Privacy policy

Effective August 21, 2026

HIPAA Chat is a work assistant for care-operations teams. Your organization signs up for HIPAA Chat and provisions your account — you never buy it or sign up on your own. This policy explains, in plain terms, what information passes through HIPAA Chat, where it lives, how long it is kept, and how to have it deleted. The short version: we collect only what the service needs to function, everything runs inside AWS, we show no ads, run no third-party analytics, and never sell data.

Your account

HIPAA Chat accounts are created by your organization's administrator — there is no self-signup. The account holds your name and work email address, which we use to sign you in (via Amazon Cognito) and to associate your conversations and files with you and your organization.

Your conversations

Messages you send to HIPAA Chat — and documents you attach to them — are processed by AI models running on AWS Bedrock in order to answer you. Your content is not used to train AI models. Conversation history is stored so you can pick up where you left off, and is deleted when you delete it or when your account is deleted.

Files you upload

Uploaded files are stored in Amazon S3, encrypted, in a storage area reserved for your organization. Files are automatically deleted 90 days after upload. Files HIPAA Chat produces for you (spreadsheets, documents, PDFs) live under the same rules.

Voice

When you dictate or use voice mode, your audio is transcribed by Amazon Transcribe. The transcript becomes part of your conversation and is kept with it; the audio recording itself falls under the same automatic 90-day deletion as uploaded files. Spoken replies are generated by Amazon Polly and are not retained as audio.

Web search

Some answers require current information from the web. When that happens, a search query is sent to Tavily, our search provider — without your name, email, account ID, or any other identifier attached. Only the search text itself is sent.

Payments

Subscriptions are purchased by organizations through Stripe on our website. Card details go directly to Stripe; we never see or store card numbers. Payment is handled entirely on the web — the mobile app contains no purchasing.

Audit logs

For security and compliance, HIPAA Chat keeps an audit trail of account activity — things like “a chat was started” or “a file was transcribed,” with timestamps and token counts. These logs are metadata only: they never contain the text of your messages, your documents, or the AI's responses.

What we do not do

  • No advertising, and no advertising SDKs in the app.
  • No third-party analytics or tracking SDKs.
  • No sale of personal information — ever, to anyone.
  • No use of your content to train AI models.

Security and HIPAA

HIPAA Chat runs entirely in AWS, in the US East (N. Virginia, us-east-1) region, with encryption in transit and at rest and each organization's data isolated from every other's. For customers handling protected health information, we operate under Business Associate Agreements (BAAs) with the customer organization, and AWS services in our stack are used under AWS's HIPAA-eligible terms. HIPAA Chat is a tool for your work — it is not a medical record system, and AI answers should always be verified before being used in care decisions.

Retention and deletion

Files and voice recordings are deleted automatically after 90 days. Conversations persist until you delete them. To delete your account and everything associated with it, follow the steps on the account deletion page— deletion completes within 30 days. Some audit records are retained where the law requires it.

Changes and contact

We may update this policy as the service evolves; the effective date above always reflects the current version, and material changes will be communicated to your organization. Questions, concerns, or requests: support@laborhq.io.