Privacy Policy
Last updated: August 2026
Information We Collect
CheetahScribe collects the information needed to provide clinical documentation services: your name and email (account), practice details, audio recordings and transcriptions you submit, and clinical images you upload. We also collect usage data (e.g., feature interactions) to improve the product.
How We Use Your Information
We use your information to generate AI-assisted chart notes and referral reports, deliver them through our secure portal, write back to your practice management system when authorized, and operate and maintain the service. We do not sell your information.
Protected Health Information
CheetahScribe is designed to operate in a HIPAA-compliant manner. Patient names are de-identified in the browser before storage where applicable, audio recordings are retained only for the configured retention period then securely destroyed, and access to PHI is governed by role-based permissions and audit logging. A Business Associate Agreement (BAA) is available for covered entities.
Data Retention
Recordings, transcripts, and generated notes are retained according to your tenant-configured retention policy (default seven days) and then purged. Audit logs are retained for security and compliance investigations.
Data Security
We use industry-standard encryption in transit and at rest, enforce row-level security so one practice cannot see another's data, and log access to PHI-bearing resources for audit and breach investigation.
Your Rights
You may request access to, correction of, or deletion of your personal data by contacting your practice administrator. Patients should direct requests through their treating provider.
Contact
Questions about this policy can be directed to your CheetahScribe practice administrator or to CheetahScribe support.