Legal
Privacy Policy
Last updated: April 29, 2026
1. What this policy covers
This policy explains what FriendMedi collects, how we use it, and the choices you have. FriendMedi is a clinical documentation assistant currently in private beta, used by physicians to turn consultations into structured notes.
2. What we collect
- Account information — your name, email address, and password (stored as a hash by our authentication provider), plus profile details you choose to add.
- Consultation content — audio you record, the transcripts and translations produced from it, and the draft notes generated for your review.
- Usage data — basic logs such as sign-in events, session counts, and error reports, used to operate and improve the service.
3. Beta: synthetic data only, no PHI
During the private beta the service is restricted to synthetic or simulated consultations only. Real patient data and protected health information (PHI) must not be submitted until we have executed Business Associate Agreements (BAAs) with each of our infrastructure providers. We will notify users when the service is cleared for PHI. Until then, we treat all consultation content as non-PHI test data, and you are responsible for keeping real patient information out of the service.
4. How we use your information
- to provide the service: transcription, translation, and note drafting;
- to secure accounts and prevent abuse;
- to fix bugs and improve reliability during the beta;
- to communicate with you about the beta, including material changes.
We do not sell your data, and we do not use your consultation content for advertising.
5. Who processes your data
We rely on a small number of service providers to run FriendMedi: cloud hosting and database infrastructure, an authentication provider, and AI providers that perform speech-to-text and text generation. These providers process data only on our behalf to deliver the service. Before the service handles PHI, each provider in the processing path will be covered by a signed BAA.
6. Retention and deletion
Consultation content is retained so you can review and export your notes. You can delete individual sessions in the app, and you can request deletion of your account and all associated data at any time by emailing us. We honor deletion requests promptly, subject to short backup-rotation windows and any retention required by law.
7. Security
Data is encrypted in transit and at rest by our infrastructure providers, and access to production systems is limited to those who need it to operate the service. No system is perfectly secure; during the beta, the synthetic-data-only rule (Section 3) is an additional safeguard.
8. Changes to this policy
As FriendMedi moves out of beta — in particular, when BAAs are in place and PHI handling begins — this policy will be revised and re-dated. Material changes will be announced by email or in-app before they take effect.
9. Contact
Privacy questions or deletion requests: hello@friendmedi.com.