CareMinutes
    Healthcare AI notes

    Legal

    Privacy Policy

    Last updated: September 4, 2026

    1. Overview

    This Privacy Policy explains what information CareMinutes ("we", "us") collects when you use the CareMinutes Service, how we use it, and the choices you have. It applies to visitors of our public pages (like Pricing and Contact) and to authenticated users of the internal workspace.

    2. Information we collect

    • Account information: your name, email address, and — if you register with a password — a salted, one-way hash of that password (we never store the password itself). Your account role (member or admin) and email-verification status are also stored.
    • Google Sign-In data: if you choose "Continue with Google", Google shares your name, email address, and profile picture with us. See section 4 for how this data is used.
    • Session data: a randomly generated session identifier stored in a secure, HTTP-only cookie so you stay signed in (see section 5).
    • Meeting content: transcripts, structured meeting notes, action items, and any content you or your team submit to the workspace, which may include protected health information (PHI) on plans with an executed Business Associate Agreement.
    • Contact & sales information: name, email address, organization, and message content submitted through the Pricing or Contact pages.
    • Technical data: IP address, request metadata, and rate-limit counters, used only for security, abuse prevention, and reliability.

    3. How we use information

    • To provide, maintain, and secure the Service, including authentication and rate limiting;
    • To generate AI-assisted meeting summaries when you use the summarizer feature;
    • To respond to sales, support, billing, and privacy inquiries submitted via the Contact page;
    • To detect, prevent, and investigate fraud, abuse, or security incidents.

    4. Google Sign-In and Google user data

    CareMinutes offers sign-in with Google as an optional alternative to an email and password. When you use it, we request only the basic profile scopes (openid, email, profile) and receive your name, verified email address, and profile picture. We use this information solely to create your CareMinutes account, sign you in, and display your name inside the app.

    • We do not access your Gmail, Calendar, Drive, Contacts, or any other Google service.
    • We do not sell Google user data, use it for advertising, or share it with third parties except as needed to operate the Service (for example, our hosting and database providers).
    • We do not use Google user data to train AI or machine-learning models.
    • You can revoke CareMinutes' access at any time from your Google Account permissions page, and you can delete your CareMinutes account through the Contact page.

    CareMinutes' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

    5. Cookies

    We use a small number of strictly necessary cookies and no advertising or cross-site tracking cookies:

    • cm_sess — keeps you signed in for up to 30 days. Secure, HTTP-only, first-party.
    • cm_oauth — a short-lived (10 minute) cookie that protects the Google sign-in flow against forgery. Deleted once sign-in completes.
    • A theme preference (light or dark) is stored in your browser's local storage and never sent to our servers.

    6. AI processing and sub-processors

    When you use the AI transcript summarizer, the transcript text is sent to our underlying AI model provider solely to generate the summary and is not used by us to train models. We select sub-processors that offer contractual data-protection commitments. If your organization has an executed BAA with us, PHI-covered transcripts are only routed to sub-processors covered by that agreement.

    7. Data retention

    Meeting notes and action items are retained for as long as your account is active. Account information is deleted within 30 days of an account-deletion request. After a downgrade or cancellation, your data remains exportable for 90 days, after which it is deleted, unless a shorter retention period is requested in writing or required by your organization's own PHI retention policy. Contact and lead-capture submissions are retained for as long as needed to respond to the inquiry and for reasonable record-keeping.

    8. Data security

    All traffic is encrypted in transit (HTTPS). Passwords are hashed with bcrypt, session tokens are stored hashed, and each user's meeting data is isolated by account. We apply security headers, rate limiting on authentication and data-submission endpoints, input validation, and least-privilege access controls (all internal pages require sign-in). No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

    9. Your rights

    Depending on your location, you may have the right to access, correct, export, or delete personal data we hold about you, or to object to certain processing. To exercise any of these rights, reach us through our Contact page and select "Privacy request" as the topic. We will respond within a reasonable time.

    10. Children's privacy

    The Service is intended for business use by adults and is not directed at children under 18. We do not knowingly collect personal information from children.

    11. International data transfer

    We may process and store data in locations outside your country of residence. Where required, we rely on appropriate safeguards for such transfers consistent with applicable data-protection law.

    12. Changes to this policy

    We may update this Privacy Policy periodically. Material changes will be reflected by an updated "Last updated" date on this page and, where appropriate, communicated by email.

    13. Contact

    For privacy questions or data requests, use our Contact page.