment and mental health facilities in the United States. Our software, Fenna, answers their phone, their website chat, their texts and their email.

There are two kinds of information here, and they work differently. Information about a patient or a caller belongs to the facility, and we only handle it for them. Information about you as a visitor to our website or a user of our product is ours, and this policy governs it. Section 1 explains the split.

1. The two kinds of information

Information we handle for a facility

When you call, chat, text or email a treatment center and Fenna answers, everything you say belongs to that center. We are what the law calls a business associate. We hold that information for them, under a signed business associate agreement and qualified service organization agreement, and we use it only to run the service for them.

This policy does not govern that information. That agreement does, along with the facility’s own notice of privacy practices. We do not sell it. We do not use it to train models. We do not use it for our own purposes.

If you want to see what a facility holds about you, correct it, or complain, ask the facility. They are the ones who can answer, and the law puts the decision with them, not with us. If you are not sure who to contact, write to us at privacy@fennahealth.com and we will point you to the right place.

Information that is ours

Everything else in this policy is about information we collect for ourselves: people who visit fennahealth.com, people who book a demo, staff at our customers who sign in to the product, billing contacts, and people who write to support. We decide what happens to that information, so the rest of this page is about it.

2. What we collect and why

WhatWhere it comes fromWhy we have itHow long we keep it
Name, work email, phone number, facility name and roleYou, when you book a demo, write to us or are given an accountTo reply to you, run your account and support youWhile you have an account, then three years
Account credentials and sign-in recordsYou and your adminTo let you in and keep others outWhile you have an account, then one year
What you do in the product, and error reportsOur servers, as you use the productTo keep the service working, find faults and prevent abuseTwelve months
Billing contact and payment statusYou and StripeTo invoice you and take paymentSeven years, because tax law says so
Pages you visited on our marketing site, roughly where you were, and what browser you usedCookies and Google Analytics on fennahealth.com onlyTo understand which pages are usefulFourteen months
What you write to usEmail and support messagesTo answer you and keep a recordThree years

We do not buy lists. We do not collect information from children, and our product is not for anyone under eighteen.

3. We do not sell your information

We do not sell personal information. We do not share it for cross-context behavioral advertising. We have not done either in the last twelve months, and we do not plan to. Because of that there is no “Do Not Sell or Share My Personal Information” link on this site, and there is nothing to opt out of.

We still honor an opt-out preference signal such as Global Privacy Control across this site, so if your browser sends one, we treat it as a valid instruction.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All of the categories above exclude text messaging originator opt-in data and consent, and that information will not be shared with any third parties.

4. Who else touches the information

We use other companies to run Fenna. Everything stays in the United States. We hold written agreements with the companies that store, carry and transcribe patient information, and we are working through the same agreements with the rest. Ask us at privacy@fennahealth.com which companies are covered today and we will tell you plainly.

  • Microsoft Azure hosts the service and stores the data.
  • ElevenLabs gives Fenna her voice and answers the phone.
  • Telnyx carries the phone calls and the text messages.
  • Stedi asks insurers about eligibility.
  • Language model providers write what Fenna says on chat, text and email, and read insurance cards.
  • Stripe takes payment. We never see your card number.
  • Google Analytics counts visits to our marketing site, and nothing else.

We will tell customers before we add a company that handles patient information. We also hand over information when the law makes us, and we will tell the facility first unless we are forbidden from doing so.

5. When you connect your mailbox or calendar

A facility can connect its admissions mailbox so Fenna can read and answer email, and its calendar so she can book assessments. That connection is made by an administrator, it is limited to the one mailbox and the one calendar you choose, and you can disconnect it at any time from the Fenna page. We support Microsoft 365, through Microsoft Outlook and Microsoft Calendar, and Google Workspace, through Gmail and Google Calendar.

From Gmail and Microsoft Outlook we read the messages in the mailbox you connect: the sender, the subject, the body and the attachments. We read them so Fenna can write a reply, so your team can see the thread in the product, and so a callback can be opened when someone asks for a call. We send a reply from that same mailbox. We do not read any other mailbox in your organization.

From Google Calendar and Microsoft Calendar we read the free and busy times on the calendar you connect, and the events Fenna created. We read them so she can offer a time that is actually free, and we write an event when someone books an assessment. We do not read the contents of events we did not create.

We keep that content for as long as the facility uses Fenna, because it is their record of the conversation, and we delete or return it when they leave, as the business associate agreement requires. We share it only with the companies listed above, which host and run the service. We do not use it to train models. We do not use it for advertising. We do not sell it. No human at Fenna Health reads it except to support your team when you ask, to keep the service secure, or where the law requires it.

Fenna’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

6. Recorded calls

Calls to a facility that Fenna answers are recorded and written down, so the facility has a record of what was said and can pick the conversation up where it stopped. The recording and the transcript belong to that facility.

Some states require everyone on a call to agree before it is recorded. The facility is responsible for getting that agreement, and our agreement with them says so. If you are on a call and you would rather it was not recorded, say so and ask for a person.

We do not use recordings or transcripts to train voice or language models.

7. Text messages

If you text a facility’s number, Fenna replies once and then a person takes over. If you leave a number for a callback, the facility may text you about it. Facility staff get texts telling them a caller is waiting.

Message frequency varies. Message and data rates may apply. Reply HELP for help or STOP to stop at any time, and STOP stops it for good on that number. We also honor quit, cancel, end and unsubscribe.

We do not send marketing texts, and we do not text people who have not contacted a facility first.

8. Cookies and analytics

Our marketing site, fennahealth.com, uses Google Analytics to count visits and see which pages people read. It sets cookies to do that. You can read how Google uses information from sites that use their services, and you can turn it off for every site with the Google Analytics opt-out add-on.

There is no analytics and there are no advertising pixels anywhere behind a sign-in, on the chat window a facility puts on its site, or on any page where you type something to us. We never send personal information to Google Analytics.

The product itself uses one cookie, the one that keeps you signed in. It is not used to track you.

9. Your rights

Wherever you live in the United States, you can ask us to do all of these, free, and we will answer within forty-five days. If we need longer we will tell you why, and we will not treat you worse for asking.

  • Tell you what we hold about you, where we got it, why we have it and who we gave it to
  • Give you a copy
  • Correct anything that is wrong
  • Delete it
  • Stop using sensitive information for anything beyond running the service
  • Stop making decisions about you by automated means, and explain any we have made

Write to privacy@fennahealth.com or use the form on our site. We may need to check who you are before we answer, which usually means replying from the address we already hold. Someone can act for you if they show us they are allowed to.

If you are unhappy with our answer you can appeal by writing to the same address with the word appeal in the subject. We will answer an appeal within forty-five days and tell you how to contact your state attorney general if you are still unhappy.

California residents: we have set out above the categories we collect, where they come from, why we have them, who we give them to and how long we keep them. We do not sell or share personal information, and we do not use sensitive personal information for anything beyond providing the service you asked for. The information Fenna handles for a treatment facility is protected health information and is outside these rights, because the business associate agreement and federal health privacy law govern it instead.

Washington residents: your consumer health data has its own policy. Read the consumer health data privacy policy.

10. Keeping it safe, and how long we keep it

Everything is encrypted in transit and where it is stored. Access is limited to the people who need it and is logged. We review who has access, and we keep the servers patched.

The table above says how long we keep each thing. When a facility stops using Fenna, they have thirty days to export their data, and after that we delete or return patient information as the business associate agreement requires and delete the rest on the schedule above. Backups age out on their own cycle within ninety days.

No system is perfectly safe, and we will not pretend otherwise. If something goes wrong with information we hold for a facility, we tell that facility without unreasonable delay, and in any case within sixty days of finding out, as federal law requires. It is then their job to tell the people affected. If something goes wrong with information that is ours, we tell you directly and tell whoever else the law says we must.

11. Changes, and how to reach us

We will update this policy when what we do changes. The date at the top says when this version took effect. If a change matters, we will email account holders before it lands.

Fenna Health LLC. Write to privacy@fennahealth.com about anything on this page, and to legal@fennahealth.com about the terms of service. We answer every message.