Privacy Policy
Last updated: January 14, 2026
1. Introduction
Coral, Inc. ("the Company," "we," "us," or "our") operates the website trycorai.org and the Coral clinical document automation service (the "Service"). This Privacy Policy explains what information we collect, how we use it, and the choices you have.
Coral's core service is built for infusion centers and DME providers: we read inbound referral faxes, extract the clinical fields needed for prior authorization, and assist intake coordinators in filing those authorization requests. That work necessarily involves contact with protected health information ("PHI") as defined under the Health Insurance Portability and Accountability Act ("HIPAA"). When Coral processes PHI on behalf of a covered entity (such as a clinic or DME provider), Coral acts as a Business Associate and that relationship is governed by a Business Associate Agreement ("BAA"), not by this Privacy Policy. This Privacy Policy governs the separate category of information Coral collects from visitors to trycorai.org and from administrative contacts (clinic managers, coordinators, and other personnel) who interact with us through the website and communications channels.
The Company is based at 1033 Demonbreun Street, Suite 300, Nashville, TN 37203 and can be reached at [email protected].
2. Information We Collect
2.1 Information You Provide
We collect information you submit directly, including:
- Contact details (name, email, phone number) when you fill out a demo request, early-access inquiry, or contact form;
- Clinic or organization information you choose to share (clinic name, role, number of locations, referral volume);
- The content of messages you send us through the site or by email.
2.2 Information Collected Automatically
When you visit trycorai.org, we automatically collect limited technical information:
- IP address and approximate location (city/region level);
- Browser type, operating system, device class;
- Pages visited, referring URLs, time on page;
- Cookie and similar identifiers (see Section 5 and our Cookie Policy).
2.3 PHI Handled Under BAA: Separate from This Policy
Referral document content, extracted clinical fields, patient demographic data, and other PHI that Coral processes on behalf of a clinic or DME provider are handled under the terms of the applicable BAA, which incorporates HIPAA's privacy and security requirements. That data is not described here and is not commingled with the website and administrative information this Policy covers. If you have questions about how Coral handles PHI in the service context, contact [email protected].
2.4 We Do Not Knowingly Collect Children's Data
trycorai.org is not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact [email protected] and we will delete it.
3. How We Use Information
We use the information we collect from website visitors and administrative contacts to:
- Respond to early-access inquiries, demo requests, and general questions about the Coral service;
- Operate and maintain trycorai.org;
- Send service updates and, where you have requested them, communications about the Coral early-access program;
- Measure site usage and improve the experience for intake coordinators and clinic managers evaluating Coral;
- Detect and prevent fraud or abuse;
- Comply with applicable legal obligations.
We do not use referral document content or extracted clinical fields for any purpose other than providing the authorized service to the clinic that submitted the documents. We do not use PHI to train machine-learning models without explicit written consent from the covered entity. We do not sell personal information for monetary value.
4. Sharing of Information
We share personal information only with:
- Service providers acting on our behalf (such as hosting infrastructure, email delivery, and usage analytics) under contractual confidentiality terms;
- Authorities, when required by law or to protect rights, safety, or property;
- A successor entity in the event of a merger, acquisition, or asset sale, subject to this Policy.
We do not sell personal information to third parties. PHI is shared only as permitted by the applicable BAA and HIPAA's permissible disclosure rules.
5. Cookies and Tracking
We use cookies and similar technologies to operate the site, remember preferences, and measure usage. For details and choices, see our Cookie Policy.
6. Data Retention
We retain personal information from website visitors and administrative contacts only as long as needed for the purposes described above, to comply with legal or accounting obligations, and to resolve disputes. Inactive marketing-list contacts are purged after 24 months. Server access logs are retained 90 days, then aggregated and de-identified.
Retention of PHI processed under a BAA is governed by the terms of that agreement and by HIPAA's record retention requirements. Coral's default practice is to delete PHI from active processing queues after the authorization workflow for that referral is complete, unless the clinic has configured a longer retention window under their plan terms.
7. Security
We use administrative, technical, and physical safeguards designed to protect personal information, including TLS encryption in transit, encryption at rest for stored documents, restricted-access databases, and least-privilege access controls. The service is hosted on US-based cloud infrastructure. No system is perfectly secure; we cannot guarantee absolute security. If you have questions about our security practices, see our Security page or contact [email protected].
8. Your General Rights
Depending on your jurisdiction, you may have rights including access to, correction of, deletion of, and the ability to limit certain processing of your personal information. To make a request, email [email protected]. We will respond within the timeframe required by applicable law.
9. Tennessee Residents (TIPA)
Under the Tennessee Information Protection Act ("TIPA"), Tennessee residents have the rights described below.
9.1 Your TIPA Rights
- Right to Confirm and Access personal data we process about you.
- Right to Correct inaccuracies, taking into account the nature of the data and processing purposes.
- Right to Delete personal data we have collected from or about you.
- Right to Data Portability in a portable format where technically feasible.
- Right to Opt Out of targeted advertising, sale, and profiling for significant decisions.
9.2 How to Exercise
Email [email protected]. We respond within 45 days; one 45-day extension is available with notice.
9.3 Appeal
You may appeal a denial by replying to our response. Unresolved appeals may be reported to the Tennessee Attorney General.
9.4 California Visitors
If you are a California resident visiting from another state, you may also exercise the rights granted under the California Consumer Privacy Act ("CCPA") and California Privacy Rights Act ("CPRA"), including the right to know, the right to delete, the right to correct, and the right to opt out of sale or sharing. We do not sell personal information and do not "share" personal information for cross-context behavioral advertising.
To submit a CCPA/CPRA request, email [email protected] with the subject line "California Privacy Request."
10. Changes to This Policy
We may update this Policy from time to time. Material changes will be reflected by a new "Last updated" date and, where appropriate, a notice on the Service.
11. Contact
Questions, requests, or complaints can be sent to:
Coral, Inc.1033 Demonbreun Street, Suite 300
Nashville, TN 37203
Email: [email protected]
Phone: +1 (615) 274-0148