Legal
Privacy Policy
Effective September 16, 2026 · Version 2026-09-16.1
1. Notice at collection
RoundsBrief collects identifiers and account details, professional-learning content, optional calendar data, and security, consent, subscription, and usage metadata for the purposes described below. We do not sell personal information, share it for cross-context behavioral advertising, or use advertising trackers under the current pilot.
Do not submit identifiable patient information, patient recordings, or live EHR data. The current service is limited to synthetic information or material already de-identified through an appropriate process.
2. Information we collect
- Beta access requests: name, email, professional role, optional specialty, recorded permission to respond, optional newsletter choice, and limited campaign labels included in the request link, such as source and campaign name. We do not use cross-site advertising pixels.
- Optional email updates: If you opt in, we store your email-update preference and the time of your choice and may email product news and newsletters. You can withdraw this consent in Privacy & settings after creating an account or through the unsubscribe method in a future message. Requesting access or signing up alone does not subscribe you.
- Identifiers: name, email address, internal account, organization, and workspace IDs, and verification status. Legacy mobile numbers collected before email-only signup may remain until the account is deleted or a valid deletion request is completed.
- Credentials, consent, and security: password hash, session-token hash, accepted policy versions and timestamps, login and security events, hashed rate-limit keys derived from an IP address or account identifier, and operational timestamps. RoundsBrief does not store plaintext passwords or session tokens.
- Workspace content: debrief transcripts, organized segments, cases, notes, tasks, research questions, insights, conversations, edits, source wording, provenance, preferences, and feedback you choose to save.
- Audio: when you request transcription, the browser sends a recording to the RoundsBrief host. The host-local adapter writes a temporary file for processing and deletes it afterward. The application does not intentionally add audio to the workspace database. If transcription fails, the browser-held recording may remain available in that browser tab for retry, listening, re-recording, or manual transcription until you clear it, navigate away, reload, or close the tab.
- Calendar information: event titles, descriptions, dates, external source IDs, revisions, import timestamps, and connection metadata for imports you enable. Google access is read-only in RoundsBrief.
- Commercial information: plan, subscription and billing-customer identifiers, payment and cancellation status, renewal dates, and paid-invoice amounts. Stripe—not RoundsBrief—collects card and payment details on its hosted pages.
- Operational metadata: feature actions, success or failure, model/provider labels, latency, error codes, consent and audit records, and pseudonymous actor or resource references. We do not use session replay in the current pilot.
3. Sources
We receive information directly from you, automatically from your interactions with the service, from your browser or device, from administrators limited to permitted account and pilot operations, and from integrations you deliberately enable, such as calendar or future payment providers.
4. Why we use information
We use information to review and respond to beta requests; understand which first-party campaign brought a request; create and authenticate accounts; record legal consent; provide transcription, organization, search, recall, tasks, calendar import, export, and deletion; secure and troubleshoot the service; prevent fraud and abuse; process and administer subscriptions; respond to incidents and legal obligations; and measure aggregate feature adoption, reliability, and pilot readiness.
When product-improvement analytics are enabled for your account, metadata-only reports may use feature actions, completion counts, success or failure outcomes, latency, plan state, and account-level return patterns to improve product speed, reliability, usability, and workflow design. You can change this choice in Privacy & settings. Turning it off excludes your account activity from product-improvement reports; required security and service-operation records may still be retained and used for those limited purposes.
Private workspace content is not used for targeted advertising, sold to data brokers, exposed in owner analytics, or used to train public models under the current pilot configuration. Enabling product-improvement analytics does not authorize access to private workspace content.
5. Processing locations, providers, and disclosures
The current application and host-local transcription run on the computer operating the RoundsBrief pilot; this is not necessarily your device. The invitation site is exposed through secure networking infrastructure. Optional Google Calendar access involves Google. Stripe processes paid Checkout, subscription management, invoices, fraud controls, and related payment communications when an invited user chooses a paid plan. Production account and newsletter email delivery is not active unless separately configured and enabled.
Information may be disclosed to service providers performing a narrowly defined function; to a customer organization only under a separate agreement and permission model; during a business transaction subject to appropriate protections; or when reasonably necessary to comply with law, protect rights, investigate abuse, or address an emergency. Providers receive only information needed for the enabled function.
The current pilot does not promise a particular data-residency jurisdiction or cross-border transfer mechanism. A verified provider and subprocessor inventory, contracts, residency position, and transfer analysis are required before production use.
6. Owner analytics and administrator access
The owner console includes beta access requests, their contact permission and first-party source or campaign labels; an account directory; signup trends; plan and beta-preview status; billing-period and cancellation status; and aggregate paid-invoice amounts from a configured payment provider. It also shows newsletter and analytics choices and their recorded dates, plus the versions, time, and source of the latest agreement acceptance. These account, billing, consent, and security records support operating the service and are separate from optional product-improvement reporting.
Newsletter contacts can be exported only for active accounts with a verified current email and a recorded newsletter opt-in. Access-request newsletter consent is stored separately until an approved sender and unsubscribe system are configured; it does not automatically create an account or trigger a message. Feedback follow-up permission applies to submitted feedback and does not enroll someone in newsletters. Optional newsletters are separate from necessary account, security, or billing notices. Commercial messages must include an unsubscribe method when sending is enabled.
The site owner can review account identity and operational details needed to run the invitation pilot, including name, email, account and verification status, signup and recent-activity timestamps, plan status, product-improvement sharing choice, and submitted feedback. Contact details attached to feedback are shown only when the user consents to follow-up.
Product-adoption counts, RoundsMind control counts, successful feature-event reports, and retention funnels include only accounts with product-improvement analytics enabled. The owner dashboard displays the sharing state and withholds per-account feature counts when sharing is disabled. Required failure and security metadata may remain available for service operation.
Owner analytics do not expose passwords, session tokens, private transcripts, notes, task titles, cases, research questions, conversations, Ask Rounds prompts or answers, RoundsMind maps, source excerpts, or audio. Platform, practice, support, and billing administrators do not receive standing access to private workspace content. Break-glass content access is disabled in the pilot.
Host operators and persons with privileged access to the application host or database may technically be able to access stored files. Access is restricted operationally, but the current pilot has not completed production-grade privileged-access management, independent monitoring, or formal workforce controls.
7. Health information and HIPAA
RoundsBrief is not authorized to receive protected health information in the current pilot and is not represented as a production HIPAA environment. Whether an organization is a covered entity or business associate depends on the parties and service relationship; a privacy policy does not create HIPAA compliance.
If RoundsBrief ever processes PHI for a covered entity, an executed business associate agreement, approved architecture, risk analysis, vendor agreements, safeguards, training, incident procedures, and other legal and technical requirements must be completed before processing.
The identifier scanner does not establish Safe Harbor or Expert Determination. Even properly de-identified information can retain residual re-identification risk.
8. Retention and deletion
Beta access requests remain while the invitation is under review or while follow-up permission remains useful for the disclosed purpose. A requester may ask to withdraw or delete the request through the pilot support channel. Active account and workspace records remain in the local database until the account is deleted or the pilot operator lawfully removes them. Authentication sessions expire after 12 hours. Verification challenges and Google OAuth state expire after about 10 minutes, although expired rows may remain until later cleanup.
A validated account-deletion request removes account credentials, active sessions, legal-consent rows, private workspace content, feedback, preferences, local calendar tokens, and account-linked billing metadata from the active database. It also attempts to revoke Google access when connected; local token deletion continues even if Google is unavailable. Retained operational audit events are stripped of organization, user, resource, and metadata links and re-hashed so they are no longer directly attributable through the deleted account.
Temporary transcription files are deleted after each completed or failed processing attempt. Browser-held recordings follow the browser behavior described above.
Local SQLite backup files can contain an earlier copy of records, including records later deleted from the active database. The current pilot has backup and restore tooling and daily local retention, but it does not yet provide independently verified encrypted off-host recovery. Backups are excluded from the source repository and must be access-restricted. A defined, tested production schedule and deletion-verification process are launch requirements.
We will not retain personal information longer than reasonably necessary for the disclosed purpose unless law requires otherwise. Billing, tax, fraud, dispute, or legal-hold records may require a different period if those functions are activated; the applicable schedule must be published before activation.
9. Export, choices, and privacy rights
Account settings let you enable or disable metadata-only product-improvement analytics. The stored choice is included in your export and removed with your account. Account settings also provide password-confirmed JSON export and password, email, and exact-phrase-confirmed account deletion. The export includes account and consent information, workspace records, relationships, tasks, research, conversations, preferences, dashboard history, user-owned knowledge-source metadata, integration metadata without secret tokens, and attributable audit events. It is a point-in-time application export, not a promise of compatibility with every third-party system.
You may disconnect calendar access and control what content you submit. Depending on applicable law and your location, you may also have rights to know, access, correct, delete, restrict, object, appeal, or obtain a portable copy of personal information and to receive non-discriminatory treatment.
RoundsBrief does not currently sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising. Legally required request, appeal, and authorized-agent channels must be added before broader launch.
10. Cookies and browser storage
The service uses an essential HTTP-only, SameSite=Strict session cookie for authentication. It may keep an unsent recording in memory within the active browser tab as described above. The current pilot does not use advertising cookies or cross-site behavioral tracking. Future analytics or cookie changes require updated disclosure and consent where applicable.
11. Security and incidents
Current controls include BCrypt password hashing, hashed session tokens, HTTP-only and SameSite=Strict cookies, owner- and workspace-scoped queries, same-origin mutation checks, content-type and declared-size validation, rate limits, restricted owner authorization, metadata-only administration, encrypted local storage of Google refresh tokens when that integration is configured, dependency scanning, security headers, audit metadata, processor gates, backup and restore scripts, and health checks.
The pilot does not promise end-to-end encryption, managed key custody, encrypted managed backups, multi-factor authentication, an independently validated penetration test, uninterrupted availability, or compliance certification. No safeguard eliminates all risk.
We will investigate suspected incidents and provide notices required by applicable law. A documented incident-response plan, named contacts, escalation coverage, and jurisdiction-specific breach analysis remain production requirements. Health-app breach obligations may apply even when HIPAA does not.
12. Children and international use
The service is intended for adults 18 and older and is not directed to children. International production availability, data-transfer mechanisms, representative appointments, and region-specific terms are not currently enabled for this U.S.-oriented invitation pilot.
13. Policy changes and consent evidence
Material changes use a new version and require renewed acceptance when appropriate. Consent versions and timestamps are retained while the account is active. They are included in export and removed with account deletion under the current pilot architecture, subject to older backup copies as disclosed above.
14. Contact and unresolved privacy fields
A monitored privacy email, final legal business name, physical notice address, privacy-request channel, appeal process, and jurisdiction-specific notices must be added before expanding beyond the limited invitation pilot. Until then, use the support channel provided directly to invitation-pilot participants.