Privacy Policy
Effective September 16, 2026
1. What we collect
- Account information: name, email address, and password hash (or, if you use Google sign-in, your Google account's name and email).
- Encounter text you submit: the de-identified clinical description you type in to generate a note.
- Usage and billing metadata: credit balance, transaction and voucher-redemption records, and generation counts. As a rule, we log that a note was generated and when — not the clinical content itself.
- Payment data: handled directly by Stripe; we receive confirmation of payment, not full card details.
- Technical data: standard request metadata (IP address, browser type, timestamps) for security and abuse prevention.
2. How we use it
- To operate your account, authenticate you, and track your credit balance.
- To generate SOAP notes and guideline references by sending your encounter text to our AI model provider.
- To process payments and issue receipts through Stripe.
- To maintain security, detect abuse, and enforce our Terms of Service.
- To communicate service updates, billing notices, and — only with your consent where required — product updates.
3. AI providers and sub-processors
To generate a note, your encounter text is sent to a third-party AI model provider (currently Hugging Face-hosted open models and/or the Anthropic API, depending on configuration) for the sole purpose of producing that note. We do not sell your data. Payments are processed by Stripe, and account data is stored with our database provider (MongoDB Atlas). Each of these providers processes data under its own terms and security commitments; we choose providers that offer contractual data protection commitments appropriate to the data we send them.
4. Data retention
We retain account and billing records for as long as your account is active and as needed to meet legal, tax, and dispute-resolution obligations. Generated note text is returned to your browser for you to use and is not intentionally retained server-side beyond what's needed to serve the request and short-lived operational logs; usage logs record metadata (credit amount, reason, timestamp) rather than clinical content. You can request deletion of your account as described in Section 6.
5. Security
Passwords are stored as salted bcrypt hashes, never in plain text. We use industry-standard transport encryption (HTTPS) and access controls on our database. No method of transmission or storage is 100% secure, and we can't guarantee absolute security.
6. Your rights and choices
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, or to object to certain processing. To exercise these rights, contact us at privacy@clinnotes.example. We'll verify your identity before acting on the request.
7. Children's privacy
ClinNotes is intended for licensed and trainee healthcare professionals and is not directed to children. We do not knowingly collect data from anyone under 18.
8. International data transfers
Our infrastructure and sub-processors may store or process data in countries other than your own. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for such transfers.
9. Changes to this policy
We may update this Privacy Policy from time to time. We'll update the effective date above when we do, and, for material changes, provide additional notice where required by law.
10. Contact
Questions about this policy? Reach us at privacy@clinnotes.example.