CERESTI HEALTH, INC.
WEBSITE, ALWAYS-ON DEVICE AND MOBILE APPLICATION
PRIVACY POLICY

CERESTI HEALTH, INC.

PRIVACY POLICY

Last Updated: 6-17-2026

This policy covers ceresti.com and all Ceresti digital properties. For questions, contact privacy@ceresti.com.

TABLE OF CONTENTS

1. Introduction

2. Information We Collect

3. Sources of Personal Information

4. How We Use Your Information

5. How We Share Your Information

6. Cookies and Tracking Technologies

7. Sensitive Personal Information

8. Your Privacy Rights

9. Data Retention

10. Data Security

11. HIPAA and Protected Health Information

12. Children's Privacy

13. SMS/Text Messaging Program and Mobile Opt-in Data

14. Changes to This Policy

15. Contact Us

1. INTRODUCTION

Ceresti Health, Inc. ("Ceresti," "we," "us," or "our") provides caregiver support and care coordination services for patients living with Alzheimer's disease and other dementia conditions. We are committed to protecting the privacy and security of your personal information.

This Privacy Policy explains how we collect, use, share, and protect personal information through our website (ceresti.com), our tablet-based Always-On Device ("AOD"), and our mobile applications (collectively, "Ceresti Services").  All Ceresti services and websites are intended for use only in the United States only.

This policy applies to users including patients, primary caregivers, authorized family members and friends, and healthcare providers interacting with Ceresti Services, as well as individuals who visit our websites, and those who communicate with us about our products and services.

This Policy does not apply to protected health information that we collect from individuals pursuant to the Health Insurance Portability and Accountability Act (HIPAA).  Please see Section 11 below for our HIPAA obligations.

We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising.

By using our Service, you consent to our Privacy Policy and our collection, use and sharing of your information and data, and other activities, as described below.

2. INFORMATION WE COLLECT

We collect the following categories of personal information, which we reference by name throughout this policy:

A. Identifying Information

Full name, physical address, email address, telephone number, username, and login credentials.

B. Health and Care Information

Medical conditions, vital signs, medications, cognitive function assessments, care plan details, and clinical records. When collected on behalf of a HIPAA Covered Entity, this information is Protected Health Information (PHI) subject to our HIPAA obligations (see Section 11).

C. Caregiver and Family Information

Information about the patient's primary caregiver and authorized family members including demographic data, health status relevant to caregiving, goals, behavior, and questionnaire responses.

D. Communications and Media

Messages, photographs, images, audio, and videos shared through Ceresti Services between patients, caregivers, family members, and healthcare providers.

E. Device and Technical Information

Device type, IP address, MAC address, mobile device identifiers, browser type, operating system, and device location (with your permission).

F. Activities and Usage Information

Pages viewed, features used, links clicked, time spent in the application, session data, and engagement metrics collected through log files and similar technologies.

G. Cookies and Tracking Data

Information collected through cookies, pixel tags, web beacons, and similar technologies when you visit our website. See Section 6 for details.

3. SOURCES OF PERSONAL INFORMATION

We collect personal information from the following sources:

  • Directly from you when you register, use Ceresti Services, or communicate with us.
  • From the patient's healthcare provider or health plan, who may share clinical information to support care coordination.
  • From authorized caregivers, family members, and friends acting on behalf of the patient.
  • Automatically through your use of Ceresti Services, including through the AOD, mobile applications, and website.
  • From third-party service providers who support our operations (e.g., cloud hosting, analytics, communications platforms) - see Section 5.

4. HOW WE USE YOUR INFORMATION

We use your personal information for the following purposes. Each row identifies the categories of information used and the legal basis for processing.

Purpose

Information Categories Used

Legal Basis

Provide and deliver Ceresti Services; fulfill care coordination obligations under service agreements

Identifying Information

Health and Care Information

Caregiver and Family Information

Communications and Media

Device and Technical Information

Contract Performance

Legal Obligations

Support caregivers with training, coaching, and care best practices

Health and Care Information

Caregiver and Family Information

Communications and Media

Contract Performance

Legitimate Interest

Facilitate communications between patients, caregivers, and family

Identifying Information

Communications and Media

Device and Technical Information

Contract Performance

Consent

Generate enrollment, engagement, retention, and outcome reports for health plans and providers

Health and Care Information

Activities and Usage Information

Contract Performance

Legal Obligations

Improve Ceresti Services; analyze usage patterns; develop new features

Activities and Usage Information

Device and Technical Information

Cookies and Tracking Data

Legitimate Interest

Ensure security, prevent fraud, and respond to legal process

Identifying Information

Device and Technical Information

Activities and Usage Information

Legitimate Interest

Legal Obligations

Defend Our Rights

Administer your account; respond to inquiries; provide customer support

Identifying Information

Communications and Media

Activities and Usage Information

Contract Performance

Legitimate Interest

5. HOW WE SHARE YOUR INFORMATION

We do not sell your personal information. We may share your personal information only in the following circumstances:

Healthcare Providers and Health Plans

We share Health and Care Information with the patient's Covered Entity healthcare providers and health plans as directed by the applicable Business Associate Agreement and HIPAA. We cannot share this information in ways the Covered Entity could not.

Authorized Caregivers, Family Members, and Friends

With the patient's authorization, we share Care Information, Communications, and Media with the patient's primary caregiver and authorized family members and friends.

Service Providers

We share information with third-party service providers who perform functions on our behalf, such as cloud hosting, analytics, communications, and customer support. Service providers are contractually bound to protect your information and may not use it for their own purposes. Categories include:

  • Cloud hosting and infrastructure providers
  • Analytics providers (e.g., Google Analytics - see Section 6)
  • Communication and messaging service providers
  • Customer support and helpdesk platforms

Business Transfers

If Ceresti is acquired or merges with another entity, your personal information may be transferred to the successor organization. We will notify you before your information becomes subject to a materially different privacy policy.

Legal and Compliance

We may disclose information as required by law, court order, or governmental authority, or when we believe disclosure is necessary to protect rights, property, or safety.

With Your Consent

For any uses not described above, we will seek your explicit consent before sharing your information.

6. COOKIES AND TRACKING TECHNOLOGIES

What We Use

When you visit ceresti.com, we use cookies, pixel tags, web beacons, and similar technologies (collectively, "Cookies") to support website functionality and understand how our site is used. Cookie categories include:

  • Strictly Necessary: Strictly Necessary Cookies
  • Required for the website to function. Cannot be disabled.
  • Performance / Analytics: Performance / Analytics Cookies
  • Help us understand how visitors interact with the site. We use Google Analytics for this purpose. Google Analytics may collect your IP address and usage data.  
  • Functional: Functional Cookies
  • Remember your preferences and settings to improve your experience.
  • Targeting / Advertising: Targeting / Advertising Cookies
  • Ceresti uses advertising cookies to identify who is already receiving services and manage the type of outreach based on patterns.

Cookie Consent Banner (CookieBot)

Our website uses CookieBot to manage cookie consent. When you first visit ceresti.com, a consent banner will appear allowing you to accept all, reject all, or customize cookies by category. Your preferences are saved and can be updated at any time via the Cookie Preferences link in the website footer. Non-essential cookies will not be loaded until you consent.

Global Privacy Control (GPC)

Our website recognizes Global Privacy Control (GPC) signals. If your browser sends a GPC signal, we will treat it as a request to opt out of the sale or sharing of your personal information. To learn more or enable GPC, visit globalprivacycontrol.org.

Do Not Track

Some browsers transmit Do Not Track (DNT) signals. Because DNT signals are not yet standardized, we respond to GPC signals rather than DNT signals. Use GPC to exercise your opt-out preferences.

Disabling Cookies

If you decide at any time that you no longer wish to accept cookies from our services for any of the purposes described above, then you can typically instruct your browser, by changing its settings, to remove or stop accepting cookies or to prompt you before accepting a cookie from the websites you visit. In order to do this, consult your browser’s technical information (instructions are usually located within the “settings, ” “help” “tools” or “edit” facility). Many browsers are set to accept cookies until you change your settings.

Further information about cookies, including how to see what cookies have been set on your computer or mobile device and how to manage and delete them, visit: www.allaboutcookies.org.

If you do not accept our cookies, you may experience some inconvenience or not be able to use all portions of the services or all functionality of the services.

7. SENSITIVE PERSONAL INFORMATION

Ceresti collects sensitive personal information as defined under applicable privacy laws, including:

  • Health information (medical conditions, medications, vital signs, psychiatric conditions, cognitive function)
  • Precise geolocation data (device location, where permitted)
  • Contents of communications (messages, photos, and videos shared through Ceresti Services)
  • Account login credentials

We use sensitive personal information only for the purposes described in this policy. Where required by law, we will seek your explicit consent before using sensitive personal information for any additional purpose.

California residents have the right to limit our use of sensitive personal information beyond what is necessary to perform the requested services. To exercise this right, contact us at privacy@ceresti.com.

De-identification

Ceresti will de-identify data to enable historical patterns and reduce the personal identifiable data set to the minimum required to improve our use of digital platforms.

8. YOUR PRIVACY RIGHTS

Depending on your state of residence, you may have the following rights regarding your personal information:

Right

Description

Right to Know

Request disclosure of the categories and specific pieces of personal information we have collected about you, the sources, our business purposes, and the third parties with whom we share it.

Right to Delete

Request deletion of your personal information, subject to certain exceptions (e.g., HIPAA retention obligations, legal holds).

Right to Correct

Request correction of inaccurate personal information we hold about you.

Right to Opt-Out

Opt out of the sale or sharing of your personal information. Note: Ceresti does not sell or share personal information for cross-context behavioral advertising.

Right to Limit Sensitive PI

Limit our use and disclosure of sensitive personal information to purposes necessary to perform the services you requested.

Right to Non-Discrimination

We will not discriminate against you for exercising any of these rights.

How to Exercise Your Rights

Submit a request using any of the following methods:

  • Email: privacy@ceresti.com
  • Mail: Privacy Officer, Ceresti Health, Inc., 2888 Loker Avenue East, Suite 110, Carlsbad, CA 92010

We will verify your identity before responding to your request. We will respond within 45 days of receiving a verifiable request. We may extend this period by an additional 45 days where necessary and will notify you of any extension.

Authorized agents may submit requests on your behalf. We will require written authorization and may verify your identity directly.

9. DATA RETENTION

We retain personal information for as long as necessary to provide Ceresti Services, comply with legal and contractual obligations, prevent fraud, resolve disputes, and enforce our agreements. Key retention considerations include:

  • Health and care records: Retained in accordance with HIPAA and applicable state law requirements (typically 7 years from last service date for adults).
  • Account information: Retained for the duration of the service relationship plus 2-3 years, unless a longer period is required by law.
  • Communications and media: Retained as part of the patient's care record, per applicable retention schedules.
  • Technical and usage data: Retained for up to 24 months for analytics and security purposes.
  • Marketing preferences and suppression lists: Retained indefinitely to honor opt-outs.

When personal information is no longer required, we dispose of it securely using industry-standard methods.

10. DATA SECURITY

We implement organizational, technical, and administrative safeguards to protect your personal information, including:

  • Encryption of data in transit between devices and Ceresti systems
  • Encryption of data at rest for sensitive and health information
  • Role-based access controls and the principle of least privilege
  • Multi-factor authentication for system access
  • Regular security assessments and vulnerability testing
  • Employee background checks and security training

Note: Information transmitted via standard email or SMS is not secured by Ceresti's controls. Use Ceresti's secure in-application messaging for sensitive communications.

In the event of a data breach affecting your personal information, we will notify you as required by applicable law, including the California data breach notification law (Cal. Civ. Code § 1798.82). We will not rely on you to detect or report breaches.

If you believe your information may have been compromised, contact us immediately at privacy@ceresti.com.

Unfortunately, no security measures are perfect, and we cannot assure you that Information will never be

accessed or used in an unauthorized way.  We encourage you to use caution at all times. If you have reason to believe that your personal information has been compromised, please contact us immediately.

11. HIPAA AND PROTECTED HEALTH INFORMATION

When Ceresti collects, stores, uses, or discloses Protected Health Information (PHI) on behalf of a HIPAA Covered Entity healthcare provider or health plan, we do so as a Business Associate under a Business Associate Agreement (BAA).

As a Business Associate, we:

  • May only use and disclose PHI as permitted by the applicable BAA and HIPAA
  • Apply the HIPAA Security Rule safeguards to PHI in our custody
  • Cannot use or disclose PHI in a manner that the Covered Entity itself could not
  • Will notify the Covered Entity of any breach of unsecured PHI

Your HIPAA rights (including rights to access, amend, and receive an accounting of disclosures of your PHI) are in addition to, not instead of, the privacy rights described in Section 8. Where these rights overlap, we will honor both sets of rights to the fullest extent practicable.

Requests related to PHI that require the Covered Entity's involvement will be referred to the appropriate healthcare provider or health plan.

12. CHILDREN'S PRIVACY

Ceresti Services are not directed at children under the age of 16. Children may only use Ceresti products under the instructions, supervision, and with the consent of their healthcare provider and a parent or legal guardian.

We do not knowingly collect personal information directly from children under the age of 16 without verifiable parental or guardian consent. If we learn that we have collected personal information from a child under 16 without proper consent, we will delete such information promptly.

If you are a parent or guardian and believe we may have collected information about your child without proper authorization, please contact us at privacy@ceresti.com.

We do not sell or share the personal information of consumers under the age of 16 without affirmative opt-in consent, as required by California law.

13. SMS/TEXT MESSAGING PROGRAM AND MOBILE OPT-IN DATA

If you consent to receive SMS from Ceresti, you agree to receive conversational text messages from us. These are one-to-one messages between a Ceresti coach and a caregiver enrolled in our program, relating to your care journey, coaching check-ins, and program support. Messaging frequency may vary. Message and data rates may apply. Reply STOP to opt out at any time; reply HELP for support, or call (800) 755-3982 or visit www.ceresti.com. Visit https://www.ceresti.com/privacy-policy/ to see our privacy policy and terms and conditions.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing to subcontractors in support services, such as customer service, is permitted. All other use case categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

14. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top of this policy and post the revised policy on our website.

If changes are materially adverse to your privacy rights, we will provide additional notice as required by law. Your continued use of Ceresti Services after the effective date of a revised policy constitutes acceptance of the updated terms.

We encourage you to review this policy periodically.

15. CONTACT US

If you have questions about this Privacy Policy, wish to exercise your privacy rights, or have a privacy complaint, contact us using any of the following methods:

Method

Details

Email

privacy@ceresti.com

Mail

Privacy Officer Ceresti Health, Inc. 2888 Loker Avenue East, Suite 110 Carlsbad, CA 92010

You will not be penalized or discriminated against for submitting a privacy request or complaint.

For California residents, you also have the right to lodge a complaint with the California Privacy Protection Agency (cppa.ca.gov) or the California Attorney General.

© 2026 Ceresti Health, Inc. All rights reserved.  |  privacy@ceresti.com  |  www.ceresti.com