Privacy Policy

Miravio is a product of Antitropy LLC ("Antitropy", "we", "us", or "our"). We take your privacy and the security of your healthcare data seriously. This Privacy Policy outlines how we collect, use, and protect your information across our ABA therapy platform, tailored to parents, clinicians, and clinic owners.

Beta status. Miravio is currently in invite-only beta and does not accept protected health information. Beta participants agree to use demo or synthetic data only. Where this policy describes how we handle PHI, it describes how the platform is designed to operate once the required Business Associate Agreements are executed, not how it operates today. See the Beta Terms, which govern for the duration of the beta, and our security and HIPAA posture.

1. Information We Collect

We collect information that you explicitly provide to us, including:

  • Account Information: Names, email addresses, phone numbers, and authentication credentials.
  • Protected Health Information (PHI): Patient demographics, clinical data, session notes, and treatment progress (subject to HIPAA in the US). Not collected during the beta: these fields exist in the product and are expected to hold demo or synthetic data only until the regulated lane is live.
  • Financial Information: Billing details strictly for platform subscription services and RCM integration.

2. How We Use Your Information

Your data is strictly utilized to provide and improve the Miravio platform:

  • Facilitating clinical workflows, scheduling, and charting.
  • Communicating platform updates, performance analytics, and security alerts.
  • Ensuring legally mandated compliance formatting for healthcare and insurance processing.

3. Data Security and HIPAA

Miravio encrypts data in transit (TLS) and at rest (AES-256, per our infrastructure provider's published documentation). Row-Level Security (RLS) is enforced at the database level so that access is restricted to authorized users within a specific clinic tenant, with role-based permission checks on the server, rate-limited sign-in, and session revocation when a team member is removed or downgraded.

No Business Associate Agreement is currently in force, with a clinic or with our infrastructure vendors. For that reason the platform does not accept PHI during the beta. When the regulated lane is stood up, a BAA with each US clinic will govern the treatment of that clinic's PHI, sitting on top of the vendor BAAs that must be executed first. The sequence, and what is still outstanding in it, is set out in full on our HIPAA posture page.

4. Sharing of Information

We do not sell your personal data. We only share information with third-party sub-processors directly required to provide Miravio's services. Today that means our hosting, database and transactional email providers. Insurance clearinghouse connections are not live: those features run against a simulator and are labelled as simulated data in the product. Any sub-processor that would handle PHI must be under a Business Associate Agreement before it is enabled, which is part of why the beta accepts no PHI.

5. Your Rights

Depending on your jurisdiction, you have the right to access, export, or request deletion of your personal data. Clinic administrators retain primary control over organizational clinical records in accordance with medical record retention laws.

6. Contact Us

For any privacy-related inquiries, email privacy@miravio.ai and we will respond with specifics. Miravio has not appointed a Data Protection Officer, and this page will say so until one is appointed.

    Privacy Policy | Miravio