Effective April 19, 2026 · Last updated June 11, 2026
ezScribe ("ezScribe", "we", "us", or "our") provides an AI-powered medical transcription and clinical-documentation service for licensed healthcare providers. This Privacy Policy explains what information we collect when you use ezScribe, how we use it, how we protect it, and the rights you have.
ezScribe is operated from the United States. If you access our Services from outside the U.S., you understand your data will be processed in the U.S.
This policy applies to the ezScribe website (ezscribe.net), the authenticated application (app.ezscribe.net), and our Android mobile application ("Services").
If you are a patient whose visit was recorded by a healthcare provider using ezScribe, your provider is the Covered Entity under HIPAA. ezScribe is a Business Associate acting on their behalf. Your rights over your health information are governed by your provider's Notice of Privacy Practices and your provider-patient agreement. Contact your provider first for requests concerning your PHI; we will support any lawful request they forward to us.
Collectively this is "Clinical Content". It may contain Protected Health Information ("PHI") as defined under HIPAA. We treat all Clinical Content as PHI by default.
We use the information described above only to:
We do not use your Clinical Content to train third-party foundation models, advertise to you, profile patients, or share with data brokers.
ezScribe operates as a HIPAA Business Associate to the healthcare providers who use the Services. We maintain administrative, physical, and technical safeguards required by 45 C.F.R. §§ 164.308, 164.310, and 164.312. Contact support@ezscribe.net with any questions about our HIPAA safeguards.
We use your Clinical Content solely to provide the Services to you. We will not use or disclose PHI in any manner not permitted by HIPAA.
We use a limited number of vetted subprocessors to deliver the Services. Each is contractually bound to confidentiality, security, and, where applicable, HIPAA.
| Subprocessor | Purpose | Receives PHI? |
|---|---|---|
| OpenAI (Whisper, GPT) | Transcription & summarization | Yes, under BAA / API zero-retention |
| Cloud hosting provider | Application & database hosting | Yes, under BAA |
| Stripe | Payment processing | No (billing info only) |
| PostHog | Product analytics (no PHI) | No |
| Google Analytics | Aggregate site performance (no PHI) | No |
A current list is maintained at ezscribe.net/subprocessors and updated on material change.
By default, we retain Clinical Content for 30 days from the date of recording, after which it is automatically and irreversibly deleted from primary storage. Encrypted backups are rotated on a 30-day cycle and purged accordingly.
Account information is retained for the life of your subscription and up to 90 days after account closure for billing reconciliation and legal compliance. You may request earlier deletion of your account at any time at support@ezscribe.net.
No system is perfectly secure. If we become aware of a breach affecting your PHI, we will notify you and the applicable Covered Entity without unreasonable delay and in accordance with 45 C.F.R. § 164.410.
Depending on your jurisdiction, you may have some or all of the following rights with respect to your personal information:
For PHI, exercise these rights through the provider who recorded the visit. For account and billing data, email support@ezscribe.net. We will respond within 30 days (or as required by your local law).
ezScribe is designed for licensed healthcare professionals and is not directed to children under 13. We do not knowingly collect personal information from children. A provider may record a visit involving a pediatric patient; that recording is treated as PHI of the patient and governed by this Privacy Policy.
We use a minimal set of first-party cookies to keep you signed in and remember preferences, and privacy-preserving analytics (PostHog) to understand aggregate product usage. We do not use advertising cookies or cross-site trackers. You can disable cookies in your browser, but some parts of the Services may not function.
If you are a resident of California, Colorado, Virginia, Connecticut, Utah, Texas, or another state with a comprehensive consumer privacy law, the rights in Section 9 apply to you regardless of your account type. We do not "sell" personal information or engage in "targeted advertising" as those terms are defined under these laws. HIPAA-governed information is exempt from many of these laws, but we honor all applicable rights you retain over non-PHI personal information.
For healthcare providers practising in Canada, ezScribe is designed to support compliance with the Personal Information Protection and Electronic Documents Act ("PIPEDA") and provincial health-privacy legislation, including Ontario's Personal Health Information Protection Act (PHIPA), Alberta's Health Information Act (HIA), British Columbia's Personal Information Protection Act (PIPA), and Quebec's private-sector privacy law as amended by Law 25.
ezScribe is intended for use within the United States. If you access the Services from the European Economic Area, United Kingdom, or other regions with data-protection laws, the legal basis for our processing is performance of a contract (providing the Services), your consent (for optional features), and our legitimate interest in securing and improving the Services. You may contact us at privacy@ezscribe.net to exercise GDPR rights.
We may update this Privacy Policy from time to time. Material changes will be announced by email and/or in-app notice at least 30 days before taking effect. The "Last updated" date at the top of this page reflects the most recent revision.
Questions, requests, or complaints? Reach our Privacy team at:
ezScribe Privacy Team
Email: privacy@ezscribe.net
Support: support@ezscribe.net