Privacy policy
Effective date: October 2, 2026
Aera is a guided pulmonary rehabilitation program provided by Aera Health LLC, a Delaware limited liability company based in Thousand Oaks, California and part of Frontline Healthcare Holdings. In this policy, “Aera,” “we,” “us,” and “our” mean Aera Health LLC. This policy explains, in plain language, what information we collect, why we collect it, who else handles it, how long we keep it, and what you can ask us to do. It applies to the aerahealth.us website and to the Aera app in the United States. It takes effect on October 2, 2026, and it replaces every earlier version.
The short version
- This website collects only what you type into a form. The Aera app collects health information, because that is what the program is.
- We do not sell your personal information, we do not share it for advertising, and we do not use it to build profiles about you.
- Aera holds your health information as a business associate of your healthcare provider under HIPAA.
- Your health information stays in the United States, on Amazon Web Services, under a signed Business Associate Agreement.
- Artificial intelligence writes plain-language explanations of your check-ins, answers your questions in Ask Aera, translates messages between you and your care team, and helps your clinician draft notes and summaries. A clinician reviews any note or summary it drafts before it becomes part of your record. Check-in explanations, Ask Aera answers and message translations are generated automatically, with no human review, and are labeled as AI. It is never used to diagnose you or to decide your care.
- Aera is for adults 18 and older, by invitation from a clinician.
- You can close your account yourself, in the app. Your health record is kept as a sealed record for the years the law requires, and then securely destroyed.
This website vs. the Aera app
This public website (aerahealth.us) is for learning about Aera and getting in touch. It does not collect health information. Health information is collected only inside the Aera app, where you record it as part of your routine. The two are handled under different rules, and this policy says which rule applies where. Please do not type health details into a website form — if you do, we treat them as sensitive, use them only to answer you, and delete them when that is done.
Information we collect
From this website we collect only what you type into a form — your name, your email address, and, if you choose, your role and a short message. The referral form clinicians use asks for more, because we have to call the office back: your name, your practice, a callback phone number, your email address, when you prefer to be reached, and, if you choose to give it, your National Provider Identifier. It asks for nothing about a patient, and it refuses a note that looks like it contains patient details. Referral emails are deleted 90 days after the referral is resolved, and any clinical detail a sender includes anyway is deleted when we triage it. We do not use advertising cookies, we do not run analytics or crash-reporting tools, and we do not track you across other websites.
The Aera app collects more, because it has to. Here is the whole list.
- When you set up your account: your name, mobile phone number, email address, year of birth, sex, and the contact details of the clinician you name.
- If you choose to add a helper — a family member or friend who helps you with Aera — their name, how they are related to you, and their phone number or email address.
- Your insurance member ID, including your Medicare Beneficiary Identifier if you have Medicare. Your practice’s billing staff enter it, not you, and we store it encrypted.
- The time zone your phone is set to, so each daily check-in counts on the right day.
- What you record each day: your oxygen and pulse readings, your answers about breathlessness and other symptoms, cough and mucus, rescue-inhaler use, and how you felt.
- About your health background: your medications, whether you smoke, whether you use oxygen at home, and your past flare-ups and hospital stays.
- Answers and scores, including the standard breathlessness questionnaire, your weekly progress questions ("Your Week"), and the mood and anxiety questionnaires.
- Your exercise and breathing sessions — what you did, for how long, and how it felt.
- How many minutes you spend active in the app. Your care team uses this for their remote monitoring records.
- Any side effect or flare-up you report to us.
- Flare-ups your care team records, including the care you received (for example steroid pills, antibiotics, an emergency-room visit or a hospital stay) and their notes.
- The messages you exchange with your care team, and any photo or document you attach to them.
- If you talk to Aera by voice (Ask Aera or the spoken setup), the sound from your microphone while the conversation is open, which is turned into text. We keep the text of what you said and of Aera’s answers, the same as if you had typed; we do not keep recordings of your voice. If you use read-aloud, the text being read to you.
- If you turn on reminders, a notification token that identifies your phone to Apple or Google. It is not your phone number and it does not contain health information.
- An access record of every action taken on your information — what was done, by whom, when, from which internet address, and with which device or browser.
Almost all of this comes from you. Some of it comes from the clinician or clinic that invited you — for example, your name and phone number so we can send your invitation, and the fact that you are enrolled in their program. Some of it comes from your care team — for example, the flare-ups they record and the care you received for them.
How we use information
We use your information to run the program you signed up for and for nothing else. That means: setting up and securing your account; showing you your daily routine and your progress; passing your check-ins to the care team you were referred by; letting you and your care team message each other; sending the reminders and one-time sign-in codes you asked for; supporting you when you contact us; keeping the program safe and working; and meeting our legal, record-keeping, and billing-support obligations. We do not use your information for advertising, we do not build profiles about you for marketing, and we do not sell it.
How we use artificial intelligence
Aera uses artificial intelligence for a few narrow jobs: writing plain-language explanations of your own check-ins back to you; answering your questions about the program, typed or spoken (Ask Aera); helping you set up your account by conversation, typed or spoken; translating messages between you and your care team when you do not use the same language (you always see the original message too, and the translation is marked as a machine translation); and helping your clinician draft notes and summaries. These features run on Claude models hosted inside Amazon Web Services (Amazon Bedrock), under the same Business Associate Agreement that covers the rest of the program. When you talk to Aera instead of typing, Amazon Transcribe turns your speech into text and Amazon Polly reads the answer aloud, under the same agreement. When a voice conversation starts, Aera says that you are talking with an AI assistant, and it says so again when the conversation ends. Amazon does not use these requests or your voice for its own purposes or to train its models. Aera keeps the text of your messages and of your Ask Aera conversations as part of your record, as described above, and does not use them to train artificial intelligence models. A clinician reviews any note or summary the AI drafts before it becomes part of your record. Translations are not checked by a person before you see them; if one looks wrong, or for anything about your care, contact your care team.
Artificial intelligence is never used to diagnose you, to change your treatment, to decide what care you receive, or to decide whether you stay in the program. Those are decisions for you and your clinician.
Who else handles your information
We do not sell your personal information and we do not share it for advertising. A small number of service providers process it strictly on our instructions, under contracts that require them to protect it and forbid them from using it for their own purposes. This is the whole list.
- Amazon Web Services runs the Aera program in the United States — the database, file storage, sign-in, the one-time codes we text you (Amazon SNS), email to clinicians (Amazon SES), the AI features described above, including message translation (Amazon Bedrock), turning your speech into text when you talk to Aera (Amazon Transcribe), and reading text aloud (Amazon Polly). Amazon Web Services signed a Business Associate Agreement with us on September 16, 2026.
- Apple and Google deliver notifications to your phone. They receive only a token identifying your device and an identifier for the message. They never receive your health information.
Separately from those providers, we send your information where you and the law direct it: to the care team at the clinic that invited you, to any family member you choose to share with, and — if the law ever requires it — in response to a valid legal demand, to prevent a serious threat to someone’s health or safety, or to a regulator supervising us. If we are ever part of a merger or sale, your information moves with the program and stays under this policy until we tell you otherwise.
If we ever add a service provider that would handle health information, we will put an agreement in place first and update this page before it starts.
How we protect your information
Aera holds your health information as a business associate of your healthcare provider under the U.S. Health Insurance Portability and Accountability Act (HIPAA). Your provider’s Notice of Privacy Practices governs how your health information may be used and disclosed, and we follow it. We also handle medical information under California’s Confidentiality of Medical Information Act.
Inside the Aera program: your information travels over encrypted connections (TLS), it is encrypted where it is stored using Amazon Web Services Key Management Service, and access is restricted on a least-privilege basis — your care team and our compliance staff, and only what each of them needs. You sign in with a one-time code sent to your phone. Every single access is written to an access record that cannot be altered or erased. We keep no advertising or analytics software in the app at all.
No system can be promised to be perfectly secure, and we will not pretend otherwise. If a breach ever affects your information, we will notify you and the authorities as the law requires.
Children
Aera is for adults aged 18 and over. It is offered by invitation from a clinician, and it is not directed to children. We do not knowingly collect personal information from anyone under 18. If we learn that we have, we delete it and close the account. If you believe a child has given us information, email us and we will act on it.
Cookies & tracking
This website uses only the cookies and local storage it needs to work — for example, remembering the language you chose. There are no advertising cookies, no analytics or crash-reporting tools, no advertising identifiers, and no tracking across other websites or apps. The Aera app contains no advertising or analytics software either.
Some browsers send a “Do Not Track” or Global Privacy Control signal. Because we do not track you across websites and do not sell or share personal information, there is nothing for those signals to switch off — our behavior is the same either way.
How long we keep information
How long we keep something depends on what it is. Information from this website — contact and access-request forms, and waitlist entries — is kept only as long as we need it to answer you or to set up your account, and is deleted when that is done or when you ask us to delete it. Your health record inside the Aera app is different: the law and our agreements with your hospital require us to keep medical records for a set number of years, usually 7 to 10 depending on which rules apply to your hospital, so we hold yours as a sealed record and then securely destroy it when that period ends. Access records and consent records are kept for as long as the law requires. Secure backups hold a copy for 7 days and then age out on their own. The section “Deleting your information” below explains what “sealed” means.
Your choices & rights
Inside the app you choose who can see your information — your care team, and any family member you invite. You can change or withdraw that choice at any time in Settings. Your rights over the health record itself, including the right to see it, to get a copy, and to ask for a correction, run through the healthcare provider who referred you; ask them, and we will help them answer. Depending on where you live you may also have the right to know what personal information we hold, to get a copy, to correct it, to ask us to delete it, and to opt out of its sale or sharing — we do not sell or share personal information, so there is nothing to opt out of. To exercise any of these, email info@aerahealth.us. We will ask you for enough information to confirm who you are before we act, and we will answer within 45 days. If we need more time, we will tell you why and take no more than another 45 days.
Your rights over your health record under HIPAA — to see it, to get a copy, to ask for a correction, to ask for a restriction, and to get a list of certain disclosures — run through the healthcare provider who referred you to Aera, because the record belongs to them. Ask them first. We hold the information for them and we will help them answer you.
California privacy notice
This section is for people who live in California, and it is our notice at collection under the California Consumer Privacy Act as amended by the CPRA. It covers information from this website and from setting up and running your account. It does not cover your medical record: medical information held by a business associate under HIPAA, and medical information covered by California’s Confidentiality of Medical Information Act, are handled under those laws instead (Cal. Civ. Code § 1798.145(c)). The section below on deleting your information explains exactly where that line falls and why.
These are the categories of personal information we collect, what we use them for, and how long we keep them.
- Identifiers — your name, mobile phone number, email address, account identifier, and the internet address recorded in the access log. If you choose to add a helper, it also includes their name, how they are related to you, and their phone number or email address. For a clinician sending a referral, that also includes the practice callback phone number, which the referral form requires. We use them to create and secure your account, to sign you in, to reach you, and to keep the program safe. Website form entries are kept until we have answered you or set up your account, and referral emails are deleted 90 days after the referral is resolved; account identifiers are kept for the life of your account and then as described under “Deleting your information.”
- Customer-records information under Cal. Civ. Code § 1798.80(e) — your name and contact details as you gave them to us, and your insurance member ID, including your Medicare Beneficiary Identifier if you have Medicare. Your practice’s billing staff enter the insurance member ID, not you. We store it encrypted, use it only to support your practice’s billing for your care, and keep it with your record. Your name and contact details are used and kept as above.
- Protected characteristics — your year of birth and sex. We use them only to set up the program correctly for you and to interpret your readings. Kept with your record.
- Internet or network activity — how you move through the app, how many minutes you spend active in it, the time zone your phone is set to, and the device or browser recorded in the access log. We use it to make the program work — including counting each check-in on the right day — to support you when you call, and to detect misuse. Your care team also uses your active minutes for their remote monitoring records. Access records are kept for the period the law requires; your active minutes and time zone are kept with your record.
- Audio, electronic, and visual information — microphone audio while a voice conversation with Aera is open, and any photo or document you attach to a message. Used only to do the thing you asked for, or to show your care team what you sent. We do not keep voice recordings; the text of a voice conversation and your attachments are kept with your record.
- Professional information — for clinicians and clinic staff only: your role, your clinic or practice, your work contact details, when you prefer to be called, and your National Provider Identifier if you give it. The National Provider Identifier is a public professional number, not a government identification number, and we use it only to find your practice faster. Kept while you have an account with us; on a referral, deleted with the referral email 90 days after the referral is resolved.
- Sensitive personal information — health information, and the credentials used to sign in to your account. See the next paragraph.
- We do not collect precise location, bank account or payment card details, Social Security numbers, driver’s license, state ID, or passport numbers, your contacts, browsing history from other sites, biometric identifiers, or advertising identifiers, and we draw no inferences about you for advertising or profiling. The only government identification number we may hold is your Medicare Beneficiary Identifier, and only when your practice’s billing staff enter it, as described above.
We use sensitive personal information only for the purposes California regulations allow without an opt-out (11 CCR § 7027(m)): to provide the program you asked for, to keep your account secure and prevent fraud, and to keep the program safe and working correctly. We do not use it to infer characteristics about you and we do not disclose it for anyone else’s purposes. Because of that, we are not required to offer a “Limit the use of my sensitive personal information” link, and we do not display one.
We have not sold or shared personal information in the past 12 months, and we do not sell or share it now. “Share” here means California’s meaning — disclosing it for cross-context behavioral advertising. We have never done that and we have no plans to. We also do not sell or share the personal information of anyone we know to be under 16.
If you live in California, you have the right to:
- Know what personal information we have collected about you, where it came from, why we collected it, and who we disclosed it to.
- Get a copy of the personal information you gave us, in a portable form.
- Correct personal information that is wrong.
- Ask us to delete personal information, subject to the exceptions we set out plainly in “Deleting your information.”
- Opt out of the sale or sharing of your personal information — we do neither, so there is nothing to opt out of.
- Be free from discrimination for exercising any of these rights.
To make a request, email us. Say which right you are exercising. We will ask you for enough information to confirm you are who you say you are — usually the name, phone number, or email address already on your account — and we use what you give us only to check your identity. We answer within 45 days and may take one further 45 days if a request is complex, in which case we will tell you before the first 45 days are up. You can use an authorized agent; we will ask for written permission signed by you and we may still ask to verify you directly.
We will not deny you the program, charge you a different price, give you a lower level of service, or treat you any differently because you exercised a privacy right (Cal. Civ. Code § 1798.125). We do not offer financial incentives for personal information.
We handle, store, and dispose of medical information under California’s Confidentiality of Medical Information Act (Cal. Civ. Code § 56 and following). If you have a question about the confidentiality of your medical information, email us and it will go to our Privacy Officer.
Deleting your information
Website, marketing, and pre-signup information — what you send through a contact or access-request form, and waitlist entries — is genuinely deleted when you ask us to delete it. We also instruct our service providers to delete their copies, as California law requires (Cal. Civ. Code § 1798.105(c)).
A deletion request inside the Aera program is a different thing, and we would rather be exact than reassuring. It closes your account: you are signed out on every device, you cannot sign in again, and your name, phone number, and email address are removed from the active app. It does not delete your health record.
The health record you build in the Aera program — your check-ins, breathing numbers, assessments, and your messages with your care team — is kept as a sealed record. Sealed means the record stays intact but is closed to ordinary use: access is limited to your care team and our compliance staff, every look needs a documented reason, and every look is written into an access record. We keep it for the number of years your hospital’s agreement and the law require, and the Aera app shows you that exact number before you confirm a deletion. When those years are up, we securely destroy the record.
Keeping that record is a legal-obligation and compliance exception to the California deletion right (Cal. Civ. Code § 1798.105(d)) — not a refusal to honor your request. As 11 CCR § 7022(f) requires, these are the categories we retain and why: health and program records, records of the consents you gave and withdrew, records of any side effect or flare-up you reported, and access and audit records. We retain each of them to meet legal and contractual record-keeping obligations, including California’s Confidentiality of Medical Information Act and the medical-record retention duties we take on through our agreements with your hospital.
The record of who opened your information, and when, cannot be erased at all. California’s Confidentiality of Medical Information Act requires that trail to survive with the names and times attached (Cal. Civ. Code § 56.101(b)).
Deleting your Aera account does not change or remove anything in your doctor’s or your hospital’s own records. Those records are theirs, and they keep them under their own rules. If you want something in your hospital record corrected, contact the hospital directly — you have the right to ask them to amend it. Information already sent to your care team stays with them.
Step-by-step instructions for closing your Aera account are on our account deletion page.
Where your information is held
Aera in the United States is operated from, and stores information in, the United States. We do not transfer your health information outside the United States, and we do not send it to any program Frontline Healthcare Holdings operates in another country.
Changes
We may update this policy. When we do, we post the new version here with a new effective date and keep the old one available on request. If a change materially affects how we handle your information, we will tell you before it takes effect — in the app, by email, or both — and, where the law requires your agreement, we will ask for it.
Contact
Questions about this policy? Email info@aerahealth.us, or use our contact form.
Our Privacy & Security Officer is Ricky Yau. Email reaches him at the address above. You can also write to Aera Health LLC, 555 Marin St Ste 120, Thousand Oaks, CA 91360, United States.
If you believe your privacy rights have been violated, you can complain to us and we will investigate. You can also complain to your healthcare provider, and to the U.S. Department of Health and Human Services, Office for Civil Rights, at hhs.gov/ocr/complaints or by calling 1-800-368-1019. California residents may also contact the California Privacy Protection Agency or the California Attorney General. We will not retaliate against you, cut off your program, or treat you any differently for making a complaint.