Privacy Policy

Effective April 19, 2026 · Last updated June 11, 2026

1. Who we are

ezScribe ("ezScribe", "we", "us", or "our") provides an AI-powered medical transcription and clinical-documentation service for licensed healthcare providers. This Privacy Policy explains what information we collect when you use ezScribe, how we use it, how we protect it, and the rights you have.

ezScribe is operated from the United States. If you access our Services from outside the U.S., you understand your data will be processed in the U.S.

2. Scope of this policy

This policy applies to the ezScribe website (ezscribe.net), the authenticated application (app.ezscribe.net), and our Android mobile application ("Services").

If you are a patient whose visit was recorded by a healthcare provider using ezScribe, your provider is the Covered Entity under HIPAA. ezScribe is a Business Associate acting on their behalf. Your rights over your health information are governed by your provider's Notice of Privacy Practices and your provider-patient agreement. Contact your provider first for requests concerning your PHI; we will support any lawful request they forward to us.

3. Information we collect

3.1 Account information

  • Name, email address, professional credentials (e.g., NP, MD)
  • Practice / organization name (optional)
  • Password (stored only as a one-way salted hash)
  • Billing contact information (processed by our payment processor)

3.2 Clinical content you provide

  • Audio recordings of patient visits that you choose to record
  • Transcripts derived from those recordings
  • AI-generated clinical summaries, ICD-10 code suggestions, and translations
  • Any edits, notes, or labels you add

Collectively this is "Clinical Content". It may contain Protected Health Information ("PHI") as defined under HIPAA. We treat all Clinical Content as PHI by default.

3.3 Technical information

  • Device type, operating system, browser, and app version
  • IP address, approximate location derived from IP
  • Log timestamps, page/route views, error traces
  • Aggregated product-usage analytics (no PHI is sent to analytics tools)

3.4 Information we do NOT collect

  • We do not access your device microphone except while you actively record
  • We do not access your contacts, photos, or files outside the app
  • We do not use advertising identifiers or cross-site tracking
  • We do not sell, rent, or lease your personal information or Clinical Content to anyone, ever

4. How we use your information

We use the information described above only to:

  • Provide, maintain, and improve the Services
  • Transcribe audio and generate clinical summaries on your behalf
  • Authenticate your account and prevent fraud or abuse
  • Process payments and manage subscriptions
  • Respond to your support requests
  • Send you transactional communications (e.g., password reset)
  • Comply with legal obligations and enforce our Terms

We do not use your Clinical Content to train third-party foundation models, advertise to you, profile patients, or share with data brokers.

5. Legal basis and HIPAA

ezScribe operates as a HIPAA Business Associate to the healthcare providers who use the Services. We maintain administrative, physical, and technical safeguards required by 45 C.F.R. §§ 164.308, 164.310, and 164.312. Contact support@ezscribe.net with any questions about our HIPAA safeguards.

We use your Clinical Content solely to provide the Services to you. We will not use or disclose PHI in any manner not permitted by HIPAA.

6. Third-party processors

We use a limited number of vetted subprocessors to deliver the Services. Each is contractually bound to confidentiality, security, and, where applicable, HIPAA.

SubprocessorPurposeReceives PHI?
OpenAI (Whisper, GPT)Transcription & summarizationYes, under BAA / API zero-retention
Cloud hosting providerApplication & database hostingYes, under BAA
StripePayment processingNo (billing info only)
PostHogProduct analytics (no PHI)No
Google AnalyticsAggregate site performance (no PHI)No

A current list is maintained at ezscribe.net/subprocessors and updated on material change.

7. Data retention & deletion

By default, we retain Clinical Content for 30 days from the date of recording, after which it is automatically and irreversibly deleted from primary storage. Encrypted backups are rotated on a 30-day cycle and purged accordingly.

Account information is retained for the life of your subscription and up to 90 days after account closure for billing reconciliation and legal compliance. You may request earlier deletion of your account at any time at support@ezscribe.net.

8. Security

  • TLS 1.2+ encryption in transit for all requests
  • AES-256 encryption at rest for databases and object storage
  • Role-based access control; production PHI access limited to trained personnel on a need-to-know basis with full audit logging
  • Separation of duties, least-privilege IAM, MFA on all administrative accounts
  • Periodic third-party security assessments and penetration tests
  • Incident-response program with breach-notification commitments per HIPAA and applicable state laws

No system is perfectly secure. If we become aware of a breach affecting your PHI, we will notify you and the applicable Covered Entity without unreasonable delay and in accordance with 45 C.F.R. § 164.410.

9. Your rights

Depending on your jurisdiction, you may have some or all of the following rights with respect to your personal information:

  • Access — request a copy of the information we hold about you
  • Correction — ask us to fix inaccurate information
  • Deletion — ask us to delete your information
  • Portability — receive your information in a structured, machine-readable format
  • Opt-out — opt out of non-essential communications at any time
  • Non-discrimination — we will not retaliate against you for exercising these rights

For PHI, exercise these rights through the provider who recorded the visit. For account and billing data, email support@ezscribe.net. We will respond within 30 days (or as required by your local law).

10. Children

ezScribe is designed for licensed healthcare professionals and is not directed to children under 13. We do not knowingly collect personal information from children. A provider may record a visit involving a pediatric patient; that recording is treated as PHI of the patient and governed by this Privacy Policy.

11. Cookies & similar technologies

We use a minimal set of first-party cookies to keep you signed in and remember preferences, and privacy-preserving analytics (PostHog) to understand aggregate product usage. We do not use advertising cookies or cross-site trackers. You can disable cookies in your browser, but some parts of the Services may not function.

12. California, Colorado, Virginia & other U.S. privacy laws

If you are a resident of California, Colorado, Virginia, Connecticut, Utah, Texas, or another state with a comprehensive consumer privacy law, the rights in Section 9 apply to you regardless of your account type. We do not "sell" personal information or engage in "targeted advertising" as those terms are defined under these laws. HIPAA-governed information is exempt from many of these laws, but we honor all applicable rights you retain over non-PHI personal information.

13. Canadian users — PIPEDA & provincial health-privacy laws

For healthcare providers practising in Canada, ezScribe is designed to support compliance with the Personal Information Protection and Electronic Documents Act ("PIPEDA") and provincial health-privacy legislation, including Ontario's Personal Health Information Protection Act (PHIPA), Alberta's Health Information Act (HIA), British Columbia's Personal Information Protection Act (PIPA), and Quebec's private-sector privacy law as amended by Law 25.

  • Your role. As the health information custodian / trustee, you remain responsible for obtaining any patient consent required to record and process visit audio.
  • Cross-border processing. Audio and transcripts are processed by AI service providers located in the United States. We disclose this so you can inform patients as required by PIPEDA, PHIPA, and Quebec Law 25; an in-app patient-consent script is provided for accounts set to the Canada region.
  • Code-free notes. Accounts set to the Canada region generate clinical notes without ICD-10 billing codes, using descriptive diagnostic terminology only.
  • Safeguards. The same encryption (at rest and in transit), access controls, audit logging, 30-day automatic deletion, and breach-notification readiness described in this policy apply to Canadian users.
  • Your patients' rights. Canadian patients may request access to or correction of their personal health information through you as their provider, and may direct complaints to the Office of the Privacy Commissioner of Canada or the relevant provincial commissioner.

14. International users / GDPR

ezScribe is intended for use within the United States. If you access the Services from the European Economic Area, United Kingdom, or other regions with data-protection laws, the legal basis for our processing is performance of a contract (providing the Services), your consent (for optional features), and our legitimate interest in securing and improving the Services. You may contact us at privacy@ezscribe.net to exercise GDPR rights.

15. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be announced by email and/or in-app notice at least 30 days before taking effect. The "Last updated" date at the top of this page reflects the most recent revision.

16. Contact us

Questions, requests, or complaints? Reach our Privacy team at:

ezScribe Privacy Team
Email: privacy@ezscribe.net
Support: support@ezscribe.net