MyJourney Privacy Policy

Effective date: September 10, 2026

This Privacy Policy explains how RSBB Group LLC, doing business as MyJourney, handles information in connection with the MyJourney mobile application, web application, websites, and related services.

1. MyJourney's role

MyJourney provides health engagement software services to healthcare practices, medical spas, weight-management clinics, and other organizations. In most cases, an Organization creates or provisions a user's account and determines how information is collected, processed, and used through the Services.

When MyJourney creates, receives, maintains, or transmits Protected Health Information (PHI) on behalf of a HIPAA-covered Organization, RSBB Group LLC acts as that Organization's Business Associate and handles PHI under a Business Associate Agreement and applicable HIPAA requirements. An Organization's own Notice of Privacy Practices may also apply.

2. Information we may collect

3. How we use information

4. How we disclose information

Authorized personnel at the Organization controlling your account may access your account information based on assigned role permissions. MyJourney may also disclose information to service providers and subcontractors needed to operate the Services, as required by law, or in connection with a business transaction subject to applicable protections.

When a subcontractor or service provider handles PHI on our behalf, we require appropriate contractual protections, including a HIPAA-compliant Business Associate Agreement where required.

5. No sale of PHI; aggregated and de-identified analytics

MyJourney does not sell PHI, personal health data, or identifiable user information. We do not share PHI or identifiable personal data with third-party advertising networks, data brokers, or targeted marketing platforms.

Subject to applicable law, Business Associate Agreements, customer agreements, and any required written authorizations, MyJourney may create and use aggregated or de-identified data for internal service operation, security, quality, performance, product improvement, customer reporting, and analytics permitted by the applicable agreement.

MyJourney will not externally publish, license, sell, commercialize, or disclose PHI-derived de-identified data to third parties, or use such data for external AI model training or evaluation, unless expressly authorized in writing by the applicable Organization and permitted by law.

6. Cookies and storage technologies

The web application uses cookies and local storage that are necessary for session authentication, security state, anti-CSRF protections, and user interface preferences. MyJourney does not use tracking cookies for cross-site advertising.

7. Data security safeguards

MyJourney implements administrative, physical, and technical safeguards designed to protect PHI and personal data, including encryption, access controls, audit logging, secrets and key management, monitoring, backup controls, vulnerability management, and incident response procedures.

8. Retention, rights, and account closure

Information is retained for as long as necessary to fulfill Organization instructions, comply with legal and contractual retention requirements, resolve disputes, and maintain system security. To request access to, correction of, or deletion of health records managed by a clinic or med spa, contact that Organization directly. MyJourney will support the Organization in fulfilling valid requests.

9. Contact

RSBB Group LLC d/b/a MyJourney
2038 Creekbend Drive
Lancaster, OH 43130
Privacy: privacy@rsbbgroup.com
Support: support@rsbbgroup.com