Legal
Privacy Policy
Effective date: July 1, 2026 · Last updated: August 18, 2026
HIPAA notice: ClariteNote is a tool for licensed healthcare providers. We process Protected Health Information (PHI) on behalf of a covered entity only under an applicable Business Associate Agreement (BAA). This privacy policy describes ClariteNote's practices; it does not replace a covered entity's own Notice of Privacy Practices or other HIPAA obligations.
Privacy Policy
1. Who We Are
ClariteNote ("we," "us," or "our") provides an AI-powered clinical documentation platform for licensed therapists and mental health professionals. We are a Business Associate as defined under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations.
2. Information We Collect
We collect only the information necessary to provide the service:
- Account information: Name, email address, and hashed password used to authenticate your account.
- Session audio: Audio recordings you submit for transcription. Audio is processed in real time and is not permanently stored after transcription.
- Clinical notes & transcripts: AI-generated clinical documentation associated with your clients. Stored clinical records are encrypted at rest using Fernet authenticated encryption and transmitted over TLS.
- Client profiles: Minimum-necessary identifying information you enter for your clients.
- Audit logs: Timestamped records of system access and actions for HIPAA compliance. Logs do not contain PHI content.
3. How We Use Information
- To transcribe session audio and generate clinical notes using configured Amazon Bedrock models.
- To maintain session continuity (prior session summaries used to improve note quality).
- To enforce authentication, session timeouts, and access controls.
- To generate and maintain audit logs for HIPAA compliance.
4. How We Share Information
We do not sell, rent, or share PHI with any third party for marketing purposes. PHI is shared only as permitted or required by law, or with service providers operating under signed BAAs:
- Amazon Web Services (AWS): Hosting and configured Amazon Bedrock AI processing. Workloads involving PHI must remain within HIPAA-eligible services and accounts covered by the applicable AWS BAA and security configuration.
- Stripe and transactional email providers: Payment, account, and service-message processing. ClariteNote does not intentionally send clinical note content, transcripts, session audio, or client PHI to these providers.
- Law enforcement / legal process: As required by applicable law, court order, or to protect safety.
5. Data Retention
Medical-record retention periods are generally determined by applicable state law, professional rules, payer requirements, contracts, and your organization's policies; HIPAA does not establish a universal medical-record retention period. You are responsible for selecting and following the retention period that applies to your practice. ClariteNote provides record download and deletion controls to support that responsibility.
6. Security Safeguards
- All data encrypted in transit via TLS 1.2+
- Stored clinical records encrypted at rest using Fernet authenticated encryption
- Automatic session logout after 15 minutes of inactivity
- Per-user data isolation — no cross-account data access
- Audit logging of all access and modification events
- API keys and secrets stored in environment variables, never in code
- Sensitive file paths are blocked from direct access
- Security headers enforced on all responses (HSTS, CSP, X-Frame-Options)
7. Your Rights
As a provider using this platform, you retain full ownership of your clinical records. You may:
- Download any session note at any time.
- Edit, amend, or delete notes before or after sign-off.
- Delete client records and all associated data.
- Request account deletion by contacting us at the address below.
8. Analytics
We do not use third-party analytics, tracking pixels, or advertising SDKs. No PHI is ever transmitted to analytics platforms.
9. Children
ClariteNote is intended solely for use by licensed clinical professionals. It is not directed at individuals under 18.
10. Changes to This Policy
We will notify users via email of any material changes to this policy at least 30 days before they take effect.
HIPAA Roles and Requests
This section summarizes how ClariteNote supports customers when PHI is processed under a BAA. The healthcare provider remains responsible for its own Notice of Privacy Practices and for responding to individuals as required by law.
Our Obligations as a Business Associate
ClariteNote operates as a Business Associate (BA) under HIPAA. We are required to:
- Maintain the privacy of your clients' PHI.
- Use and disclose PHI only as permitted by the applicable BAA or as required by law.
- Notify you if a breach of unsecured PHI occurs.
- Require applicable subcontractors that handle PHI to accept appropriate privacy and security obligations.
Permitted Uses and Disclosures
We may use or disclose PHI only as follows:
- Treatment support: Generating, storing, and organizing clinical notes on your behalf.
- Business Associate services: Using configured AWS services, including Amazon Bedrock, to provide transcription and clinical-documentation functions under applicable agreements and safeguards.
- Required by law: In response to lawful subpoenas, court orders, or regulatory requirements.
- Preventing harm: To avert a serious threat to health or safety as permitted by applicable law.
Uses and Disclosures Requiring Authorization
We will not use or disclose PHI for any purpose not listed above without your prior written authorization.
Individual Rights
Your clients may have rights regarding their PHI that you, as the covered entity, are responsible for honoring. ClariteNote supports customer responses by providing:
- Access: Session notes and records can be downloaded at any time.
- Amendment: Notes can be edited and saved at any time prior to final sign-off.
- Restriction: You may delete individual sessions or entire client records.
- Accounting of disclosures: Audit logs are available in Settings > Audit Log.
Breach Notification
In the event of a breach of unsecured PHI, we will notify affected Covered Entities without unreasonable delay and no later than 60 days after discovery, as required by 45 CFR § 164.410.
Complaints
If you believe your privacy rights have been violated, you may file a complaint with us using the contact information below, or with the U.S. Department of Health and Human Services Office for Civil Rights at www.hhs.gov/ocr. We will not retaliate against you for filing a complaint.