Privacy Policy
Last updated: September 2026
Who we are
MedFlow AI provides workflow automation software for healthcare practices. This policy explains what information we handle when a practice uses our platform.
Information we collect
- Account details: name, work email, practice name, role, and sign-in records.
- Practice details: specialty, provider count, locations, contact information, and branding.
- Operational data: appointments, message templates, message send logs, and activity logs.
- Billing details: plan, billing interval, and payment status. Card data is handled by Stripe, not by us.
How we use information
We use information to operate the platform, deliver the features a practice has enabled, process subscriptions, provide support, and keep accounts secure. We do not sell personal information, and we do not use practice or patient information to train public AI models.
Protected health information
Where a practice processes protected health information through MedFlow AI, a Business Associate Agreement is signed before any PHI is handled. Data is encrypted in transit and at rest, access is role-based, and administrative actions are recorded in an activity log.
Separation between practices
Each practice has its own isolated workspace. Records are scoped to the practice that owns them, and access is checked on the server on every request.
Service providers
We use third parties to run the platform, including cloud hosting and database infrastructure, Stripe for payments, and an email delivery provider for transactional messages.
Retention and your choices
We keep information for as long as the account is active or as required for legal, accounting, or security reasons. Practices can request access, correction, export, or deletion of their data at any time.
Contact
Questions about this policy: info@medflowai.tech.
Need help? Email info@medflowai.tech.