E-Labus
    HIPAA-Aligned

    Privacy Policy

    Last updated: June 4, 2026 · ConveLabs Inc. DBA E-Labus

    1. Who We Are

    ConveLabs Inc. ("ConveLabs," "we," "us," or "our") operates the E-Labus health platform ("Platform") at elabus.com. E-Labus is a HIPAA-regulated health technology service that enables individuals to upload laboratory results and receive AI-assisted interpretations, and enables licensed healthcare providers to review those results with patient consent.

    As a covered entity and/or business associate under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), we are required by law to maintain the privacy of your Protected Health Information ("PHI") and to provide you with this Notice of our privacy practices.

    Privacy Contact:
    ConveLabs Inc. — Privacy Officer
    Email: info@convelabs.com
    Subject line: "Privacy Request"

    2. Protected Health Information We Collect

    We collect and process the following categories of information in connection with your use of the Platform:

    Health & Medical Information (PHI)

    • Laboratory test results, panels, and PDF reports you upload
    • Biomarker values (e.g., glucose, lipid panels, CBC, hormone levels)
    • Health history and conditions you voluntarily provide
    • Medication lists and supplement information
    • AI-generated interpretations and health insights associated with your results
    • Provider notes or annotations added with your consent

    Account & Identity Information

    • Name, email address, date of birth, and account credentials
    • Provider credentials, NPI number, and practice affiliation (for provider accounts)

    Billing Information

    • Payment method details (processed by Stripe; we do not store raw card numbers)
    • Subscription tier and billing history

    Usage & Technical Data

    • IP address, browser type, and device identifiers
    • Pages visited, features used, and timestamps (for security and HIPAA audit logs)

    3. How We Use Your Information

    We use your information for the following purposes:

    • AI-Assisted Lab Interpretation: Submitting your lab data to our AI analysis pipeline (powered by an enterprise AI provider under a signed Business Associate Agreement, which never uses your data to train its models) to generate plain-language insights and trend analysis.
    • Provider Sharing: Displaying your lab results and AI summaries to licensed healthcare providers you have explicitly authorized via the in-platform consent mechanism.
    • Account Management: Creating and maintaining your account, authenticating your identity, and managing your subscription.
    • Billing & Payments: Processing subscription payments, issuing receipts, and managing refunds through Stripe.
    • Communications: Sending transactional emails (e.g., upload confirmations, results ready, security alerts) via Mailgun. We do not send unsolicited marketing emails containing PHI.
    • Security & Compliance: Maintaining HIPAA audit logs, detecting unauthorized access, and fulfilling legal obligations.
    • Service Improvement: Aggregated, de-identified analytics to improve platform features. We do not use individually identifiable PHI for model training without explicit written consent.

    4. Who We Share Your Information With

    We do not sell your PHI. We share information only with the following categories of Business Associates and service providers, each bound by a HIPAA-aligned Business Associate Agreement (BAA) where applicable:

    VendorPurposeData Shared
    Enterprise AI provider (HIPAA BAA)AI-powered lab interpretation and insights generationLab values, biomarker data (PHI)
    Supabase, Inc.Encrypted database storage (PostgreSQL) and authenticationAll account and PHI data
    Mailgun (Sinch)Transactional email deliveryEmail address, notification content
    Stripe, Inc.Payment processing and subscription managementName, email, payment method (no PHI)

    We may also disclose PHI as required by law, court order, or to prevent serious harm, in accordance with 45 CFR 164.512.

    5. Your HIPAA Rights

    As a patient whose PHI we hold, you have the following rights under HIPAA (45 CFR Part 164, Subpart E):

    • Right to Access (45 CFR 164.524): You may request a copy of your PHI in our records. We will provide access within 30 days. Electronic copies are available via your account dashboard.
    • Right to Amendment (45 CFR 164.526): If you believe your PHI is inaccurate or incomplete, you may request an amendment. We will respond within 60 days.
    • Right to Accounting of Disclosures (45 CFR 164.528): You may request a list of disclosures of your PHI made by us in the past six years (excluding disclosures for treatment, payment, or healthcare operations).
    • Right to Request Restrictions (45 CFR 164.522): You may request that we restrict certain uses or disclosures of your PHI. We are not required to agree, except where you pay out-of-pocket in full and request restriction to your health plan.
    • Right to Confidential Communications (45 CFR 164.522(b)): You may request that we communicate with you by alternative means or at alternative locations.
    • Right to File a Complaint: If you believe your privacy rights have been violated, you may file a complaint with us at info@convelabs.com or with the U.S. Department of Health and Human Services, Office for Civil Rights at hhs.gov/ocr. You will not be retaliated against for filing a complaint.

    To exercise any of these rights, email info@convelabs.com with the subject line "HIPAA Rights Request" or use the Privacy Center in your account settings.

    6. Data Retention

    We retain PHI for the duration of your active account plus seven (7) years following account termination, in accordance with HIPAA's minimum retention standards and applicable state law (Florida: Fla. Stat. § 456.057). Some records may be retained longer where required by law or ongoing legal proceedings.

    Upon deletion request, we will de-identify or destroy PHI within 90 days, except where retention is legally required. Backup copies may persist for up to 30 additional days during standard backup rotation.

    7. Security Measures

    We implement administrative, physical, and technical safeguards as required by the HIPAA Security Rule (45 CFR Part 164, Subpart C):

    • Encryption in Transit: All data transmitted between your browser and our servers uses TLS 1.2 or higher.
    • Encryption at Rest: PHI stored in Supabase (PostgreSQL) is encrypted using AES-256. Uploaded lab PDFs are stored in encrypted object storage.
    • Row-Level Security (RLS): Database access is enforced at the row level so users can only access their own records; providers can only access records of patients who have granted consent.
    • HIPAA Audit Logs: We maintain immutable audit logs of all access to and disclosures of PHI, retained for at least six years.
    • Access Controls: Role-based access control (RBAC) limits internal staff access to PHI on a need-to-know basis.
    • Breach Notification: In the event of a breach affecting your PHI, we will notify you and HHS as required by the HIPAA Breach Notification Rule (45 CFR Part 164, Subpart D).

    8. Cookies and Tracking

    E-Labus uses a minimal cookie footprint consistent with our HIPAA obligations. We use only:

    • Session cookies: Required for authentication and to maintain your logged-in state. These expire when you close your browser or after a period of inactivity.
    • Security cookies: Used to detect and prevent cross-site request forgery (CSRF) attacks.

    We do not use third-party advertising cookies, cross-site tracking pixels, or analytics cookies that share PHI with external advertising networks.

    9. California Residents — CCPA Rights

    If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the CPRA, grants you additional rights. Note that PHI collected and maintained subject to HIPAA is exempt from the CCPA (Cal. Civ. Code § 1798.145(c)(1)(A)). For non-PHI personal information, California residents have the right to:

    • Know what personal information we collect, use, disclose, and sell
    • Delete personal information we hold about you (subject to exceptions)
    • Opt out of the sale or sharing of personal information (we do not sell personal information)
    • Non-discrimination for exercising your CCPA rights
    • Correct inaccurate personal information
    • Limit use of sensitive personal information

    To submit a CCPA request, contact us at info@convelabs.com with the subject line "California Privacy Request." We will respond within 45 days.

    10. SMS & Text Messaging

    E-Labus offers an opt-in text-messaging service ("Ellie") through which we send health notifications and answer questions about your own lab results. You enroll only by entering your own mobile number in your account settings and confirming by reply (a double opt-in); message frequency varies and message and data rates may apply. Reply STOP to cancel or HELP for help at any time.

    We do not share, sell, or rent your mobile phone number or your SMS opt-in/consent information to any third parties or affiliates for their marketing or promotional purposes. Your number is used solely to operate the messaging service and is delivered through our messaging provider (Twilio) for that purpose only. Full details, including the opt-in steps and message types, are in our SMS / Text Messaging Terms.

    11. Contact Us

    For privacy questions, rights requests, or to report a privacy concern, contact our Privacy Officer:

    ConveLabs Inc. DBA E-Labus

    Privacy Officer

    Email: info@convelabs.com

    Subject: "Privacy Request"

    We may update this Privacy Policy periodically. Material changes will be communicated via email and an in-app notice at least 30 days before they take effect. Continued use of the Platform after the effective date constitutes acceptance of the revised Policy.

    Ellie

    BY E-LABUS

    Hi, I'm Ellie.

    Your whole health story — one intelligence.

    vmsfoxq27 · Aug 5, 2026, 06:13 AM UTC