Privacy policy
What we collect, who else touches it, how long we keep it, and what you can make us do with it.
Last updated September 20, 2026
Who is responsible for what
If you are a clinician or practice using NeuroScribe, you are the controller of your patients’ data. We process it on your behalf, under your instructions, and we acquire no rights to it by handling it. You decide what goes into the product, what comes out, and when it is deleted.
Neurocareva is the controller for your own account data: your name, email, practice details and billing information.
What we collect
Who processes your data
These are the only third parties that receive data from NeuroScribe. Each one is limited to the purpose listed, and none of them are permitted to use your data for their own purposes.
Stores your account, patients, notes, templates and appointments. Encrypted at rest.
Serves the application and runs the API routes. Does not retain request bodies.
Receives the transcript, your template and your learned style. Commercial API terms exclude the content from model training.
Receives session audio in a single streamed request and returns a transcript with speakers separated.
Handles subscriptions as merchant of record. Receives your billing details. Never receives clinical data.
Only if you connect it. Receives appointment times and titles, never note content.
Data is stored and processed in the United States. We do not sell data, we do not share it for advertising, and we do not run analytics that follow you across other websites.
HIPAA and our role as a business associate
When you use NeuroScribe to document patient care, you are a covered entity (or the business associate of one) and we are your business associate under 45 CFR Parts 160 and 164. We will execute a Business Associate Agreement with your practice before you put protected health information into the product. Ask and we will send one the same day.
Where this policy and a signed BAA differ, the BAA governs.
What we may and may not do with PHI
We use protected health information only to provide and support the service you are paying for: transcribing a session, generating a note, answering a question about a chart, and keeping those records available to you. We do not sell PHI, we do not use it for marketing, and we do not use it to train artificial intelligence models. Any use for our own purposes is limited to the proper management of the service and is carried out on de-identified data wherever it is possible to do so.
Minimum necessary
Each part of the system receives only what it needs. Transcription receives audio and returns text. The language model receives the transcript, your template and your learned style for a single request. Style learning receives text that has already had identifiers stripped. Our application logs carry identifiers and counts, never note content, patient names or any other identifier.
Safeguards
Administrative, physical and technical safeguards are in place as required by the Security Rule: encryption in transit and at rest, row-level access control keyed to the individual provider, two-factor authentication available on every account, column-level restrictions on privileged fields, an audit trail of security-relevant events, and access to production data restricted to the small number of people who operate the service. The technical detail is on the security page.
Subcontractors
HIPAA makes a business associate directly liable for its subcontractors. Every company that can touch PHI on our behalf is bound by a Business Associate Agreement carrying the same obligations we owe you. The current list is published on the security page, and we do not add one without an executed agreement first.
Breach notification
If we discover a breach of unsecured protected health information, we will notify you without unreasonable delay and in no case later than 60 calendar days after discovery, as required by 45 CFR 164.410. The notice will identify the individuals affected so far as we are able, what happened, what information was involved, what we have done about it, and what we recommend you do. You remain responsible for notifying affected individuals, HHS and, where applicable, the media, because that duty sits with the covered entity.
Helping you meet individual rights
If a patient exercises a right you must satisfy, we will give you what you need to satisfy it. That covers access to their designated record set under 45 CFR 164.524, amendment of it under 164.526, and an accounting of disclosures under 164.528. In practice most of this is already in your hands: every note is exportable to PDF or Word from inside the product at any time, without asking us.
Termination
When your agreement ends, we return or destroy the protected health information we hold, at your election, and we stop using it immediately. Where a backup makes destruction infeasible within the retention window described above, the information remains protected under these terms and is destroyed when that window expires.
HHS access
We will make our internal practices, books and records relating to our use of PHI available to the Secretary of Health and Human Services for the purpose of determining your compliance with the Privacy Rule.
How long we keep it
Your rights
You can export every note in your account to PDF or Word at any time, without asking us. You can delete patients, notes and style profiles from inside the product. You can ask us to delete your whole account and everything in it by writing to the address below, and we will confirm when it is done.
Depending on where you live you may also have rights to access, correct, restrict or object to processing, and to receive your data in a portable format. Ask and we will action it. We will not charge you and we will not ask why.
Security
Encryption in transit and at rest, provider-level isolation enforced in the database, and column-level restrictions on privileged fields. The detail, including what we have not finished, is on the security page.
Changes and contact
If we change this policy in a way that affects how your data is handled, we will tell account holders by email before it takes effect, not by quietly changing the date at the top.
Privacy questions and deletion requests: privacy@neurocareva.com
Security reports: security@neurocareva.com