TheraLoop← Back

Privacy Policy

Mast Labs LLC · TheraLoop · Effective: July 2026

This Privacy Policy describes how Mast Labs LLC ("Mast Labs," "we," "us") collects, uses, and protects information in connection with the TheraLoop platform, including our websites (theraloop.io, app.theraloop.io), mobile applications, and AI-powered services (collectively, "Services").


1. Information We Collect

Patient Health Information (PHI): When you use TheraLoop through a participating clinic, we may process health-related information on behalf of your healthcare provider, including pain assessments, medical history, treatment plans, and home exercise program data. This information is collected through our AI assistant MILO during conversational intake and through your interactions with the patient portal.

Account Information: Phone number (for OTP verification), name, and contact details provided during intake or portal registration.

Usage Data: Device type, browser, IP address, pages visited, and interaction patterns. We do not use cookies for advertising or tracking.

Clinical Data: For physical therapist users, we process clinical notes, evaluation forms, session records, and scheduling data entered through the PT workspace.

2. How We Use Information

We use collected information to:

  • Deliver the TheraLoop platform and MILO AI assistant services
  • Facilitate patient intake, scheduling, and communication with care teams
  • Pre-fill clinical evaluation forms from structured intake data
  • Provide home exercise programs and track adherence
  • Authenticate users via OTP verification
  • Improve platform performance and reliability
  • Comply with legal and regulatory requirements

We do not sell personal information. We do not use patient data for advertising.

3. HIPAA Compliance

TheraLoop is designed to comply with the Health Insurance Portability and Accountability Act (HIPAA). We enter into Business Associate Agreements (BAAs) with healthcare providers who use our platform. PHI is encrypted in transit (TLS 1.2+) and at rest (AES-256). Access to PHI is controlled through role-based permissions and managed identity authentication.

Our infrastructure runs on Microsoft Azure with HIPAA-eligible services. No PHI is stored in client-side storage (localStorage, sessionStorage, or cookies). Authentication uses HTTP-only secure cookies with server-managed sessions.

4. MILO AI Assistant

MILO is TheraLoop's AI-powered clinical assistant. MILO processes patient messages to facilitate structured intake, triage communications, and surface clinical insights for healthcare providers. MILO does not make clinical decisions — all clinical judgment remains with licensed healthcare professionals.

Conversations with MILO are stored as part of the patient record and are accessible to the patient's care team. MILO does not share patient information across clinics or Harbors (clinic deployments).

5. Data Sharing

We share information only as follows:

  • With your healthcare provider: Your intake data, messages, and portal activity are shared with the clinic and care team managing your treatment.
  • Service providers: We use Microsoft Azure for infrastructure, Twilio/Azure Communication Services for SMS, and other service providers under BAAs where PHI is involved.
  • Legal requirements: We may disclose information when required by law, subpoena, or court order.

We do not share your data with advertisers, data brokers, or unrelated third parties.

6. Data Security

We implement technical and organizational safeguards including:

  • Encryption in transit and at rest
  • Role-based access control with least-privilege principles
  • OTP-based authentication (no passwords stored)
  • Managed identity authentication for all infrastructure
  • Audit logging of data access
  • Harbor isolation — each clinic's data is logically separated

7. Data Retention

Patient records are retained in accordance with applicable state and federal requirements (minimum 7 years for medical records). You may request access to or deletion of your personal information by contacting your healthcare provider or reaching out to us directly.

8. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, delete, or port your personal data. For PHI, these rights are governed by HIPAA and should be directed to your healthcare provider. For non-PHI inquiries, contact us at the address below.

9. Children's Privacy

TheraLoop is not directed to individuals under 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, contact us immediately.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated through the platform or via email. Continued use after changes constitutes acceptance.

11. Contact

Mast Labs LLC
Fort Lauderdale, FL
Email: legal@mastlabs.ai
Web: mastlabs.ai