Privacy policy.
How we collect, use, and protect your information.
MedNote (“MedNote”, “we”, “us”) provides a clinical documentation drafting service at mednote.me and app.mednote.me (the “Service”). This policy explains what information we collect, why we collect it, and the choices you have. It applies to everyone who uses the Service. Because the Service is used by healthcare professionals, we treat everything you submit as confidential — but the Service is designed to work without patient identifiers, and our terms require you to keep them out. This policy describes how we handle your information; it is not an invitation to submit patient information.
1. Information we collect
Account information. When you create an account we collect your email address, which is your account identity. You may optionally add a display name. If you sign in with Google, we receive your email address from Google; we do not receive your contacts or any other Google data.
Content you submit. The clinical input you type or dictate, the drafts generated from it, your chat threads and their titles, and your settings: selected note template, response and dictation languages, and your retention window. Voice dictation is transcribed in your browser by your device’s speech service; audio is not sent to or stored on our servers.
Billing information. Payments are processed by Stripe. Your card details go directly to Stripe and never touch our servers. We store your plan, a Stripe customer reference, and subscription status so the Service knows what you have paid for.
Usage information. We record product events on our own servers: sign-ins, note generations, feature and plan-limit encounters, and billing events, associated with your account. We use this to operate the Service, enforce plan allowances, and understand what to improve. We do not use third party analytics services, advertising trackers, or session recording tools.
Technical information. Standard server logs, including IP addresses, which we use for security, debugging, and rate limiting.
2. How your content is processed by AI
When you generate a note, your input and your selected template are sent over an encrypted connection to our AI model provider (Anthropic), which returns the draft. This happens only when you request a generation, and only with the content needed for it. Under our provider’s commercial terms, content submitted through its API is not used to train its models. We do not train models on your content either, we do not sell it, and we do not use it for advertising. Generated drafts are stored in your account solely so you can access your history, subject to the retention controls below.
3. Clinical content and protected health information
The Service is not currently offered under a business associate agreement, and our terms prohibit submitting protected health information. The workflow is built so you do not need to: drafts carry bracketed placeholders for identifying details, which you fill in inside your own record system after the note leaves the Service. Nevertheless, we handle all submitted content as confidential: it is encrypted in transit, stored scoped to your account, never shared except with the processors listed in this policy, and deleted on the schedule you control. If you believe you have submitted identifying information by mistake, delete the thread (deletion is immediate) or contact us and we will remove it.
4. How we use information
- To provide the Service: authenticate you, generate your drafts, and store your note history.
- To bill you for a paid plan and manage your subscription and trial.
- To secure the Service: prevent abuse, enforce rate limits and plan allowances, and investigate incidents.
- To improve the product, using our own usage measurements.
- To communicate with you about your account: sign-in links, billing receipts, and material changes to the Service. We do not send marketing email without your consent.
Where the law requires a legal basis, we process your information to perform our contract with you (providing the Service you signed up for), for our legitimate interests in securing and improving the Service, and to meet legal obligations such as tax record keeping. We do not sell your information and do not share it with advertisers.
5. Cookies
We use one essential cookie: a session cookie that keeps you signed in across mednote.me and its subdomains. During Google sign-in, two short-lived cookies protect the sign-in flow and are deleted when it completes. None of these are used for tracking or advertising, and we set no third party cookies. If you clear them you are simply signed out.
6. Service providers
We share information with a small number of providers only as needed to run the Service:
- Anthropic for AI draft generation, as described in section 2.
- Stripe for payment processing and subscription management.
- Mailgun for delivering sign-in links and account email.
- Cloudflare for DNS, content delivery, and protection against network attacks.
- Google only if you choose to sign in with Google.
Each provider receives only what it needs for its function and is bound by its own privacy commitments. We may also disclose information if required by law, or to protect the rights, safety, or property of MedNote or its users.
7. Data retention — you control it
Your account has a retention window, set in Account settings: notes and threads older than your window (1 to 30 days) are permanently deleted by a nightly purge, or you can turn retention off to keep history until you delete it. Deleting a thread deletes its messages immediately. Copy finished notes into your own record system promptly — the Service is a drafting tool, not a system of record. Account information is kept while your account exists; product usage events are kept for the operation of the Service and deleted with your account, except where aggregated and no longer tied to you. Billing records are retained as required for tax and accounting purposes.
8. Your rights
You can access and update your account details, preferences, and retention window in Account settings, and copy any of your notes at any time. You may also request a copy of the personal information we hold about you, ask us to correct it, or ask us to delete your account and its content. Depending on where you live, including the EEA, the UK, and California, these may be legal rights. To exercise any of them, contact us through the contact form from your account email and we will respond within 30 days. Deleting your account removes your notes, threads, and personal information.
9. Security
All traffic to the Service is encrypted in transit. Sessions use secure, httpOnly cookies. Your notes and threads are stored scoped to your account, and AI generation runs in an isolated server environment with access only to the content of the request. Access to production systems is restricted. No service can promise perfect security; if we learn of a breach affecting your personal information, we will notify you as required by law.
10. Children
The Service is for healthcare professionals and is not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
11. International transfers
The Service is operated from servers in the United States. If you use it from elsewhere, your information is processed in the United States under this policy.
12. Changes to this policy
If we change this policy we will post the new version here and update the effective date above. For material changes we will also notify account holders by email. Continued use of the Service after a change means you accept the updated policy.
13. Contact
Questions about this policy or your information reach us through the contact form.