1. Scope and roles
Docuchart provides business software to clinics. This policy applies to our websites, mobile applications, and related services (collectively, the “Services”).
A customer organization generally decides what information about its patients and personnel is entered into the Services and why it is used. For that customer-controlled information, Docuchartprocesses the information to provide the Services on the customer's behalf. We separately handle account, billing, security, support, and website information needed to operate our business and the Services.
Patient and clinical records
2. Information we handle
- Account and organization information: names, business contact details, role and permission information, authentication identifiers, organization settings, subscriptions, and support communications.
- Customer records: contact information, appointments, services, forms, documents, communications, notes, transactions, and other information an authorized user enters or uploads.
- Patient and clinical information: demographics, medical history, allergies, medications, treatment details, clinical notes, consents, signatures, photographs, and uploaded identity or insurance documents.
- Face-chart information: treatment photos, facial landmarks and annotations, three-dimensional meshes, pose or depth information, blendshape measurements, injection zones, products, and dose entries.
- Payment information: transaction amount, status, invoice and refund details, and limited payment-method information returned by a payment processor. Full card or bank credentials are handled by the selected payment provider rather than stored directly by Docuchart.
- Device and usage information: IP address, browser or device details, push-notification tokens, timestamps, application events, audit history, error information, cookies, and similar technologies.
- AI inputs and outputs: prompts, selected records, notes, messages, photos, and resulting drafts or suggestions when an authorized user activates an AI-powered feature.
3. Face data and artificial intelligence
Face data
Face-chart features can process patient photographs and technical facial geometry to create treatment documentation, position chart annotations, build a three-dimensional visualization, and support clinician-reviewed chart suggestions. Depending on the feature selected, this may include facial landmarks, mesh vertices, blendshapes, pose, depth, and treatment-zone information.
Docuchart does not use face data to identify a person, authenticate an account, track someone across services, advertise to them, or build an advertising profile. We do not sell face data. Face data is used only to provide and support the clinic-directed charting and documentation features described here.
Face photos and related geometry may be stored with the patient's clinic record in Cloudflare storage. If a clinic selects cloud reconstruction, landmark detection, or AI chart suggestions, the information needed for that request may also be processed by Replicate, Anthropic, or Vercel's AI Gateway. It is retained as described in Section 5 and can be included in a verified deletion request.
AI-assisted features
AI features may create drafts, summaries, classifications, messages, chart annotations, or other suggestions. When an authorized user activates one of these features, the relevant input may be sent to an AI service provider. AI output can be incomplete or incorrect and must be reviewed by an authorized professional before it is relied upon, signed, or sent.
Professional review is required
4. How we use and disclose information
We use information to:
- authenticate users and provide charting, scheduling, forms, documents, communications, billing, reporting, and other enabled features;
- create user-requested AI drafts and suggestions, maintain audit history, and support customer-directed integrations;
- secure, monitor, maintain, troubleshoot, and improve the Services;
- provide support, administer subscriptions, enforce our agreements, and comply with law.
We disclose information only as needed to provide those functions, at a customer's direction, in connection with a business transaction, or when required to protect rights, safety, security, or comply with law. We do not sell patient medical information or face data, and we do not use either for targeted advertising.
Service providers and integrations
Depending on the features a customer enables, providers may include:
- Clerk for authentication; PlanetScale for database infrastructure; and Cloudflare for hosting, storage, and network security.
- Anthropic and Vercel for AI features, and Replicate for selected face-landmark and three-dimensional reconstruction features.
- Stripe and Square for customer-selected payment processing and connected-account services.
- Expo for mobile app and push-notification infrastructure, and PostHog for product analytics when configured.
- WhatsApp and Whapi for customer-enabled messaging.
Customers may connect additional services. Their use of those services is also governed by the provider's terms and privacy notice.
5. Retention and security
We retain information for as long as reasonably necessary to provide the Services, maintain the customer's records, meet contractual or legal obligations, resolve disputes, prevent abuse, and enforce agreements. Retention can depend on the type of record, customer instructions, enabled integrations, and applicable professional or legal requirements.
When information is deleted from active systems, limited copies may remain in protected backups until they are overwritten through standard backup cycles or retained where law requires. De-identified information that cannot reasonably identify a person may be kept.
We use administrative, technical, and organizational safeguards designed for the sensitivity of the information we handle, including access controls, encrypted network connections, logging, and service-provider controls. No storage or transmission method is completely secure, so we cannot guarantee absolute security.
6. Your privacy choices
Depending on your location and relationship with Docuchart, you may be able to request access, correction, export, or deletion of personal information, or object to or restrict certain processing. We may verify your identity and authority before completing a request.
Visit Privacy Choices for request options, or email support@docuchart.com. Patients should normally contact the clinic that created or maintains the record first.
7. Children
The Services are business tools intended for organizations and their authorized personnel, not for independent use by children. A customer may enter information about a minor when legally permitted and necessary for its services. In that case, the customer is responsible for obtaining required authorization, and we process the information under the customer's instructions and this policy.
8. Changes and contact
We may update this policy as the Services or legal requirements change. We will post the updated version here and revise the effective date. Material changes may also be communicated through the Services or by email when appropriate.
Questions or privacy requests can be sent to support@docuchart.com. Please do not include unnecessary patient or other sensitive information in an ordinary email.
