Chartflow
Chartflow

Privacy Policy

Effective date: July 27, 2026

Chartflow Health, Inc. ("Chartflow", "we", "us", or "our") operates the Chartflow mobile application, website, and browser extension (collectively, the "Service") — an AI-powered medical-scribe platform built for home health clinicians. We are committed to protecting the privacy of our users and to maintaining compliance with applicable law, including the Health Insurance Portability and Accountability Act (HIPAA).

This Privacy Policy explains what information we collect, how we use and share it, and the rights you have with respect to your data.

1. Information We Collect

Account Information

When you register for Chartflow we collect your name, email address, and professional role (e.g., registered nurse, physical therapist). If you sign in via Google or Apple, we receive the profile information those providers share with us.

Patient-Visit Audio Recordings

Chartflow records the audio of patient visits that you initiate in the app. These recordings may contain protected health information (PHI). Audio is transmitted over encrypted connections to AssemblyAI for transcription and the resulting transcript to Google Cloud Vertex AI for draft-note generation (see §4 for both), and is stored encrypted as part of the clinical documentation record (see §5, Data Retention).

Transcripts and Generated Notes

The Service converts your audio recording into a text transcript and then uses AI to draft a clinical note. Both the transcript and the generated note are stored in your account and may contain PHI. You are responsible for reviewing, editing, and finalising all AI-generated content before it enters any medical record.

Usage and Technical Data

We collect standard server logs (IP address, browser or app version, timestamps, pages viewed) and crash-diagnostic data (via Firebase Crashlytics — device model, OS version, and stack traces; never audio, transcripts, or PHI). We use this information solely to operate and improve the Service. Optional product-usage analytics are off by default and collected only if you enable them; you can turn them on or off at any time in the app (Settings → Data & Privacy).

Billing Information

Subscription payments are handled by a PCI-DSS Level 1 certified payment processor. Chartflow does not store your full card number, CVC, or bank-account details — that information is held exclusively by the payment processor. We receive and store only non-sensitive billing identifiers (customer reference, subscription status, last-four digits of your card). Our payment processor never receives clinical data or PHI.

Browser Extension Data

The Chartflow browser extension operates as follows with respect to data. (1) Authentication token:the Chartflow web application relays the clinician's authentication identity token to the extension via the Chrome messaging API; the extension stores that token in chrome.storage solely to authenticate requests to the Chartflow backend. The token is cleared on sign-out or expiry. (2) Note content:the extension fetches the finalised clinical note from the Chartflow backend and writes it into the clinician's EHR charting form. Note content may contain PHI; it is held in memory only for the duration of the push operation and is not persisted by the extension. (3) EHR page content: the extension reads the DOM of the active EHR page solely to locate the correct form fields and to verify patient identity before writing, as a guard against writing to the wrong chart. (4) Field-mapping snapshots: when generating a new EHR field mapping, the extension captures an HTML snapshot of the EHR form. That snapshot is scrubbed to remove patient data before transmission to the Chartflow backend. (5) Diagnostic telemetry: the extension sends non-PHI diagnostic data (reason codes, field-discovery counts, frame-scan statistics) to the Chartflow backend to support reliability monitoring. No PHI is included in telemetry. The extension does not record audio and does not read or access any web page other than the EHR domains the clinician has explicitly granted access to.

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Service;
  • Transcribe your audio recordings and generate draft clinical notes;
  • Send transactional and administrative communications (account verification, billing receipts, security alerts);
  • Comply with legal obligations;
  • Detect, investigate, and prevent fraud and abuse.

We do not sell your personal information or PHI to third parties. We do not use your clinical data to train general-purpose AI models without your explicit consent.

3. Legal Basis for Processing

Where applicable law requires a legal basis, we process your personal information on the basis of contract performance (to provide the Service you signed up for), legitimate interests (security, fraud prevention, product improvement), and legal obligation. For PHI, our processing is governed by HIPAA and any Business Associate Agreement (BAA) in effect with your agency or covered entity.

4. Service Providers and Third Parties

We share information with a limited set of service providers (sub-processors) solely to deliver the Service. They fall into the following categories:

AssemblyAI, Inc. Speech-to-text transcription

Patient-visit audio is transmitted to AssemblyAI to produce the text transcript. AssemblyAI operates under a Business Associate Agreement (BAA) with Chartflow, processes your audio solely to provide the Service, and is contractually prohibited from using your audio or transcripts to train its general-purpose AI models.

Google Cloud — Vertex AI (Gemini) AI draft-note generation

Visit transcripts are processed by Google Cloud's Vertex AI language models (Gemini) to draft clinical notes and extract structured documentation fields. This processing occurs under Google Cloud's HIPAA Business Associate Agreement; Google does not use your transcripts or notes to train its general-purpose AI models.

Google Cloud Platform & Firebase Hosting, storage, identity, and crash diagnostics

The Service is hosted on Google Cloud Platform (HIPAA-eligible services, United States regions) under a BAA. This includes encrypted storage of recordings, transcripts, and notes. Firebase provides user sign-in / authentication, push notifications, and crash-diagnostic reporting (Firebase Crashlytics); crash reports contain device and stack-trace information and never include audio, transcripts, or PHI.

Stripe, Inc. Subscription billing

Stripe, a PCI-DSS Level 1 certified payment processor, handles subscription payments. Stripe never receives clinical data or PHI; we store only non-sensitive billing identifiers.

Every third party with whom we share your data is bound by written agreements — including BAAs where PHI is involved — requiring them to protect your data to a standard at least as protective as this policy. We do not share your data with advertising networks or data brokers. A current list of our sub-processors is available to customers and their compliance teams on request at hello@chartflow.health.

We may share information with law-enforcement or regulatory bodies when required by law, court order, or to protect the rights or safety of Chartflow, our users, or third parties.

5. Data Retention

We retain your account information for as long as your account is active. Clinical documentation — including visit audio recordings, transcripts, and generated notes — forms part of the medical record and is retained in encrypted storage for as long as required by applicable medical-record retention laws and any agreement with your agency or covered entity, even after your account is closed. If you delete your account, we delete your login credentials, profile, and device data within 30 days; clinical records are retained as described in §6 and remain subject to legal retention obligations. Billing records may be retained for up to 7 years to comply with financial reporting requirements.

6. Your Rights

Depending on your jurisdiction, you may have the following rights with respect to your personal information:

  • Access: request a copy of the personal information we hold about you.
  • Correction: request correction of inaccurate data.
  • Deletion: you can request account deletion from within the app or by contacting us at hello@chartflow.health. We aim to delete your login, profile, and device data within 30 days of a verified request. Clinical notes, encounters, and medical records are retained as required by medical-record retention laws and remain attributed to you as the authoring clinician.
  • Consent withdrawal:you can turn off optional usage analytics at any time in the app (Settings → Data & Privacy) and revoke microphone access in your device's system settings.
  • Portability:you can download a copy of your data at any time using the "Download My Data" feature in the app (Settings → Data & Privacy).
  • Objection / restriction: object to or request restriction of certain processing.

To exercise any right not available through the app, contact us at hello@chartflow.health. We will respond within 30 days.

If you are a patient whose PHI was captured during a home-health visit, your rights under HIPAA are governed by your provider's Notice of Privacy Practices. Please contact your clinician or agency directly.

7. Security

We implement administrative, technical, and physical safeguards designed to protect your information, including:

  • Encryption in transit using TLS 1.2+ for all data transmitted between your device, our servers, and our sub-processors;
  • Encryption at rest for all stored data, including audio recordings, transcripts, and clinical notes, using AES-256;
  • Role-based access controls limiting data access to authorised personnel;
  • Audit logging of access to PHI;
  • Regular security assessments and penetration testing.

No method of transmission over the internet or method of electronic storage is 100% secure. If you believe your account has been compromised, contact us immediately at hello@chartflow.health.

8. Browser Extension

The Chartflow browser extension (Chrome MV3) exists for a single purpose: to transfer a completed Chartflow clinical note into the clinician's EHR charting form. It does not perform any function beyond that purpose.

Host Access Model

The extension declares static access only to the EHR domains Chartflow currently supports (Elation and Kinnser/WellSky). If Chartflow adds support for an additional EHR, the clinician is presented with a one-time Chrome permission prompt for that specific domain before any access is taken. The clinician may revoke access to any domain at any time from chrome://extensions.

No Advertising and No Sale of Data

The extension does not use data for advertising purposes. We do not sell extension data to third parties. We do not share extension data with advertising networks or data brokers.

Chrome Web Store Limited Use

Chartflow's use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. We use extension data only to provide and improve the extension's single purpose, we do not transfer it to third parties except as described in this policy, we do not use it for advertising, and we do not allow humans to read it except as described in §7 and §9.

Data Retention for Extension Data

The authentication token stored by the extension is cleared on sign-out or token expiry. The extension does not maintain its own long-term store of PHI; note content is held in memory only for the duration of the push operation and is not written to persistent extension storage.

For extension-specific privacy questions, contact us at hello@chartflow.health.

9. HIPAA and Business Associate Agreements

Chartflow is designed to support HIPAA-covered entities and their business associates. If your organisation is a covered entity or business associate under HIPAA, you may enter into a Business Associate Agreement (BAA) with Chartflow as part of your subscription. Contact hello@chartflow.health for details.

10. Children's Privacy

The Service is intended for licensed healthcare professionals. We do not knowingly collect personal information from individuals under the age of 18. If you believe a minor has provided us with personal information, please contact us and we will delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and, where appropriate, by sending an email to the address associated with your account. Your continued use of the Service after the effective date of any change constitutes your acceptance of the updated policy.

12. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:

Chartflow Health, Inc.
Email: hello@chartflow.health