Legal

Privacy Policy

This policy explains how Mozart LLC collects, uses, stores, shares, and protects information when you use our websites, applications, and services.

Effective August 23, 2026

1. Scope

This Privacy Policy applies to Mozart-owned websites and services that link to it, including the Mozart Website Measurement integration. A healthcare organization's use of Mozart may also be governed by a signed services agreement, a business associate agreement, and other product-specific notices. Those agreements control where they impose more specific privacy or security obligations.

Mozart provides technology to healthcare organizations. Those organizations determine how they collect and use patient and workforce information in their own operations and may provide additional privacy notices. This policy does not replace a customer's notice to its patients, workforce, or website visitors.

2. Information we collect

Depending on how you interact with Mozart, we may collect:

  • Information you provide, such as your name, work email address, organization, support request, or other information you send to us.
  • Account and service data, such as account identifiers, tenant membership, permissions, configuration choices, and security or audit records.
  • Technical data, such as IP address, browser and device information, request timestamps, referring pages, and diagnostic or security events generated when our services are used.
  • Google Website Measurement data, as described in Section 4, when an authorized tenant administrator chooses to connect Google Search Console or Google Analytics 4.

Do not submit protected health information through Mozart's public marketing website or general contact channels. Protected health information processed within contracted Mozart services is handled under the applicable customer agreement and business associate agreement.

3. How we use information

We use information to:

  • provide, secure, maintain, and improve Mozart services;
  • authenticate users and enforce tenant permissions;
  • respond to requests and communicate about the services;
  • detect, prevent, and investigate misuse or security incidents;
  • meet legal, regulatory, contractual, and audit obligations; and
  • provide the user-facing Website Measurement features described below.

4. Google Website Measurement

The Website Measurement integration is optional. It is available to a tenant administrator who affirmatively chooses to connect Google data for a public marketing site and who has authority to grant that access. Mozart requests only read-only Google Search Console and Google Analytics permissions needed for the feature.

Google data we access

  • Search Console site identifiers, verification and permission status, and bounded aggregate website performance metrics;
  • Analytics account, property, and web data-stream identifiers and configuration, including the selected site origin and Measurement ID; and
  • bounded aggregate Analytics reporting metrics used in Mozart's tenant-facing website reports.

Mozart does not use this integration to access Gmail, Google Calendar, contacts, Google Drive, or health records. Mozart does not ingest raw search queries by default, raw Analytics events, Google advertising audiences, person identifiers, or browser identifiers through this integration.

How we use Google data

We use Google data only to let the connecting tenant discover and select its properties, verify the selected public-site connection, and view website performance, freshness, and coverage in Mozart. We do not sell Google user data, use it for advertising or credit decisions, or use it to train generalized artificial-intelligence models.

How we store and share Google data

Mozart stores the connection configuration, encrypted Google OAuth refresh token, bounded aggregate reporting facts, and limited security and audit receipts. Authorization codes and callback material are kept only as long as needed to complete the connection. Data is tenant-bound and protected in transit and at rest. Access is limited to authorized users and service providers that process data for Mozart under confidentiality and security obligations.

We do not transfer Google user data except as needed to provide the visible integration at the user's direction, maintain security, or comply with applicable law. A transfer connected with a merger, acquisition, or sale of assets would occur only with the user consent required by Google's policy.

Limited Use compliance

Mozart's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Disconnecting Google

An authorized tenant administrator can disconnect the integration in Mozart. Disconnecting immediately prevents Mozart from using the stored grant, removes the stored refresh token from active use, and requests revocation from Google. A user may also revoke Mozart's access from the security settings of the Google Account. Limited audit, security, and legal records may be retained as required, but they cannot be used to reconnect the integration.

5. How we disclose information

We may disclose information:

  • to infrastructure, security, communications, and other service providers that process it for Mozart;
  • to the customer organization that controls the relevant Mozart tenant;
  • when required by law or reasonably necessary to protect rights, safety, and service integrity; or
  • in a corporate transaction, subject to applicable law, contractual commitments, and the additional Google-data restriction in Section 4.

We do not sell personal information.

6. Retention and security

We retain information for as long as needed to provide the services, satisfy the purposes described in this policy, and meet legal, contractual, security, and audit obligations. Retention periods depend on the type of information and the governing customer agreement. We use administrative, technical, and physical safeguards designed to protect information, but no system can guarantee absolute security.

7. Your choices and rights

You may choose not to provide optional information, disconnect an integration, or contact us to request access, correction, or deletion. Rights vary by location and may be subject to legal exceptions. If your information is controlled by a healthcare organization using Mozart, please contact that organization first; Mozart will support it in responding as required by the applicable agreement and law.

8. Children

Mozart's public website and business services are not directed to children under 13. Patient information handled for a healthcare organization is governed by that organization's services, notices, and applicable agreements.

9. Changes to this policy

We may update this policy as our services or legal obligations change. We will post the updated version here and revise the effective date. If a change materially expands how we use Google user data, we will provide notice and obtain consent before using that data for the new purpose.

10. Contact us

Questions or privacy requests may be sent to hello@mozarthq.com.