Privacy Policy

Effective June 26, 2026

This Privacy Policy explains how attest (“attest,” “we,” “us,” or “our”), a product of Cardinal Vector LLC, collects, uses, discloses, and protects information when you use our website, applications, and clinical AI services (collectively, the “Service”). attest is built for licensed clinicians and authorized healthcare organizations.

The Service is designed for de-identified, synthetic, or hypotheticalclinical data. An automated server-side safeguard redacts direct patient identifiers from submissions before they are processed, and you must not enter Protected Health Information (“PHI”). attest does not process PHI. Processing PHI would require a separate signed Business Associate Agreement (“BAA”); without one, attest operates on de-identified data only.

1. Information we collect

We collect the following categories of information:

  • Account information: name, email, professional title, NPI/registration number, organization, and credentials you provide during registration.
  • Authentication and security data: passwords (hashed), multi-factor authentication factors, session tokens, IP address, browser and device metadata, and audit log events.
  • User-generated clinical content: free-text notes, voice recordings, transcripts, uploaded documents, generated note drafts, assessment & plan content, and chat messages exchanged with the AI. This content is expected to be de-identified, synthetic, or hypothetical.
  • No Protected Health Information (PHI): attest does not collect PHI. Direct patient identifiers are redacted from inputs, and the Service must not be used with PHI.
  • Usage data: pages visited, features used, AI calls made, timestamps, performance metrics, error reports, and aggregated telemetry needed to operate and improve the Service.
  • Billing data: subscription tier, billing contact, and payment metadata. We do not store full payment card numbers; payment processing is handled by our PCI-compliant payment provider, Stripe.

2. How we use information

  • Provide the Service: authenticate users, render the application, generate Attest AI outputs, persist your content, and operate the production environment.
  • Improve the Service: monitor performance, debug failures, measure feature usage in de-identified aggregate, and evaluate model quality on data not containing PHI.
  • Security and integrity: detect abuse, prevent unauthorized access, maintain audit logs, and respond to security incidents.
  • Communications: deliver transactional emails (account confirmations, billing receipts, security alerts) and, with your consent, occasional product updates.
  • Legal compliance: respond to lawful subpoenas, court orders, and regulatory requests; enforce our Terms of Service; protect rights, property, and safety.

We do not use your clinical content to train, fine-tune, or otherwise improve general-purpose AI models. Clinical content is processed only for the specific task you initiated.

3. Attest AI processing

Attest AI uses only the minimum clinical content necessary to perform the task you request. Our AI subprocessor is OpenAI, which provides text generation, speech-to-text transcription, document vision/OCR, and embeddings. OpenAI has signed a BAA with attest, and we require a Zero Data Retention configuration.

We contractually prohibit our AI subprocessors from using your inputs or outputs to train, fine-tune, or improve their models. Anthropic (Claude) is permanently blocked in our application code and receives no customer data in any mode. Because attest operates on de-identified data, direct identifiers are redacted from every input before it is sent to a subprocessor.

4. Sharing and disclosure

We share information only as needed to operate the Service or as required by law. We do not sell personal information, and we do not share it with advertisers.

Principal subprocessors. We rely on the following service providers, each bound by written terms at least as protective as this Policy:

  • Google Cloud (GCP), hosting and infrastructure.
  • Self-hosted database, authentication, and storage running on Google Cloud.
  • OpenAI, AI text generation, transcription, document OCR, and embeddings (BAA signed).
  • ZeroEntropy, optional retrieval and reranking over medical reference literature.
  • Tavily, optional web search behind the Web sources feature: it runs only when you turn Web sources on, sends a non-PHI query to a trusted allowlist of public medical-society domains, and never receives patient data.
  • Amazon SES (AWS), transactional email.
  • Stripe, subscription billing and payments (billing data only; no PHI).

Subprocessors receive only de-identified or non-PHI data; attest does not send PHI to subprocessors. A current subprocessor list is available at contact@attest.health, and we provide at least 30 days' notice before adding a new subprocessor that processes personal data. Processor terms are set out in our Data Processing Agreement.

We also disclose information in these limited situations:

  • Within your organization: content is accessible to authorized members of your organization, governed by your organization's access controls and role assignments.
  • Legal requests: when compelled by court order, subpoena, or other legal process, we notify the affected customer unless prohibited by law.
  • Business transfers: in the event of merger, acquisition, or asset sale, with the same protections in place at the successor entity.
  • With your explicit consent for any other disclosure not described here.

5. Data security

attest maintains administrative, technical, and physical safeguards designed to protect information against unauthorized access, disclosure, alteration, or destruction:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256).
  • Role-based access controls and row-level security on the database, scoped to the authenticated user and organization.
  • Multi-factor authentication available for all accounts and required for administrators.
  • Comprehensive audit logging of clinical-data access events (phi_access_log), retained per our retention policy.
  • Annual penetration testing and continuous vulnerability scanning.
  • Background checks and privacy and security training for all personnel with access to clinical data.
  • Incident response procedures, including notification to affected customers without undue delay.

6. Data retention and deletion

We retain account information and user-generated content for the duration of your subscription plus any post-termination window described in your order form. Audit logs are retained per our retention policy. You may request deletion of your account at any time; we will delete or de-identify your data within thirty (30) days of confirmed request, except where retention is required by law or to resolve disputes.

7. Your rights and choices

Depending on your jurisdiction, you may have the right to:

  • Access the personal information we hold about you.
  • Correct inaccurate or incomplete information.
  • Request deletion (subject to legal retention requirements).
  • Object to or restrict certain processing.
  • Receive a portable copy of your data.
  • Lodge a complaint with a supervisory authority (residents of the EEA/UK).

Because attest operates on de-identified data and does not process PHI, it is not a HIPAA covered entity or business associate for information entered through the Service. Patient rights under the HIPAA Privacy Rule are handled by the treating clinician or their organization, not by attest.

8. U.S. state privacy rights

Depending on your state of residence, you may have additional rights under U.S. state privacy laws, including the California Consumer Privacy Act as amended (CCPA/CPRA), the Washington My Health My Data Act, Nevada law, and the comprehensive privacy laws of states such as Virginia, Colorado, Connecticut, Texas, Oregon, and Utah.

Important exemptions. Properly de-identified data is generally exempt from these laws. This section therefore applies mainly to account, billing, and usage data, and to other personal information we process.

  • California (CCPA/CPRA): we do not sell or share your personal information for cross-context behavioral advertising, and we do not use sensitive personal information beyond providing the Service. You may request to know, access, correct, or delete your personal information, may appoint an authorized agent, and will not be discriminated against for exercising these rights.
  • Washington (My Health My Data Act): the Service is designed not to collect consumer health data, because direct identifiers are redacted and clinical content is expected to be de-identified, synthetic, or hypothetical. Where any consumer health data is collected, we do so to provide the Service you requested or with your consent, you may withdraw consent or request deletion, and we do not sell consumer health data.
  • Preference signals: because we do not sell or share personal information for cross-context behavioral advertising, there is nothing to opt out of; where required, we honor the Global Privacy Control (GPC). No common Do-Not-Track (DNT) standard exists, so we do not separately respond to DNT browser signals.

How to exercise these rights. Email contact@attest.health or submit a request through the Service. We will verify your request and respond within the timeframes required by applicable law. If we deny a request, you may appeal by replying to our response.

9. Children

The Service is not directed to individuals under the age of 18, and it must not be used with patient data, including pediatric information. It is intended for licensed clinicians working with de-identified, synthetic, or hypothetical data.

10. International data transfers

attest stores data on infrastructure located in the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States. We implement appropriate safeguards (e.g., Standard Contractual Clauses) for cross-border transfers where required.

11. Changes to this policy

We will notify customers in writing of any material changes at least thirty (30) days before they take effect. Continued use after the effective date constitutes acceptance.

12. Contact us

  • Email (privacy, security, and general inquiries): contact@attest.health
  • Mail: Cardinal Vector LLC, Attn: Privacy Officer, 5697 SW 49th Rd, Ocala, FL 34474, United States

This Privacy Policy works together with your applicable Order Form, Data Processing Agreement, and Terms of Service.