Privacy Policy
How Julep Health collects, uses, and protects your information — on this website and in our mobile app.
The short version
- We collect only what we need to run the practice, this website, and our app.
- We never sell your information. Not to advertisers, not to data brokers, not to anyone.
- Your medical record is protected by HIPAA and our Notice of Privacy Practices.
- The Julep Health mobile app contains no advertising and no third-party tracking.
Who we are
Julep Health is an independent, physician-owned internal medicine practice in Ridgeland, Mississippi. This policy covers our public website, julephealth.com, and the Julep Health mobile app (com.julep.health). It explains what information we collect, why we collect it, and the choices you have.
Your medical record: HIPAA comes first
Julep Health is a covered entity under HIPAA. Your protected health information — your medical record, and health information we hold as your care team — is governed by our Notice of Privacy Practices, not by this page. The Notice describes how your health information may be used and disclosed for treatment, payment, and healthcare operations, and the rights you have under HIPAA. You can get a copy at the practice or by contacting us using the details at the bottom of this page.
This page covers everything else: what the website and the app themselves collect, and how we handle it.
What we collect on the website
Booking requests. When you book a visit we ask for your name, date of birth, phone number, email, and the reason for your visit. We use it to schedule you and to send you confirmations and reminders.
Visit checklist. If you complete our pre-visit checklist, we collect the identity, contact, emergency-contact, and health-history details you choose to provide. These submissions are encrypted before they are stored.
Newsletter. If you sign up, we collect your email address.
Store and prepayment. If you buy something from our wellness store or prepay for a visit, we keep the order details. Payment itself happens with our payment processor, Square — your full card number goes to Square, not to our servers.
Health calculators. Our health calculators run entirely in your browser. We do not receive or store the numbers you enter.
Technical basics. Like nearly every website, our server keeps standard logs (IP address, page requested, timestamp). Forms use a session cookie so they work, and Cloudflare Turnstile to block spam.
Advertising measurement. We use the Meta Pixel on the website to see whether our ads actually bring people to the site. It records page views. We do not send it the contents of any form, it has no access to your medical record, and it is not present in the mobile app. Ad blockers stop it, and the site works fine without it.
What the mobile app collects
The Julep Health app is for our patients and their care team. At release, the app collects:
- Account and identity information — your name, contact details, and sign-in credentials.
- Health information you or your care team enter — for example care plans, messages, and documents. This is your health information and is handled under HIPAA and our Notice of Privacy Practices.
- Photos and documents you choose to submit, such as an insurance card, photo ID, or record you upload or share.
- User and device identifiers needed to secure the app, such as an app account identifier, session identifier, and trusted-device identifier.
- A push notification token, if you turn notifications on.
- Insurance and coverage information you provide or that is used to support your care, such as payer, member, group, coverage, and eligibility details.
The app uses photo-library or document access only when you choose to upload something, notifications only if you enable them, and biometric features only if you choose device-based unlock. The app does not request your location, contacts, HealthKit data, or Health Connect data.
The app contains no advertising, no advertising or analytics SDKs, and no tracking pixels.
How we use information
We use the information above to schedule and provide your care, run the website and fill store orders, send appointment confirmations and reminders by text and email, send the newsletter you asked for, keep our systems secure, and (on the website only) measure whether our advertising works.
Sharing
We share information with service providers that help us run the practice: payment processing (Square), text and fax delivery, email delivery, spam protection (Cloudflare), and hosting. They work for us under contract, and when a service provider handles protected health information on our behalf, we use a business associate agreement when HIPAA requires one. We also disclose information when the law requires it.
We do not sell personal information. Ever.
Retention
Medical records are retained for the periods required by law. Website form submissions are kept as long as we need them for scheduling and practice operations. Server logs rotate on a routine schedule. Newsletter addresses are kept until you unsubscribe. Where we are not legally required to keep something, we honor deletion requests.
Security
Connections to the website and the app are encrypted in transit. Sensitive website submissions — booking requests and visit checklists — are encrypted at rest and stored outside the web server's public directory. The app also uses authentication, trusted-device protections, and access controls designed to protect information. Access is limited to the people who need it to care for you. No system is perfectly secure, and if a breach ever affects your information we will notify you as the law requires.
Children
The website and app are not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has given us personal information, contact us and we will delete it.
App-account deletion and medical records
In the currently configured mock store build, open Account, select Delete app account, review the notice, type DELETE, and select Delete app account again. The action clears the app session, stored trusted-device credential and profile, and session-scoped local caches on that device, then signs you out. It does not send a server deletion request, invalidate credentials, or prevent the same mock sign-in information from being used again.
The current in-app action does not delete a server-side app account, patient portal account, or medical records held by the practice. Medical records are retained as required by applicable law and remain protected under HIPAA and our Notice of Privacy Practices. To request a server-side account change or make a broader privacy, portal-access, or medical-record request, contact the practice using the details below. See our account-deletion instructions for the current app behavior and the app-versus-records distinction.
Your choices
- Newsletter: unsubscribe any time using the link in any email, or by contacting us.
- Messages: you can opt out of promotional messages. Operational messages — like appointment reminders — continue while you are a patient.
- Advertising pixel: browser ad blockers and tracking protection stop it, and the site still works.
- Account deletion: the current mock-build Delete app account action clears local app state and signs you out; it does not send a server deletion request. Contact the practice for a server-side account, privacy, portal-access, or medical-record request.
- Your medical record: your rights to access and amend it are described in our Notice of Privacy Practices.
Changes to this policy
When we make a material change, we will update this page and note it here.
- August 1, 2026 — Clarified app data, optional permissions, account deletion, service-provider agreements, and security statements.
- July 27, 2026 — First published.
Contact us
Julep Health
731 South Pear Orchard Road, Suite 16
Ridgeland, MS 39157
Phone: (769) 567-1826
Fax: (855) 564-1771
Email: contact@julephealth.com