Privacy Policy

Last updated: September 2026

Who we are

MedFlow AI provides workflow automation software for healthcare practices. This policy explains what information we handle when a practice uses our platform.

Information we collect

  • Account details: name, work email, practice name, role, and sign-in records.
  • Practice details: specialty, provider count, locations, contact information, and branding.
  • Operational data: appointments, message templates, message send logs, and activity logs.
  • Billing details: plan, billing interval, and payment status. Card data is handled by Stripe, not by us.

How we use information

We use information to operate the platform, deliver the features a practice has enabled, process subscriptions, provide support, and keep accounts secure. We do not sell personal information, and we do not use practice or patient information to train public AI models.

Protected health information

Where a practice processes protected health information through MedFlow AI, a Business Associate Agreement is signed before any PHI is handled. Data is encrypted in transit and at rest, access is role-based, and administrative actions are recorded in an activity log.

Separation between practices

Each practice has its own isolated workspace. Records are scoped to the practice that owns them, and access is checked on the server on every request.

Service providers

We use third parties to run the platform, including cloud hosting and database infrastructure, Stripe for payments, and an email delivery provider for transactional messages.

Retention and your choices

We keep information for as long as the account is active or as required for legal, accounting, or security reasons. Practices can request access, correction, export, or deletion of their data at any time.

Contact

Questions about this policy: info@medflowai.tech.

Need help? Email info@medflowai.tech.