aemy.ai

Privacy Policy

Last updated: July 10, 2026

Aemy is operated by Tech Surfer Co. ("Aemy", "we", "us"). Aemy provides AI-driven concierge, booking, and clinical-workflow software to wellness, longevity, and aesthetics providers (each a "Clinic"). When you interact with Aemy — through a Clinic's booking page, a Clinic's lobby kiosk, an Aemy SMS thread, or this website — this Policy explains what we collect, how we use it, and your choices.

What we collect

  • Contact information: name, mobile phone number, email address.
  • Booking and visit information: services requested, appointment times, deposits, gift card balances, membership and package status.
  • Conversation content: messages exchanged with the Aemy concierge by chat, voice, or SMS, used to respond to your request and to maintain continuity across visits.
  • Photos and clinical notes, only when you visit a Clinic and a provider records them as part of your care.
  • Technical data: IP address, user agent, and audit information about reads and writes of your record, retained for security and HIPAA compliance.

SMS and text messaging

We send appointment-related texts only to recipients who have provided explicit, opt-in consent through one of three paths: (1) a clearly labeled consent notice and checkbox on a Clinic's online booking form; (2) a signed paper intake form at a Clinic's front desk; or (3) entering your mobile number into a Clinic-operated Aemy lobby kiosk after agreeing on the screen. Marketing texts require a separate, double opt-in confirmation and are never a condition of booking.

Reply STOP at any time to opt out. You will receive one final confirmation message and no further messaging from that Clinic. Reply HELP for contact information for the Clinic that texted you.

Message frequency varies based on your interactions with the Clinic; most recipients receive between two and fifteen messages per month, and conversational threads with the Aemy concierge may briefly exceed that during an active exchange. Standard message and data rates may apply, depending on your wireless plan and carrier. Carriers are not liable for delayed or undelivered messages.

We do not sell your mobile phone number, your SMS opt-in status, or the contents of your SMS conversations to any third party for marketing. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are not shared with any third parties, excluding the providers that deliver our messages. Your text messaging data is shared only with our message delivery providers (Twilio for SMS, and Apple iMessage via our managed messaging infrastructure when your device supports it) and the Clinic you consented to receive messages from. Standard message and data rates may apply.

Voice and conversation

Aemy is an AI concierge, not a person. Before any voice session begins — on a phone call, a played notice states that you are speaking with Aemy, an AI, and that the call may be transcribed to serve you better; on the web, the same disclosure appears before the microphone activates. Aemy identifies itself as an AI in its opening words as well.

When you speak with Aemy by voice — in a browser, on a phone call, or at a Clinic kiosk — your audio is streamed to Google's Gemini Live model and transcribed and processed in real time. We do not record or retain the audio; audio is not kept beyond the active session. We do retain a written transcript of the conversation as part of your record at the Clinic you spoke with, on the same terms as your chat and SMS conversations. The transcript is used to respond to you, maintain continuity across visits, and meet security and compliance obligations. A Clinic staff member can edit or delete (“forget”) what Aemy remembers about you at your request, and you may ask the Clinic to remove your conversation history subject to applicable recordkeeping law.

Please do not read payment card numbers aloud to Aemy. Aemy will never ask for a card number by voice and will offer you a secure link or use a card you have already saved. If a card number is nonetheless spoken, that audio transits Google's commercial Gemini API before we can act on it (the paid API does not use your data to train its models), and our systems automatically remove card-number-shaped text from any stored transcript. This voice channel is not a payment-card or protected-health-information intake channel.

Health information

For Clinics that are HIPAA covered entities, Aemy operates as a Business Associate under a signed Business Associate Agreement. Your protected health information (PHI) is stored encrypted, accessed only through audited workflows, and disclosed only as permitted by HIPAA and the BAA between us and the Clinic. Aemy does not use your PHI for marketing.

How we use information

  • To run the bookings, payments, memberships, packages, photos, forms, SOAP notes, and consents that the Clinic asked us to handle on its behalf.
  • To respond when you message or call Aemy.
  • To improve safety, prevent abuse, and meet legal and audit obligations.
  • We do not use the contents of your conversations or your PHI to train AI models.

Sharing

We share your information with: (1) the Clinic you booked with or messaged; (2) our infrastructure subprocessors (Google for AI, Twilio for SMS and voice carrier services, Apple iMessage via our managed messaging infrastructure for message delivery, Resend for email delivery, Square for payments, Cloudflare for encrypted file storage and backups, and Klaviyo for service communications on behalf of your Clinic), each governed by a Business Associate Agreement where applicable; and (3) authorities when legally compelled. We do not sell your personal information.

Your choices

  • SMS: reply STOP at any time.
  • Email: appointment emails (confirmations, changes, receipts) are sent as part of delivering the service you requested. To stop non-essential email, reply to any message, contact your Clinic, or email privacy@aemy.ai. Marketing email, where offered, will include an unsubscribe link.
  • Account: ask the Clinic to update or delete your record. The Clinic is the controller of your data; we act on its instructions.
  • California / EU residents: contact your Clinic to exercise CCPA / GDPR rights. We will support the Clinic in honoring requests.

Nevada residents

We do not sell covered information as defined by Nevada law (NRS Chapter 603A). Nevada residents may submit a verified request, including a request that we not sell covered information, to our designated request address: privacy@aemy.ai. We will respond within 60 days (extendable by up to 30 additional days where permitted, in which case we will notify you). You may review your information and request corrections through your Clinic or via the same address. We do not authorize third parties to collect personally identifiable information about your online activities over time and across different internet websites when you use our service.

Security

Field-level encryption on PHI columns, TLS 1.2 or higher in transit, encrypted backups, append-only audit logs, and BAAs with every PHI-touching subprocessor.

Children

Aemy is not directed at children under 13 and we do not knowingly collect personal information from children. Clinics that serve minors do so under their own consent and intake processes.

Changes

We may update this Policy. The "Last updated" date at the top reflects the most recent change. Material changes will be communicated via the Clinic that texted or messaged you.

Contact

Questions about this Policy: privacy@aemy.ai.