Privacy Policy
Applies to visitors of zaha.health and to clients using the Zaha platform.
Effective date: 11 September 2026
Last updated: 11 September 2026
1. Who we are
Zaha Health, Inc., a Delaware corporation, and its wholly-owned operating subsidiary Zaha Health Operations LLC (together, "Zaha," "we," "us") operate the zaha.health website (the "Site") and the Zaha Health platform (the "Platform").
Not a HIPAA covered entity. Zaha is cash-pay and does not bill insurance, so Zaha is generally not a “covered entity” or “business associate” under HIPAA, and HIPAA does not apply to most information we hold. We instead treat the health-related information described in this Policy as consumer health data protected by this Policy, by the FTC Act and the FTC Health Breach Notification Rule, and by state consumer-health and privacy laws. Your Providers remain independently bound by the confidentiality obligations of their professions.
For questions about this Policy, contact hello@zaha.health.
2. Information we collect
2.1 Information you give us directly
| Category | Examples |
|---|---|
| Identifiers | Name, email, phone, mailing address, date of birth, state of residence |
| Account credentials | Username, password, authentication tokens |
| Intake and matching information | Program interest, presenting concern, faith context, provider preferences (including gender preference and sect preference), timezone |
| Health-related information you share | Symptoms, history, and clinical or spiritual concerns you share on intake and in sessions |
| Payment information | Payment card details, billing address (processed by our payment processor; we do not store full card numbers) |
| Communications | Emails, in-Platform messages, support inquiries |
| Scholarship applications | Financial-need information you provide when applying for scholarship |
2.2 Information Providers create in the course of care
- Session notes and clinical documentation created by your Counselor
- Spiritual-care notes created by your Spiritual Advisor
- Your Care Plan and Collaborative Care Summaries
- Outcomes measurement scores (for example: PHQ-9, GAD-7 responses)
2.3 Information collected automatically
- Device information (browser, OS, device identifiers)
- Log data (IP address, access times, pages viewed)
- Cookies and similar technologies (see Section 7)
- Approximate location derived from IP address
2.4 Information from third parties
We may receive information from third parties, including our payment processor, our video conferencing vendor, referral partners (with your permission), and public directories used during provider matching. We handle third-party-sourced information consistently with this Policy.
3. How we use information
We use information to:
- Deliver the service. Match you with Providers, schedule sessions, host your Care Plan, host session infrastructure (video and documentation), process payments, and support the Coordinated Care workflow between paired Providers.
- Communicate with you. Send appointment reminders, service updates, program-related communications, and (with your permission) newsletters or content.
- Improve the service. Analyze Platform usage, run A/B tests on non-clinical features, and improve matching, onboarding, and workflows.
- Measure outcomes. Analyze aggregated and de-identified outcomes data (PHQ-9, GAD-7, program completion, satisfaction) to improve the Programs and, where appropriate, publish research.
- Meet legal obligations. Respond to legal process, defend our legal rights, and comply with applicable law.
- Safety. Respond to safety concerns, escalate crises consistent with our Clinical Safety Manual, and prevent fraud or misuse.
3.1 De-identified data
We may aggregate and de-identify information such that it can no longer reasonably be associated with you. De-identified data may be used, disclosed, and retained without the restrictions of identified information for purposes including research, benchmarking, product development, and reporting to funders and partners.
4. How we share information
4.1 With your Providers
Information relevant to your care is shared between you and your Counselor, between you and your Spiritual Advisor, and between the two Providers in the Coordinated Care workflow you consent to in the Patient Consent.
4.2 With service providers we use
We share limited information with vendors that support the Platform, including:
- Our care platform and clinical documentation vendors
- Video conferencing (our designated video vendor)
- Payment processing (e.g., Stripe)
- Communications (e.g., email delivery, transactional SMS)
- Website hosting and form handling (our site host receives waitlist and contact form submissions)
- Cloud infrastructure and backup
We require these service providers to use information only to perform services for us and to maintain appropriate safeguards.
4.3 For legal reasons
We may share information when we believe in good faith it is necessary to (i) comply with law or legal process; (ii) protect the safety of a person; (iii) protect our rights or those of Providers; or (iv) investigate fraud or misuse.
4.4 In a business transaction
If Zaha is involved in a merger, acquisition, or asset sale, information may be transferred as part of that transaction, subject to the acquirer maintaining substantially similar privacy protections.
4.5 With your consent
We may share information for other purposes with your specific, informed consent.
4.6 What we do NOT do
5. Your choices and rights
5.1 Access and correction
You may access and correct much of your account and intake information within the Platform. For records held by your individual Provider (session notes, clinical documentation), access requests should be directed to that Provider consistent with state record-ownership rules.
5.2 Deletion
You may request that we delete your account and associated information by contacting hello@zaha.health. We will honor deletion requests to the extent required by applicable law, subject to (a) Provider record-retention obligations under state law, (b) our own reasonable retention for legal, financial, or safety purposes, and (c) de-identified data that has already been aggregated.
5.3 Marketing communications
You may opt out of marketing emails via the unsubscribe link in each email or by contacting us. Transactional communications (appointment reminders, billing notices, safety-critical messages) may continue.
5.4 State-specific rights
Around twenty states now have comprehensive consumer privacy laws, and more take effect each year. If you live in one of them you may have additional rights: to know what we hold about you, to have it corrected or deleted, to opt out of sale or targeted advertising, and to appeal if we refuse. Separately, Washington’s My Health My Data Act gives Washington residents specific rights over consumer health data. Similar consumer-health-data laws in Nevada and Connecticut give residents of those states rights over consumer health data, including rights to access and delete it and to withdraw consent; where those laws apply, we collect and share consumer health data only with your consent or as necessary to provide services you request. Where your state’s law permits, you may use an authorized agent, and if we decline a request you may appeal our decision by replying to it. To exercise these rights, contact hello@zaha.health. We do not discriminate against you for exercising these rights.
6. Security
We implement administrative, technical, and physical safeguards designed to protect information from unauthorized access, use, or disclosure, including:
- Encryption in transit and at rest for Platform-hosted data
- Access controls limiting Company personnel access to what is needed to perform their role
- Vendor management including security review of key service providers
- Provider training on confidentiality and information security
- Incident response and notification protocols
No system is perfectly secure. If we become aware of a security incident affecting your information, we will notify you without unreasonable delay and in any event no later than sixty (60) days after discovering it, consistent with the FTC Health Breach Notification Rule and applicable state breach-notification laws. If a breach involves the identifiable health information of 500 or more individuals, we will also notify the Federal Trade Commission, and prominent media where the Rule requires, on the timelines the Rule prescribes; we will notify state regulators where state law requires. The notice will tell you what happened, what information was involved, what we are doing about it, and what you can do.
7. Cookies and analytics
The zaha.health website sets no cookies and runs no analytics or tracking scripts. There is nothing to opt out of.
The Platform, once you have an account, uses cookies that are strictly necessary to keep you signed in and to keep your session secure. Blocking those will stop the Platform working.
We do not use ad-network tracking pixels, third-party advertising cookies, or session-replay tools anywhere, and we never will on a service that handles what this one handles.
8. Children
The Site and Platform are not directed to individuals under 18. We do not knowingly collect information from children under 18. If you believe a minor has provided us information, please contact hello@zaha.health so we can delete it.
9. Retention
We retain information for as long as reasonably necessary to (a) deliver the service, (b) meet Provider record-retention obligations under applicable state law (typically 7–10 years for clinical records), (c) meet our own legal, tax, or accounting obligations, and (d) resolve disputes or enforce agreements. When information is no longer needed for these purposes, we delete or de-identify it.
10. International users
The Platform is designed for use by adults residing in the United States and matched with Providers licensed to practice in the client's U.S. state of residence. If you access the Site from outside the United States, you consent to the transfer and processing of your information in the United States.
11. Changes to this Policy
We may update this Policy from time to time. When we make material changes we will notify you through the Site or by email and update the "Last updated" date at the top. If a change would materially expand how we use or share your health-related information, we will obtain your affirmative consent before applying it to information we collected earlier. Continued use of the Site or Platform after the effective date of a change indicates acceptance of the updated Policy.
12. Contact
Zaha Health, Inc. / Zaha Health Operations LLC
c/o Harvard Business Services, Inc., Registered Agent
16192 Coastal Highway, Lewes, Delaware 19958
hello@zaha.health