Privacy Policy
Last Updated: January 27, 2026
VeloNote is committed to protecting privacy while supporting secure, compliant clinical documentation workflows. This Privacy Policy explains how information is handled when you use the VeloNote platform.
This Policy is informational and does not expand VeloNote's obligations beyond applicable law or an executed Business Associate Agreement (BAA).
Scope and Applicability
This Privacy Policy applies to users of the VeloNote platform. It does not replace or modify any executed Business Associate Agreement ("BAA") between VeloNote and a covered entity or business associate under HIPAA.
In the event of a conflict, the BAA governs solely with respect to Protected Health Information ("PHI"), to the minimum extent required by law.
Information We Process
Account and Administrative Information
We collect limited account-related information, including:
- •name and email address
- •authentication credentials
- •usage metadata such as timestamps and feature access
This information is used solely to provide, secure, and operate the Service.
Clinical Content and Files
Users may upload clinical documents (such as PDFs, text notes, or screenshots) for the purpose of generating draft medical documentation.
Important clarifications:
- •VeloNote processes text-based clinical documents, not raw imaging data (e.g., CT, MRI, or X-ray files).
- •Uploaded files are processed transiently for OCR and analysis.
- •Generated reports are stored client-side within the user's browser session unless exported by the user.
VeloNote does not independently create or source PHI.
AI Processing
Clinical content is processed using HIPAA-eligible cloud AI services strictly for user-initiated documentation workflows.
- •Patient data is not used to train AI models
- •AI output is probabilistic and requires user review
- •VeloNote does not perform autonomous clinical decision-making
How Information Is Used
Information is used solely to:
- •provide and secure access to the Service
- •process user-initiated documentation requests
- •authenticate users and manage sessions
- •maintain audit logs and system integrity
- •comply with applicable legal and regulatory requirements
VeloNote does not sell personal data or PHI.
Data Storage and Retention
- •Account and system metadata are stored in encrypted databases.
- •Uploaded files are processed in memory and not retained beyond processing where technically feasible.
- •Generated documentation remains under the user's control once exported.
Important: Once data is copied, downloaded, or transmitted outside the Service, VeloNote no longer has custody or control over that data.
Third-Party Service Providers
VeloNote uses vetted, HIPAA-eligible cloud providers (such as AWS and Google Cloud) for infrastructure, authentication, and AI processing. These providers process data only as necessary to support the Service and under appropriate contractual safeguards.
Security Measures
VeloNote implements administrative, technical, and physical safeguards designed to protect information, including encryption in transit and at rest, access controls, and audit logging.
No system can guarantee absolute security.
User Responsibilities
Users are responsible for:
- •ensuring proper authorization to upload clinical information
- •complying with applicable privacy and security laws
- •reviewing AI-generated content prior to clinical or regulatory use
- •securing exported data outside the Service
Your Rights
Depending on jurisdiction, users may have rights to access, correct, or delete account information. Requests may be submitted using the contact information below.
Updates to This Policy
We may update this Privacy Policy periodically. Continued use of the Service constitutes acceptance of the updated policy.
Contact
For privacy-related inquiries, contact: [email protected]