Privacy policy
A plain-language summary of what we collect, how PHI is protected, and what you control. The full BAA governs PHI handling for paid accounts.
What we collect
Account details you provide (name, practice, email), the content of requests you send while using the product, and basic usage data needed to keep the service running and secure.
How PHI is handled
Identifying details in a request are tokenized before it reaches any AI model. Tokenized data is only resolved back to a patient record inside your own account, under your account's encryption.
What we don't do
We don't sell patient data, and nothing you submit is used to train external models. Access to your account's data is limited to you and the teammates you invite.
Retention and deletion
You can delete individual conversations, drafts, or your entire account at any time. Deleted data is removed from active systems on a routine schedule.
Business Associate Agreement
A signed BAA is included on every paid plan and governs how PHI is handled under HIPAA, alongside this policy.
Contact
Questions about this policy or a request related to your data can be sent through our contact page.