Privacy Policy
Effective Date: September 10, 2026·Version 2.10
MyPrechart (myprechart.co) is a home health documentation SaaS app operated by MyPrechart LLC, a Texas limited liability company based in Haltom City, TX 76117. This Privacy Policy explains how we collect, use, and protect information when you use MyPrechart.
Our users are licensed home health registered nurses and case managers. This policy is written in plain language because we know you are clinicians, not lawyers.
Data We Collect
- Account data: name, email address, professional credentials, and payment information. Payment details are handled by Stripe, or by Apple for iOS in-app purchases — we never see or store your credit card numbers. If you submit the agency contact form on our website, we also store the name, job title, agency name, nurse count, email address, phone number, and notes you provide. If you sign up through a referral link, we store which account referred you.
- Clinical inputs: patient visit data and other clinical details you enter into the app to generate documentation narratives.
- Wound care photos: uploaded temporarily for AI analysis only and never stored in our database.
- Operational telemetry: we do not use any page-view analytics, product analytics, or session replay tooling. What we do record is limited to voice session timing and error metrics (session length, turn counts, and error categories, with no transcript or clinical text), counters for how often each AI operation is called, and server error logs from our processing infrastructure.
- Voice conversation audio: when you start a voice conversation, your microphone audio is streamed live to Amazon Nova Sonic on AWS Bedrock (US East region) through our own server, and the spoken reply is streamed back. Audio is processed in the moment and is not recorded, written to a database, or kept in logs by us. A voice session ends automatically after 20 minutes. Spoken replies are cached on your device only, so the same sentence is not re-synthesized, and are cleared with app storage.
- Phrase requests: if a smart phrase search returns nothing and you tap "Request this phrase," we store the words you typed in the search box, the visit type selected on the form, and the time, so we can consider adding that phrase. Nothing is sent unless you tap. Do not include patient identifiers in a search term.
- Local interface settings: your light, dark, or automatic appearance choice is saved in your browser or app storage on your device, under the key
myprechart.ui.theme, so the app opens in the appearance you picked. It holds only the wordslight,dark, orauto. It contains no health information and nothing that identifies you, it is never sent to our servers, and clearing your browser or app storage removes it.
What We Do Not Store
New notes, drafts, queued requests, visit details, and custom wording are held only in the current app session. Reloading, closing the app, signing out, or changing accounts removes this new work. Copy finished notes into your agency's EMR before leaving. Older records already saved on this device remain unchanged and are available through explicit, read-only recovery; they are not loaded or sent automatically.
Clinical content sent for narrative generation passes through our AWS processing infrastructure in memory only and is not written to any database or log. Wound care photos are processed transiently and are never written to our database or to any storage bucket.
We do not sell, share, or use your data to train AI models.
How We Use Your Information
We use your information to provide the MyPrechart service, process your subscription payments, send you account and billing notifications, and improve the app's reliability and usability. We do not sell your personal information to any third party.
AI Processing
MyPrechart uses Claude AI by Anthropic via AWS Bedrock to generate documentation narratives, AWS Polly for spoken output, and Amazon Nova Sonic for voice conversation with the clinical assistant. Dictation-based speech-to-text is not currently offered in the app. Clinical inputs you enter are transmitted to these AWS services for processing and are not stored by us after generation. AI output must be reviewed, verified, edited, and signed by the licensed clinician of record before clinical use.
The in-app disclosure you agree to before any AI feature runs reads as follows, and this page states it in the same words:
- What is sent: When you generate, correct, or dictate documentation, what leaves your device is the visit type and date, diagnoses and comorbidities, vitals, assessment findings, wound details, medications, teaching and plan entries, anything you type or dictate in your own words, any photograph you attach, anything you type into the clinical chat, and your microphone audio while a voice session is active.
- Who receives it: It travels over an encrypted connection to MyPrechart's own processing server in the United States, which passes it to Amazon Web Services: Bedrock running Claude by Anthropic for text and photographs, Amazon Nova Sonic for voice conversation, and Amazon Polly for spoken output. AWS operates under a signed HIPAA Business Associate Agreement with MyPrechart. One lookup goes elsewhere: a diagnosis code search sends the search term only to the U.S. National Library of Medicine, and the app blocks that lookup when the term looks like a patient identifier.
- What we do not do: We do not write your clinical content to our database or to our logs, we do not use it to train AI models, we do not sell it, we do not share it with anyone beyond the processing providers named above, and we do not keep finished notes on our servers. Clinical content is held in memory for the length of the request and then discarded.
- Your part: We do not ask for and do not need direct patient identifiers, and you agreed at sign-up not to enter them. The app does not remove identifiers for you — clinical text is transmitted exactly as you typed it, so what you leave out is what stays out.
- Your choice: Nothing is sent until you tap Agree and continue. You can turn AI features off again at any time in Settings > Data & AI, and the rest of the app keeps working without them.
Photographs are their own data class. A wound photograph or a photograph of a document you attach is transmitted to AWS Bedrock for analysis in the same request path as clinical text. Photographs are processed transiently, are never written to our database or to any storage bucket, and are not used to train AI models.
Every third party that receives clinical content on our behalf is contractually required to provide protections for that content equal to or greater than the protections we provide ourselves.
Enter only the minimum patient information necessary to generate your documentation. MyPrechart does not automatically detect, strip, or scrub patient identifiers from the clinical text you enter, so the text is transmitted as you typed it. You are responsible for limiting what you enter.
Your consent is required first. Before any clinical content leaves your device for AI processing, MyPrechart shows you a disclosure explaining what is sent, where it goes, and that AWS operates under a signed Business Associate Agreement with MyPrechart and provides HIPAA-equivalent protections for this data. No clinical data is transmitted to any AI service until you agree. If you decline, the app keeps working — you can still fill out visit forms, use templates, smart phrases, and the reference library — but the features that require AI, including narrative generation, narrative correction, SBAR, homebound statements, risk analysis, wound photo analysis, spoken output, and voice conversation, stay switched off.
You can change your mind at any time. Go to Settings > Data & AI to see your current choice and to turn AI features off or back on. Turning them off takes effect on the device you turn it off on right away — even with no connection — and blocks further transmission to AI services from that device. Other devices and other browser sessions apply the change the next time they can read your setting. It cannot recall information that was already sent before you turned it off, and it does not delete documentation already on your device. If we materially change this disclosure, we ask for your agreement again before AI features resume.
HIPAA Business Associate Status
MyPrechart LLC operates as a Business Associate under HIPAA. A HIPAA Business Associate Agreement is in place with Amazon Web Services, our cloud infrastructure provider, covering the HIPAA-eligible AWS services we use to process protected health information. AWS provides HIPAA-equivalent protections for this data under that agreement.
Two destinations sit outside that AWS agreement, and we name them rather than imply blanket coverage. The first is the U.S. National Library of Medicine's public diagnosis code lookup, described below, which receives a diagnosis search term only, and only for a term the app's built-in code list does not contain. The second is Supabase, which hosts your account, billing, and team data, your saved templates, smart phrases, procedures, and charting preferences, your acknowledgment and referral records, and the operational counters described under Data Retention. It holds no clinical documentation: clinical documentation is stored only on the device you are working on, in the app's local database, and there is no server-side copy of your clinical documentation of any kind, short-lived or otherwise.
Users, as covered entities or their business associates, remain responsible for their own HIPAA obligations, including proper use of the app, securing their account credentials, and reviewing AI-generated documentation before clinical use. Our breach notification procedures follow HIPAA requirements.
Third-Party Services
We use the following third-party services to operate MyPrechart:
- Amazon Web Services: cloud infrastructure, AI inference (Bedrock/Claude), voice synthesis (Polly), voice conversation (Nova Sonic), container compute, load balancing, and operational logging. Covered by an executed Business Associate Agreement for the HIPAA-eligible services we use.
- Supabase: authentication, application database, edge functions, and email queue infrastructure. It holds your account, billing, and team data, your saved templates, smart phrases, procedures, and charting preferences, your acknowledgment and referral records, and the operational counters described under Data Retention. It holds no clinical documentation: clinical documentation is stored only on the device you are working on, in the app's local database, and there is no server-side copy of your clinical documentation of any kind, short-lived or otherwise.
- Stripe: payment processing and subscription management for subscriptions purchased on the website.
- Lovable email delivery: sends account, billing, and team notification emails from our notify.myprechart.co domain. It receives your email address, your first name, and the contents of those account emails. No clinical content is ever included in an email.
- Google Workspace: business email, calendar, and collaboration tooling used for account and billing notifications and for support correspondence. It receives the contents of email you send to or receive from us. No clinical content is routed through email by design, but because we cannot control what a user chooses to send us, a HIPAA Business Associate Agreement is in place with Google covering the HIPAA-eligible Google Workspace services we use.
- Apple: payment processing and subscription management for in-app purchases made in the iOS app. Apple provides us a transaction identifier and subscription status; we never receive your payment details.
- Lovable: application hosting, deployment, and source repository.
- Diagnosis code lookup happens on your device. The ICD-10-CM FY2026 code list is bundled into the app and searched locally. Earlier versions of the app sent a term the bundled list did not contain to a public U.S. government code-lookup service (clinicaltables.nlm.nih.gov), first from your browser and later by way of our own server. That path has been removed: no diagnosis term you type is sent to any outside service, and a term the bundled list does not contain simply shows no results. The diagnosis field still accepts anything you type, so charting is never blocked. Terms searched in earlier app versions may still appear in that service's historical access logs; we cannot remove them.
These services have their own privacy policies and security practices.
Texas-Specific Protections
We comply with the Texas Medical Records Privacy Act (Texas Health & Safety Code Chapter 181, commonly known as HB 300), which provides privacy protections for medical records that are often stricter than federal HIPAA rules.
All patient data associated with Texas residents is processed within the United States. MyPrechart does not integrate with any electronic health record system.
As required by Texas SB 1188, we disclose that clinical documentation generated in MyPrechart is created with the assistance of artificial intelligence and must be reviewed and approved by a licensed clinician before use.
Data Security
We use encrypted connections (TLS 1.2 or higher) for all traffic, row-level security on account data, strict access controls, and optional two-factor authentication (TOTP) that you can enable on your account from account settings. Once you have enrolled TOTP, the app requires the second factor again when a stored session is resumed, rather than trusting the stored session on its own, and the app signs you out automatically after 15 minutes of inactivity. Encryption at rest for data on our servers is provided by our managed platforms, Supabase and Amazon Web Services.
Clinical documentation stored on your device is not encrypted by the app itself. The app applies no application-layer encryption to its local browser or app storage (IndexedDB); that data relies on your device's own disk encryption and, in the iOS app, on the optional Face ID or Touch ID app lock if you have enabled it. In a web browser there is no app-level lock. You are therefore responsible for device-level security, including a device passcode or biometric lock and platform full-disk encryption.
Data Retention
We retain your account information for as long as your account is active. New notes, drafts, queued requests, visit details, and custom wording are held only in the current app session. Reloading, closing the app, signing out, or changing accounts removes this new work. Copy finished notes into your agency's EMR before leaving. Older records already saved on this device remain unchanged and are available through explicit, read-only recovery; they are not loaded or sent automatically. Deleting your account from the app removes your account record, your preferences, templates, smart phrases, procedures, device registrations, notifications and charting counters, and it deletes the clinical documentation stored on the device you delete from. Clinical documentation you saved on any other device is not reached by that deletion and must be cleared from that device. On the device you delete from, we remove your own notes, drafts and pending offline notes. Anything stored there before we began recording which account owns it, or belonging to a different account, is deliberately left alone rather than guessed at — we will not delete a colleague's pending work on a shared device. If that applies, the app tells you plainly at the time so you can clear the app's storage yourself.
Operational telemetry on our servers is retained on fixed schedules: voice session timing and error metrics are retained for 30 days, and the per-operation AI usage records used for quota metering are retained for 30 days. Both are ordinarily deleted automatically by a scheduled job. Separately, an audit log records each AI operation your account runs — the operation name, a character count, a processing time, and the time it ran, with no clinical text — along with consent events. That audit log has no automatic expiry and is retained indefinitely unless we delete it.
Automatic deletion may be suspended. Where we are subject to a legal hold, a preservation obligation, or an open regulatory or legal matter, scheduled deletion is paused and the affected records are retained until that obligation is released. During any such period the retention schedules above do not apply, and data is kept longer than the periods stated. This does not change what we collect, and it does not apply to clinical documentation, which is never stored on our servers in any case.
Your Rights
You may update your email and password from account settings at any time. You may delete your account from account settings. Deletion is not accepted unless we can first confirm and cancel any subscription we bill, so you are never left paying for an account you cannot reach; an Apple subscription must be cancelled by you in Settings on your iPhone, because only the Apple ID holder can cancel it. A small set of records survives deletion, because they are our own business, security and legal-acceptance records rather than a copy of your work: your record of accepting these terms and our policy versions, our security and AI audit logs, your signup record, your training attestation, and our email and billing records. Because your profile is removed with your account, we also keep a small record of your name, email address and signup date attached to those retained records, with a note of where it came from and why — without it they name nobody and cannot show what they exist to show. It contains no clinical documentation and is not readable from the app by anyone. We keep those to show what was agreed, to investigate security events and to meet tax and accounting requirements — not because any law obliges us to keep every one of them indefinitely, and we will delete any of them where we are free to and you ask us to. Clinical documentation saved on another device must be deleted from that device. Data deletion requests are fulfilled within 30 days.
For any other requests, contact info@myprechart.co.
Patient Requests
MyPrechart does not hold patient records. Clinical documentation lives on the clinician's device and is entered into the agency's system of record, so we cannot look up, produce, amend, or account for disclosures of any individual patient's information. If a patient or their representative sends us a request about their records, we will refer it to the home health agency that holds those records — the covered entity — and ask the clinician's employer to route it.
Contact
MyPrechart LLC, info@myprechart.co, myprechart.co.
