← Back to DocApps

Privacy Policy

Effective date: Not yet in effect — pending legal review · Drafted 2026-07-26

Draft — pending legal review. This document has been prepared for review by counsel and is not yet in effect. It may contain bracketed placeholders. Do not rely on it as a statement of our current obligations. Questions? support@docapps.ai.

This Privacy Policy explains how Praxis Health Labs (“we”, “us”) collects, uses, shares and protects information in connection with DocApps, the practice growth suite for medical practices and part of the DocApps suite (the “Service”).

Our customers are medical practices and the people who work in them. In most cases the practice is our customer and controls the information in its account; where the Service processes patient information, the practice remains responsible for that information and we act on its instructions.

1. Summary

  • We collect the account and practice details you give us, the content you create or upload in the Service, and technical records generated when you use it.
  • We use that information to operate the Service, to support and secure it, and to bill you.
  • We do not sell your information, and we do not use your content or patient information to train generative AI models.
  • We use a small number of vendors to run the Service. They are listed by name below.
  • Our default is to retain your content until you delete it or close your account.

2. Information we collect

Information you provide

  • Account information: name, email address, and password credentials (handled by our authentication provider — we do not store your password).
  • Practice information: practice name, contact details, address, logo, colours, specialties, and team members you invite.
  • Billing information: your plan and billing contact. Payment-card details go directly to our payment processor; we do not receive or store full card numbers.
  • Support and correspondence: messages you send us, including anything you choose to include in them.
  • Suite content: the products your practice has enabled, your team roster and their roles, and the integrations you connect.

Information from connected accounts

If you connect a third-party account — for example a review platform, social network, or electronic health record system — we receive the access credentials and the data that connection is scoped to, and only for as long as the connection remains active. You can disconnect at any time in the Service's settings; disconnecting stops future access but does not by itself delete data already retrieved.

Information collected automatically

  • Log and diagnostic data: IP address, browser and device type, pages and features used, timestamps, and error reports.
  • Security records: sign-in events, authentication failures, and rate-limiting counters used to detect and prevent abuse.
  • Cookies and similar technologies used to keep you signed in and to remember preferences. We do not use advertising cookies or third-party ad trackers in the Service.

3. How we use information

  • To provide, operate and maintain the Service, including generating the output you ask for.
  • To authenticate you, enforce access controls, and keep the Service secure.
  • To bill you and manage your subscription.
  • To respond to your support requests and to communicate about service changes, incidents and security matters.
  • To monitor performance and reliability, diagnose faults, and improve the Service.
  • To comply with law and to enforce our agreements.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising.

4. Artificial intelligence processing

Parts of the Service use generative AI and speech-to-text to draft content for you. Where that happens, the content you submit is sent to our AI provider for processing and the result is returned to your account.

  • AI processing runs on Google Cloud Vertex AI, under our enterprise agreement with Google.
  • Your content and any patient information are not used to train generative AI models, ours or our providers’.
  • AI output is a draft. It can be wrong, incomplete, or inappropriate for a particular patient, and a qualified person must review it before it is relied on or shared. This is a condition of using the Service — see the Terms of Service.

5. How we share information

We share information only as described here. Each vendor below processes information on our behalf, under contract, and is not permitted to use it for its own purposes.

  • Google Cloud Platform / Firebase — Hosting, authentication, database (Firestore), file storage, serverless functions, and logging. Primary infrastructure for every product.
  • Google Cloud Vertex AI — Generative AI processing for drafting and summarisation features, and speech-to-text transcription.
  • Stripe — Payment processing and subscription billing. Stripe receives payment-card details directly; we do not receive or store full card numbers.
  • Emailit — Transactional and notification email delivery.

We may also disclose information:

  • To comply with law, legal process, or a lawful government request, and to establish or defend legal claims.
  • To protect the rights, property or safety of our customers, the public, or us — including to investigate fraud or a security incident.
  • In connection with a merger, acquisition, financing or sale of assets, subject to the acquirer honouring this policy for information transferred.
  • With your direction or consent.

6. Protected Health Information and HIPAA (where applicable)

Where a practice uses the Service to create, receive, maintain or transmit Protected Health Information (“PHI”) as defined by the Health Insurance Portability and Accountability Act (“HIPAA”), the practice is the Covered Entity and we act as its Business Associate.

A Business Associate Agreement (“BAA”) must be executed before PHI is submitted to the Service. Do not submit PHI until a BAA is in place between your practice and Praxis Health Labs. Where a BAA is in effect, its terms govern our handling of PHI and control over any conflicting term in this Policy.

Under that arrangement we:

  • Use and disclose PHI only as the BAA permits, as you direct, or as law requires.
  • Apply administrative, physical and technical safeguards designed to protect PHI.
  • Require our subcontractors that handle PHI to give equivalent protections.
  • Report to you any use or disclosure not permitted by the BAA, and any breach of unsecured PHI, within the timeframes the BAA specifies.
  • Make PHI available so you can meet your access, amendment and accounting obligations to patients.

We are not a healthcare provider and do not have a treatment relationship with your patients. Patients who want to exercise rights over their health information should contact their practice, which is the entity responsible for those records.

7. How long we keep information

Our default is to retain your content until you delete it or close your account. We do not automatically age out clinical or patient-related records; deletion happens when you or your practice administrator deletes the underlying item, or when you ask us to close the account.

  • Content and records you create: retained until deleted by you or on account closure.
  • Short-lived operational records — background job status and rate-limiting counters — are deleted automatically approximately 30 days after they expire.
  • Backups and point-in-time recovery snapshots persist for a limited window after deletion (currently 7 days of point-in-time recovery, daily backups retained 7 days, weekly backups retained 14 weeks) before ageing out.
  • Account, billing and security records are retained as long as needed for legal, tax, audit and dispute-resolution purposes.

Deleting an item removes it from the Service; residual copies may remain in backups until those backups expire on the schedule above.

8. Security

  • Information is encrypted in transit (TLS) and at rest by our infrastructure provider.
  • Access is scoped to your account and your practice, enforced on the server, and re-checked on every request rather than trusted from the browser.
  • Administrative access is restricted to personnel who need it, and privileged operations are logged.
  • We maintain backups and point-in-time recovery, and we test our recovery procedure.
  • We monitor for errors and anomalous activity and alert on them.

No system is perfectly secure. If we become aware of a breach affecting your information, we will notify you as required by law and — where a BAA applies — on the terms it sets.

9. Your choices and rights

You can review and update most account and practice information directly in the Service's settings, disconnect third-party integrations, and delete content you have created. To request access to, correction of, export of, or deletion of information we hold about you, contact us at support@docapps.ai.

If you are a member of a practice, some requests are directed to the practice, since it controls its account and its records. If you are a patient, contact the practice that treated you.

US state privacy rights

Depending on where you live, you may have the right to know what personal information we collect and how we use it, to request access, correction, deletion or a portable copy, and to be free from discrimination for exercising these rights. We do not sell personal information or share it for cross-context behavioural advertising, so no opt-out is required. To exercise a right, use the contact details in section 12; we will verify your request before acting on it, and you may use an authorised agent where the law allows. Much health information is governed by HIPAA rather than state consumer-privacy law, and is handled under section 6.

10. Children

The Service is intended for use by medical practices and their staff and is not directed to children. We do not knowingly collect personal information directly from children as users of the Service. Patient records a practice maintains — which may relate to minors — are handled as PHI under section 6, on the practice's instructions.

11. Where information is processed

The Service is operated from the United States and information is processed and stored there. If you access the Service from outside the United States, you are transferring information to the United States, where privacy laws may differ from those in your jurisdiction.

12. Changes and contact

We may update this Policy. If a change is material we will give notice through the Service or by email before it takes effect, and we will update the date shown at the top of this page.

Questions, requests, or privacy concerns: support@docapps.ai, or Praxis Health Labs, [REGISTERED ADDRESS], [STATE].