Effective date: [EFFECTIVE DATE]
This Privacy Policy describes how MDside AI LLC ("MDside", "we", "us") collects, uses, and shares information across our services:
- mdside.ai - our public marketing site
- app.mdside.ai - the application used by clinics and reviewing providers
- Clinic storefronts at
<clinic>.store.mdside.ai- online stores we host on behalf of healthcare clinics - api.mdside.ai - our API for clinics' own systems
1. Our role: we work for your clinic
MDside provides technology to healthcare clinics. When you submit health information through a clinic's storefront, or a clinic submits it on your behalf, the clinic is your healthcare provider and is responsible for your care. MDside processes that information as a service provider (HIPAA "business associate") of the clinic, under a Business Associate Agreement, and only to provide the services described here. The clinic's own Notice of Privacy Practices governs how your health information is used in your care; this policy explains what MDside itself does.
For information you give us directly (for example, creating an account or contacting us), MDside is responsible for it as described in this policy.
2. What we collect
Everyone (all surfaces)
- Account information: email address and, optionally, your name. Sign-in is by one-time email code; we never store a password you chose.
- Session and security data: IP address, browser/user agent, and sign-in timestamps, kept for security and legally required audit records.
Store customers (patients) When you place an order that requires provider review, we collect the health intake needed for that review:
- Name, date of birth, sex, and the U.S. state you are in
- The products you requested
- Clinical details you provide: reason for the request, height, weight, blood pressure, resting heart rate, activity level, medical history, current medications, drug allergies, alcohol and tobacco use, and answers to screening questions
- Order history with the store, and payment confirmation (see Payments below)
By design, the clinical review record excludes your contact details. Our intake pipeline keeps only the clinical fields listed above; email, phone, and address are removed from the review record at ingest. The original submission is preserved in a restricted-access archive for legally required record keeping.
Clinic staff Business contact details, clinic organization details (legal name, licensing and registration information), and role assignments.
Providers Name, email, NPI number, state licenses, credentialing details, and review activity (every decision is recorded with the deciding provider and time).
Payments Payments are processed by our payment processor ([Stripe]); MDside does not store card numbers. We receive confirmation of payment, not your full card details. [VERIFY before publishing - payments are not yet live.]
3. How we use information
- To provide the service: route your request to a licensed provider in your state, support their review, deliver the decision back to you and your clinic, and host the storefront.
- AI-assisted review preparation: before a licensed provider reviews a request, our system prepares a preliminary safety screen and a draft clinical note. Before any AI processing, the case is de-identified: your name is removed, your date of birth is converted to an age, and identifying patterns are redacted from free text. AI output never decides your request; every decision is made by a licensed provider.
- Security and compliance: we keep an append-only audit log of every access to health records (who viewed what, when, from which IP address), as HIPAA requires.
- Communications: transactional email only - sign-in codes, order and review status, account notices. We do not send marketing email without separate consent, and status emails are written to contain the minimum necessary (for example "your order has an update" plus a link, rather than medical details).
We do not sell personal information, use it for third-party advertising, or use third-party analytics trackers on our surfaces.
4. Who we share it with
Your clinic and its reviewing providers - they are providing your care.
Service providers that host and run the platform under contract:
Provider Purpose Neon Database hosting Vercel Application hosting and AI gateway (AI receives de-identified data only) Resend Transactional email delivery [Stripe] Payment processing [when payments launch] Legal: when required by law, subpoena, or to protect safety, and to regulators where applicable.
Business transfers: if MDside is acquired or merged, information may transfer with the business under the same protections.
We do not share your health information with data brokers, advertisers, or social media platforms.
5. How long we keep it
- Clinical records (intake submissions, review notes, decisions): retained for 7 years to meet medical record-keeping requirements. Records removed from active view are archived, never erased, during this period.
- Audit logs: retained as append-only records for HIPAA compliance.
- Account data: kept while your account is active and as needed for the retention above.
Because these retention periods are legal requirements, we cannot delete clinical records on request during the retention window, but they remain access-restricted and are used for no other purpose.
6. Security
- Encryption in transit on all surfaces; data stored with encryption at rest by our hosting providers [VERIFY provider configuration].
- Role-based access: clinic staff see only their clinic's records; providers see only requests they are licensed and authorized to review; internal access is role-gated and logged.
- Every access to a health record is written to an append-only audit log.
- API credentials are stored hashed; webhooks to clinics are signature-verified.
No system is perfectly secure. If a breach affects your information, we will notify the responsible clinic and, where required, you and regulators, as HIPAA and state law require.
7. Your rights
Health information: HIPAA gives you rights to access, amend, and receive an accounting of disclosures of your health records. Because your clinic is the responsible healthcare provider, please direct these requests to your clinic; MDside supports the clinic in fulfilling them.
State privacy rights: depending on where you live (for example California or Washington), you may have rights to access, correct, or delete personal information, and to know how it is shared. Contact us at [PRIVACY EMAIL] to exercise them; we will honor them subject to the legally required retention described above. We do not sell or share personal information for behavioral advertising, so there is nothing to opt out of on that front.
8. Cookies
We use only the cookies needed to keep you signed in (session cookies). We do not use advertising or analytics cookies.
9. Children
Our services are for adults 18 and older. We do not knowingly collect information from children under 18. [Attorney: confirm policy for parent/guardian-managed care if that becomes a supported flow.]
10. Changes
We will post changes here and update the effective date. For material changes affecting how we handle health information, we will notify account holders and, where acceptance is required, ask you to review and accept again.
11. Contact
MDside AI LLC [ADDRESS] [PRIVACY EMAIL] - privacy requests [SUPPORT EMAIL] - general support