← Back to Bridge

Privacy

Privacy Policy

Last updated: June 26, 2026

This policy is written for a nationwide U.S. launch posture and privacy-by-design operation. It is not legal advice and must be reviewed by licensed privacy, health care, education, disability, and consumer-protection counsel before broad public launch.

What Bridge is

Bridge is supportive technology for routines, communication supports, care coordination, education, documentation, and functional skill-building. Bridge is not an emergency service, not a crisis hotline, not a medical diagnosis tool, and not a replacement for licensed clinical, educational, legal, or professional care.

Information we may collect

Depending on how Bridge is used, we may collect:

  • Account information such as name, email, role, and login status.
  • Profile information such as age group, support notes, preferences, goals, routines, and care-team links.
  • Care coordination content entered by users, including messages, notes, reports, and access-code links.
  • Supportive app activity such as page views, setup completion, feature usage, and safety alerts.
  • Technical information needed for security, debugging, fraud prevention, and service reliability.

Bridge is designed to avoid collecting unnecessary sensitive information. Users should not enter Social Security numbers, payment card numbers, full medical records, or emergency-only information unless a specifically approved workflow asks for it.

Sensitive personal information and health-related data

Bridge may contain disability, developmental, behavioral, mental-health, caregiver, veteran-support, or education-related information. We treat this information as sensitive. We use it to provide Bridge, maintain safety, support care coordination, improve reliability, and comply with legal obligations. We do not sell sensitive personal information. We do not use sensitive support data for third-party advertising.

HIPAA and provider relationships

Bridge is not automatically a HIPAA covered entity. If Bridge contracts with a covered health care provider, health plan, or other covered entity as a business associate, separate HIPAA terms, security obligations, and a Business Associate Agreement may apply. Until such an agreement is signed, customers should not assume Bridge is operating as their HIPAA business associate.

How we use information

  • Provide accounts, dashboards, routines, reports, access codes, and care-team coordination.
  • Maintain safety boundaries, detect abuse, investigate errors, and protect users.
  • Improve Bridge using privacy-minimized analytics and aggregated operational signals.
  • Respond to support, privacy, export, deletion, legal, or security requests.
  • Comply with applicable federal, state, and international legal obligations.

Sharing

We share information only as needed to operate Bridge, at the user’s direction, with linked care-team members, with service providers under appropriate obligations, for safety/security reasons, in business transactions with protections, or when legally required. Access codes should be shared only with trusted caregivers, therapists, educators, coordinators, or support-team members.

State privacy rights

Residents of California and other states with privacy laws may have rights to know, access, correct, delete, port, or limit certain personal information, and to appeal certain decisions. Bridge will honor applicable rights based on the user’s state, the type of data, verified identity, legal exceptions, and whether Bridge acts as a business, processor/service provider, or business associate in that context.

Children and dependent users

Bridge is intended to be used by parents/guardians, caregivers, professionals, organizations, and, where appropriate, supported users with proper consent. A parent, guardian, school, provider, or organization is responsible for obtaining required permissions before entering information about a child, teen, dependent adult, student, client, or veteran.

Security and retention

We use administrative, technical, and organizational safeguards designed to protect Bridge data. No system can be guaranteed completely secure. We retain information only as needed for the service, legal duties, safety, audit, dispute resolution, backups, and legitimate business purposes, then delete or de-identify it when appropriate.

Contact

Questions, privacy requests, data export requests, safety concerns, or legal notices may be sent to privacy@nuviobridge.com. If that inbox is not yet active, use your organization’s designated Bridge administrator until counsel approves final contact channels.