GastroNote.ai Privacy Policy

How we collect, use, protect, and manage your data

Effective Date: March 18, 2026  |  Last Updated: March 18, 2026

GastroNote.ai ("GastroNote," "we," "us," or "our") is a clinical documentation platform operated by RadhAM LLC, a South Carolina limited liability company, with its principal place of business in Greenville, South Carolina. GastroNote provides AI-powered SOAP note generation and clinical documentation tools for gastroenterology healthcare providers.

This Privacy Policy describes how we collect, use, disclose, and protect information — including Protected Health Information ("PHI") as defined under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") — when you use our website at gastronote.ai, our iOS mobile application, and any related services (collectively, the "Services").

By accessing or using GastroNote, you acknowledge that you have read, understood, and agree to this Privacy Policy. If you are a covered entity under HIPAA, your use of GastroNote is also subject to the terms of a Business Associate Agreement ("BAA") executed between you and RadhAM LLC.

1. HIPAA Compliance

GastroNote is designed and operated as a HIPAA-compliant platform. We function as a Business Associate to healthcare providers (Covered Entities) who use our Services. In that capacity, we:

2. Information We Collect

2.1 Account Information

When you create an account, we collect your email address and an encrypted password. Authentication is managed through Google Firebase Authentication. We do not store passwords in plaintext.

2.2 Protected Health Information (PHI)

In the course of providing the Services, we process the following categories of PHI on behalf of healthcare providers:

Data CategoryDescription
Patient NamesNames entered by the provider for documentation purposes
Audio RecordingsVoice recordings of patient encounters captured during clinical visits
TranscriptsText transcriptions generated from audio recordings
Clinical NotesAI-generated and provider-edited SOAP notes, including Subjective, Objective, Assessment, and Plan sections
Clinical DocumentsUploaded PDFs, images, lab results, and pathology reports
Pre-visit SummariesAI-generated summaries derived from previous visit notes and workup data

2.3 Device and Technical Information

We collect limited technical information necessary for the operation and security of the Services, including device identifiers (for cross-device synchronization), IP addresses (for security and access logging), and browser or app version information. This information is used solely for operational purposes and is not combined with PHI.

2.4 Information We Do NOT Collect

We do not collect Social Security numbers, insurance or billing information, financial account information, biometric data (Face ID authentication is processed entirely on your device and never transmitted to our servers), or information from minors under the age of 18.

3. How We Use Information

We use the information we collect exclusively for the following purposes:

We never use PHI for advertising, marketing, training AI models, or any purpose other than providing the clinical documentation services described herein.

4. How We Protect Information

4.1 Infrastructure Security

4.2 Application Security

4.3 Mobile Application Security

5. Third-Party Service Providers (Subcontractors)

We engage the following third-party service providers who may process PHI on our behalf. Each operates under a Business Associate Agreement or equivalent data protection agreement:

ProviderServiceData ProcessedBAA in Place
Google Cloud PlatformInfrastructure, compute, storage, AI (Vertex AI / Gemini)All PHI (encrypted)Yes
AssemblyAIAudio transcriptionAudio recordingsYes
Google FirebaseAuthentication, real-time databaseEmail, device sync signals (no clinical PHI)Yes (covered under GCP BAA)

We do not share, sell, rent, or disclose PHI to any party other than the subcontractors listed above, except as required by law or with the explicit authorization of the Covered Entity.

6. Data Retention and Deletion

Healthcare providers may delete specific patient records directly through the application at any time. All associated data is permanently removed within 14 days of deletion. Providers may also contact us to request bulk data deletion.

7. Your Rights

7.1 HIPAA Rights

If you are a patient whose data is processed through GastroNote, your HIPAA rights — including the right to access, amend, and receive an accounting of disclosures of your PHI — are administered by your healthcare provider (the Covered Entity). Please contact your healthcare provider directly to exercise these rights.

7.2 Provider Rights

Healthcare providers using GastroNote may:

7.3 California Residents

If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to request deletion, and the right to opt out of the sale of personal information. We do not sell personal information. To exercise your rights, contact us using the information provided below.

8. Cookies and Tracking

GastroNote uses only essential cookies required for authentication and session management. We do not use advertising cookies, tracking pixels, third-party analytics services, or any form of cross-site tracking. We do not serve advertisements within the Services.

9. Children's Privacy

GastroNote is designed for use by licensed healthcare professionals. We do not knowingly collect personal information from individuals under the age of 18. The Services are not directed to children, and we do not permit minors to create accounts.

10. Breach Notification

In the event of a breach of unsecured PHI, we will notify affected Covered Entities without unreasonable delay and no later than 60 days after discovery of the breach, in accordance with 45 CFR § 164.410. Our notification will include the information required by 45 CFR § 164.404(c), including identification of each individual whose PHI has been or is reasonably believed to have been compromised.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the "Last Updated" date at the top of this page and, where required, provide notice through the Services or via email. Your continued use of the Services after any changes constitutes acceptance of the updated Privacy Policy.

12. Contact Information

If you have questions about this Privacy Policy, wish to exercise your rights, or need to report a privacy concern, please contact us:

RadhAM LLC (GastroNote.ai)
Greenville, South Carolina
Email: support@gastronote.ai
Website: https://gastronote.ai

For HIPAA-related inquiries or to report a potential breach, please include "HIPAA" in the subject line of your communication to ensure priority handling.