Effective Date: March 17, 2026
Last Updated: April 23, 2026
ClearChartAI, Inc. ("ClearChartAI," "we," "us," or "our") is committed to protecting your privacy and safeguarding your personal and health information.
This Privacy Policy explains how we collect, use, store, disclose, and protect information when you access or use the ClearChartAI platform and AI health assistant ("Clari") (collectively, the "Service").
This Privacy Policy applies to information processed by ClearChartAI through the Service. Certain functions of the Service rely on third-party service providers such as identity verification vendors, cloud infrastructure providers, and health information networks. These providers process information only to perform services on behalf of ClearChartAI and are contractually required to protect that information. Their own privacy policies may also apply.
When retrieving medical records from healthcare providers or health information networks, ClearChartAI relies on information supplied by those providers. ClearChartAI does not control and cannot guarantee the accuracy, completeness, or timeliness of records provided by third parties.
ClearChartAI processes health information only with the authorization of the individual whose records are being retrieved.
If you use our Individual Access Services to retrieve medical records through the Trusted Exchange Framework and Common Agreement (TEFCA), additional terms apply. Please review our IAS Privacy & Security Notice.
At your direction and with your authorization, we may collect and process medical records from healthcare providers, including:
This information may constitute Protected Health Information (PHI).
To verify your identity and retrieve medical records, ClearChartAI uses a Credential Service Provider (CSP) to perform identity verification. During this process, the CSP may temporarily process information such as:
This information is used solely to confirm your identity and prevent unauthorized access to medical records. The CSP performs the verification process and returns only a verification result or status to ClearChartAI.
ClearChartAI does not receive or store copies of government-issued identification documents, biometric data, or Social Security numbers used during verification unless required for compliance or audit purposes.
Important: Identity verification data is not used for advertising, profiling, or training public artificial intelligence models.
We may collect and log:
This supports system safety, compliance, fraud prevention, and performance improvement.
We use information to:
We do not sell personal information. We do not use identifiable health data, SSN, biometric data, or identity documents to train public AI models. We may use de-identified or aggregated information to improve system performance in accordance with applicable law.
The Service uses Google Gemini, a family of large language models provided by Google Cloud, to analyze authorized health data and generate informational insights. Your health data is sent to Google Gemini for processing under our Business Associate Agreement with Google Cloud.
The Service does not provide medical advice, diagnosis, or treatment recommendations. AI-generated information is intended to help individuals better understand their health records and should not replace consultation with licensed healthcare professionals.
AI-generated outputs:
Google does not use your health data submitted through ClearChartAI to train or improve its general AI models. Processing is governed by Google Cloud's HIPAA-compliant terms and our BAA.
When using the voice health assistant, audio is processed in real time and is not recorded or stored. Voice sessions are subject to daily usage limits.
We do not sell personal information.
We may share information with:
We share information with the following service providers, each bound by contractual obligations to safeguard your data:
Google Cloud Platform (Google LLC)
Provides cloud infrastructure, data storage, AI processing (Google Gemini), authentication, text-to-speech, and speech-to-text services. All health data is stored and processed within Google Cloud under a signed Business Associate Agreement (BAA). Data is encrypted in transit (TLS 1.3) and at rest (AES-256).
Persona (PersonaIdentities, Inc.)
Provides identity verification services (Credential Service Provider). When you verify your identity, Persona receives your government-issued ID, selfie, and verification data to confirm your identity. Persona processes this data under its own privacy policy and our data processing agreement. ClearChartAI does not store copies of your ID documents on our servers.
CommonWell Health Alliance
A nationwide health data network that enables retrieval of your medical records from participating healthcare providers through the Trusted Exchange Framework and Common Agreement (TEFCA). When you authorize record retrieval, your verified identity information is used to locate and request your records through the CommonWell network. Data shared through TEFCA follows TEFCA rules and applicable healthcare regulations.
Sinch (Sinch AB / Sinch America, Inc.)
Provides fax and SMS transmission services. When you use the "Share with Provider" feature to fax records to a healthcare provider, Sinch transmits the records on our behalf to the fax number you specify. Sinch also delivers security-related SMS messages (such as verification codes). Only the information required for the requested transmission — including the records you selected and the destination fax number or phone number — is shared with Sinch, under a signed Business Associate Agreement (BAA). Sinch does not retain the transmitted records beyond what is necessary to complete delivery and meet its legal obligations.
When transmitting record requests at your direction through the CommonWell Health Alliance network or direct provider connections.
When required by law.
Your data is stored on Google Cloud Platform infrastructure located in the United States. We implement administrative, technical, and physical safeguards designed to protect sensitive information, including:
No system can guarantee absolute security.
We retain information:
Identity verification documents and biometric data are retained only as long as necessary for verification and compliance purposes.
You may request deletion of your account at any time.
Before deletion, you may export your health records and AI-generated summaries.
Upon verified deletion:
Upon confirmation, your account enters a 7-day grace period during which you may cancel the request. If you need immediate deletion, you may contact our support team at team@clearchartai.io.
Certain limited information may remain in encrypted backups, audit logs, or as required by law. If you provide a reason for closing your account, it may be used to improve our services.
Exported data is available for download for a limited time. Support request history is retained for service quality and compliance purposes.
Depending on your state of residence, you may have rights to:
HIPAA: ClearChartAI is not a covered entity under HIPAA. In certain contexts, ClearChartAI may operate as a Business Associate under agreements with healthcare organizations. As applicable, you have rights under HIPAA including the right to access your health information, request amendments, and receive an accounting of disclosures.
ClearChartAI does not sell or share personal information for cross-context behavioral advertising.
To exercise any of these rights, please contact us at team@clearchartai.io. We will respond to your request within the timeframe required by applicable law. We may need to verify your identity before processing your request.
The Service is not intended for individuals under 18 years of age. We do not knowingly collect information from children. Parents or legal guardians may use our Service to manage health records on behalf of minors under their care.
We use essential cookies for authentication and security purposes only. We do not use advertising cookies or third-party tracking. Your session information is managed securely through our authentication infrastructure.
We may update this Privacy Policy periodically. If material changes occur, we will notify users by email or through a notice on our Service. Your continued use after changes take effect constitutes acceptance of the updated policy.
If you have questions about this Privacy Policy, want to exercise your rights, or have concerns about how we handle your information, please contact us:
If you believe your privacy rights have been violated, you also have the right to file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights.
© 2026 ClearChartAI, Inc. All rights reserved.