Bright Patient — Privacy Policy
This policy explains what the Bright Patient mobile application
collects, how it is used, and the choices you have over your information.
It applies to the Android app (com.brighthealth.patientapp)
and the iOS app of the same name published by Bright Health.
Effective date: April 2026
1. Who we are
Bright Health (“we”, “us”, “our”) operates the Bright Patient app, which lets patients book consultations, chat with licensed doctors, make voice/video calls, receive appointment reminders, and locate partner labs/pharmacies. If you have questions about this policy, see the Contact us section below.
2. Information we collect
2.1 Information you provide
- Account info: phone number, full name, email, date of birth, gender, profile photo.
- Health-related info you choose to share: symptoms you type into the symptom checker, messages you send to doctors in chat, files or photos you attach to a consultation, water-intake logs and other self-tracked data.
- Payment info: when you pay for a consultation we pass the payment request to a third-party payment gateway (e.g. Stripe, local mobile-money providers). We never see or store your full card number; we only store the gateway’s transaction reference and a masked summary (last 4 digits, card brand).
- Support messages: anything you send us through in-app support or email.
2.2 Information collected automatically
- Device identifiers: a stable random device UUID we generate, OS version, device model, app version, preferred language.
- Push-notification token: Firebase Cloud Messaging (FCM) registration token, stored so we can deliver chat and appointment notifications.
- Approximate & precise location: only when you open a screen that needs it (e.g. finding the nearest lab or getting directions to a pharmacy). Location is not tracked in the background.
- Camera & microphone: used only during a voice/video consultation you initiate. The audio/video stream is routed through our real-time calling provider (ZEGOCLOUD) and is not recorded by us.
- Diagnostic logs: crash reports and minimal performance data if you opt in.
3. Permissions we request
| Permission | Why it is requested |
|---|---|
| Camera | Video consultations, profile photo capture. |
| Microphone | Voice and video consultations. |
| Location (coarse & fine) | Finding the closest lab / pharmacy and rendering directions. |
| Notifications | Incoming chat messages, incoming call invitations, appointment reminders. |
| Full-screen intent / display over other apps | Showing an incoming call UI the same way your phone app does. |
| Foreground services (mic/camera/phone-call) | Keeping a voice/video call alive when the screen locks. |
| Photos / media access | Attaching an image to a chat or uploading a profile picture. |
4. How we use your information
- Create and secure your account (phone-number verification via Firebase Authentication).
- Deliver the core features: booking, chat, video/audio calls, appointment reminders, water-intake tracking, and finding nearby medical facilities.
- Send transactional notifications (incoming messages, call invitations, appointment reminders).
- Detect fraud and debug crashes.
- Comply with applicable law.
We do not sell your personal information, do not use it to build advertising profiles, and do not share it with data brokers.
5. Service providers we rely on
Sub-processors that receive limited personal data so we can operate the service:
- Google Firebase (Authentication, Firestore, Cloud Messaging, Cloud Functions) — authentication, chat storage, push delivery.
- Google Maps Platform — showing maps and computing directions to labs/pharmacies.
- ZEGOCLOUD — real-time voice/video call routing and call-invitation push. Call media is transmitted, not recorded by us.
- Payment gateways (e.g. Stripe, regional mobile-money providers) — processing payment for consultations.
- Our backend API — hosted on secured cloud infrastructure to store your appointments, prescriptions, and related records.
6. Where your data is stored
Data is stored on servers operated by the sub-processors above. Google Firebase data is stored in Google data centers (multi-region). Our backend API stores data in an encrypted database hosted on commercial cloud infrastructure.
7. How long we keep your data
- Account profile & appointments: for as long as your account is active, and up to 5 years after account deletion if required to satisfy healthcare record-keeping obligations in your jurisdiction.
- Chat messages: retained while the conversation exists; you can delete individual messages; deleting the conversation permanently removes the associated messages.
- Crash logs & diagnostics: up to 90 days.
- Push-notification tokens: removed automatically when you log out or reinstall.
8. Your rights and choices
- Access & export: request a copy of the personal data we hold about you.
- Correction: update your profile in-app at any time.
- Deletion: request account deletion from inside the app (Profile → Delete account) or by emailing us. Deletion is irreversible.
- Revoke permissions: camera / mic / location permissions can be revoked in your device settings at any time; the associated features will simply stop working.
- Opt out of notifications: disable notifications in your OS settings.
9. Children
The Bright Patient app is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, contact us and we will delete it.
10. Security
We use TLS for all data in transit and rely on Google Firebase and commercial cloud infrastructure for at-rest encryption. No system is perfect — if you believe your account has been compromised, contact us immediately.
11. Changes to this policy
We may update this policy to reflect new features or legal requirements. The “Effective date” at the top of the page shows the latest revision. Material changes will be announced in-app before they take effect.
12. Contact us
Email: brighthealth247@gmail.com
Postal: Bright Health, Privacy Team (physical address on request).