Talarga

A Product of STL Innovation, LLC

PRIVACY POLICY

Version 1.1.1 | Effective Date: July 16, 2026 | Last Modified: July 22, 2026

STL Innovation, LLC ("STL Innovation," "we," "us," or "our") operates the Talarga platform as a direct-to-consumer medical identity protection and healthcare fraud monitoring service. This Privacy Policy describes how we collect, use, disclose, and safeguard the personal information — including protected health information ("PHI") — of individuals who access Talarga through our mobile application (iOS/Android) or our website (collectively, the "Service").

By accessing or using the Service, creating an account, or otherwise providing us with personal information, you agree to the terms of this Privacy Policy. If you do not agree, please do not use the Service. This Privacy Policy is incorporated by reference into the Talarga Terms of Service.

This Privacy Policy does not address the privacy practices of third-party healthcare providers, health plans, health insurance companies, CMS-regulated Patient Access APIs, or other entities whose data you authorize Talarga to retrieve. Please review those entities' own privacy notices separately.

1. Key Definitions

For purposes of this Privacy Policy, the following definitions apply:

2. Information We Collect

We collect different categories of information depending on how you interact with the Service. The principal categories are described below.

2.1 Information You Provide to Us

When you create an account, subscribe to a plan, or otherwise interact with the Service, you may provide us with:

  • Identity and Contact Data. Your full legal name, date of birth, email address, mailing address, and telephone number.
  • Account Credentials. Your username and password (passwords are stored in hashed/salted form and are never stored in plaintext).
  • Billing and Payment Information. Subscription plan selection and payment card information processed through a PCI-DSS-compliant third-party payment processor. Talarga does not store full credit card numbers.
  • Government Identity Verification Data. Where required for identity restoration guidance, Social Security Number (SSN) (last four digits), or other government-issued identification data, which is encrypted at rest and in transit and handled in accordance with Section 6 (HIPAA Notice).
  • Family Tier Member Information. Names, dates of birth, and relationship information for household members you add to a Family Tier plan, subject to Section 11 (Children and Family Tier / COPPA).
  • Communications. Content of messages, inquiries, or support tickets you submit to us.
  • Sensitive Health Conditions Acknowledgment. Certain healthcare records retrieved via FHIR APIs may contain information related to sensitive health conditions (e.g., mental health, HIV/AIDS status, substance use disorders, reproductive health). You acknowledge that by authorizing FHIR data retrieval, such sensitive categories of information may be ingested by the Service for fraud monitoring purposes. See Section 2.2 below.

2.2 Health Data and Protected Health Information (FHIR-Ingested)

The core function of Talarga is to retrieve, analyze, and monitor your healthcare claims data on your behalf. When you grant Talarga authorization through a patient-directed OAuth 2.0 consent flow:

  • We connect to CMS-regulated Patient Access APIs, TEFCA/QHIN endpoints, and other HL7 FHIR R4-compliant data sources you designate.
  • We retrieve medical claims, explanation of benefits (EOB) records, diagnosis codes (ICD-10), procedure codes (CPT/HCPCS), medication records (RxNorm), laboratory results (LOINC), and provider encounter data.
  • This data may constitute PHI as defined by HIPAA, and is handled in strict accordance with our HIPAA compliance program described in Section 6.
  • You may revoke FHIR data access at any time through your account settings, subject to Section 9 (Data Retention) regarding data previously retrieved.

2.3 Usage and Technical Information

When you access the Service through our mobile application or website, we automatically collect certain technical and usage information, including:

CategoryExamples
Device InformationDevice type, model, operating system version, device identifiers (IDFA/IDFV on iOS; Android Advertising ID), mobile network information.
Log DataIP address, browser type and version, pages or screens visited, time and date of access, referring URLs, clickstream data, session duration.
App Performance DataCrash reports, diagnostic data, application load times, error logs (collected via Firebase Crashlytics or equivalent). This data is used solely for platform stability and security monitoring.
Geolocation (Approximate)Country- and region-level location derived from IP address, used to determine applicable privacy rights and to detect anomalous access patterns. Talarga does not collect precise GPS location.
Analytics DataAggregate usage patterns, feature engagement metrics, and user flow analysis collected via Firebase Analytics or Mixpanel. See Section 13 for your opt-out options.

2.4 Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies. Our mobile application uses software development kits (SDKs) that perform analogous functions. See Section 13 for a detailed description of these technologies and your control options, including our response to Global Privacy Control (GPC) signals and Do Not Track (DNT) browser signals.

2.5 Information from Third-Party Sources

In addition to FHIR-ingested health data (Section 2.2), we may receive personal information from the following third-party sources:

  • Identity Verification Services. Third-party identity verification or credit-header data providers used to authenticate your identity prior to account activation or identity restoration guidance.
  • Healthcare Ecosystem Partners. With your authorization, participating health information exchanges (HIEs), qualifying health information networks (QHINs), or TEFCA-connected entities.
  • Customer Support Channels. Information you provide through support ticket platforms or live chat tools integrated into the Service.

3. How We Use Your Information

We use the personal information we collect for the following purposes, and only to the extent permitted by applicable law:

We do not use PHI or AHI for marketing or behavioral advertising purposes without your explicit opt-in consent.

4. How We Share Your Information

4.1 Service Providers and Business Associates

We engage third-party service providers to help us operate the Service. These providers process personal information only on our behalf, under our documented instructions, and pursuant to binding data protection agreements (and, where applicable, HIPAA Business Associate Agreements). Current categories of service providers include:

  • Cloud Infrastructure. Google Cloud Platform (GCP) for secure hosting, encrypted data storage, and infrastructure operations.
  • Analytics. Firebase Analytics and/or Mixpanel for aggregated, pseudonymized usage analysis and crash reporting. We configure these services to limit data collection to what is necessary for platform stability and improvement. Health data is excluded from analytics pipelines.
  • Payment Processing. A PCI-DSS Level 1 certified payment processor for subscription billing. We do not transmit or store full payment card numbers.
  • Identity Verification. Third-party identity verification providers used for account authentication and fraud prevention.
  • Customer Support. Third-party customer relationship management (CRM) platforms used to manage support inquiries.
  • Legal and Compliance Vendors. Law firms, auditors, and compliance consultants engaged under professional confidentiality obligations.

4.2 HIPAA-Covered Disclosures

To the extent Talarga processes PHI, we may disclose such information for Treatment, Payment, and Healthcare Operations (TPO) purposes as permitted by HIPAA, and as necessary to support identity restoration guidance. We do not disclose PHI for marketing purposes without your written authorization, except as expressly permitted by HIPAA.

4.3 Healthcare Ecosystem and Interoperability Partners

With your explicit authorization, we may share information with your designated healthcare providers, health information exchanges (HIEs), or TEFCA-connected entities to facilitate fraud reporting, care coordination, or data correction in connection with identity restoration guidance. Such sharing occurs only upon your direction and is documented accordingly.

4.5 Business Restructuring

In the event that STL Innovation, LLC undergoes a merger, acquisition, divestiture, bankruptcy, reorganization, or sale of all or substantially all of its assets, your personal information may be transferred to the surviving or successor entity as part of that transaction. We will notify you via email and/or a prominent notice on the Service prior to any such transfer becoming effective and will require the successor entity to honor this Privacy Policy or provide you with notice of any material changes.

4.6 We Do Not Sell or Share Your Personal Information for Advertising

Talarga does not sell, rent, license, or share your personal information — including any health data or PHI — to third parties for their own marketing, advertising, or commercial purposes. We do not permit third-party advertising networks to collect your information through the Service for cross-context behavioral advertising.

California residents: this means Talarga does not engage in "sale" or "sharing" of personal information as defined under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA). See Section 14.2 for your full California rights.

5. Your Obligations Regarding Third-Party Personal Information

You are permitted to provide personal information to the Service only if: (a) the information is accurate, current, and relevant; (b) you have the full right and authority to provide it; and (c) such disclosure does not violate any applicable privacy law or infringe any individual's rights. If you provide Talarga with personal information about any third party (including a household member on a Family Tier plan), you represent and warrant that you have obtained all consents and authorizations required under applicable law to share such information with us. You agree to indemnify STL Innovation, LLC for any damages, losses, or regulatory penalties arising from your breach of this obligation.

6. HIPAA and Health Information Notice

6.1 Scope of HIPAA Applicability

Talarga operates at the intersection of patient-directed FHIR data access and HIPAA compliance. As a direct-to-consumer (D2C) service receiving health data pursuant to patient-authorized OAuth 2.0 flows under the 21st Century Cures Act interoperability framework, STL Innovation, LLC's status as a HIPAA Business Associate (BA) or as an entity operating outside HIPAA's direct application requires individualized legal assessment.

6.2 HIPAA Protections We Apply

Regardless of the resolution of the entity classification question, STL Innovation, LLC applies the following HIPAA-equivalent protections to all PHI processed through the Service:

  • PHI is encrypted in transit using TLS 1.2 or higher and at rest using AES-256 encryption.
  • Access to PHI is restricted on a role-based, need-to-know basis with multi-factor authentication required for administrative access.
  • PHI is not used or disclosed for purposes other than those described in this Privacy Policy without your written authorization, except as permitted or required by law.
  • We maintain a comprehensive HIPAA Security Rule compliance program, including risk assessments, workforce training, and incident response procedures.
  • We enter into Business Associate Agreements (BAAs) with all service providers that access PHI on our behalf.
  • In the event of a breach of unsecured PHI, we will notify affected individuals, the Secretary of HHS, and (where required) applicable state authorities in accordance with the HIPAA Breach Notification Rule (45 C.F.R. Part 164, Subpart D).

6.3 Sensitive Health Categories

Certain categories of health information are accorded heightened legal protection under federal and state law, including information relating to:

  • Mental and behavioral health conditions and psychotherapy records
  • HIV/AIDS status and testing
  • Sexually transmitted diseases (STDs/STIs)
  • Substance use disorders and addiction treatment (subject to 42 C.F.R. Part 2)
  • Reproductive health, abortion, and family planning
  • Genetic information (subject to GINA)

Talarga processes these categories only to the extent they appear in FHIR-retrieved claims data you authorize us to access for fraud monitoring purposes. We apply additional access controls to sensitive category data and do not use it for any purpose beyond direct fraud detection and, at your direction, identity restoration guidance. We do not display the full content of sensitive clinical records in user-facing alerts — alerts reference anomalies at a categorical level only.

6.4 HIPAA Authorization

Certain uses or disclosures of PHI that are not otherwise permitted by HIPAA require your written authorization. You may revoke any HIPAA authorization you provide at any time by contacting us at privacy@talarga.com or using the delete account option in the Settings menu of the application, subject to actions already taken in reliance on that authorization.

7. Automated Decision-Making and AI-Powered Fraud Detection

7.1 How Automated Processing Works

Talarga uses automated processing, including artificial intelligence and machine learning algorithms, as core components of the fraud detection service. Specifically:

  • FHIR Data Ingestion. Your authorized health data is retrieved via FHIR APIs and stored in a secure, encrypted data environment.
  • Clinical Coherence Scoring. Our proprietary algorithm maps your retrieved claims data against clinical ontologies (ICD-10, SNOMED CT, RxNorm, LOINC) to compute a Clinical Coherence Score representing the statistical plausibility of your medical history. Scores outside defined thresholds trigger fraud alerts.
  • Multi-Agent Fraud Investigation. Our AI system uses multiple coordinated analytical agents to cross-reference anomalies across claim types, providers, dates, and geographic locations.
  • Alert Generation. The system generates plain-language mobile alerts describing detected anomalies. These alerts are informational only and do not constitute a legal determination or diagnosis.

8. AI and Algorithmic Services

8.1 Limitations of AI-Powered Detection

The Platform employs artificial intelligence ("AI") and machine learning algorithms (including Gemini Enterprise Agent Platform), supplemented by deterministic rule-based detection systems, to identify potentially fraudulent or unauthorized claims activity. While STL Innovation invests significant resources in the accuracy and reliability of these systems, you acknowledge and agree that:

  • AI-generated outputs and insights, including fraud alerts, risk scores, plain language explanations, and analytical findings, are probabilistic assessments, are not definitive determinations of fraud, and may be inaccurate, incomplete, or outdated;
  • The Platform may generate false positives (flagging legitimate activity as suspicious) or false negatives (failing to detect actual unauthorized activity) and does not guarantee 100% detection accuracy;
  • AI models are trained on historical data and may not accurately predict or detect novel fraud techniques, including but not limited to deepfake-assisted identity fraud, synthetic identity schemes, or coordinated social engineering attacks;
  • STL Innovation continually updates its detection models but cannot guarantee that updates will address all emerging threats;
  • The Platform does not support a Large Language Model (LLM)-based chat interface and, as such, you will have no ability to select an LLM of their choice;
  • You are responsible for independently verifying any alerts or findings generated by the Platform before taking action, including but not limited to filing disputes, contacting providers, or contacting law enforcement; and you assume all risk for decisions made based on probabilistic outputs generated by the Platform, particularly where such outputs materially affect your financial, medical, or legal decisions.

8.2 User Verification Responsibility

You are solely responsible for independently verifying any fraud alert, risk assessment, or recommendation generated by the Platform before taking any action, including:

  • Contacting healthcare providers or insurance companies;
  • Filing fraud reports with law enforcement or regulatory agencies;
  • Disputing charges or claims with payers or credit bureaus; or
  • Canceling or modifying insurance coverage or healthcare services.

8.3 Algorithmic Injury and Risk Allocation

You acknowledge that the use of AI and algorithmic systems in fraud detection carries inherent risks, including the risk of "algorithmic injury" — harm resulting from decisions made in reliance on AI-generated outputs. You expressly agree that:

  1. STL Innovation shall not be liable for any loss, damage, cost, or expense arising from actions you take (or fail to take) based on Platform-generated alerts, risk scores, or recommendations;
  2. STL Innovation shall not be liable for any false positive alert that results in inconvenience, unnecessary contact with providers, or disruption of legitimate healthcare services;
  3. STL Innovation shall not be liable for any false negative that results in undetected fraudulent activity; and
  4. The allocation of risk in this Section 8.3 is a fundamental element of the bargain between you and STL Innovation, and the pricing of the Service reflects this allocation.

8.4 AI Governance

STL Innovation maintains internal AI governance policies and procedures, including model validation, bias testing, and performance monitoring. STL Innovation documents model training data provenance, testing methodologies, and performance benchmarks as part of its internal quality assurance program. While federal requirements regarding AI model transparency may evolve, STL Innovation is committed to responsible AI practices. STL Innovation will make reasonable efforts to provide general transparency regarding the types of data used in its models and the methodologies employed, without disclosing proprietary algorithms, trade secrets, or information that could be exploited to circumvent the Platform's detection capabilities.

8.5 Use of PHI in Relation to Use of AI

When you give us consent to receive information from your insurance carrier, that information includes PHI, as well as claims, procedure, diagnostic, and service data. We use third-party AI platforms, such as the Gemini Enterprise Agent Platform, to review and process the information we collect to provide the Service. This is necessary and vital to the provision of the Services and is a condition to the use of the Service and Platform.

PHI, such as your name, date of birth, address, phone number, social security number, email, member identification number and policy number for your health plan, and your healthcare provider's name, is not sent to any third-party AI platform. Any other identifying information is replaced with internal cryptographic tokens prior to being sent to any third-party AI platform.

If you do not wish for your data to be used in this manner, do not use the Service or Platform.

9. Data Retention

We retain your personal information for as long as necessary to provide the Service, comply with applicable legal obligations, resolve disputes, enforce our agreements, and fulfill the purposes described in this Privacy Policy. Specific retention periods include:

CategoryRetention Period / Basis
Account and Identity DataRetained for the duration of your active account plus 7 years following account closure, or as required by applicable law (e.g., HIPAA requires certain records to be retained for 6 years from creation or last effective date).
FHIR-Ingested Health Data / PHIRetained in active monitoring storage for the duration of your subscription. Upon account termination, PHI is purged within 60 days after the customer requested deletion, subject to applicable minimum legal retention periods under HIPAA and state law.
Fraud Detection Logs and Clinical Coherence RecordsRetained for 7 years following alert generation to support identity restoration guidance, regulatory compliance, and potential legal proceedings.
Payment RecordsRetained for 7 years to comply with financial recordkeeping obligations.
Analytics and Diagnostic DataAggregated or de-identified analytics data may be retained indefinitely as it cannot be used to identify any individual.
Legal Hold DataAny data subject to a litigation hold or regulatory investigation will be retained until the hold is released, regardless of the standard retention schedule.

10. Security

STL Innovation, LLC maintains a comprehensive information security program designed to protect personal information, including PHI, against unauthorized access, disclosure, alteration, and destruction. Our security measures include, without limitation:

Notwithstanding the foregoing, no information security program can guarantee absolute protection against all threats. You are responsible for the security of your account by maintaining a strong, unique password and enabling multi-factor authentication. You must notify us immediately at security@talarga.com if you believe your account credentials have been compromised.

In the event of a data security incident involving your personal information or PHI, we will notify you as required by applicable law, including HIPAA's Breach Notification Rule and applicable state data breach notification statutes.

11. Children and Family Tier — COPPA Notice

11.1 General Age Restriction

The Talarga Service is not directed to, and we do not knowingly collect personal information from, children under the age of thirteen (13). If you are under 13, you may not use the Service or create an account. If we learn that we have collected personal information from a child under 13 without verifiable parental consent, we will delete that information as promptly as practicable. If you believe a child under 13 has provided us with personal information, please contact us at privacy@talarga.com.

11.2 Family Tier — Minor Household Members (Ages 13–17)

Talarga's Family Tier plan permits adult account holders to add minor household members (ages 13–17) to their plan for medical identity fraud monitoring purposes. The following terms apply to minor household members:

  • Parental/Guardian Consent and Control. By adding a minor to your Family Tier plan, you represent that you are the minor's parent or legal guardian and that you consent to the collection, use, and disclosure of the minor's personal information and health data as described in this Privacy Policy.
  • Data Access. As the account holder, you have access to fraud alerts and monitoring information for minor household members on your plan. Minor household members do not have independent account access.
  • FHIR Data Authorization. You, as parent or guardian, provide the OAuth authorization for FHIR data retrieval on behalf of minor household members, consistent with applicable law.
  • Sensitive Minor Health Information. Health records for minor household members may include sensitive information (e.g., mental health, reproductive health, substance use). Such information is subject to the heightened protections described in Section 6.3 and is not displayed in granular detail in fraud alerts.
  • Removal from Plan. You may remove a minor household member from your Family Tier plan at any time through your account settings. Upon removal, the minor's FHIR access authorization will be revoked and their health data purged in accordance with Section 9.

11.3 Operators That Collect or Maintain Information from Children

A list of all operators that may collect or maintain personal information of children through the Service is available at www.talarga.com. Please direct inquiries about any third-party operator's privacy practices and use of children's information through the contact information provided on the list.

12. Public Postings and User Content

The Service does not currently include public forums, message boards, or social features through which users can post content visible to others. If Talarga introduces such features in the future, this Privacy Policy will be updated accordingly. Any content you submit to Talarga (e.g., support tickets, feedback) is treated as non-public and handled in accordance with this Privacy Policy.

13. Cookies, Tracking Technologies, and Analytics

13.1 Types of Tracking Technologies We Use

We use the following categories of tracking technologies:

  • Strictly Necessary Cookies/Tokens. Authentication tokens, session management, and security cookies required to operate the Service. These cannot be disabled without impairing Service functionality.
  • Analytics and Performance Cookies. Firebase Analytics and/or Mixpanel SDKs (mobile app) and cookies (website) that collect pseudonymized data about how users interact with the Service, used to improve functionality and identify bugs. Health data is explicitly excluded from analytics collection pipelines.
  • Preference Cookies. Cookies that remember your settings and preferences (e.g., language, notification preferences).

We do not serve third-party advertising cookies or cross-context behavioral advertising trackers. No advertising network SDKs or pixels are embedded in the Talarga Service.

13.3 Do Not Track and Global Privacy Control (GPC)

Do Not Track (DNT): Our website does not currently take action in response to DNT signals, because there is no universally accepted standard for what DNT signals should cause a website to do. We will revisit this position as standards evolve.

Global Privacy Control (GPC): We recognize and honor GPC signals from supported browsers as an opt-out of the sale or sharing of personal information, consistent with our California obligations under CPRA. Because we do not sell or share personal information for advertising purposes, receipt of a GPC signal will be logged and acknowledged but will not change the data practices described in this Privacy Policy.

14. Your Privacy Rights

14.1 Rights Available to All Users

Regardless of your location, you have the following rights with respect to your personal information:

  • Access. You may access, review, and obtain a copy of the personal information we hold about you through your account settings or by contacting privacy@talarga.com.
  • Correction. You may correct inaccurate personal information in your account profile. For corrections to FHIR-retrieved health data, you must contact the originating healthcare provider or health plan directly.
  • No Authoritative Record. You acknowledge and agree that neither We nor the Service serves as the official repository, medical record of custody, or "source of truth" for your health information. The Service is provided for informational and convenience purposes only.
  • Requests for Official Data Exports. To obtain official, certified, or complete copies of your medical records and personal health information, you must submit your data export or access requests directly to your healthcare providers, health plans, health insurance carriers, or any other third-party entities you have authorized to interact with the Service.
  • Revocation of FHIR Authorization. You may revoke Talarga's authorization to access your FHIR data at any time through account settings or by contacting privacy@talarga.com. Revocation will terminate ongoing data retrieval but will not delete previously retrieved data unless you separately submit a deletion request.
  • Deletion. You may request deletion of your account and associated personal information, subject to our legal obligations to retain certain data. We will fulfill verified deletion requests within 45 days or the timeframe required by applicable law.
  • Complaint. If you believe we have violated your privacy rights, you may file a complaint with us at privacy@talarga.com or with the applicable regulatory authority in your jurisdiction.

14.2 California Residents — CCPA/CPRA Rights

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), subject to certain exceptions:

  • Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you, the purposes of collection, and the categories of third parties to whom your information has been disclosed.
  • Right to Delete: You may request deletion of personal information we have collected from you, subject to certain legal exceptions.
  • Right to Correct: You may request correction of inaccurate personal information we maintain about you.
  • Right to Opt-Out of Sale/Sharing: Talarga does not sell or share personal information for cross-context behavioral advertising. No opt-out action is required.
  • Right to Limit Use of Sensitive Personal Information (SPI): Health data, government ID numbers, account login credentials, and precise geolocation constitute SPI under CPRA. Talarga uses SPI only for the purposes of providing the core fraud monitoring Service, and you may request that we limit SPI use to these purposes.
  • Right Against Discrimination: Talarga will not discriminate against you for exercising your CCPA/CPRA rights.
  • Shine the Light (Cal. Civil Code § 1798.83): California customers may request information about our disclosure of personal information to third parties for direct marketing purposes. Because we do not disclose personal information for direct marketing purposes, no disclosure list exists.

To exercise your California rights, submit a verifiable consumer request to privacy@talarga.com. We will respond within 45 days (with a possible 45-day extension where reasonably necessary). We may require identity verification before processing your request. Authorized agents may submit requests on your behalf with appropriate written authorization.

16. International Data Transfers

STL Innovation, LLC is headquartered in the United States. If you are located outside the United States, do not use the Platform or Service.

17. Email Marketing and Communications Preferences

Talarga may send you transactional emails (e.g., fraud alerts, account notifications, security warnings) and, with your consent, educational communications about medical identity protection best practices and Service updates. You may opt out of non-transactional communications at any time by:

You cannot opt out of transactional or security-related communications while maintaining an active Talarga account, as these communications are integral to the Service.

Please note that email communications are not always secure. Do not include PHI, payment card information, or other sensitive personal information in emails sent to Talarga.

18. Accessibility

STL Innovation, LLC is committed to making this Privacy Policy and the Talarga Service accessible to individuals with disabilities. If you require this Privacy Policy in an alternative format (e.g., large print, audio, or screen-reader-compatible format), please contact us at support@talarga.com and we will make reasonable efforts to accommodate your needs.

19. Changes to This Privacy Policy

STL Innovation, LLC reserves the right to modify this Privacy Policy at any time. We will notify you of material changes by: (a) posting the revised Policy on the Talarga website and within the mobile application with an updated 'Last Modified' date; (b) sending you an email notification at the address associated with your account; and/or (c) displaying a prominent in-app banner for a reasonable period following the update.

Your continued use of the Service after the effective date of a revised Privacy Policy constitutes your acceptance of the revised terms. If you do not agree to the revised Privacy Policy, you must discontinue use of the Service and may request deletion of your account pursuant to Section 14.1.

For material changes to the processing of PHI, Talarga will provide at least 30 days advance notice before the change takes effect, consistent with HIPAA Notice of Privacy Practices requirements.

20. Contact Us

For questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us through any of the following channels:

STL Innovation, LLC — Talarga Privacy Team

Email: privacy@talarga.com

Security Issues: security@talarga.com

Accessibility: support@talarga.com

General help: support@talarga.com

Mailing Address: STL Innovation, LLC, 1 2ND Street, Unit 308, Jersey City, NJ 07302

For HIPAA-related complaints or to exercise your HIPAA rights, you may also contact the U.S. Department of Health and Human Services, Office for Civil Rights (OCR): https://www.hhs.gov/hipaa/filing-a-complaint.

END OF PRIVACY POLICY

Talarga Privacy Policy v1.1.1 © 2026 STL Innovation, LLC.

All Rights Reserved. Talarga is a trademark of STL Innovation, LLC.