Back
LeafNote

Privacy Policy

Last updated: March 5, 2026

1. Introduction

LeafNote Inc. (“LeafNote,” “we,” “us,” or “our”) is committed to protecting the privacy and security of your data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our clinical documentation platform.

2. Information We Collect

Account Information

  • Email address (for authentication and communication)
  • Full name (for account personalization)
  • Practice name (optional)
  • Payment information (processed by Stripe; we never store card numbers)
  • Browser-session metadata used to list and revoke active sessions

Clinical Data

  • Reviewed, Scrubbed Session Notes: Raw session notes remain in the active browser tab while supported identifier patterns are replaced and presented for review. The reviewed scrubbed version is submitted to our servers; automated detection can miss identifiers.
  • AI-Generated SOAP Notes: The structured clinical notes produced by our AI system.
  • Patient Pseudonyms: Coded labels you assign to organize records; names and contact details are prohibited.
  • Encrypted Draft Recovery: The browser can store a raw draft as AES-GCM ciphertext in IndexedDB for up to 24 hours under a non-extractable, browser-local key.

Optional Credentials and Group Practice Data

  • An optional Anthropic API key, encrypted on the server and never displayed again after it is saved.
  • Practice membership, roles, invitation email addresses, usage totals, retention settings, and ownership changes.
  • Information you submit in priority-support and onboarding requests.

Usage Data

  • Page views and conversion events (via privacy-focused analytics)
  • Note generation counts
  • Subscription and billing events

3. Zero-Trust Data Architecture

LeafNote employs a Zero-Trust security model for clinical data:

  • Client-Side PII Scrubbing: Supported formats for names, phone numbers, SSNs, email addresses, dates of birth, and physical addresses are flagged and redacted in your browser before transmission. You must review the preview because automated detection cannot identify every possible form of PII.
  • Server-Side Validation: A secondary PII scrubbing pass runs server-side as a safety net.
  • AES-256-GCM Encryption: All clinical text is encrypted at the application level before database storage.
  • Row-Level Security: Database access is isolated per user — therapists can only access their own records.
  • Application Data Minimization: Clinical text is not written to application logs or caches during AI processing. Provider retention is described separately below.

4. AI Data Processing

When you generate a SOAP note, your PII-scrubbed text is sent to Anthropic's Claude API for processing. Commercial API data is not used for model training by default. Provider retention depends on the active account configuration and agreement and may be up to 30 days unless an eligible zero-data-retention agreement applies.

5. How We Use Your Information

  • To provide and maintain the clinical documentation service
  • To process your subscription and billing
  • To send transactional emails (welcome, password reset, billing)
  • To improve the platform based on aggregated, non-identifying usage metrics
  • To comply with legal obligations

6. Data Sharing

We do not sell your data. We share data only with:

  • Supabase: Database hosting and authentication. The production region and HIPAA configuration must be verified before clinical use.
  • Anthropic: AI processing under the retention and training terms of the active commercial agreement
  • Stripe: Payment processing (PCI DSS Level 1 compliant)
  • Vercel: Application hosting (SOC 2 compliant)
  • Resend: Transactional Group Practice invitation delivery, including the invitation recipient and secure invitation URL

7. Data Retention

Your clinical data is retained while your account is active. Notes have a 30-day delete-and-restore window. You can schedule account deletion after password verification and cancel it during the 30-day recovery period; after the due date, the maintenance process permanently removes the account and encrypted clinical data while retaining required security audit records. Group Practice owners can also set a practice retention period that moves older notes into the same recoverable-deletion workflow.

8. Your Rights

  • Access: You can download a complete portable JSON archive of your account data, including your recoverable clinical records and revision history, from Settings.
  • Correction: You can edit generated SOAP notes; each save creates an encrypted revision, and finalization is an explicit action.
  • Deletion: You can delete and restore individual notes for 30 days, or schedule recoverable account deletion from Settings.
  • Portability: You can export the complete account archive as JSON and the current version of active SOAP notes as CSV.

9. HIPAA Considerations

LeafNote is designed with HIPAA-conscious security measures. We implement technical safeguards including encryption, access controls, audit logging, and automatic session timeouts. Clinical use requires confirmed Business Associate Agreements and compliant configurations with each service provider; these must be verified before launch.

10. Analytics & Tracking

We use privacy-focused analytics to understand conversion flows. We explicitly disable all analytics, session recording, and keystroke tracking on clinical workspace pages to support the documented privacy boundary.

11. Cookies

We use only essential cookies required for authentication and session management. We do not use advertising cookies or cross-site tracking.

12. Data Residency

Production data residency depends on the configured Supabase and hosting regions. The selected regions and any cross-border processing must be verified and documented before clinical launch.

13. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated via email at least 30 days in advance.

14. Contact

For privacy inquiries or data requests, contact us at privacy@leafnote.ai.