# MYJOURNEY PRIVACY POLICY

**Effective Date:** September 10, 2026

This Privacy Policy explains how **RSBB Group LLC**, doing business as **MyJourney** (“MyJourney,” “we,” “us,” or “our”), handles information in connection with the MyJourney mobile application, web application, websites, and related services (collectively, the “Services”).

**Website:** https://www.rsbbgroup.com  
**Privacy Contact:** `privacy@rsbbgroup.com`  
**Support Contact:** `support@rsbbgroup.com`  

---

## 1. MyJourney’s Role

MyJourney provides multi-tenant health engagement software services to healthcare practices, medical spas, weight management clinics, and other organizations (“Organizations”).

In most cases, an Organization creates or provisions a user’s MyJourney account and determines how information is collected, processed, and used through the Services.

When MyJourney creates, receives, maintains, or transmits Protected Health Information (“PHI”) on behalf of a HIPAA-covered Organization, RSBB Group LLC acts as that Organization’s **Business Associate** and handles PHI strictly under a Business Associate Agreement (“BAA”) and applicable HIPAA Security & Privacy Rule requirements.

An Organization’s own privacy practices and Notice of Privacy Practices also apply to your PHI. This Privacy Policy does not replace or override an Organization’s HIPAA Notice of Privacy Practices.

---

## 2. Information We May Collect

Depending on how an Organization configures and uses MyJourney, the Services process the following categories of information:

### Account and Identity Information

- Full name, email address, and account credentials;
- Organization membership, assigned role (e.g., Patient, Clinician, Med Spa Admin, Super Admin), and permission grants;
- Multi-factor authentication (MFA/TOTP) setup state and authentication logs;
- Contact information provided by the user or Organization.

### Health and Wellness Information (PHI)

The Services process health-related information entered by users or clinical staff, including:

- Body measurements (weight, body fat percentage, muscle mass, waist/chest measurements);
- GLP-1 weight management analytics, dosage history, and plateau state progress tracking;
- Medication administration logs (prescribed medications, dose timestamps, skip/pause/stop status);
- Daily hydration and nutritional macro tracking (protein, calories, carbs, fats);
- Patient progress photographs and related images;
- Symptom logger entries and check-ins;
- AI Coach interaction logs and personalized health goals.

### Device and Technical Information

We receive technical information necessary to secure, operate, and troubleshoot the Services:

- Device model, operating system version, browser type, and mobile app build version;
- IP address, request timestamps, and user-agent details;
- Service event metadata necessary to operate real-time and asynchronous platform features;
- Security and audit events;
- Redacted application diagnostic logs (PII/PHI masked by automated redaction filters prior to log storage).

### Support Information

If you contact support, we process the information provided in your request and related correspondence.

---

## 3. How We Use Information

We use information to:

- Provide, operate, and maintain the Services;
- Authenticate users and enforce role-based access controls (RBAC) and multi-tenant isolation;
- Process health measurements, medication schedules, and clinical progress tracking;
- Maintain security and audit trails required by law, contract, and security policies;
- Detect and prevent unauthorized access, brute-force attacks, or security threats;
- Provide technical customer support and system diagnostics;
- Comply with legal, regulatory, and contractual obligations;
- Enforce our agreements and terms of service.

When information constitutes Protected Health Information (PHI), our uses and disclosures are limited by applicable BAAs, HIPAA regulations, and strict least-privilege administrative access controls.

---

## 4. How We Disclose Information

We disclose information only as follows:

### To the Organization Responsible for Your Account

Authorized personnel at the Organization controlling your account (e.g., attending physicians, med spa clinicians, clinic admins) have access to your account information based on their assigned role permissions.

### To Service Providers and Subcontractors

We use select infrastructure providers, service providers, and subcontractors to operate the Services, such as providers for hosting, data storage, secrets management, payment processing, support, and AI-enabled features where enabled by the Organization.

Payment processors may receive billing, contact, and transaction information needed to process Organization-paid billing. MyJourney does not intentionally send clinical PHI to payment processors.

When a subcontractor or service provider handles PHI on our behalf, we require appropriate contractual protections, including a HIPAA-compliant Business Associate Agreement (BAA) where required.

Customer-specific subprocessors are identified in the applicable agreement or in MyJourney’s published subprocessor list when available.

### As Required by Law

We disclose information when required by law, court order, subpoena, or governmental request, strictly consistent with HIPAA Permitted Disclosures.

### Business Transactions

If RSBB Group LLC undergoes a merger, acquisition, or asset sale, information will remain protected under the terms of this Policy, applicable BAAs, and HIPAA requirements.

---

## 5. We Do Not Sell PHI; Aggregated & De-Identified Analytics

### No Sale of PHI or Identifiable Personal Information
**MyJourney does not sell PHI, personal health data, or identifiable user information.** 

We do not sell user lists, nor do we share PHI or identifiable personal data with third-party advertising networks, data brokers, or targeted marketing platforms. No third-party ad SDKs or ad-tracking scripts are embedded in the MyJourney mobile application or web dashboard.

### De-Identified Data and Aggregated Analytics
Subject to applicable law, Business Associate Agreements (BAAs), customer agreements, and any required written authorizations, MyJourney may create and use aggregated or de-identified data:

- **HIPAA De-Identification**: When data is derived from PHI, de-identification is performed using a HIPAA-recognized method, such as Safe Harbor or Expert Determination, as applicable.
- **Permitted Analytical Uses**: Aggregated or de-identified data may be used for internal service operation, security, quality, performance, product improvement, customer reporting, and analytics permitted by the applicable agreement.
- **No External Commercialization Without Authorization**: MyJourney will not externally publish, license, sell, commercialize, or disclose PHI-derived de-identified data to third parties, or use such data for external AI model training or evaluation, unless expressly authorized in writing by the applicable Organization and permitted by law.
- **Non-Re-identification**: MyJourney does not attempt to re-identify de-identified data except as permitted by law and expressly authorized in writing for validation, security, or compliance purposes.

---

## 6. Cookies and Storage Technologies

The web application uses secure HTTP-only cookies and local storage strictly necessary for:
- User session authentication & refresh token rotation;
- Security state & anti-CSRF protections;
- User UI preference persistence (e.g., dark mode, active tab state).

We do not use tracking cookies for cross-site advertising.

---

## 7. Data Security Safeguards

We implement administrative, physical, and technical safeguards designed to protect PHI and personal data:

- **Encryption**: Encryption for data in transit and at rest, as appropriate;
- **Access Controls**: Role-based access controls and tenant isolation controls;
- **Audit Logging**: Security and audit logging for sensitive activity;
- **Secret and Key Management**: Controlled management of application secrets and encryption keys;
- **Monitoring and Response**: Security monitoring, backup controls, vulnerability management, and incident response procedures.

---

## 8. Data Retention

We retain information for as long as necessary to fulfill Organization instructions, comply with legal and contractual retention requirements, resolve disputes, and maintain system security. HIPAA compliance documentation may be retained for at least six (6) years where required; health records are retained according to Organization instructions, applicable BAAs, and applicable law.

Data retention and purging follow the *MyJourney Data Retention and Disposal Policy*.

---

## 9. Individual Rights (Access, Amendment, Deletion)

### PHI Managed by an Organization
To request access to, correction of, or deletion of health records managed by a clinic or med spa, contact your healthcare provider/Organization directly. MyJourney will support the Organization in fulfilling valid requests.

### Directly Controlled Information
For inquiries regarding information controlled directly by RSBB Group LLC, contact:

**`privacy@rsbbgroup.com`**

---

## 10. Account Closure

Accounts may be closed upon request by the user or Organization. Closing an account disables active access; historical health records and audit logs are retained in accordance with HIPAA, state medical record retention laws, and Organization instructions.

---

## 11. Children’s Privacy

MyJourney is designed for use by adults or by minors under the direct supervision and authorization of a parent, legal guardian, or treating healthcare provider.

---

## 12. State Privacy Rights

Depending on your state of residence (e.g., California, Ohio, Virginia), state privacy laws may grant specific consumer privacy rights. Health records governed by HIPAA are generally exempt from state consumer privacy acts, but remain protected under HIPAA and state medical privacy statutes.

---

## 13. International Data Transfers

MyJourney is hosted and operated in the United States. If you access the Services from outside the U.S., your information will be transferred to and processed in the United States under U.S. privacy laws.

---

## 14. Changes to This Privacy Policy

We may update this Privacy Policy periodically. Material updates will be posted with an updated effective date on our website.

---

## 15. Contact Us

**RSBB Group LLC d/b/a MyJourney**  
2038 Creekbend Drive  
Lancaster, OH 43130  
Website: https://www.rsbbgroup.com  
Privacy Contact: `privacy@rsbbgroup.com`  
Support Contact: `support@rsbbgroup.com`  
