Skip to content
LELAND

Privacy

Privacy Policy

Last updated September 12, 2026. This policy explains what Inverse Collective LLC d/b/a Leland Health collects through this website, why, who it goes to, and what you can ask us to do about it. It covers the website only.

What this policy covers, and what it does not

This policy covers information this website collects from a visitor: the email address you give us, the pages you look at, and the cookies the site sets.

It does not cover a medical record, because there is none. Leland Health is not enrolling patients through this website and collects no health information here. Please do not send us any.

When clinical care begins, the medical record is held by OpenLoop Health, the independent telehealth practice whose clinicians provide it — not by Leland Health. That record is governed by HIPAA and by the practice's own notice, which is issued by the practice and linked here directly.

OpenLoop Health Notice of Privacy Practices

What we collect

Information you give us. Today that is one thing: the email address you type into the waitlist form, so we can tell you when enrollment opens. Nothing on the form asks for a name, a date of birth, a phone number or any health information, and we ask you not to put any of those in it.

Information that arrives with a waitlist signup. Alongside your email we store a one-way hash of the confirmation token we emailed you, the page you first arrived on — not the page you signed up from — and the campaign parameters in the link that brought you here, if any.

Information collected automatically. Like most websites this one records which pages are viewed and how visitors move between them, using a product-analytics service. Your IP address and browser are part of a request to any website, ours included.

Information kept to stop abuse of the forms. When a form is submitted we store a one-way hash of the address it came from and of the email typed into it, so that one machine cannot submit a thousand signups. We store the hash rather than the address itself, though we will not overstate what that buys: it is a plain digest, not a secret-keyed one, so it is better read as a promise that we do not keep your address in the clear than as a promise that your address cannot be recovered from it. That log is deleted a day later.

Cookies and local storage. None of it is for advertising. A short-lived, HTTP-only cookie carries a waitlist confirmation between the email link and the page that completes it. A session cookie signs staff into our internal console, which is not part of the public site. The product-analytics service sets a cookie of its own, and a matching entry in your browser's local storage, so that a returning browser is counted once rather than twice. One more entry is ours: when you arrive, this site records the page you landed on and any campaign parameters in your browser's SESSION storage, so that a signup can be credited to the link that earned it. Session storage is erased when you close the tab, and we use it rather than a cookie deliberately — a marker that survived the tab would be a record of who keeps coming back to read about weight-loss medication.

Where analytics deliberately stops

Pages about a specific medication, a specific side effect, or a comparison between treatments are excluded from analytics. So are the paths a patient moves through once care begins: get started, eligibility, intake, consult, checkout and account. The waitlist form itself is NOT on that list — reading about a drug says something about you, and asking to be told when enrollment opens says much less, so we measure the second and not the first.

Excluded means two things, and the weaker one is worth stating: arrive on one of those pages directly and the analytics library is never loaded at all; reach it by clicking through from a marketing page and the library is already running, so instead we discard the event and strip the address before anything leaves your browser. That is not an oversight about measurement. The URL of a page about one drug's side effects is itself a statement about the person reading it, and handing that to an analytics vendor would disclose something health-related about a visitor who only read a public article. We gave up the measurement instead.

This site carries no advertising pixel today, and those pages are excluded from the one analytics tool it does carry. A full audit of every marketing tag, which is what would let us state this as a standing guarantee rather than as today's inventory, has not been completed.

Why we use it

  • To confirm your waitlist signup and to tell you when enrollment opens in your state.
  • To understand which pages are useful, in aggregate, so the site gets better.
  • To keep the site working and secure, including detecting abuse of the forms.
  • To meet a legal obligation, or to respond to a lawful request we are required to answer.

We do not sell personal information. We do not share it for cross-context behavioral advertising. We do not use an email address you gave us for the waitlist to advertise a different company's product.

Who it goes to

Service providers who run parts of this site for us: hosting, the database, the service that sends our email, and the product-analytics service.

We are not going to tell you what those companies may do with it until we can point at the paper. The individual providers, and the written data-processing terms each one is held to, are being finalized; until they are, treat this section as an honest list of who is involved rather than as a guarantee about how they behave.

We may also disclose information if we are legally required to, to protect someone's safety, or in connection with a merger or sale of the business, in which case this policy travels with it.

How long we keep it

Your waitlist entry — confirmed or not — is kept until enrollment opens in your state or until you ask us to remove it. We do not delete it on a schedule, and we would rather write that than publish a timetable we do not keep.

Some records that sit alongside it have an age at which they become eligible for deletion. The anti-abuse log described above becomes eligible 24 hours after the attempt it records. A confirmation receipt becomes eligible a year after it is used, and a row in the ledger of links we have issued becomes eligible a year after that LINK EXPIRES — which is later than the day it was sent, not the same day.

Eligible is not the same as deleted, and we would rather be exact than flattering. The cleanup is opportunistic: it runs at most hourly, piggybacked on somebody else signing up or confirming, it removes a bounded number of rows per pass, and if it fails it is logged and retried later rather than escalated. So a record past its age is one nobody is keeping deliberately — but if this site goes quiet, the cleanup that would have removed it goes quiet with it. There is no scheduler behind these numbers today.

Your own entry is not on any of those clocks. When you confirm, we erase the hash of the link from your entry, so the link cannot be used a second time — but we do not pretend that erases it everywhere: a copy of that hash stays in the issued-links ledger described above, attached to your row, until it reaches the age at which it becomes eligible for deletion. What stays on the entry itself is the fact that you confirmed and when, and that lasts as long as the entry does.

You can leave at any time: email help@lelandhealth.com and we will delete your entry. There is no unsubscribe link in the confirmation email, because it is the only message we send and there is not yet anything to unsubscribe from; when that changes, the mail that follows will carry one.

Your rights

Wherever you live in the United States, you can ask us what we hold about you, ask for a copy, ask us to correct it, and ask us to delete it. You will not be treated differently for asking.

Residents of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Montana, Oregon, Tennessee, Texas, Utah and Virginia have those rights under their own state privacy laws, including the right to appeal if we refuse a request. California residents have additional rights set out in the California notice on our legal page.

California Privacy Rights

To make a request, email help@lelandhealth.com from the address you gave us. We verify that a request is really yours before acting on it, and we answer within 45 days.

Security

Traffic to this site is served over HTTPS. Confirmation tokens are stored as one-way hashes rather than as the value we emailed you, so the stored record cannot be used to confirm a signup. Access to the database and to the internal console is limited to the people who need it. A full review of encryption at rest and of administrative audit logging is underway, and this section will state its findings rather than anticipate them.

No method of transmission or storage is perfectly secure, and we do not claim otherwise.

Children

This site is not for anyone under 18, and we do not knowingly collect information from a child. If you believe a child has given us information, email us and we will delete it.

Changes, and how to reach us

When this policy changes we update the date at the top of the page. A change that materially affects how we handle information already collected will be announced on the site rather than only dated.

Inverse Collective LLC d/b/a Leland Health. Email help@lelandhealth.com.