This Privacy Policy describes how Gnosis Concepts Inc. (“Company,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal information when you or your Authorized Users access and use the PsychNote AI platform (“Platform”). This Privacy Policy is incorporated by reference into the PsychNote AI Terms of Service and applies to all Subscribers and Authorized Users as defined therein.
This Policy is written for healthcare providers. We recognize that you operate under your own HIPAA obligations to your patients, and we take our role as your Business Associate seriously. To the extent this Privacy Policy references or relates to PHI, the Business Associate Agreement (“BAA”) between you and the Company shall govern. In the event of a conflict between this Privacy Policy and the BAA with respect to PHI, the BAA shall control.
Terms used but not defined in this Policy have the meanings set forth in the PsychNote AI Terms of Service. In addition:
When you register for a subscription, we collect: your name, practice name, professional credentials, email address, username, billing address, and payment information (processed by our payment processor; we do not store full card numbers). This information is used to create and manage your account, process payments, and communicate with you. We may also collect account preferences, subscription history, support communications, and other information reasonably necessary to establish, administer, secure, and support your account.
When you or your Authorized Users use the Platform, we process:
Audio recordings and transcripts are processed transiently and are used to generate your clinical note. Except as necessary for transient processing, troubleshooting, security, legal compliance, or system integrity purposes, audio recordings and transcripts are not retained on our servers after the note is produced. What is retained is the finished clinical documentation in your account.
We automatically collect technical information when you access the Platform, including IP address, browser type and version, operating system, pages viewed, features accessed, session timestamps, and error logs, device identifiers, authentication events, and other technical usage information generated through your interaction with the Platform. This data is used for security monitoring, audit logging, troubleshooting, fraud prevention, performance analysis, platform improvement, and maintaining the security, integrity, and availability of the Platform.
In compliance with HIPAA (45 CFR §164.312(b)), the Platform maintains append-only audit logs recording access to PHI, including user identity, timestamp, action taken, and data accessed. Audit logs are retained for a minimum of six (6) years in support of the Company's HIPAA compliance obligations and record-retention practices.
We use Account Data and Practice Data to: create and authenticate your account; deliver AI- assisted documentation features; store and retrieve your clinical notes and patient records; process subscription payments; provide customer support; and send operational communications including billing notices, security alerts, and product updates; maintain, troubleshoot, secure, and improve the reliability and functionality of the Platform; and fulfill our contractual obligations to Subscribers.
We use Usage Data and audit log data to detect and prevent unauthorized access, investigate security incidents, fulfill our HIPAA Security Rule obligations, respond to breach events, and comply with applicable law, enforce our Terms of Service and applicable Business Associate Agreements, and protect the security, integrity, and availability of the Platform.
We may use De-identified Information, including de-identified and aggregated Usage Data and other information derived from the Platform in accordance with HIPAA and applicable law, to analyze platform performance, improve user experience, enhance existing features, develop new features, conduct analytics, benchmarking, quality assurance, research, and improve the Platform. We will never use your PHI or patient data to train, fine-tune, or improve any artificial intelligence or machine learning model without your explicit written consent, in a manner consistent with Section 8.4 of the Terms of Service.
We may contact you by email or other contact information you provide regarding account and subscription management, product updates, security notices, and optional feedback requests. You may opt out of non-essential communications at any time by emailing support@nmpsychnote.com or using the unsubscribe mechanism provided in such communications. Operational and security communications cannot be opted out of while your account is active.
The Company processes Practice Data and PHI solely as necessary to provide the Platform and related services, to comply with applicable law, to fulfill its obligations under applicable Business Associate Agreements ("BAAs"), and for other purposes expressly authorized by the Subscriber, the applicable BAA, or applicable law. The Company uses and discloses PHI only as permitted or required by the applicable BAA, HIPAA, or other applicable law.
We do not sell your information. We do not disclose PHI except as permitted or required by the applicable BAA, HIPAA, or applicable law. We do not disclose your Practice Data to third parties for marketing or advertising purposes or permit third parties to use Practice Data for their own marketing purposes.
To deliver Platform services, we engage subprocessors that may access or process your data. Each subprocessor is bound by a written agreement containing appropriate confidentiality, security, and data protection obligations, including a Business Associate Agreement where required by HIPAA. Our current subprocessors are described in Section 6.
We may disclose information when required by applicable law, regulation, court order, or government authority; to protect the safety or rights of the Company, our users, or the public; to establish, exercise, or defend legal claims; or to enforce our Terms of Service, applicable BAAs, or other legal rights.
In the event of a merger, acquisition, asset sale, or similar transaction involving the Company, your information may be transferred as part of that transaction. Where required by applicable law, we will provide notice of any material changes to our privacy practices resulting from such transaction. Any successor entity will remain subject to applicable HIPAA obligations, Business Associate Agreements, and this Privacy Policy until it is amended in accordance with this Privacy Policy.
We may disclose information in any other circumstance with your explicit written consent.
We retain your Practice Data and PHI for the duration of your active subscription. Upon termination, Practice Data is retained for ninety (90) days, after which it may be securely deleted or de-identified, as appropriate, consistent with Section 13.4 of the Terms of Service and subject to applicable law, the applicable Business Associate Agreement, backup retention requirements, legal obligations, and the Company's record-retention practices. You may request export of your data before termination by contacting support@nmpsychnote.com.
Audit logs are retained for a minimum of six (6) years from the date of creation or the date last in effect, whichever is later, in compliance with HIPAA.
Account Data is retained for the duration of your account and for a reasonable period thereafter as needed to comply with legal obligations, resolve disputes, enforce agreements, maintain business records, and protect the security and integrity of the Platform.
Audio recordings are processed transiently and are not stored on our servers after transcription is complete. Text transcripts are held in browser memory only during the active session and are cleared immediately after a SOAP note is generated. Except as necessary for transient processing, troubleshooting, security, legal compliance, or system integrity purposes ,no audio or transcript is persisted to our database.
The following subprocessors process data on our behalf in connection with the Platform. We require each subprocessor to implement and maintain appropriate confidentiality, security, and data protection measures and, where required by HIPAA, to enter into a Business Associate Agreement before creating, receiving, maintaining, or transmitting PHI on our behalf.
The Platform will not process PHI through any subprocessor unless appropriate contractual protections, including a Business Associate Agreement where required by HIPAA, are in place.
The Company may update or replace subprocessors from time to time as necessary to support the Platform, provided that any replacement subprocessor will be subject to confidentiality, security, and contractual obligations consistent with this Privacy Policy and applicable law.
We implement and maintain reasonable administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of PHI and other information, consistent with the HIPAA Security Rule (45 CFR Part 164, Subpart C). These safeguards may include, as appropriate:
No security measure is perfect or impenetrable. In the event of a breach of unsecured PHI, we will notify you as required by the applicable BAA, the HIPAA Breach Notification Rule (45 CFR §§164.400–414), and other applicable law, without unreasonable delay and no later than sixty (60) calendar days after discovery, unless a shorter period is required by the applicable BAA or law.
You may access, view, and export your clinical documentation and patient records through the Platform at any time, subject to your subscription status and applicable law. If you require assistance exporting your data, contact support@nmpsychnote.com.
You may update or correct your Account Data through your account settings. For corrections to clinical documentation, you may edit notes directly within the Platform.
You may request deletion of your account and associated data by contacting support@nmpsychnote.com. Following your request, we will initiate the ninety (90)-day retention period described in Section 5.1, after which your data may be securely deleted or de-identified, as appropriate, subject to audit log retention requirements, applicable law, the applicable Business Associate Agreement, backup retention requirements, and the Company's record-retention practices.
As a Subscriber and, where applicable, covered entity, you are responsible for honoring your patients’ rights to access, amend, and receive an accounting of disclosures of their PHI. The Platform supports your ability to fulfill these obligations. Patients who wish to exercise their HIPAA rights should contact their healthcare provider as the covered entity, not the Company.
To opt out of non-essential communications, email support@nmpsychnote.com or use the unsubscribe link in any marketing email. You may not opt out of operational, security, billing, or other communications necessary to administer your account or provide the Platform.
The Platform uses essential session cookies solely to authenticate your session, maintain secure access, support core Platform functionality, and enhance the security and performance of the Platform. We do not use advertising cookies, cross-site tracking, or third-party analytics that share your data with advertisers. Disabling cookies in your browser or devise settings may prevent access to or impair the functionality of the Platform.
The Platform is intended exclusively for use by licensed healthcare professionals and is not directed to individuals under 18 years of age. The Company does not knowingly collect personal information directly from children as users of the Platform. However, the Platform may process information relating to minor patients on behalf of healthcare providers in the Company's capacity as a Business Associate and in accordance with applicable Business Associate Agreements, HIPAA, and applicable law. If you believe a child has created an account or otherwise submitted personal information directly to the Platform other than through a healthcare provider's authorized use of the Platform, please contact privacy@nmpsychnote.com.
We may update this Privacy Policy from time to time. Material changes will be communicated via email notice and/or notice within the Platform at least thirty (30) days before the change takes effect, consistent with Section 15.2 of the Terms of Service. Your continued use of the Platform after the effective date of the revised Privacy Policy constitutes acceptance of the updated Policy, to the extent permitted by applicable law.
To the extent applicable, this Privacy Policy shall be interpreted and applied in conjunction with the PsychNote AI Terms of Service. Any issues relating to the interpretation or enforcement of this Privacy Policy shall be governed by the governing law provisions set forth in the Terms of Service.
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact:
Gnosis Concepts Inc.
Privacy Officer / HIPAA Security Officer: Adekoye Sanni Email: privacy@nmpsychnote.com
General inquiries: info@nmpsychnote.com Support: support@nmpsychnote.com Website: nmpsychnote.com
For urgent privacy or security concerns, including suspected PHI breaches, contact privacy@nmpsychnote.com.
Questions relating to the exercise of patient rights under HIPAA should be directed to the applicable healthcare provider or Covered Entity.
© 2026 Gnosis Concepts Inc. All rights reserved.
This Privacy Policy applies to PsychNote AI operated by Gnosis Concepts Inc., San Antonio, Texas.