A Product of STL Innovation, LLC
STL Innovation, LLC ("STL Innovation," "we," "us," or "our") operates the Talarga platform as a direct-to-consumer medical identity protection and healthcare fraud monitoring service. This Privacy Policy describes how we collect, use, disclose, and safeguard the personal information — including protected health information ("PHI") — of individuals who access Talarga through our mobile application (iOS/Android) or our website (collectively, the "Service").
By accessing or using the Service, creating an account, or otherwise providing us with personal information, you agree to the terms of this Privacy Policy. If you do not agree, please do not use the Service. This Privacy Policy is incorporated by reference into the Talarga Terms of Service.
This Privacy Policy does not address the privacy practices of third-party healthcare providers, health plans, health insurance companies, CMS-regulated Patient Access APIs, or other entities whose data you authorize Talarga to retrieve. Please review those entities' own privacy notices separately.
For purposes of this Privacy Policy, the following definitions apply:
We collect different categories of information depending on how you interact with the Service. The principal categories are described below.
When you create an account, subscribe to a plan, or otherwise interact with the Service, you may provide us with:
The core function of Talarga is to retrieve, analyze, and monitor your healthcare claims data on your behalf. When you grant Talarga authorization through a patient-directed OAuth 2.0 consent flow:
When you access the Service through our mobile application or website, we automatically collect certain technical and usage information, including:
| Category | Examples |
|---|---|
| Device Information | Device type, model, operating system version, device identifiers (IDFA/IDFV on iOS; Android Advertising ID), mobile network information. |
| Log Data | IP address, browser type and version, pages or screens visited, time and date of access, referring URLs, clickstream data, session duration. |
| App Performance Data | Crash reports, diagnostic data, application load times, error logs (collected via Firebase Crashlytics or equivalent). This data is used solely for platform stability and security monitoring. |
| Geolocation (Approximate) | Country- and region-level location derived from IP address, used to determine applicable privacy rights and to detect anomalous access patterns. Talarga does not collect precise GPS location. |
| Analytics Data | Aggregate usage patterns, feature engagement metrics, and user flow analysis collected via Firebase Analytics or Mixpanel. See Section 13 for your opt-out options. |
In addition to FHIR-ingested health data (Section 2.2), we may receive personal information from the following third-party sources:
We use the personal information we collect for the following purposes, and only to the extent permitted by applicable law:
We do not use PHI or AHI for marketing or behavioral advertising purposes without your explicit opt-in consent.
You are permitted to provide personal information to the Service only if: (a) the information is accurate, current, and relevant; (b) you have the full right and authority to provide it; and (c) such disclosure does not violate any applicable privacy law or infringe any individual's rights. If you provide Talarga with personal information about any third party (including a household member on a Family Tier plan), you represent and warrant that you have obtained all consents and authorizations required under applicable law to share such information with us. You agree to indemnify STL Innovation, LLC for any damages, losses, or regulatory penalties arising from your breach of this obligation.
Talarga operates at the intersection of patient-directed FHIR data access and HIPAA compliance. As a direct-to-consumer (D2C) service receiving health data pursuant to patient-authorized OAuth 2.0 flows under the 21st Century Cures Act interoperability framework, STL Innovation, LLC's status as a HIPAA Business Associate (BA) or as an entity operating outside HIPAA's direct application requires individualized legal assessment.
Regardless of the resolution of the entity classification question, STL Innovation, LLC applies the following HIPAA-equivalent protections to all PHI processed through the Service:
Certain categories of health information are accorded heightened legal protection under federal and state law, including information relating to:
Talarga processes these categories only to the extent they appear in FHIR-retrieved claims data you authorize us to access for fraud monitoring purposes. We apply additional access controls to sensitive category data and do not use it for any purpose beyond direct fraud detection and, at your direction, identity restoration guidance. We do not display the full content of sensitive clinical records in user-facing alerts — alerts reference anomalies at a categorical level only.
Talarga uses automated processing, including artificial intelligence and machine learning algorithms, as core components of the fraud detection service. Specifically:
IMPORTANT: Talarga fraud alerts, Clinical Coherence Scores, and all outputs of the Service are provided for informational purposes only. They do not constitute: (a) a medical diagnosis or clinical opinion; (b) a legal determination of fraud; (c) a guarantee that fraud has occurred or has not occurred; or (d) a complete or definitive accounting of your medical history. You should consult qualified medical and legal professionals before taking any action based on a Talarga alert.
The Platform employs artificial intelligence ("AI") and machine learning algorithms (including Gemini Enterprise Agent Platform), supplemented by deterministic rule-based detection systems, to identify potentially fraudulent or unauthorized claims activity. While STL Innovation invests significant resources in the accuracy and reliability of these systems, you acknowledge and agree that:
You are solely responsible for independently verifying any fraud alert, risk assessment, or recommendation generated by the Platform before taking any action, including:
You acknowledge that the use of AI and algorithmic systems in fraud detection carries inherent risks, including the risk of "algorithmic injury" — harm resulting from decisions made in reliance on AI-generated outputs. You expressly agree that:
STL Innovation maintains internal AI governance policies and procedures, including model validation, bias testing, and performance monitoring. STL Innovation documents model training data provenance, testing methodologies, and performance benchmarks as part of its internal quality assurance program. While federal requirements regarding AI model transparency may evolve, STL Innovation is committed to responsible AI practices. STL Innovation will make reasonable efforts to provide general transparency regarding the types of data used in its models and the methodologies employed, without disclosing proprietary algorithms, trade secrets, or information that could be exploited to circumvent the Platform's detection capabilities.
When you give us consent to receive information from your insurance carrier, that information includes PHI, as well as claims, procedure, diagnostic, and service data. We use third-party AI platforms, such as the Gemini Enterprise Agent Platform, to review and process the information we collect to provide the Service. This is necessary and vital to the provision of the Services and is a condition to the use of the Service and Platform.
PHI, such as your name, date of birth, address, phone number, social security number, email, member identification number and policy number for your health plan, and your healthcare provider's name, is not sent to any third-party AI platform. Any other identifying information is replaced with internal cryptographic tokens prior to being sent to any third-party AI platform.
If you do not wish for your data to be used in this manner, do not use the Service or Platform.
We retain your personal information for as long as necessary to provide the Service, comply with applicable legal obligations, resolve disputes, enforce our agreements, and fulfill the purposes described in this Privacy Policy. Specific retention periods include:
| Category | Retention Period / Basis |
|---|---|
| Account and Identity Data | Retained for the duration of your active account plus 7 years following account closure, or as required by applicable law (e.g., HIPAA requires certain records to be retained for 6 years from creation or last effective date). |
| FHIR-Ingested Health Data / PHI | Retained in active monitoring storage for the duration of your subscription. Upon account termination, PHI is purged within 60 days after the customer requested deletion, subject to applicable minimum legal retention periods under HIPAA and state law. |
| Fraud Detection Logs and Clinical Coherence Records | Retained for 7 years following alert generation to support identity restoration guidance, regulatory compliance, and potential legal proceedings. |
| Payment Records | Retained for 7 years to comply with financial recordkeeping obligations. |
| Analytics and Diagnostic Data | Aggregated or de-identified analytics data may be retained indefinitely as it cannot be used to identify any individual. |
| Legal Hold Data | Any data subject to a litigation hold or regulatory investigation will be retained until the hold is released, regardless of the standard retention schedule. |
STL Innovation, LLC maintains a comprehensive information security program designed to protect personal information, including PHI, against unauthorized access, disclosure, alteration, and destruction. Our security measures include, without limitation:
Notwithstanding the foregoing, no information security program can guarantee absolute protection against all threats. You are responsible for the security of your account by maintaining a strong, unique password and enabling multi-factor authentication. You must notify us immediately at security@talarga.com if you believe your account credentials have been compromised.
In the event of a data security incident involving your personal information or PHI, we will notify you as required by applicable law, including HIPAA's Breach Notification Rule and applicable state data breach notification statutes.
The Talarga Service is not directed to, and we do not knowingly collect personal information from, children under the age of thirteen (13). If you are under 13, you may not use the Service or create an account. If we learn that we have collected personal information from a child under 13 without verifiable parental consent, we will delete that information as promptly as practicable. If you believe a child under 13 has provided us with personal information, please contact us at privacy@talarga.com.
Talarga's Family Tier plan permits adult account holders to add minor household members (ages 13–17) to their plan for medical identity fraud monitoring purposes. The following terms apply to minor household members:
A list of all operators that may collect or maintain personal information of children through the Service is available at www.talarga.com. Please direct inquiries about any third-party operator's privacy practices and use of children's information through the contact information provided on the list.
The Service does not currently include public forums, message boards, or social features through which users can post content visible to others. If Talarga introduces such features in the future, this Privacy Policy will be updated accordingly. Any content you submit to Talarga (e.g., support tickets, feedback) is treated as non-public and handled in accordance with this Privacy Policy.
Regardless of your location, you have the following rights with respect to your personal information:
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), subject to certain exceptions:
To exercise your California rights, submit a verifiable consumer request to privacy@talarga.com. We will respond within 45 days (with a possible 45-day extension where reasonably necessary). We may require identity verification before processing your request. Authorized agents may submit requests on your behalf with appropriate written authorization.
The Service may contain links to third-party websites, applications, or services — including healthcare provider portals, health plan websites, and CMS.gov — that are not owned or controlled by STL Innovation, LLC. This Privacy Policy does not apply to those third-party services. We are not responsible for the privacy practices of any third party and encourage you to review the privacy policies of any third-party service you access. The inclusion of a link to a third-party website does not imply endorsement by Talarga or STL Innovation, LLC.
Additionally, to the extent the Service integrates with social media platforms (e.g., for account sharing or referral features), your interactions with those platforms are governed by their own privacy policies. Social media platforms may provide Talarga with certain profile information pursuant to the permissions you grant. We use such information only for account creation or authentication purposes and do not share health data with social media platforms.
STL Innovation, LLC is headquartered in the United States. If you are located outside the United States, do not use the Platform or Service.
Talarga may send you transactional emails (e.g., fraud alerts, account notifications, security warnings) and, with your consent, educational communications about medical identity protection best practices and Service updates. You may opt out of non-transactional communications at any time by:
You cannot opt out of transactional or security-related communications while maintaining an active Talarga account, as these communications are integral to the Service.
Please note that email communications are not always secure. Do not include PHI, payment card information, or other sensitive personal information in emails sent to Talarga.
STL Innovation, LLC is committed to making this Privacy Policy and the Talarga Service accessible to individuals with disabilities. If you require this Privacy Policy in an alternative format (e.g., large print, audio, or screen-reader-compatible format), please contact us at support@talarga.com and we will make reasonable efforts to accommodate your needs.
STL Innovation, LLC reserves the right to modify this Privacy Policy at any time. We will notify you of material changes by: (a) posting the revised Policy on the Talarga website and within the mobile application with an updated 'Last Modified' date; (b) sending you an email notification at the address associated with your account; and/or (c) displaying a prominent in-app banner for a reasonable period following the update.
Your continued use of the Service after the effective date of a revised Privacy Policy constitutes your acceptance of the revised terms. If you do not agree to the revised Privacy Policy, you must discontinue use of the Service and may request deletion of your account pursuant to Section 14.1.
For material changes to the processing of PHI, Talarga will provide at least 30 days advance notice before the change takes effect, consistent with HIPAA Notice of Privacy Practices requirements.
For questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us through any of the following channels:
STL Innovation, LLC — Talarga Privacy Team
Email: privacy@talarga.com
Security Issues: security@talarga.com
Accessibility: support@talarga.com
General help: support@talarga.com
Mailing Address: STL Innovation, LLC, 1 2ND Street, Unit 308, Jersey City, NJ 07302
For HIPAA-related complaints or to exercise your HIPAA rights, you may also contact the U.S. Department of Health and Human Services, Office for Civil Rights (OCR): https://www.hhs.gov/hipaa/filing-a-complaint.
END OF PRIVACY POLICY
Talarga Privacy Policy v1.1.1 © 2026 STL Innovation, LLC.
All Rights Reserved. Talarga is a trademark of STL Innovation, LLC.