Framewise Health
Graded against 811 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.
Lower concern: subprocessors data sharing
Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.
States that personal information is not sold, then introduces categories of permitted sharing — establishes a baseline prohibition on sale as user-favorable.
Restricts the website from collecting or processing PHI, and specifies that PHI is handled exclusively within the clinical platform under separate agreements — a user-favorable limitation that prohibits PHI collection through the public website.
Prohibits sharing of mobile opt-in data, consent records, and patient phone numbers with any third parties or affiliates for any purpose, expressly including marketing or promotional purposes — user-favorable restriction on data sharing.
How to read this page: Overall risk rates what Framewise Health's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Fully verified — complete core corpus captured and read in full.
- Privacy PolicyVerified - read in full - 19 citationsstaticLast captured 2026-07-20
- Terms of ServiceVerified - read in full - 0 citationsstaticLast captured 2026-09-01
Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.
Declares that the company operates as a Business Associate when processing Protected Health Information on behalf of Covered Entity customers and commits to maintaining administrative, physical, and technical safeguards to protect PHI, establishing a compliance obligation and framing the protective scope of PHI handling.
" Framewise Health operates as a Business Associate under HIPAA when processing Protected Health Information (PHI) on behalf of our Covered Entity customers. We maintain appropriate administrative, physical, and technical safeguards to prote..."
Describes implementation of security measures including encryption and secure hosting under a Business Associate Agreement, but then disclaims absolute security by stating no method of electronic transmission or storage is 100% secure — limits liability for security failures.
" We implement industry-standard security measures to protect your information, including encryption, secure hosting on AWS with a signed Business Associate Agreement, and regular security reviews. However, no method of electronic transmissi..."
Requires Business Associate Agreements with all applicable service providers, imposing a contractual obligation that restricts how subprocessors may handle protected data — user-favorable requirement.
" Business Associate Agreements (BAAs) with all applicable service providers"
Evidence appendix
Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.
" We do not sell your personal information. We may share information with:"
States that personal information is not sold, then introduces categories of permitted sharing — establishes a baseline prohibition on sale as user-favorable.
AI-generated interpretation, not legal advice.
" This website does not collect or process PHI. PHI is handled exclusively within our clinical platform under separate agreements with healthcare provider customers."
Restricts the website from collecting or processing PHI, and specifies that PHI is handled exclusively within the clinical platform under separate agreements — a user-favorable limitation that prohibits PHI collection through the public website.
AI-generated interpretation, not legal advice.
" Mobile opt-in data, consent records, and patient phone numbers will not be shared with any third parties or affiliates for any purpose, including marketing or promotional purposes."
Prohibits sharing of mobile opt-in data, consent records, and patient phone numbers with any third parties or affiliates for any purpose, expressly including marketing or promotional purposes — user-favorable restriction on data sharing.
AI-generated interpretation, not legal advice.
" Framewise Health, Inc. ("Framewise," "we," "us," or "our") is committed to protecting the privacy and security of your information. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you visit our website at framewisehealth.com or use our services."
Declares the company's commitment to protecting privacy and security and describes the scope of the policy — collection, use, disclosure, and safeguarding of information — establishing an overarching obligation to handle information in accordance with the described practices.
AI-generated interpretation, not legal advice.
" Contact information (name, email address, phone number) when you book a demo or contact us"
Defines the specific contact data items collected when a user books a demo or contacts the company, establishing the scope of voluntarily provided personal data subject to policy obligations.
AI-generated interpretation, not legal advice.
" Send you information about our products and services (with your consent)"
States that information is used to send product and service communications conditional on user consent, imposing a consent requirement as a precondition for this processing purpose — user-favorable restriction.
AI-generated interpretation, not legal advice.
" To exercise these rights, contact us at contact@framewisehealth.com ."
Provides the procedure for users to exercise their stated rights by contacting the organization at a specified email address.
AI-generated interpretation, not legal advice.
" SMS delivery and engagement metadata (delivered, failed, opted out, link clicks)"
Identifies SMS delivery and engagement metadata as data collected through the program, defining behavioral and operational data within the SMS program's processing scope.
AI-generated interpretation, not legal advice.
" Framewise Health operates as a Business Associate under HIPAA when processing Protected Health Information (PHI) on behalf of our Covered Entity customers. We maintain appropriate administrative, physical, and technical safeguards to protect PHI, including:"
Declares that the company operates as a Business Associate when processing Protected Health Information on behalf of Covered Entity customers and commits to maintaining administrative, physical, and technical safeguards to protect PHI, establishing a compliance obligation and framing the protective scope of PHI handling.
AI-generated interpretation, not legal advice.
" Framewise Health, Inc. operates an SMS messaging program for patients enrolled by sponsoring partner hospitals as part of their hospital discharge education. Full program Terms and Conditions are at framewisehealth.com/terms . A standalone description is at framewisehealth.com/sms-program ."
Describes the SMS messaging program's operational context — patients enrolled by partner hospitals for discharge education — and references external terms and program description documents, incorporating those documents by reference and defining the program scope.
AI-generated interpretation, not legal advice.
" Patients (or their authorized caregivers) opt in by signing a written consent form during hospital intake or discharge planning at the sponsoring partner hospital. Consent is not a condition of treatment or care. "
Specifies that patients or authorized caregivers opt in via written consent during hospital intake or discharge planning, and expressly states that consent is not a condition of treatment or care — establishing a consent collection procedure and a user-protective restriction prohibiting coerced consent.
AI-generated interpretation, not legal advice.
" Patients receive recurring messages during the 30 days following hospital discharge. Up to 14 messages per 30-day post-discharge enrollment period. Message frequency varies. Standard message and data rates may apply."
Defines the SMS message frequency parameters — recurring messages for 30 days post-discharge, up to 14 messages per enrollment period — and discloses that standard message and data rates may apply, establishing the scope and cost conditions of SMS processing.
AI-generated interpretation, not legal advice.
" Reply STOP to 1-833-449-2833 at any time. Opt-out is processed by our messaging provider via mobile carrier routing."
Specifies the opt-out mechanism — replying STOP to a designated number at any time — and describes how opt-outs are processed through the messaging provider via carrier routing, establishing a user right to withdraw from SMS communications and the procedure for exercising it.
AI-generated interpretation, not legal advice.
" We implement industry-standard security measures to protect your information, including encryption, secure hosting on AWS with a signed Business Associate Agreement, and regular security reviews. However, no method of electronic transmission or storage is 100% secure."
Describes implementation of security measures including encryption and secure hosting under a Business Associate Agreement, but then disclaims absolute security by stating no method of electronic transmission or storage is 100% secure — limits liability for security failures.
AI-generated interpretation, not legal advice.
" Depending on your jurisdiction, you may have the right to:"
Introduces jurisdiction-dependent user rights over personal information held by the organization, conditioning their availability on the user's jurisdiction.
AI-generated interpretation, not legal advice.
" Our website may use cookies and similar technologies to analyze traffic and improve your experience. You can control cookies through your browser settings."
States that the website may use cookies and similar technologies to analyze traffic and improve user experience, and informs users they can control cookies through browser settings — grants a limited user control right alongside the permission to use tracking technologies.
AI-generated interpretation, not legal advice.
" We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page with a revised "Last updated" date."
Establishes the procedure for policy updates, requiring material changes to be communicated by posting the updated policy with a revised date, defining notice obligations to users.
AI-generated interpretation, not legal advice.
" Business Associate Agreements (BAAs) with all applicable service providers"
Requires Business Associate Agreements with all applicable service providers, imposing a contractual obligation that restricts how subprocessors may handle protected data — user-favorable requirement.
AI-generated interpretation, not legal advice.
Clause detail — protections, your obligations, and coverage
Every clause below is a verbatim quote from Framewise Health's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.
✅ Protections found
0 verified clausesClauses in Framewise Health's policies that work in your favour — commitments the platform made to you.
No protective clause has been verified in Framewise Health's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.
📋 Rules you must follow
0 verified clausesWhat Framewise Health requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.
No user-conduct rule has been verified in Framewise Health's published policies yet.
What the policies actually cover
0 topicsNone of Framewise Health's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause permits sale of personal data or information.
“We do not sell your personal information. We may share information with:”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| All applicable tiers | subprocessors data sharing | worsens | HIGH | 1 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
Latest stance: sale or sell on subprocessors data sharing
“We do not sell your personal information. We may share information with:”Open timeline citation
Capture recency
- Privacy Policy:Last captured 2026-07-20· verified 2026-07-20verified once — not yet re-verified
- Terms of Service:Last captured 2026-09-01· verified 2026-09-01verified once — not yet re-verified
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
20 findings first captured First scan: July 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Framewise Health's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Every finding above is a verbatim quote from Framewise Health's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.