Legal

Privacy Policy

Last updated: June 18, 2026

This Privacy Policy explains how KolAI collects, uses, and protects information about clinics, their staff, and the patients they serve. We take privacy seriously — especially given the sensitive nature of healthcare data.

1. Who We Are

KolAI is operated by Supertubos AI, Inc. ("KolAI", "we", "us", or "our"). We provide an AI-powered patient care coordination platform for US dermatology clinics. Our principal place of business is in the United States. You can reach us at garvita@supertubos.ai.

2. Information We Collect

We collect two categories of information:


Clinic and User Information: When you create an account or contact us, we collect your name, email address, clinic name, phone number, and billing information. We use this to provide and improve our service.


Patient Information (on behalf of clinics): When a clinic uses KolAI, we process patient names, contact details, appointment history, and clinical communication on behalf of that clinic as a Business Associate under HIPAA. We do not own or independently use this data — it belongs to the clinic and their patients.

3. How We Use Information

We use clinic and user information to:

  • Provide, operate, and improve the KolAI platform
  • Send transactional communications (billing, onboarding, support)
  • Respond to inquiries and support requests
  • Comply with legal obligations

  • We use patient information solely to perform the services the clinic has contracted us to provide — automated follow-up, clinical Q&A, and rebooking coordination. Patient data is never used to train AI models, sold to third parties, or used for advertising.

    4. HIPAA and Patient Data

    KolAI operates as a HIPAA Business Associate for each clinic we serve. We sign a Business Associate Agreement (BAA) with every clinic before processing any Protected Health Information (PHI). All PHI is:

  • Encrypted at rest (AES-256) and in transit (TLS 1.2+)
  • Stored in US-based infrastructure
  • Accessible only to authorised KolAI personnel on a need-to-know basis
  • Retained only for as long as required by the clinic's instructions or applicable law
  • Never used for AI model training or any purpose beyond service delivery

  • For HIPAA-specific details, see our HIPAA Compliance page at /hipaa.

    5. Cookies and Analytics

    Our website uses essential cookies required for the site to function, and optional analytics cookies (e.g. Google Analytics) to understand how visitors use the site. No patient data is ever sent to analytics platforms. You can disable non-essential cookies in your browser settings.

    6. Data Sharing

    We do not sell your data. We share information only in the following circumstances:

  • Service providers: Trusted vendors who help us operate (e.g. hosting, email delivery, payment processing), each bound by data processing agreements
  • Legal requirements: When required by law, court order, or to protect the rights, property, or safety of KolAI, our clients, or others
  • Business transfers: In connection with a merger, acquisition, or sale of assets, with notice to affected parties
  • 7. Data Retention

    We retain clinic and user data for as long as your account is active and for a reasonable period thereafter to fulfil our legal obligations. Patient data (PHI) is retained per your clinic's instructions and applicable HIPAA requirements. You may request deletion of your account data at any time by contacting us at garvita@supertubos.ai.

    8. Your Rights

    Depending on your location, you may have rights to access, correct, delete, or port your personal data. To exercise these rights, contact us at garvita@supertubos.ai. For patient rights requests (access to PHI), patients should contact their clinic directly; the clinic will coordinate with us as required.

    9. Security

    We implement industry-standard technical and organisational measures to protect information against unauthorised access, alteration, disclosure, or destruction. These include encryption at rest and in transit, access controls, audit logging, and regular security reviews. No method of transmission over the internet is 100% secure; we encourage clinics to report any suspected security incidents immediately.

    10. Children's Privacy

    KolAI is a business-to-business platform and is not directed at individuals under 18. We do not knowingly collect personal information from minors. Patient data involving minors is processed solely on behalf of and under the instruction of the contracted clinic.

    11. Changes to This Policy

    We may update this Privacy Policy from time to time. We will notify you of material changes via email or a notice on our website at least 14 days before the change takes effect. Continued use of KolAI after the effective date constitutes acceptance of the updated policy.

    12. Contact Us

    For any questions about this Privacy Policy or how we handle your data, contact us at:


    KolAI / Supertubos AI, Inc.

    Email: garvita@supertubos.ai