Docipal
  • Features
  • How it works
  • Pricing
  • Security
  • FAQ
Sign inSign up

Privacy Policy

Last updated: August 30, 2026

Docipal (“Docipal”, “we”, “us”) provides an AI-powered clinical documentation platform consisting of our mobile apps, web application, browser extension, and this website (together, the “Service”). This Privacy Policy explains what information we collect, how we use it, and the choices you have. It applies to clinicians and staff who use Docipal and to visitors of this website.

1. Information we collect

Account information

When you create an account we collect your name, email address, profile photo (optional), and workspace membership details such as your organization and role.

Patient information processed on your behalf

When you use Docipal to document a visit, we process information on behalf of you or your organization, including audio recordings of patient visits, transcripts, generated clinical notes, and patient demographic details you enter (such as name, date of birth, and medical record number). This information may include protected health information (“PHI”). Recording begins only after you explicitly start a session and grant microphone permission.

Payment information

Subscription payments are processed by Stripe. We do not store your full card details; we receive limited billing information such as plan, payment status, and the last digits of your card.

Usage and device information

We collect logs and technical data needed to operate and secure the Service (such as IP address, device and browser type, and feature usage). Our marketing website uses Google Analytics to understand aggregate visitor traffic; our clinical applications do not send patient information to analytics tools.

2. How we use information

  • To provide the Service: recording, transcription, and generation of clinical notes in your chosen templates.
  • To operate your workspace: authentication, role-based access, and organization-level data isolation.
  • To process subscriptions, provide support, and communicate service updates.
  • To secure the Service, prevent abuse, and comply with legal obligations.

Transcription and note drafting are performed with the help of third-party AI providers named in Section 4. Before any visit data is shared with these providers, the Docipal apps display an in-app disclosure describing what is sent and to whom, and require your explicit agreement.

We do not sell personal information, and we do not use patient information to train general-purpose AI models; our AI providers are contractually prohibited from using it to train theirs.

3. HIPAA

Where Docipal processes PHI on behalf of a covered entity, we act as a business associate. We enter into Business Associate Agreements (BAAs) with organizations that require them and maintain administrative, technical, and physical safeguards appropriate for PHI, including encryption in transit, access controls, audit logging, and per-organization data isolation enforced at our API layer.

4. How we share information

We share information only with service providers who help us operate the Service:

  • Cloud hosting and storage (Amazon Web Services).
  • Speech-to-text: visit audio recordings are sent to Groq, Inc. to be transcribed.
  • Clinical note drafting: transcripts and visit details are processed by Anthropic Claude models running on Amazon Bedrock (Amazon Web Services) to draft notes and clinical insights.
  • Payment processing (Stripe) and identity/authentication services.
  • Analytics for the marketing website only (Google Analytics).

These AI providers act as our processors: they are bound by confidentiality and data-processing obligations that provide protection equal to or greater than this policy, may use the data only to provide the service to us, and do not use it to train their models.

We may also disclose information if required by law, or in connection with a merger or acquisition, in which case this policy will continue to apply to your information.

5. Data retention and deletion

We retain account and clinical documentation data for as long as your account or your organization’s workspace is active, and as required by applicable law. Organization administrators control their workspace’s data. You may request deletion of your account or workspace data by contacting us; we will honor requests subject to legal and contractual retention obligations.

6. Security

We use industry-standard safeguards including TLS encryption in transit, encrypted storage, OAuth 2.0 authentication with short-lived tokens, role-based access control, and audit logging. No system is perfectly secure; we encourage you to use strong credentials and to report any suspected vulnerability to us.

7. Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise these rights, contact us using the details below. If you are a patient whose information was processed by a clinician using Docipal, please direct requests to your healthcare provider, who controls that record; we will assist them in fulfilling your request.

8. Children

The Service is intended for use by healthcare professionals and is not directed to children. Patient records concerning minors are processed solely on behalf of the treating provider.

9. Changes to this policy

We may update this policy from time to time. We will post the updated version here and update the “Last updated” date; material changes will be communicated through the Service.

10. Contact us

Questions or requests about privacy can be sent to privacy@docipal.com.

Docipal

The AI medical scribe that turns
patient visits into finished notes.

Product
FeaturesHow it worksBrowser extensionPricingSign upiOS app
Company
Sign inContact
Legal
Privacy policyTerms of serviceSecurity

© 2026 Docipal. All rights reserved.

Made for clinicians who’d rather be with patients than paperwork.