Privacy

Privacy Policy

Your privacy matters. Learn how we collect, use, and protect your personal information.

Last updated: January 1, 2026·Effective: January 1, 2026
01

Information We Collect

We collect information you provide directly — including your name, email, phone number, profile details, health preferences, payment information, communications with providers, reviews, and any health information you choose to share.

We also collect information automatically when you use Welli, such as device information (IP address, browser type, operating system), usage data (pages viewed, time spent, click patterns), location information (with your permission), and cookies and similar tracking technologies.

02

How We Use Your Information

We use your information to connect you with healthcare providers, process appointments and payments, provide customer support, send service notifications, and personalize your experience on the platform.

We may also use your information for communications — including appointment confirmations and reminders, service updates, marketing communications (with your consent), and educational health content.

03

Information Sharing

We do not sell your personal information. We may share information with healthcare providers to facilitate your appointments and care, and with trusted service providers who help us operate (payment processors, hosting, analytics).

We may also disclose information when required by law, to protect our rights, or to ensure user safety. In the event of a merger, acquisition, or asset sale, your information may be transferred as part of that transaction.

04

Provider Profiles & NPPES Data

Welli operates a directory of healthcare providers in the United States. Profiles in this directory are generated automatically from the National Plan and Provider Enumeration System (NPPES), the public federal registry maintained by the Centers for Medicare & Medicaid Services (CMS).

NPPES is a public data source. When a healthcare practitioner registers for a National Provider Identifier (NPI) — which is required for most clinicians who bill insurance — their information becomes publicly available, including their name, credentials, taxonomy, and the practice contact information they registered. Welli displays this public information without requiring authorization from the listed provider, the same way other healthcare directories (including Healthgrades, Vitals, Zocdoc, Doximity, and others) display NPPES data.

If you are a provider listed on Welli and would like your profile removed, you can request removal at any time by emailing privacy@welli.com with your name and NPI. We will mark your profile inactive within five business days.

Removing your profile from Welli does not remove your information from NPPES or from other directories that pull from it. To update or correct your information at the source, visit https://npiregistry.cms.hhs.gov.

Providers may also claim their profile to control the information displayed on Welli, including the ability to edit, hide specific fields, or upgrade to a paid tier with additional features.

05

Data Security

We implement robust security measures including industry-standard encryption for data in transit and at rest, secure server infrastructure, regular security audits, multi-factor authentication, and regular software updates and patches.

Our administrative safeguards include limiting access on a need-to-know basis, employee training on data protection, incident response procedures, and regular review of security policies.

Welli is not a covered entity under the Health Insurance Portability and Accountability Act (HIPAA). When we handle protected health information on behalf of a covered entity — for example, when a healthcare provider uses Welli to communicate with patients or manage care coordination — we operate as a Business Associate under HIPAA, governed by a separate Business Associate Agreement. For consumer health information that you provide directly to Welli (such as medications you track, providers you save, or goals you set), we apply the security protections described above and comply with applicable state health data privacy laws, including the Washington My Health My Data Act, Nevada SB 370, and the sensitive personal information provisions of the California Consumer Privacy Act.

06

Your Privacy Rights

You have the right to access and download your personal information, correct or update inaccurate data, request deletion of your account and data (subject to legal requirements), and opt out of marketing communications at any time.

Depending on where you live, you may have additional rights under state or national law:

California residents have rights under the CCPA/CPRA, including the right to know what personal information we collect and how it's used, the right to delete personal information, the right to correct inaccurate information, and the right to opt out of the sale or sharing of personal information. Welli does not sell personal information.

Washington residents have rights under the My Health My Data Act, including the right to confirm whether we process your consumer health data, access that data, request deletion, and withdraw consent.

Residents of Colorado, Connecticut, Virginia, Texas, Oregon, and Nevada have similar rights under their respective state privacy laws.

To exercise any of these rights, contact privacy@welli.com or visit your account settings. We will respond within the timeframes required by applicable law.

07

Cookies & Tracking

We use cookies and similar technologies to improve your experience. Essential cookies are required for basic functionality. Performance cookies help us understand usage patterns. Functionality cookies remember your preferences. Marketing cookies deliver relevant content.

You can control cookie settings through your browser. Note that disabling certain cookies may affect platform functionality. We use services like Google Analytics to understand usage — these services have their own privacy policies.

08

Communications & SMS Consent

When you provide your phone number, you may receive text messages from Welli for two distinct purposes:

Service messages — appointment confirmations, refill reminders, account verification, and security alerts. These are part of the service you sign up for.

Marketing messages — product updates, new features, and promotional content. These are sent only with your express written consent.

You can opt out of marketing messages at any time by replying STOP to any marketing text. Standard message and data rates may apply. We do not share your phone number with third-party marketers.

09

Children's Privacy

Our services are not intended for children under 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.

For users between 13 and 18, we recommend parental involvement in creating and managing accounts. If we become aware that we have collected information from a child under 13, we will delete it promptly.

10

International Data Transfers

Welli is based in the United States, and our servers and service providers may be located in various countries. When we transfer your information internationally, we ensure appropriate safeguards are in place.

For European users, we comply with applicable data protection laws and use standard contractual clauses or other approved mechanisms. By using our services, you consent to the transfer of your information to the United States and other countries where we operate.

11

Policy Updates

We may update this privacy policy to reflect changes in our practices or applicable laws. When we make significant changes, we will notify you by email or through a prominent notice on the platform.

We encourage you to review this policy periodically. The "Last Updated" date at the top indicates when it was most recently revised. Your continued use of our services after changes constitutes acceptance of the updated policy. Contact privacy@welli.com with any questions.