Skip to Content
Rendevu
Let's Rendevu

Privacy Policy

RendevuAI Inc · Effective date: September 5, 2026

Rendevu is practice management and treatment charting software for aesthetic clinics. This policy explains what information we collect through the Rendevu website (rendevu.ai), the Rendevu web application (app.rendevu.ai), and the Rendevu iOS app (together, the "Service"), how we use it, and the choices you have.

It is written for two audiences:

  • Practice staff who sign in and use Rendevu. You are our users, and most of this policy is addressed to you.
  • Clients and patients of a practice whose information a practice keeps in Rendevu. We hold that information on the practice's behalf and under its instructions. If you are a patient, your practice controls your records; please direct questions and requests about them to your practice, and see "Health information and HIPAA" below.

Information we collect

Information practice staff give us

  • Account details. Your name, email address, role at the practice, and the practice and locations you belong to. A practice administrator creates your account by invitation; there is no public sign-up.
  • Sign-in credentials. A password, a passkey, or a one-time code sent to your email, plus any two-factor method you enable. If you set a PIN for switching users on a shared device, we store only a salted hash of it. If we offer sign-in through a third-party identity provider and you use it, we receive your email address from that provider and nothing else. We do not receive your password for that provider.
  • Support requests. Whatever you include when you contact us.

Practice records entered into Rendevu

Practice staff enter information about the practice's clients and patients. This may include name, date of birth, contact details, address, photographs of treatment areas, treatment charts and steps, products used, clinical and administrative notes, intake form responses, consent forms, and signatures. This information belongs to the practice. We process it only to provide the Service to that practice.

Information from your device (iOS app)

The iOS app asks for each permission at the point it is needed, and the app works without any of them:

  • Camera — to photograph treatment areas for a client's chart. Photos are uploaded to the practice's records. The app does not record audio or video.
  • Contacts — on the Create Appointment screen, to suggest a name and phone number from your address book when you add a new client. Your address book is read on the device only. Nothing is uploaded except the single entry you choose to add.
  • Photo library — to attach existing photos to a client's chart, and to save a chart photo to the app's own album in your library if you choose to. Attaching uses the system photo picker, so we see only the photos you select. Saving into the album needs full library access on iOS; with limited access the photo is saved without an album. We do not read or upload anything from your library other than the photos you attach.

Information from integrations a practice connects

  • Square. If a practice administrator connects the practice's Square account, we sync the practice's Square customer records (names and contact details) and appointments with Rendevu, and read the practice's Square catalog items, team member list, and business profile to support that sync. We do not access payment, card, or order data. The connection is made through Square's authorization flow; we do not see your Square password, and the practice can disconnect it at any time from Settings.

Information collected automatically

  • Usage analytics. We use a third-party analytics service to understand which screens are used. We send it your Rendevu user ID, the platform (web or iOS), the environment, and screen names. We do not send names, email addresses, client records, search terms, or the text of anything you tap, and we do not record your screen.
  • Error and crash reports. We use a third-party error-reporting service to find and fix errors. Reports contain your Rendevu user ID, technical details about the error, and the URL path without its query string. Request bodies, client records, and screen recordings are not sent, and reports pass through an automated scrubber before leaving the Service.
  • Access and security logs. For security and for the audit trail that healthcare regulations require, we log who accessed which records and when, sign-in attempts, permission checks, and similar events. These logs hold identifiers, not record contents.
  • Cookies and similar technology. The web application uses a session cookie to keep you signed in and a security cookie to protect forms. Our sign-in pages use a third-party bot-protection service, which may set its own cookie. We do not use advertising or cross-site tracking cookies. We do not respond to browser "Do Not Track" signals; because we do not sell or share personal information for advertising, there is nothing for such a signal to opt out of.

Information from the website

If you use the "Stay in touch" form on rendevu.ai, we collect the details you enter, such as your name, email address, phone number, and practice, and use them only to contact you about Rendevu. The form is processed by a third-party email marketing service on our behalf, and every message we send you through it includes an unsubscribe link.

How we use information

  • To provide, operate, and secure the Service for the practice you belong to.
  • To sign you in and keep your account secure, including two-factor authentication and sending one-time sign-in codes by email.
  • To keep the audit trail that healthcare regulations require of practices and of us.
  • To fix errors and understand how the Service is used, using the limited analytics and crash data described above.
  • To respond to you when you contact us.
  • To comply with law and enforce our agreements.

We do not sell personal information. We do not use it for advertising. We do not track you across other companies' apps or websites. We may use de-identified, aggregated information that cannot reasonably identify a practice, a staff member, or a patient to improve the Service, including to develop and evaluate machine-learning features. We do not use identifiable client or patient records for that purpose.

How we share information

We share information with service providers that process it on our behalf and are restricted by contract to providing the requested services:

  • Hosting and cloud storage providers, which hold practice records and backups in encrypted form. Patient photos, charts, and notes go only to these providers.
  • Error-reporting and usage-analytics providers, which receive identifiers and technical details, not record contents.
  • An email delivery provider, which receives your email address and the content of the message (for example a sign-in code).
  • A bot-protection provider on our sign-in pages, which receives connection metadata.
  • An email marketing provider, for the website's "Stay in touch" form only.

If a practice connects Square, or you sign in through a third-party identity provider where we offer one, that company exchanges the information described above with us under its own privacy policy.

We may also disclose information when required by law or legal process, to protect the rights, safety, or property of Rendevu, our users, or others, or as part of a merger, acquisition, or sale of assets, in which case this policy will continue to apply to the information transferred.

Service data is stored and processed in the United States. If you use the Service from elsewhere, your information is transferred to and processed in the United States. The Service and the website may link to third-party sites and services we do not control; their privacy practices are governed by their own policies.

Health information and HIPAA

Whether the Health Insurance Portability and Accountability Act (HIPAA) applies to a practice depends on the practice, not on Rendevu. For a practice that is a covered entity under HIPAA and has entered into a Business Associate Agreement with us, we act as its business associate and use and disclose protected health information only as that agreement and HIPAA permit. Under such an agreement we do not share protected health information with a service provider unless it has agreed in writing to protect it. A practice can ask us about a Business Associate Agreement at the contact address below.

For every practice, whether or not HIPAA applies, the same safeguards are in place: encryption of data at rest and in transit, role-based access with clinical fields hidden from non-clinical roles, automatic sign-out, and audit logging of record access. State laws on medical and health information may also apply to a practice's records; the practice is responsible for its obligations under those laws, and we support them as described in this policy.

If you are a patient and want to access, correct, or delete your records, or have a question about how your practice uses Rendevu, contact your practice. We will help the practice respond, but we cannot act on a patient's request without the practice's instruction.

Security

We protect information with administrative, technical, and physical safeguards, including encryption in transit and at rest, role-based access controls, two-factor authentication, automatic sign-out, time-limited links for photos, and audit logging. Backups are encrypted and write-protected. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.

Retention

In general, we retain personal information for as long as reasonably needed to fulfill the purposes described in this policy, including for as long as needed to provide the Service to you or your practice, unless a longer retention period is required or permitted by law. Practice records are kept for as long as the practice uses Rendevu and are handled afterwards under our agreement with the practice. Audit logs are kept for as long as applicable law requires. Encrypted backups expire on a fixed schedule. Analytics and crash data are retained by our analytics and error-reporting providers under their standard retention periods. De-identified and aggregated information that cannot reasonably identify anyone may be retained indefinitely.

Your choices

  • Device permissions. You can revoke Camera, Contacts, or Photos access at any time in iOS Settings. The app continues to work; the related feature is simply unavailable.
  • Photos you save or share. If you save a chart photo to your device or send it through the share sheet, that copy leaves Rendevu and is governed by wherever you put it, including iCloud Photos if it is enabled. Check your practice's policy before doing so.
  • Sign-in methods. You can add or remove passkeys, two-factor methods, and any third-party sign-in we offer from Account Security in the web application.
  • Your account. Accounts belong to the practice. To deactivate your account or have your account information removed, ask your practice administrator, or contact us at the address below and we will work with the practice. Deactivation is immediate; because we must keep an accurate audit trail, some identifiers remain in access logs for as long as we keep those logs.
  • Email. Sign-in codes and security notices are part of the Service and cannot be turned off. Anything else we send includes an unsubscribe link.

Children

The Service is for use by practice staff and is not directed to anyone under 18. We do not knowingly collect personal information from children as users. A practice may store records of minors as patients; those records are controlled by the practice under the health-information terms above.

Your privacy rights

Depending on where you live, applicable law may give you the right to know what personal information we hold about you, to access, correct, or delete it, and not to be discriminated against for exercising those rights. We do not sell personal information and do not share it for cross-context behavioral advertising. Where we hold information as a service provider or business associate for a practice, we will refer your request to the practice and help it respond. To make a request, use the contact details below; we may ask you to confirm your identity first.

Changes to this policy

When we change this policy we will post the new version here with a new effective date, and we may also notify practice administrators of material changes. Continued use of the Service after a change takes effect means you accept the updated policy.

Contact

RendevuAI Inc
9 E 68th St
New York, NY 10065
[email protected]

Stay in touch, big things are coming.

Name
What software do you currently use to run your practice? (Select all that apply)

© 2026 RendevuAI IncSupportPrivacy Policy