Privacy Policy
Last updated: July 13, 2026
Alma, Inc. ("Alma", "we", "us", or "our") is an AI-powered after-hours answering service built for healthcare providers. This Privacy Policy explains how we collect, use, disclose, and protect information when you use our service at almaoncall.com and the Alma provider dashboard ("Service").
If you are a healthcare provider using Alma, you may also have a Business Associate Agreement (BAA) with us. Where our BAA applies, it governs the handling of Protected Health Information (PHI) and takes precedence over this Policy.
1. Information We Collect
From healthcare providers (account holders)
- Account information: name, email address, practice name, and billing details when you create an account.
- Usage data: how you interact with the Alma dashboard, features used, and session metadata.
- Communications: emails or messages you send to our support team.
From patient callers (on behalf of providers)
When a patient calls your Alma after-hours number, Alma collects the following on behalf of your practice:
- Call recordings and transcripts: the full audio and text of the conversation.
- Patient-provided information: name, date of birth, phone number, reason for calling, medication details, and any other information the patient shares during the call.
- Call metadata: call timestamp, duration, and caller phone number.
This information is considered Protected Health Information (PHI) under HIPAA when associated with identifiable patients. Alma acts as a Business Associate to provider-customers and handles this data accordingly.
Automatically collected data
- Log data: IP address, browser type, pages visited, and timestamps when you access our website or dashboard.
- Cookies: session cookies to keep you logged in. We do not use advertising or tracking cookies.
2. How We Use Your Information
- Provide and operate the Alma Service, including AI answering, transcript generation, and the provider dashboard.
- Generate AI-written encounter notes and call summaries for your review.
- Send you service-related notifications (e.g., new call alerts, billing receipts).
- Respond to support requests and troubleshoot issues.
- Improve and develop our AI models and service — only using de-identified or aggregated data. We do not use identifiable patient PHI to train models without explicit consent.
- Comply with legal obligations.
3. How We Share Information
We do not sell your data or patient data. We share information only as follows:
- Sub-processors: We work with third-party vendors to operate our service, including telephony infrastructure (Twilio), cloud hosting, and AI model providers. Each sub-processor is bound by data processing agreements and permitted to use data only to provide services to us.
- Legal requirements: We may disclose information if required by law, court order, or to protect the rights and safety of our users or the public.
- Business transfers: If Alma is acquired or merged, your information may be transferred as part of that transaction. We will notify you in advance.
4. HIPAA and Healthcare Data
Alma is designed to support HIPAA compliance for healthcare provider customers. We:
- Sign Business Associate Agreements (BAAs) with covered entity customers upon request.
- Store call recordings, transcripts, and patient data in encrypted form at rest and in transit.
- Limit access to PHI to personnel with a need to know for service operation.
- Maintain audit logs of access to PHI.
- Do not disclose PHI to third-party advertisers or analytics platforms.
Providers are responsible for ensuring patients are aware that their after-hours calls are handled by an AI service. We recommend including a disclosure in your patient communications.
5. Data Retention
- Call records and transcripts: retained for the duration of your active subscription plus 90 days after cancellation, then permanently deleted unless a longer period is required by applicable law.
- Account information: retained while your account is active and deleted upon written request after account closure.
- Billing records: retained for 7 years as required for financial record-keeping.
6. Security
We implement industry-standard technical and organisational measures to protect your data, including:
- TLS encryption for all data in transit.
- AES-256 encryption for data at rest.
- Role-based access controls and multi-factor authentication for our internal systems.
- Regular security reviews and vulnerability assessments.
No system is completely secure. In the event of a data breach affecting PHI, we will notify affected providers within 60 days as required by HIPAA.
7. Your Rights
As a provider-customer, you may:
- Access, export, or delete your account data and call records at any time from the Alma dashboard.
- Request a copy of your BAA or a summary of our sub-processors.
- Close your account and request deletion of all associated data by emailing abhinav@starmesh.ai.
Patient rights under HIPAA (access, amendment, accounting of disclosures) are exercised through your practice as the covered entity, not directly through Alma.
8. Children's Privacy
Our Service is intended for healthcare providers. We do not knowingly collect personal information directly from individuals under 18. Patient callers may include minors — their information is handled as PHI under the provider's care and our BAA.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify active customers by email at least 14 days before material changes take effect. Continued use of the Service after that date constitutes acceptance of the updated Policy.
10. Contact Us
Questions about this Privacy Policy or your data?
Alma, Inc.
Email: abhinav@starmesh.ai