Privacy Policy

Last Updated: December 18, 2025

Endo Mind, Inc. ("Thyra," "we") builds and operates the Thyra platform, websites, applications, and related services (the "Services"). This Privacy Policy explains what information we collect, how we use and share it, and the choices you have.

Health information. When we provide the Services to healthcare organizations, we may receive or create Protected Health Information (PHI) on their behalf. Our handling of PHI is governed by HIPAA and by our agreements with customers, including any Business Associate Agreement (BAA). If you are a patient, this policy does not replace your provider's Notice of Privacy Practices — direct medical-record requests to your provider.

What we collect

We do not intentionally collect sensitive personal information or patient records through the public marketing website.

How we use information

To provide the Services and fulfill requests, support customers, secure the platform, improve the product (using aggregated or de-identified data where feasible), communicate with you, and meet legal obligations. When we process PHI as a business associate, we use it only as permitted by HIPAA and our customer agreements. We do not use PHI for advertising.

Cookies and analytics

We and our providers use cookies and similar technologies for strictly necessary functions, analytics (e.g., Google Analytics or similar), and preferences. You can control cookies through your browser. We run only limited B2B advertising and do not build patient advertising profiles.

How we share information

We do not sell personal information. We share with service providers under contract, with your organization and authorized users, with third-party integrations you enable, for legal reasons, in a business transaction, and as de-identified/aggregated data.

Your choices and state privacy rights

You may opt out of marketing emails at any time. Depending on your state (e.g., California/CCPA and similar laws), you may have rights to know, access, delete, correct, and opt out of certain processing, plus non-discrimination. Email support@thyrahealth.com with the subject "Privacy Rights Request." State privacy laws generally do not apply to PHI regulated by HIPAA — direct PHI requests to your provider.

Security, retention, and contact

We use administrative, technical, and physical safeguards including access controls, encryption in transit, monitoring, and audit logging; no method is completely secure. We retain personal information as long as reasonably necessary; PHI retention is controlled by customers and applicable law. The Services are intended for use in the United States. Questions: support@thyrahealth.com (subject "Privacy"). Endo Mind, Inc., Delaware, United States. See also our Terms of Service.