Closefly

Privacy Policy

Version 0.1 — DRAFTEffective: not yet publishedDrafted 27 August 2026
Draft v0.1 — not yet published. Written 27 August 2026 by modelling Podium, the closest public comparable in this category. It has not been reviewed by a lawyer. Before it goes live, confirm: (1) the exact legal entity name and registered address, (2) that legal@closefly.ai and privacy@closefly.ai exist and are monitored, (3) the final subprocessor list, and (4) that a Florida attorney has read it. Delete this box when it goes live.

Contents

  1. Who this covers
  2. What we collect
  3. How we use it
  4. Text messages and consent
  5. Automated and AI-assisted messaging
  6. Who we share it with
  7. Patient information and HIPAA
  8. Cookies and tracking
  9. How long we keep it
  10. Your rights and choices
  11. Security
  12. Where your data is handled
  13. Children
  14. Changes
  15. Contact us

1. Who this covers

Closefly LLC ("Closefly", "we", "us") helps medical spas and other appointment-based businesses answer inquiries and book consultations. This policy explains what we do with personal information in two very different situations, and the difference matters:

2. What we collect

Information you give us

Information we collect automatically

Information from other sources

3. How we use it

4. Text messages and consent

If you give us your mobile number and agree to receive text messages from Closefly, you consent to receive messages from us at that number, which may be sent using automated technology and may include content generated with the help of artificial intelligence.

Carrier requirement No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text message opt-in data and consent are never sold, rented, or shared with any third party for their own marketing. Information may be shared only with the vendors that help us deliver the message on our behalf, and only for that purpose.

Our full Messaging Terms and Conditions apply to texts between you and Closefly. They do not apply to texts between you and a clinic that uses our services; those are governed by the clinic's own terms and notices.

5. Automated and AI-assisted messaging

We use artificial intelligence to help draft and send replies, both for ourselves and, on their instructions, for our clients. Messages may be composed or sent automatically without a person reading them first. AI output can be wrong or incomplete. Nothing we or our systems send is medical advice, a diagnosis, a price quote, or a promise of a clinical result. If you ask whether you are talking to a person or an automated system, our systems are instructed to tell you the truth and to hand you to a person on request.

6. Who we share it with

We do not sell personal information, and we do not share it for cross-context behavioural advertising.

We share it with:

7. Patient information and HIPAA

Some of our clients are covered entities under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"). Where we handle protected health information for such a client, we act as a business associate under a signed Business Associate Agreement. In that role:

8. Cookies and tracking

Our websites use cookies and similar technologies to make the site work, remember your preferences, measure traffic, and measure the performance of our advertising. You can block or delete cookies in your browser settings; some parts of the site may then stop working. Where a legally recognised opt-out preference signal such as Global Privacy Control is sent by your browser, we treat it as an opt-out of sale and sharing for that browser.

9. How long we keep it

We keep personal information for as long as we need it for the purpose we collected it, and then for as long as we need it to meet legal, tax, accounting, and dispute-resolution obligations. Records of text message consent and opt-out are kept for at least four years, because that is the window in which a claim about them can be brought. Information we hold as a business associate is returned or destroyed at the end of the engagement, except where the law requires us to keep it, as set out in the Business Associate Agreement.

10. Your rights and choices

Depending on where you live, you may have the right to ask us to: confirm whether we hold personal information about you and give you a copy; correct it; delete it; stop selling or sharing it, which we do not do in any case; and not be discriminated against for exercising these rights. Florida residents have these rights under the Florida Digital Bill of Rights, and California residents under the California Consumer Privacy Act. Other states have similar laws.

To make a request, email privacy@closefly.ai. We will verify who you are before we act, normally by confirming details we already hold. We will answer within 45 days and may extend once where the law allows. You may use an authorised agent; we will ask for proof. If we refuse, we will say why, and you may appeal by replying to our decision; if we deny the appeal you may complain to the Florida Attorney General or to your own state's attorney general.

If your request concerns information we hold for one of our clients, we will forward it to that client and support them in answering it. The clinic, not Closefly, decides the outcome.

11. Security

We use administrative, technical, and physical measures designed to protect personal information, including access controls, encryption in transit, multi-factor authentication on our core systems, and limiting access to the people who need it. No system is perfectly secure, and we cannot guarantee absolute security. If a breach of unsecured protected health information occurs, we will notify the affected client without unreasonable delay and within the timeframe set out in our Business Associate Agreement.

12. Where your data is handled

Closefly is based in the United States and your information is stored and processed there. Some of our service providers and technical personnel are located outside the United States, including in Argentina. Where that is the case, we require them by contract to protect the information to the same standard we apply, to use it only on our instructions, and to accept the same restrictions we have accepted, including under HIPAA where applicable. Our Subprocessor List names each provider and the country it operates from.

13. Children

Our services are for businesses. We do not knowingly collect personal information from anyone under 18. If you believe a child has given us information, email privacy@closefly.ai and we will delete it.

14. Changes

We may update this policy. We will change the effective date at the top and, if the change is significant, tell you by email or by a notice on our site before it takes effect. Older versions are available on request.

15. Contact us

Closefly LLC, Miami, Florida, United States
Privacy questions and rights requests: privacy@closefly.ai
Legal notices: legal@closefly.ai