Privacy Policy
- Provider:
- CozziTech LLC
- Applies to:
- cozzitech.com, the ctEVV™ platform, and connected calendar and meeting accounts
- Effective Date:
- August 9, 2026
- Last Updated:
- September 14, 2026
CozziTech LLC ("CozziTech," "we," "us," or "our") respects your privacy. This Privacy Policy covers distinct things, and it is important to know which part applies to you:
- Part I describes our public marketing website at cozzitech.com — the pages you are reading right now.
- Part II describes the ctEVV™ Electronic Visit Verification platform — the caregiver mobile app and the agency web portal. That is regulated software that handles health information, and it is governed by a materially different set of rules than our website.
- Part III describes what happens when you choose to connect a third-party calendar or meeting account — Google, Microsoft, or Zoom — to a CozziTech product such as ctScheduling™.
The parts are independent. Practices described in Part I do not apply to the ctEVV™ platform, and practices described in Part II do not apply to our website.
Part I — Our Website
This Part applies to cozzitech.com and any CozziTech marketing page, form, or email that links to it. It does not apply to any CozziTech application you sign in to.
1. Information You Give Us Directly
Most of our website can be read without giving us anything at all. You give us information only when you choose to contact us — for example, by submitting our contact or demo-request form, joining a waitlist or early-access list, or emailing us. Depending on the form, that may include:
- Your name
- Your email address and, if you provide it, your phone number
- Your organization or agency name and your role
- Whatever you choose to write in a message or free-text field
We use this information to respond to you, to schedule and conduct demonstrations, to answer questions about our products and services, and to follow up about the request you made. If you become a customer, we also use it to administer that relationship.
2. Website Analytics
We operate our own first-party analytics on cozzitech.com. Its purpose is narrow: to understand which pages, guides, and topics are actually useful so we can write better ones, and to understand which of our own marketing efforts bring people here. When you view a page, our analytics records:
- A random visitor identifier and a session identifier. These are randomly generated strings stored in your browser. They are not derived from your name, your email, your IP address, or any characteristic of your device, and they cannot be reversed into an identity.
- Page activity — the page address, page title, the page you came from within our site, how far down the page you scrolled, roughly how long the page was actively in front of you, and which buttons or links you clicked.
- Referral and campaign information — the website that referred you (if any) and any campaign tags or advertising click identifiers present in the address you arrived on, so we can tell which of our own campaigns and content are working.
- Coarse technical context — device category (desktop, tablet, or mobile), browser family, operating system family, viewport size, browser language, and time zone.
2.1 What our analytics deliberately does not do
- No fingerprinting. We record only the coarse categories listed above. We do not assemble a device fingerprint, and we do not attempt to recognize you when you clear your browser storage.
- No cross-site tracking and no advertising profiles. Our analytics runs only on our own website. We do not track you across other companies' websites, and we do not build advertising profiles or sell audiences.
- No capture of what you type. Values you enter into forms are not sent to our analytics. Web addresses are sanitized before they are recorded: parameters that commonly carry sensitive values — including email, phone, name, date of birth, tokens, verification codes, and password or session values — are stripped out, as is the fragment portion of the address.
- No sale or sharing for cross-context advertising. We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under California and other state privacy laws.
2.2 Third-party analytics services
In addition to our own first-party analytics, we may enable third-party website measurement services — for example, a general web analytics provider or a page-quality service that produces aggregate heatmaps and scroll maps. Where we do, we configure them for measurement rather than advertising, including truncation of IP addresses where the service supports it, and we do not authorize them to use our website data to build advertising profiles. These services are used only on our marketing website. They are never present in the ctEVV™ platform.
3. Cookies and Browser Storage
We use a small number of first-party cookies and browser storage entries. We do not place third-party advertising cookies on our website.
| What | Purpose | Lifetime |
|---|---|---|
| Visitor identifier | A random string that lets us count returning visitors without knowing who they are. | Until you clear browser storage |
| Session state | Groups page views into a single visit. A visit ends after 30 minutes of inactivity. | Rolling 30 minutes |
| Attribution | Remembers the campaign or referring site you first and most recently arrived from. | Up to 90 days |
| Privacy preference | Records the analytics and marketing choices you have made, so we can honor them. | Up to 12 months |
| Internal-traffic flag | Marks our own staff and test traffic so it is excluded from reporting. | Up to 12 months |
You can clear or block these at any time through your browser settings. Doing so does not affect your ability to read the site.
4. Global Privacy Control and Do Not Track
We honor the Global Privacy Control (GPC) signal. If your browser or extension sends a GPC signal — or a Do Not Track signal — we treat it as an opt out of non-essential analytics and of any sharing for advertising purposes, and no opt-out request or form submission is required from you.
5. How We Share Website Information
- With service providers acting on our behalf. We use a limited number of vendors to operate the website, deliver form submissions and email to us, and measure site performance. They are permitted to use the information only to provide those services to us.
- To comply with law. We may disclose information if required to do so by law, subpoena, court order, or other valid legal process.
- To protect rights and safety. We may disclose information when we believe in good faith that disclosure is necessary to investigate, prevent, or take action regarding suspected illegal activity, fraud, or threats to the safety of any person.
- In connection with a corporate transaction. If CozziTech is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to the commitments in this Policy.
We do not sell, rent, or trade personal information to third parties for their own marketing purposes.
6. Retention
Inquiry and demo-request information is retained for as long as needed to respond to you and to maintain a record of our business relationship, and thereafter as required for legal, tax, and recordkeeping purposes. Analytics records are retained in identifiable-by-random-ID form for no longer than 26 months, after which they are retained only in aggregate form or deleted.
7. Your Rights and Choices
Depending on where you live, you may have the right to access, correct, delete, or receive a portable copy of the personal information we hold about you, to opt out of certain processing, and not to be discriminated against for exercising these rights. Residents of California, Colorado, Connecticut, Virginia, and other states with comprehensive privacy laws, as well as individuals in the EU and UK, have such rights.
To exercise them, email privacy@cozzitech.com. We will verify your request and respond within the time required by applicable law. You may also opt out of analytics at any time by enabling Global Privacy Control in your browser, and you may unsubscribe from any marketing email using the link in that email.
If your question concerns information held inside a CozziTech application that a provider agency operates — for example, a consumer record in ctEVV™ — see Part II; those requests are directed to the agency.
8. Security
Our website is served over encrypted connections, and we maintain administrative and technical safeguards intended to protect information submitted to us. No method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.
9. Children
Our website is directed to businesses and organizations, not to children. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us and we will delete it.
10. International Visitors
The website is operated from the United States. By using it, you understand that your information will be processed in the United States, which may have data protection laws different from those in your country of residence.
Part II — The ctEVV™ Platform
This Part applies to the ctEVV™ mobile application for caregivers and the ctEVV™ web portal for administrators. It does not apply to our marketing website. Originally published as the ctEVV™ Privacy Policy, effective May 23, 2026.
CozziTech LLC provides the ctEVV™ Electronic Visit Verification (EVV) platform, consisting of a mobile application for caregivers and a web portal for administrators (together, the "Service"). This Part explains what information the Service collects, how we use and disclose that information, the choices you have, and the safeguards we apply.
1. Who This Part Applies To
This Part applies to three categories of individuals whose information the Service may process:
- Caregivers / Workers who log in to the ctEVV™ mobile or web application to record visits.
- Consumers / Clients (the individuals receiving services) whose records are managed in the Service by a provider agency.
- Administrators at provider agencies who use the web portal to manage consumers, visits, and reports.
In most cases, the provider agency (not CozziTech) is the "Covered Entity" under HIPAA and is the controller of the consumer information processed in the Service. CozziTech processes that information on the agency's behalf under the BAA in force with that agency.
2. Information We Collect
2.1 Consumer Information
When an agency creates or imports a consumer record, the Service stores information such as:
- Full legal name, middle name, suffix, and any "also known as" names
- Date of birth and gender
- Home address (street, city, state, ZIP, county)
- Email address(es)
- Medicaid identifier
- Program enrollment information, current plan, and assigned support coordinator
- Diagnosis codes and diagnosis description (ICD-style codes; PHI)
- A photograph reference for visual identification
2.2 Caregiver / Worker Information
- Username and a securely hashed password (passwords are never stored in plaintext)
- Worker identifier and tenant (agency) assignment
- Role and access-level indicators
- Account creation timestamp
2.3 Visit and Location Data
To verify the time, place, and delivery of services, the Service collects:
- Check-in and check-out timestamps
- Precise GPS coordinates (latitude and longitude) at check-in, at check-out, and at periodic intervals (by default approximately every five minutes) while a visit is open
- Distance from the consumer's known service address (used to alert workers if they move outside the expected service area)
- Coordinates captured at the moment of signature
- Visit notes and visit type (free-form text entered by the caregiver; may contain PHI)
- Administrative notes flagged for review
- Electronic signature image (a signature captured on the device)
2.4 Device and Authentication Information
- Session tokens used to maintain an authenticated session
- Stored credentials in the device's hardware-backed secure storage only if the caregiver enables biometric sign-in
- A biometric-enabled flag indicating that the caregiver has chosen to use device-level biometric unlock (such as Face ID, Touch ID, or Android biometric unlock) to re-authenticate
- Push notification tokens issued by the device platform's push notification service (Apple and Google), used to deliver operational alerts to the mobile app
2.5 Information We Do Not Collect
The Service does not integrate any third-party analytics, advertising, crash-reporting, or behavioral-tracking SDKs. The website analytics described in Part I are not present in the ctEVV™ mobile app or web portal. We do not sell personal information, and we do not use PHI for advertising.
3. How We Use Information
We use the information described above only for the following purposes:
- To authenticate caregivers and administrators and to keep accounts secure
- To record, verify, and report electronic visit verification events as required by the agency's payer (for example, a state Medicaid program)
- To confirm that services were delivered at the correct location and time
- To enable agency administrators to manage consumer records, schedules, and visit history
- To deliver operational notifications (for example, reminders to check out, or alerts when a worker has moved beyond the expected service area)
- To protect the Service against fraud, abuse, and unauthorized access
- To meet legal, regulatory, and contractual obligations, including those imposed by HIPAA and applicable state EVV regulations
4. Location Services
ctEVV™ requires precise location access on mobile devices in order to function as an EVV system. Location is collected only while a caregiver is signed in and a visit is open, and the device prompts for foreground and (where applicable) background location permission before any coordinates are captured. Caregivers may revoke location permission at any time in their device settings; however, the Service cannot record a compliant EVV visit without location access.
5. How We Share Information
We share information only as described below:
- With the provider agency that employs or contracts you. All consumer, worker, and visit information is made available to the agency that owns the data, in accordance with the BAA in force with that agency.
- With service providers acting on our behalf. We use a limited number of vendors to operate the Service, including:
- Cloud hosting and database providers that store Service data;
- Platform push notification services (Apple and Google) that deliver operational notifications to the mobile app. Push payloads are designed to avoid carrying PHI.
- To comply with law. We may disclose information if required to do so by law, subpoena, court order, or other valid legal process, and as permitted under 45 C.F.R. § 164.512.
- To protect rights and safety. We may disclose information when we believe in good faith that disclosure is necessary to investigate, prevent, or take action regarding suspected illegal activity or threats to the safety of any person.
- In connection with a corporate transaction. If CozziTech is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to the confidentiality and HIPAA obligations described in this Policy.
We do not sell, rent, or trade personal information or PHI to third parties for their own marketing purposes.
6. Data Security
CozziTech maintains administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of information processed by the Service, consistent with the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C). These safeguards include, among others:
- Encryption of data in transit
- Storage of caregiver passwords as salted cryptographic hashes — plaintext passwords are never persisted on our servers
- Authenticated session tokens with limited lifetimes
- Use of the device operating system's hardware-backed secure storage for any credentials cached on the device
- Role- and tenant-based access controls within the platform
- Logging and monitoring of authentication and administrative events
No method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.
7. Breach Notification
In the event of a breach of unsecured PHI, CozziTech will notify the affected Covered Entity without unreasonable delay and in any event within the timeframes required by the HIPAA Breach Notification Rule (45 C.F.R. §§ 164.400–414) and the applicable BAA. The Covered Entity is responsible for notifying affected individuals, the Secretary of Health and Human Services, and, where required, the media, unless the BAA expressly delegates that responsibility to CozziTech.
8. Data Retention
Visit records, location data, signatures, and notes are retained for as long as the provider agency's account remains active and for any additional period required by the agency's payer, by applicable state EVV regulations, or by HIPAA record-retention requirements (generally at least six years). When retention periods expire and an agency requests deletion, CozziTech will delete or de-identify the information in accordance with the BAA, except where retention is required by law.
9. Your Rights
If you are a consumer whose information is processed in ctEVV™, your HIPAA-protected rights (including the right to access, amend, and receive an accounting of disclosures of your PHI) are exercised through the provider agency that maintains your record, which is the Covered Entity for HIPAA purposes. Please direct requests to that agency. CozziTech will support the agency in responding to such requests as required by HIPAA and the applicable BAA.
If you are a caregiver, you may request access to or correction of the account information we hold about you by contacting us at the address below or by asking your agency administrator.
Depending on where you live, you may have additional rights under state privacy laws. We will honor such rights to the extent they apply and do not conflict with HIPAA or with our obligations to a Covered Entity.
10. Children's Privacy
ctEVV™ is not directed to children and is not intended to be used by individuals under 13 to create an account. The Service may, however, contain consumer records of minors who receive services through a provider agency; such records are processed at the direction of, and under the legal authority of, the agency that maintains them.
11. International Users
The Service is hosted in and operated from the United States. By using the Service, you understand that your information will be processed in the United States, which may have data protection laws different from those in your country of residence.
Part III — Connected Calendar and Meeting Accounts
This Part applies to any CozziTech product in which you choose to connect a third-party calendar or meeting account — today, ctScheduling™. It applies in addition to the practices described in Part I for our website.
1. What a Connection Is
ctScheduling™ can connect to a calendar or meeting account you already hold with a third-party provider — Google, Microsoft, or Zoom. The connection exists so the product can do the things you have asked it to do: offer other people times when you are genuinely free, show your own upcoming events back to you alongside your tasks, and put the resulting meeting on your calendar with a working meeting link attached.
Connections are always started by you. When you begin one, you are sent to the provider's own sign-in screen, where the provider — not CozziTech — authenticates you and shows you exactly which permissions are being requested. Nothing is connected unless you approve that screen. We never ask for, receive, or store your password for a connected account.
2. What We Access
We request the narrowest access that supports the feature you are using. Across all providers, that access falls into four categories:
- Availability (free/busy). On the calendars you select, we read when you are busy and when you are free — the start and end times of blocks that are already committed. This is what lets ctScheduling™ avoid offering a time you cannot make.
- Your upcoming events, to show you your own agenda. Where a product page shows your schedule back to you — today, the agenda beside your tasks — we read the title and time of your events on the connected calendar, up to 31 days ahead. Those events are shown only to you, are held in server memory for up to 10 minutes while the page is produced, and are not saved to our systems. We do not read their descriptions, attendees, or attachments.
- The events we create. When a meeting is finalized through ctScheduling™, we create the calendar event on your behalf and then read, update, or remove that event — for example, deleting it if the meeting is cancelled. This includes the event's time, title, description, invitee list, and the meeting link attached to it.
- Basic account identification. The provider gives us your name, email address, and an account identifier so the connection can be labeled correctly and matched to the right calendar. We do not receive your provider password.
2.1 What we do not do with a connected account
- We do not read the descriptions, attendee lists, or attachments of calendar events that ctScheduling™ did not create. For those events we look at when they make you busy and — only where you are being shown your own agenda — their titles and times, as described above. Nothing further.
- We do not read your email, your contacts, your files, or your chat or channel messages.
- We do not join, record, transcribe, or listen to your meetings.
- We do not use connected-account data for advertising, and we do not build advertising or marketing profiles from it.
- We do not use connected-account data to develop, improve, or train generalized artificial intelligence or machine learning models.
- We do not allow humans to read connected-account data, except with your explicit permission to resolve a support issue you have raised, where necessary for security purposes such as investigating abuse, or where required by law.
2.2 By provider
| Provider | What the connection is used for |
|---|---|
| Google Google Calendar, Google Meet |
Reading availability on the calendars you select; reading the titles and times of your upcoming events to show you your own agenda; creating, updating, and removing the events ctScheduling™ creates on your behalf, including any Google Meet link attached to them. |
| Microsoft Microsoft 365 / Outlook Calendar, Microsoft Teams |
Reading availability on the calendars you select; reading the titles and times of your upcoming events to show you your own agenda; creating, updating, and removing the events ctScheduling™ creates on your behalf; and creating the Microsoft Teams online meeting attached to those events. |
| Zoom | Creating and deleting the Zoom meetings that correspond to meetings finalized in ctScheduling™, and reading your name and email address so the connection can be labeled and the meeting created under the right account. A Zoom connection does not read any calendar. |
Where a provider offers a permission that is narrower than the one we would otherwise need, we use the narrower one. If a feature we add later requires access beyond what is described here, you will be asked to approve the additional permission before it takes effect.
3. Access Credentials and Security
When you approve a connection, the provider issues CozziTech an authorization credential — commonly called an OAuth access token and refresh token — that lets the product act within the scope you granted, and only that scope.
- Tokens are stored encrypted at rest and are transmitted only over encrypted connections.
- Tokens are never displayed in the product interface, never included in exports or reports, and never shared with another customer or user.
- Tokens are used only to perform the actions you asked for — checking your availability, showing you your own agenda, and managing the events created through the product.
- Access is restricted to the systems that need it, and administrative and technical safeguards are applied consistent with those described elsewhere in this Policy.
No method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.
4. How We Share Connected-Account Information
We do not sell connected-account information, and we do not share it for cross-context behavioral advertising or for any third party's own marketing purposes. We do not transfer it to any other application except as needed to provide the feature you are using. We share it only:
- Back to the provider you connected — for example, sending Microsoft the details of the event you asked us to place on your Microsoft calendar.
- With the people involved in the booking — an invitee who books time with you necessarily sees the meeting details and the meeting link.
- With service providers acting on our behalf to operate and secure the product, under written agreements limiting them to that purpose.
- To comply with law, or to protect rights and safety, on the same terms described in Part I.
4.1 Google user data — Limited Use
4.2 Microsoft and Zoom data
Information we receive from Microsoft or Zoom is handled on the same basis: it is used only to provide the user-facing features described in this Part, it is not sold, it is not transferred to any other application, it is not used for advertising or for training generalized AI or machine learning models, and it is not read by a human except in the limited circumstances described in Section 2.1. Your use of Google, Microsoft, or Zoom is separately governed by that provider's own terms and privacy policy, which we do not control.
5. Retention
Access credentials and the connection record are retained only while the connection is in place. When you disconnect — or when a provider revokes or expires our access — we delete the stored credentials promptly, and in any event within 30 days, including from routine backups on their normal cycle. Availability information is used to compute the times we offer and is not retained as a standing copy of your calendar. The titles and times read to show you your own agenda are held in server memory for up to 10 minutes while the page is produced and are not saved. Records of bookings made through the product are retained as part of your account's own scheduling history for as long as your account is active, and are deleted or de-identified thereafter in accordance with our agreement with you.
6. How to Disconnect
You are in control of a connection for its entire life, and you can end it at any time by either of the following methods. Either one immediately stops all further access by the product.
- From inside the product. Open your Profile → Connected calendars in ctAgencySuite™, find the calendar or meeting account, and select Disconnect. We delete our stored copy of the credential right away, and for Google and Zoom we also end the access at the provider. Microsoft does not offer us a way to remove the permission on Microsoft's side; to clear it there as well, use method 2.
- From the provider directly. You can revoke CozziTech's access from your provider's own security settings, without involving us at all:
- Google — Google Account › Third-party apps & services
- Microsoft — My Apps for a work or school account, or app access settings for a personal Microsoft account
- Zoom — Zoom App Marketplace › Installed apps
Disconnecting stops all future reading and writing. Meetings that were already placed on your calendar remain there and stay under your control — you can keep, edit, or delete them yourself. Step-by-step instructions, including what to expect afterward, are on our help page: Connect or disconnect a calendar.
If you would also like the underlying scheduling records deleted from your account, email privacy@cozzitech.com and we will handle it in accordance with Section 7 of Part I.
Part IV — Other CozziTech Products
Some CozziTech products handle information differently enough to warrant their own policy. Where a product has its own policy, that policy governs that product:
- ctLibrary™ Privacy Policy — the offline-first document and notes app, whose library never leaves your device.
For any CozziTech application you sign in to that is operated by your employer or agency, that organization determines what information is entered and who may see it, and CozziTech processes it on that organization's behalf under our agreement with them. Direct requests about your own records to that organization first.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will revise the "Last Updated" date at the top of this page and, where appropriate, provide additional notice (such as an in-app message or an email to agency administrators). The current version is always available at cozzitech.com/privacy-policy/.
Contact Us
Questions, requests, or concerns about this Policy or about how CozziTech handles information should be directed to:
CozziTech LLC
Attn: Privacy
Privacy: privacy@cozzitech.com
Support: support@cozzitech.com
© 2026 CozziTech LLC. All rights reserved.