BrilLiquid LLC — BRILL.health Terms of Use

Effective Date: [TBD] (Published v2.1 — 2026-05-10)


About this document

These are the plain-English Terms of Use for BRILL.health, the patient-facing health platform operated by BrilLiquid LLC.

A more detailed counsel-reviewed version of these Terms is maintained internally and is available on request to counsel, regulators, and sophisticated auditors. Substantive commitments are identical between the two; the detailed version retains additional regulatory citations, section numbering consistent with prior drafts, and related technical detail.


1. Agreeing to these Terms

By creating an account or using BRILL.health, you agree to these Terms. If you don't agree, don't use the service. These Terms form a binding contract between you and BrilLiquid LLC, a New Jersey limited liability company.

2. Who can use BRILL.health

You must:

There is no citizenship, residency, or immigration-status requirement to use BRILL.health.

3. Your account and security

You're responsible for:

We require multi-factor authentication and recommend Passkeys (Face ID, Touch ID, device PIN) as your primary method.

4. What BRILL.health is

BRILL.health is a patient-agent platform — we work for you. We help you:

What BRILL.health is not:

5. Two levels of platform access

Everyone gets access to the full platform except one feature — Direct Secure Messaging (a standards-based secure channel to licensed providers). Federal law and industry rules require stronger identity verification to issue Direct Secure Messaging addresses.

Direct Secure Messaging is a feature upgrade, not a platform-admission gate. You can use BRILL.health without it indefinitely. You can upgrade whenever you want.

The minimum we need to give you any service is your name, date of birth, and a way to contact you (email or phone). Everything else — SSN/ITIN, address, insurance card, government ID — is optional. Each optional element unlocks additional capabilities but isn't required for core platform access.

6. Direct Secure Messaging (for users who enable it)

If you enable Direct Secure Messaging:

7. Your designated contacts

HIPAA recognizes three distinct kinds of people in your care, each with different legal standing. You can designate any, all, or none of these:

Same person can have multiple roles, different people can have different roles, or you can designate nobody. Changes are allowed anytime.

Designating a Personal Representative through BRILL.health doesn't by itself create the legal authority — the underlying legal instrument must exist under your state's law. We provide optional tools (including online notarization) to help you create such instruments, but the legal validity depends on your jurisdiction's rules.

BRILL.health operates on granular, revocable consent. For any specific program or data-sharing arrangement, you encounter a distinct consent decision. In our initial programs you may see up to three:

You can accept or decline any of these independently. You can revoke a consent at any time.

How revocation works: effect within 30 days (often faster). It stops future uses. It can't retract data already transmitted or research already completed — but where possible we'll notify downstream recipients.

Research risks worth knowing: De-identification reduces but doesn't eliminate privacy risk. Re-identification from published results is possible though uncommon; a breach could implicate biological relatives sharing your genetic material; new techniques might introduce risks we can't currently anticipate. See our Privacy Policy §5 for details.

9. Your records and key management

BRILL.health is designed around patient-held data. Your clinical records live on your device, encrypted under keys you control in our target architecture.

Currently: we encrypt your data with industry-standard protections and AWS-managed key storage. Some keys are server-held under strict controls.

Target architecture: device-held encryption keys bound to your Passkey; our servers wouldn't have the ability to decrypt. We're implementing this in phases.

When patient-held keys are active for your account:

10. Connecting to other services

BRILL.health brings data into your record from several places:

For each of the connected paths, you authorize us at the service's own consent screen — we're a "receiving app." The third party's terms govern their side; our Privacy Policy governs ours once data reaches us.

Apple Health and Google Health Connect — patient-mediated upload only

BRILL.health runs as a web app you add to your phone's home screen — not an iPhone app from the App Store or an Android app from Google Play. That has a specific consequence: we don't connect directly to Apple Health (HealthKit) or Google Health Connect. Web apps can't read or write those services, so we don't sync from them automatically.

What we do support: you can export data from Apple Health or Google Health Connect and upload the export to BRILL.health. Apple Health is already connected to records from hundreds of hospitals, clinics, and pharmacies via Apple Health Records, so a single Apple Health export can bring records from many sources into your BRILL.health record, with full provenance preserved.

Apple's and Google's rules on health data still bind us when you upload an export:

If we ever release a native iPhone or Android app — none is currently planned — direct sync could become possible. We'll tell you well in advance.

See Privacy Policy §4 and Terms Addendum B.1 / B.2 for the full mechanics.

11. Acceptable use

You agree not to:

We may suspend or terminate accounts for serious or repeated violations. Where possible we'll give notice and a chance to correct, except where immediate action is necessary to protect others or comply with law.

12. Minors

A parent, legal guardian, or Personal Representative may enroll a minor (under 18) subject to applicable state law. State law may give the minor independent rights (for example, in reproductive health, mental health, or substance-use care) that override the Personal Representative's. Where state law gives the minor independent rights, we honor them to the extent technically feasible.

When a minor reaches the age of majority in their state, the Personal Representative relationship through BRILL.health ends automatically unless renewed under a new legal instrument.

13. No discrimination in platform access

BRILL.health does not condition platform admission on:

Stronger identity verification (for Direct Secure Messaging) may rely on documents more readily available to some than to others. We offer multiple verification paths, including paths that accept foreign government-issued identification and trusted-referee verification. If you can't complete stronger verification through any available path, you retain full access to all other platform features.

14. Patients with international ties

BRILL.health's architecture supports patients whose care crosses borders.

15. Liability

To the maximum extent permitted by law:

Nothing limits liability for willful misconduct, gross negligence, or anything that can't be excluded under applicable law.

16. Intellectual property

Content on BRILL.health — text, graphics, logos, software, designs — is ours (or our licensors'). You may use the platform only as these Terms permit.

You retain all rights in your own content (records, messages, entries). You grant us only the rights necessary to operate the platform for you.

17. Indemnification

You agree to indemnify Brilliquid from any claim, loss, or expense arising out of your breach of these Terms, your misuse of the platform, your violation of law, or your violation of another person's rights.

18. Governing law and disputes

These Terms are governed by New Jersey law. Exclusive jurisdiction for disputes is in the state and federal courts located in Morris County, New Jersey — unless mandatory consumer-protection law of your residence requires otherwise, or you have a small-claims right in your jurisdiction.

19. Changes to these Terms

For material changes, we'll notify you at least 30 days in advance (by in-app notice, email, or both). Non-material changes (typos, cross-references) may take effect immediately with the new Effective Date above.

Your continued use after the effective date of a material change means you accept it. If you don't accept, you can close your account; we'll preserve your records and export capabilities for a reasonable period.

20. Closing your account

21. Contact

BrilLiquid LLC (a New Jersey limited liability company) Florham Park, NJ 07932 General inquiries (email): am@brilliquid.com Direct Secure Messaging (for healthcare correspondence): am@brill.health Business continuity: +1-201-637-1765

Note on email: brilliquid.com is our corporate email. brill.health is a Direct Secure Messaging address — a standards-based secure channel reserved for healthcare correspondence, not a regular email inbox. A healthcare corporate email on brilliquid.health will activate later; we'll update these Terms when it does.


Acknowledgment for Users Who Enable Direct Secure Messaging

If you enable Direct Secure Messaging, you also acknowledge and agree to the following:

The governing industry policies are available on request; in the event of any conflict, those policies control for matters they address.


This is the plain-English published version of our Terms of Use. A more detailed counsel-reviewed version with additional regulatory citations and technical implementation detail is available on request.