Effective date: [EFFECTIVE DATE]
Draft — under counsel review. This page is not yet in effect; the bracketed items are placeholders.
This policy describes how [COMPANY LEGAL NAME] handles information in connection with the HealthTech Builder platform (the "Service"). It covers the Service itself. Applications built on the Service for customer organizations are operated under those organizations' own policies and agreements, not this one.
The Service's build surfaces are not intended to receive protected health information. Do not include patient names, medical record numbers, or other patient-identifying details in build conversations, project descriptions, or decision notes. See our Disclaimers and Terms of Service.
To provide and secure the Service, to build and operate your organization's applications, to bill under your agreement, to communicate service notices, and to meet legal obligations. External email notifications are deliberately content-free: they say you have an update and link into the Service; the substance stays on the platform.
We use a small set of providers to run the Service: cloud infrastructure hosting; Anthropic (AI processing of build content); Resend (transactional email); and Stripe (payment processing, when card payments are enabled). Each processes information only to provide its function to us. We do not sell personal information, and we do not permit our AI providers to train on your content.
Account and organization records are kept while the account or organization exists. Deleting your account deletes your personal records; deleting an organization deletes its platform-side build records, as described in-product at the point of deletion. Two things survive by design: audit logs (retained six years, tamper-evident, for security accountability) and your organization's exported copies — the application code and decision logs that belong to it.
Sensitive fields are encrypted at the column level with managed key rotation; transport is encrypted; sessions are server-side and revocable; multi-factor authentication is available to every account; and security-relevant actions are recorded in a hash-chained audit log. No system is perfectly secure, and we encourage strong passwords and MFA.
You can access and update account information in the Service, export your organization's decision logs and code, and delete your account from the account page. Depending on your jurisdiction you may have additional rights (access, correction, deletion, portability); requests reach us at [CONTACT EMAIL] and we respond as the law requires.
We will notify you of material changes through the Service or by email, and update the effective date above. Privacy questions: [CONTACT EMAIL]. [COMPANY LEGAL NAME], [COMPANY ADDRESS].