Legal
Privacy Policy
Last Updated: June 20, 2025
Clinical Notes AI, Inc. (“Clinical Notes AI”, “we”, “our”, or “us”) respects your privacy and is committed to protecting your personal data, including protected health information (PHI) as required by the Health Insurance Portability and Accountability Act (HIPAA). This Privacy Policy will inform you how we handle and look after your personal information, including PHI, when you use our AI-based system and will tell you about your privacy rights and how the law protects you.
This Privacy Policy sets out how we collect, use, process, store, and disclose your personal information on clinicalnotes.ai and any associated subdomains (the “Website”) and the transcription and documentation software including our mobile applications or audio capture program integrations (collectively, the “Services”).
By accessing and using our Services you freely and expressly consent to the collection, use, processing, storage, and disclosure of your personal information as set out in this Privacy Policy and our Terms of Service.
1. Personal and Protected Health Information We Collect
Information you provide directly to us
- Account Creation. When you register to use our Services, we collect contact details such as your name, email address, phone number, and professional information such as company and title.
- Inquiries and Correspondence. We may collect information from your inquiries into our services, including name, work email, phone number, company name, position title, website, social media links, and time zone.
- Payment Information. We may collect data necessary to process your subscription, such as your credit card number or other financial instrument used to make a payment.
Information we automatically collect
- Metadata and Analytics. IP address, device information, date/time of visits, new or returning visits, products viewed, page response times, URL clickstreams, time on page, and on-page activity.
Information from third parties
- Demographic or Other Third-Party information, including firmographic and demographic information about current or prospective customers.
- Social Media Activity you or the platform make available when you interact with our accounts.
Information processed through our Services, including PHI
- Data submitted or authorized from Electronic Health Record systems pertaining to your patients or customers, including information deemed PHI.
- Transcriptions of conversations, and generated notes such as SOAP notes, summaries, and associated documentation.
- Referral letters, clinical assessments, patient historical reports, or related EHR information.
- Information on how users use our product to improve it, including associated metadata.
Our Website and Services are designed for business professionals. We do not intentionally collect personal information directly from minors under the age of 16. If you believe we have obtained information associated with children, contact us at privacy@clinicalnotes.ai and we will delete it.
2. How We Use Your Personal and Protected Health Information
- To process subscription payments securely and efficiently.
- To administer our Services, including account creation and management.
- To operate our Services, including AI-assisted documentation and note services, referral letters, and record storage.
- To improve the functionality and accuracy of our systems and identify usage trends.
- For customer support and communication, including newsletters and surveys.
- To protect our Services, including fraud monitoring and prevention.
- For other business and legal purposes, and with your consent and/or express written consent under HIPAA for use of PHI.
Processing and Use of AI-Generated Information. Our platform uses different types of Artificial Intelligence, some proprietary and some third-party, trained to understand therapeutic concepts and generate notes and documentation. Because this information is generated by AI, you as a professional are required to review the information generated and choose to include it within your case notes once you’ve reviewed and edited it. We assume no responsibility for incorrect or misworded outputs.
3. How We Disclose Your Personal Information
We may disclose your information with our corporate affiliates and with vendors or service providers who help us communicate with you, manage and optimize our Website and Services, provide cloud hosting, and provide customer support, and with your consent and/or express written consent under HIPAA for use of PHI. In addition:
- Legal and Compliance Purposes. We may share information to comply with legal process, protect our rights, prevent fraud or imminent harm, and secure our Services.
- Business Transactions. In a merger, acquisition, sale of assets, bankruptcy, or other corporate change, customer information may be among the assets transferred. We will endeavor to notify customers of any completed change in ownership.
4. Use and Disclosure of De-Identified Information
“De-identified” information has undergone a process of removing all personal identifiers so there is no reasonable likelihood of re-identification. For PHI, this removes the 18 federally defined HIPAA identifiers. We may de-identify collected information to analyze how our services are used and to train our AI models, and may disclose de-identified information with select business partners under strict confidentiality agreements, or for aggregate market research.
5. Your Privacy Choices
- Access the personal information we maintain about you.
- Delete the personal information we maintain about you.
- Correct inaccurate personal information we maintain about you.
- Opt out of certain uses, including unsubscribing from marketing emails.
You can exercise these rights by contacting us at privacy@clinicalnotes.ai. If you are a current or former customer, patient, or employee of one of our Customers, please contact that Customer directly, as we cannot provide personal information on their behalf without their express written instructions.
6. Use of Cookies and Tracking Technologies
We may use cookies and similar technologies (web beacons, pixels) for functional and analytics purposes. We do not knowingly use cookies to collect or use Customer PHI for cross-contextual behavioral or targeted advertising. Most browsers let you remove or reject cookies via their settings. You can opt out via our cookie banner, industry tools at optout.aboutads.info, or directly with advertising partners including Google, Meta (Facebook), StackAdapt, Microsoft Xandr, and LinkedIn.
7. U.S. State-Specific Disclosure
Some U.S. states have enacted comprehensive privacy laws related to the “sale” or “sharing” of personal information for cross-contextual behavioral or targeted advertising. We disclose the third-party advertising services above, which may be deemed a “sale” or “sharing,” with privacy choices enabled for you to opt out. When processing PHI on behalf of our Customers, we act as a “processor” or “service provider”; to exercise rights related to PHI, please contact our Customer directly.
8. UK/EEA Residents’ Notice
Residents of the UK and EEA are provided certain privacy rights under the UK and EU General Data Protection Regulations (GDPR). We process personal data under legal bases including contract fulfillment (providing Services, customer support), legitimate interest (improving our Website and Services, service-related communications), and consent (cookies and tracking technologies). We are designated a “Controller” for information collected through this website, and may be a “processor” for information provided through our Services. All data is stored in the United States; cross-border transfers rely on Standard Contractual Clauses and the UK’s International Data Transfer Addendum. UK/EEA residents may lodge a complaint with their local data protection authority.
9. Security
We have implemented appropriate security measures to prevent your personal data, including PHI, from being accidentally lost, used, or accessed in an unauthorized way. We limit access to internal staff and third parties who have a business need to know, all subject to a duty of confidentiality. Email is not a secure medium; please do not send private information, including PHI, by email. Due to the open nature of the internet, we cannot ensure or warrant the security of any information provided online.
10. Retention
We enable Customers to set specific retention schedules. If you choose the “Retain When Saved” feature, documentation including PHI is removed from our systems within fourteen (14) days. We retain Customer information for as long as your account or inquiry is active, and for a reasonable time thereafter to comply with legal obligations, resolve disputes, and enforce agreements. We may continue to retain and use de-identified, aggregate, or anonymous data previously collected.
11. Third-Party Links
Our Services may contain links to other websites or services. We do not control the information you provide to, or that is collected by, these third-party websites. We encourage you to read their privacy policies.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will communicate directly via email and/or post the updated Privacy Policy on this page with a “Last Updated” effective date.
13. Contact Information
If you have any privacy-related questions, contact us at privacy@clinicalnotes.ai.