How we collect, use, protect, and manage your data
GastroNote.ai ("GastroNote," "we," "us," or "our") is a clinical documentation platform operated by GastroNote LLC, a South Carolina limited liability company, with its principal place of business in Greenville, South Carolina. GastroNote provides AI-powered SOAP note generation and clinical documentation tools for gastroenterology healthcare providers.
This Privacy Policy describes how we collect, use, disclose, and protect information — including Protected Health Information ("PHI") as defined under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") — when you use our website at gastronote.ai, our iOS mobile application, and any related services (collectively, the "Services").
By accessing or using GastroNote, you acknowledge that you have read, understood, and agree to this Privacy Policy. If you are a covered entity under HIPAA, your use of GastroNote is also subject to the terms of a Business Associate Agreement ("BAA") executed between you and GastroNote LLC.
GastroNote is designed and operated as a HIPAA-compliant platform. We function as a Business Associate to healthcare providers (Covered Entities) who use our Services. In that capacity, we:
When you create an account, we collect your email address and an encrypted password. Authentication is managed through Google Firebase Authentication. We do not store passwords in plaintext.
In the course of providing the Services, we process the following categories of PHI on behalf of healthcare providers:
| Data Category | Description |
|---|---|
| Patient Names | Names entered by the provider for documentation purposes |
| Audio Recordings | Voice recordings of patient encounters captured during clinical visits |
| Transcripts | Text transcriptions generated from audio recordings |
| Clinical Notes | AI-generated and provider-edited SOAP notes, including Subjective, Objective, Assessment, and Plan sections |
| Clinical Documents | Uploaded PDFs, images, lab results, and pathology reports |
| Pre-visit Summaries | AI-generated summaries derived from previous visit notes and workup data |
We collect limited technical information necessary for the operation and security of the Services, including device identifiers (for cross-device synchronization), IP addresses (for security and access logging), and browser or app version information. This information is used solely for operational purposes and is not combined with PHI.
We do not collect Social Security numbers, insurance or billing information, financial account information, biometric data (Face ID authentication is processed entirely on your device and never transmitted to our servers), or information from minors under the age of 18.
We use the information we collect exclusively for the following purposes:
We never use PHI for advertising, marketing, training AI models, or any purpose other than providing the clinical documentation services described herein.
We engage the following third-party service providers who may process PHI on our behalf. Each operates under a Business Associate Agreement or equivalent data protection agreement:
| Provider | Service | Data Processed | BAA in Place |
|---|---|---|---|
| Google Cloud Platform | Infrastructure, compute, storage, AI (Vertex AI / Gemini) | All PHI (encrypted) | Yes |
| AssemblyAI | Audio transcription | Audio recordings | Yes |
| Google Firebase | Authentication, real-time database | Email, device sync signals (no clinical PHI) | Yes (covered under GCP BAA) |
We do not share, sell, rent, or disclose PHI to any party other than the subcontractors listed above, except as required by law or with the explicit authorization of the Covered Entity.
Healthcare providers may delete specific patient records directly through the application at any time. All associated data is permanently removed within 14 days of deletion. Providers may also contact us to request bulk data deletion.
If you are a patient whose data is processed through GastroNote, your HIPAA rights — including the right to access, amend, and receive an accounting of disclosures of your PHI — are administered by your healthcare provider (the Covered Entity). Please contact your healthcare provider directly to exercise these rights.
Healthcare providers using GastroNote may:
If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to request deletion, and the right to opt out of the sale of personal information. We do not sell personal information. To exercise your rights, contact us using the information provided below.
GastroNote uses only essential cookies required for authentication and session management. We do not use advertising cookies, tracking pixels, third-party analytics services, or any form of cross-site tracking. We do not serve advertisements within the Services.
GastroNote is designed for use by licensed healthcare professionals. We do not knowingly collect personal information from individuals under the age of 18. The Services are not directed to children, and we do not permit minors to create accounts.
In the event of a breach of unsecured PHI, we will notify affected Covered Entities without unreasonable delay and no later than 60 days after discovery of the breach, in accordance with 45 CFR § 164.410. Our notification will include the information required by 45 CFR § 164.404(c), including identification of each individual whose PHI has been or is reasonably believed to have been compromised.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the "Last Updated" date at the top of this page and, where required, provide notice through the Services or via email. Your continued use of the Services after any changes constitutes acceptance of the updated Privacy Policy.
This section describes how we handle mobile telephone numbers and text (SMS) messaging. It applies to the account-notification text messaging program you may opt into during account registration.
No sharing of mobile information. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. GastroNote does not sell, rent, or share mobile telephone numbers, or the fact that you consented to receive text messages, with any third party or affiliate for that party's own marketing or promotional purposes. All other categories of personal information are handled as described elsewhere in this Privacy Policy.
When you register for an account and opt into text messaging, we collect your mobile telephone number and your consent status. We retain your consent status for as long as your account is active.
We use your mobile telephone number only to send the messages you consented to receive: one-time account verification codes, account activity and security alerts, and important service updates. We do not use your mobile number for marketing or promotional messaging.
Consent to receive text messages is obtained through an affirmative, unchecked opt-in checkbox presented during account registration. The checkbox is never pre-selected. Consent to receive text messages is not a condition of purchase and is not required to use the Services.
You will receive up to 4 messages per month. Message frequency varies based on your account activity, including the number of sign-in and verification attempts you initiate.
Message and data rates may apply depending on your mobile phone service plan. GastroNote does not charge for text messages, but your mobile carrier may. Contact your carrier for details about your plan.
You may cancel text messages at any time by replying STOP to any message you receive from us. After you reply STOP, we will send a single confirmation message and will send no further text messages to that number unless you opt in again. Opting out may prevent you from completing phone-based verification and may limit your ability to sign in to the Services.
For help, reply HELP to any message you receive from us, or email support@gastronote.ai.
Mobile numbers are disclosed only to our contracted messaging service provider, and only to the extent necessary to transmit the messages described above. That provider is contractually prohibited from using the information for any other purpose. Mobile carriers are not liable for delayed or undelivered messages; delivery is subject to effective transmission by your carrier and is not guaranteed.
Additional text messaging terms are set out in Section 13 of our Terms & Conditions.
If you have questions about this Privacy Policy, wish to exercise your rights, or need to report a privacy concern, please contact us:
GastroNote LLC (GastroNote.ai)
Greenville, South Carolina
Email: support@gastronote.ai
Website: https://gastronote.ai
For HIPAA-related inquiries or to report a potential breach, please include "HIPAA" in the subject line of your communication to ensure priority handling.