Privacy Policy
Last Updated: May 4, 2026
Scribe EMR AI ("Scribe EMR AI," "we," "us," or "our") provides a healthcare documentation platform available through https://scribe_emr.globalhealthub.com and related services. This Privacy Policy explains how we collect, use, disclose, store, and protect personal information when people visit our website, request access to the service, create or use an account, or use Scribe EMR AI to create, review, export, and share clinical documentation.
This Privacy Policy is intended to be read together with any agreement between Scribe EMR AI and the healthcare organization, clinic, hospital, or practice using the service. If a separate written agreement applies, that agreement may contain additional terms about security, data processing, retention, and regulatory compliance.
1. Scope of this Privacy Policy
This Privacy Policy applies to:
- the Scribe EMR AI marketing site and application;
- account registration, authentication, and organization administration;
- patient and clinical information processed through the platform;
- documents uploaded to the Scribe EMR AI evidence and research assistant features;
- communications with us, including access requests, support, and legal or compliance inquiries; and
- integrations with third-party electronic medical record, electronic health record, practice management, and related systems where enabled.
This Privacy Policy does not apply to third-party websites, services, or systems that are linked to, integrated with, or accessible from Scribe EMR AI but operated by other organizations under their own privacy terms.
2. Our Role
Scribe EMR AI is a business-to-business healthcare technology service. Depending on the context, we may act in different privacy roles.
When we act on behalf of a healthcare organization
When a healthcare organization uses Scribe EMR AI to process patient records, recordings, transcripts, summaries, encounter documentation, coding suggestions, uploaded medical documents, or related clinical content, Scribe EMR AI generally acts as a service provider, processor, or similar contractor on behalf of that organization. In those cases:
- the healthcare organization controls the purpose of the clinical use;
- the healthcare organization is generally responsible for patient-facing notices, consent, authorization, and legal basis requirements; and
- we process the relevant information under the instructions of that organization and the applicable service agreement.
If you are a patient and your healthcare provider uses Scribe EMR AI, your provider remains the primary point of contact for questions about your care record, consent, access, correction, or deletion requests relating to that record.
When we act for our own operational purposes
Scribe EMR AI acts as the controller or equivalent business operator for information we use for our own legitimate business purposes, such as:
- operating the website and application;
- authenticating users and managing accounts;
- handling access requests, demos, onboarding, and support;
- administering customer relationships and contracts;
- securing the service and preventing misuse;
- maintaining logs, diagnostics, and service integrity; and
- complying with legal, regulatory, and contractual obligations.
3. The Information We Collect
We may collect the following categories of personal information, including sensitive information and health information where necessary for the service or where submitted by our healthcare customers.
Account, profile, and organization information
We may collect:
- name, work email address, phone number, and other contact information;
- login and authentication information, including one-time passcode requests and verification status;
- role, organization membership, specialty, affiliation, and profile details;
- profile information such as display name, biography, date of birth, gender, language, time zone, address, avatar, and social links;
- organization details such as practice or clinic name, logo, address, contact numbers, and organization email address; and
- information you provide when you request access, ask for a demo, contact support, or communicate with us.
Patient, encounter, and clinical information
Depending on how the service is used, we may process:
- patient identifiers and demographics, such as name, age, date of birth, sex or gender, address, email address, phone numbers, and blood group;
- medical and encounter information, such as past history, occupation, anthropometric data, visit dates, timestamps, and clinical context;
- audio and video files recorded or uploaded through the service;
- plain-text transcripts uploaded by users;
- transcripts created from recordings, including speaker labels and translated transcripts;
- structured notes, summaries, analyses, letters, and other documentation created or edited in the platform;
- coding and medication suggestions, confidence indicators, supporting evidence, and related review data;
- uploaded documents used with the evidence assistant, such as PDF, DOCX, or text files; and
- export content, document templates, logos, headers, footers, and delivery details used to create final documents.
Evidence assistant and user-generated content
If you use the research, evidence, or patient-context assistant features, we may process:
- chat session titles, messages, prompts, and question history;
- uploaded reference documents and patient-linked documents;
- cited sources, excerpts, and retrieval context used to answer your questions; and
- related activity history, including CPD or similar learning records where that feature is enabled.
Technical, device, and usage information
We may automatically collect information such as:
- IP address and approximate location derived from network activity;
- browser type, operating system, device identifiers, and session timestamps;
- application activity, error logs, crash data, diagnostics, and service performance information;
- account security events, sign-in attempts, organization switching events, and session expiry or revocation events; and
- audit, operational, and access logs associated with the use of the service.
Browser storage and session data
Scribe EMR AI uses browser-based storage that may contain account or application state, including:
- a secure session token or related authentication state;
- the active organization selection for multi-organization users;
- cached patient, template, and document metadata to improve performance; and
- local application preferences needed to operate the service.
Information from third parties
We may also receive information from:
- healthcare organizations that create accounts for their workforce;
- connected EMR, EHR, scheduling, practice management, or interoperability systems;
- users who upload files or enter information about patients or colleagues;
- fraud-prevention and security providers such as reCAPTCHA services; and
- service providers that help us deliver communications, infrastructure, and support.
4. How We Collect Information
We collect information:
- directly from you when you create an account, log in, request access, upload files, edit records, or contact us;
- from healthcare organizations that administer users, patients, and organizational settings;
- from devices and browsers when you use the website or application;
- through integrations you or your organization enable with third-party systems; and
- automatically through security, operational, and diagnostic processes needed to run the service.
For example, the platform may collect information when a clinician records a consultation through the browser microphone, uploads an audio, video, or text file for processing, creates or edits a patient record, uploads evidence documents, or exports or emails final documentation.
We generally hold personal information in hosted application databases, secure file or object storage, system logs, backups, and limited browser storage on user devices where needed to operate the service.
5. How We Use Information
We use personal information to:
- provide, operate, maintain, and secure Scribe EMR AI;
- authenticate users, manage sessions, and enforce role-based access controls;
- create, store, organize, display, and export clinical documentation;
- transcribe, translate, summarize, structure, and analyze recordings and uploaded content;
- support patient-context, evidence, and document-grounded assistant features;
- generate document previews and export files, including browser-based PDF and DOCX creation;
- send documents or communications at the direction of authorized users;
- administer organizations, users, templates, settings, and integrations;
- respond to support requests, access requests, sales inquiries, and legal inquiries;
- detect, prevent, investigate, and respond to misuse, fraud, unauthorized access, security incidents, and service reliability issues;
- comply with legal obligations, enforce agreements, and protect rights, safety, and property; and
- improve the safety, reliability, usability, and performance of the service, including through testing, troubleshooting, analytics, and de-identified or aggregated reporting where permitted by law and contract.
We do not sell patient data. We do not use patient data for advertising to consumers. We do not disclose personal information for cross-context behavioral advertising.
6. Legal Bases for Processing
Where data protection law requires us to identify a legal basis for processing, we generally rely on the following:
- performance of a contract, such as providing the Scribe EMR AI service, authenticating users, administering accounts, and delivering customer-requested features;
- legitimate interests, such as maintaining platform security, preventing misuse, improving service reliability, responding to customer inquiries, and running our business responsibly;
- legal obligations, such as compliance, recordkeeping, lawful disclosures, and regulatory response; and
- consent, where consent is required or where we ask for it directly.
When Scribe EMR AI processes patient or workforce information on behalf of a healthcare organization, that organization is generally responsible for determining the appropriate legal basis or authorization for the care-related processing it instructs us to perform.
7. AI and Automated Processing
Scribe EMR AI uses automated tools, including machine-learning and language-processing systems, to assist authorized users with healthcare documentation workflows. These tools may:
- convert recordings into transcripts;
- identify or separate speakers;
- translate transcripts into English where applicable;
- generate summaries, structured notes, and draft correspondence;
- suggest diagnostic or billing-related codes and related evidence; and
- answer questions using uploaded documents, patient-linked records, or other approved knowledge sources.
These features are designed to support human users, not replace clinical judgment. Scribe EMR AI is intended to assist documentation workflows. Clinicians and other authorized users remain responsible for reviewing, editing, approving, and deciding whether to use or share any output.
Where local law requires notice, consent, or additional safeguards for automated processing, the relevant healthcare organization is responsible for meeting those requirements for its patients and workforce, and we support that organization under our service relationship.
8. How We Disclose Information
We may disclose personal information in the following circumstances.
To the healthcare organization and its authorized users
We disclose information within the customer organization as needed to provide the service, subject to permissions, organizational scoping, and account roles.
To service providers and subprocessors
We may disclose information to vendors and contractors that support the service, including providers of:
- cloud hosting, storage, backup, and infrastructure;
- security, authentication, abuse prevention, and fraud detection;
- communications and email delivery;
- transcription, language, search, retrieval, and other AI-assisted processing;
- customer support, monitoring, and technical operations; and
- integration, interoperability, and document transmission services.
These providers are permitted to use the information only to perform services for us or for our customers, subject to contractual and legal restrictions.
To integrated third-party systems
If a customer enables EMR, EHR, practice-management, scheduling, interoperability, or other external integrations, we may send or receive information with those systems as necessary to provide the integration, import patient or appointment context, or export completed notes and related documentation.
To recipients chosen by users
If an authorized user uses the service to email or otherwise share a document, we disclose the selected content to the recipient chosen by that user.
For legal, security, and corporate purposes
We may disclose information if we reasonably believe disclosure is necessary to:
- comply with law, regulation, court order, subpoena, or lawful government request;
- enforce our agreements or protect the rights, privacy, safety, or property of Scribe EMR AI, our customers, patients, users, or others;
- investigate or prevent fraud, misuse, or security incidents; or
- support a merger, acquisition, financing, reorganization, sale of assets, or similar corporate transaction, subject to appropriate safeguards.
9. Cookies, Browser Storage, and Similar Technologies
Scribe EMR AI uses cookies and similar technologies that are necessary to operate the website and application. These may include:
- secure session cookies or similar browser tokens used to keep users signed in;
- local storage and session storage used to retain application state, organization context, and limited cached data;
- security technologies used to detect abusive traffic, bots, or unauthorized access attempts; and
- functionality tools required to display, secure, and operate the service.
The login experience may also use Google reCAPTCHA Enterprise or similar anti-abuse services. These tools may collect device, browser, and interaction information and may use cookies or similar technologies in accordance with the provider's own privacy practices.
Scribe EMR AI does not use the application to serve third-party advertising based on patient data.
10. Document Generation and Local Processing
Certain export features are designed to generate final documents in the user's browser rather than sending the content to a separate document-rendering service. This reduces unnecessary disclosure during export workflows. Even so, the underlying patient and clinical information may already be stored or processed within Scribe EMR AI as part of the broader service workflow.
11. Data Retention
We retain personal information for as long as reasonably necessary to provide the service, fulfill the purposes described in this Privacy Policy, comply with law, resolve disputes, enforce agreements, and maintain security and operational integrity.
Retention periods vary depending on the type of information and the customer's configuration, contract, and legal obligations. In general:
- account, profile, and organization information is retained while the account or customer relationship remains active and for a reasonable period afterward;
- clinical records, transcripts, uploaded files, generated notes, templates, and related documentation are retained according to customer instructions, service settings, contractual obligations, and applicable law;
- some information may be moved to an archived or recoverable state before permanent deletion;
- deleted or archived information may remain in backups, logs, or disaster-recovery systems for a limited period before being overwritten or securely removed; and
- access-request, support, and security records may be retained as needed for follow-up, legal compliance, fraud prevention, and audit purposes.
When we no longer need personal information, we will delete, de-identify, aggregate, or securely dispose of it as appropriate and as permitted by law and contract.
12. Security
We use administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, disclosure, alteration, or destruction. Depending on the service configuration, those safeguards may include:
- encryption in transit;
- encryption at rest for stored service data;
- role-based access controls and organization-level scoping;
- authentication controls and session-expiry handling;
- secure upload and storage mechanisms for recordings and files;
- logging, monitoring, and incident response processes; and
- access restrictions based on job role and operational need.
No method of transmission over the internet or method of electronic storage is completely secure. For that reason, we cannot guarantee absolute security, but we take reasonable steps designed to protect the information entrusted to us.
13. International Data Transfers
Scribe EMR AI may process or store personal information in countries other than the country in which the information was originally collected. This can happen because:
- a customer chooses a particular hosting or deployment region;
- our affiliates, personnel, or contractors operate in different locations; or
- our service providers or integration partners operate internationally.
Where cross-border transfers occur, we take reasonable steps to implement appropriate contractual, technical, and organizational safeguards required by applicable law.
14. Your Rights and Choices
Depending on where you live and the context in which we process your information, you may have rights to:
- request access to personal information;
- request correction of inaccurate or incomplete information;
- request deletion of information where deletion is available and legally permitted;
- object to or request restriction of certain processing;
- request portability of certain information;
- withdraw consent where processing is based on consent; and
- lodge a complaint with a regulator or supervisory authority.
If we process information on behalf of a healthcare organization, we may need to direct your request to that organization because it controls the relevant patient or workforce data. We will support our customer in responding where required by law or contract.
If we process the information for our own operational purposes, you may contact us directly using the details in the "Contact Us" section below.
15. Access and Correction Requests
If you would like to access, review, correct, or update your personal information:
- account holders may contact us directly or their organization administrator; and
- patients should generally contact the healthcare organization or provider that collected their information and uses Scribe EMR AI in connection with their care.
We may need to verify your identity before acting on a request. In some cases, applicable law may allow or require us to refuse or limit a request, such as where doing so would affect the rights of others, compromise security, or conflict with legal obligations.
16. Complaints
If you believe we have handled your personal information in a way that is inconsistent with this Privacy Policy or applicable law, you may contact us using the details below. We will review the matter and respond within a reasonable period.
If you are not satisfied with our response, you may also have the right to complain to the relevant privacy or data protection regulator in your jurisdiction, including:
- the Office of the Australian Information Commissioner, if Australian privacy law applies; or
- the supervisory authority in your country or region, if the GDPR, UK GDPR, or similar law applies.
17. Healthcare Privacy and HIPAA-Related Terms
Scribe EMR AI is not a substitute for a healthcare provider's own privacy notice, consent process, or legal obligations to patients.
For eligible U.S. healthcare customers, Scribe EMR AI may offer additional contractual commitments, including a Business Associate Agreement or similar health-data processing terms, where appropriate. Any such agreement supplements this Privacy Policy and helps define the parties' responsibilities for protected health information.
18. Children's Information
Scribe EMR AI is designed for use by healthcare organizations, clinicians, administrators, and other authorized workforce users. It is not intended for direct use by children.
Because healthcare providers may use the service in connection with care for children or minors, Scribe EMR AI may process pediatric patient information when that information is submitted by or on behalf of an authorized healthcare organization in accordance with applicable law.
19. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in the service, legal requirements, security practices, or business operations. When we make material changes, we will update the "Last updated" date above and, where required by law, provide additional notice.
20. Contact Us
If you have questions about this Privacy Policy or would like to submit a privacy request, please contact:
Email: foundersoffice@forgeitsystems.com
Website: scribe_emr.globalhealthub.com
If you are contacting us about patient or clinical information processed for a healthcare provider, please include the name of the provider or organization so we can route the request appropriately.
© 2026 Global Scribe Healthcare. All rights reserved.