Privacy Policy

Effective and last updated: August 21, 2026 · Pre-pilot beta version 3.0

Pre-pilot beta evaluated with synthetic, fully fictional cases only. Do not enter real patient information. MedScribe is not affiliated with or endorsed by any hospital or health system. All outputs are drafts that require clinician review.

1. Current product and data boundary

MedScribe is a working pre-pilot beta for bilingual hospitalist documentation, operated by Borinquen Health Tech LLC. Its current evaluation is limited to synthetic, fully fictional cases. It is not deployed in a hospital and is not connected directly to an EHR.

Do not enter real patient information, patient recordings, identifiers, or facts from an actual clinical encounter.

2. Information the beta may collect

  • Account information such as your name, email address, username, specialty selection, language preference, and password hash.
  • Synthetic text or audio you intentionally submit, along with the structured draft, note type, language, and draft history produced from it.
  • Authentication, security, support, and operational records such as timestamps, defined account actions, error categories, and network metadata.
  • Subscription status and provider identifiers if account billing is enabled. Payment-card details are handled by the payment provider, not stored by MedScribe.

The current beta is not intended to collect real patient information. If you enter prohibited data despite this policy, stop using the beta and contact us so the incident can be reviewed.

3. How information is used

We use submitted information to authenticate accounts, transcribe synthetic audio when requested, generate and store structured drafts, run deterministic checks, support manual exports, troubleshoot the beta, and protect the service from abuse. We do not sell submitted content or use it for advertising.

Service providers may process the minimum information needed for hosting, model inference, audio transcription, email, security, or billing. This public policy does not publish vendor agreements, certificates, account identifiers, or other internal contracting material.

4. Implemented technical controls

The current repository implements password hashing, authenticated access, token revocation, rate limits on selected endpoints, audit events for defined actions, encrypted transport in the configured web deployment, pattern-based identifier reduction, and deterministic documentation checks. These controls reduce specific risks but do not detect every identifier, guarantee draft accuracy, or make real patient data acceptable in the current beta.

5. Storage, retention, and deletion

Synthetic inputs, drafts, account records, and operational records may be retained while an account is active and in backups or logs for limited operational periods. Retention depends on the record type and configured service. The interface may support soft deletion; that action is not a representation that every backup or required operational record is erased immediately.

To request account access, correction, or deletion, email privacy@medscribepr.com. Requests are reviewed against applicable technical, contractual, and legal retention requirements.

6. Your responsibilities

Use a unique password, protect your account, submit only fully fictional cases, independently review every draft, and do not treat automated checks as clinical, legal, privacy, coding, or security approval.

7. Changes and contact

We may update this policy as the product boundary changes. A future hospital deployment or real-patient workflow would require a separate policy, institutional authorization, contracting, and security review; none is represented by this page. Questions may be sent to privacy@medscribepr.com.