This Privacy Policy explains how palmER Worldwide LLC, doing business as palmER ("palmER," "we," "us," or "our"), collects, uses, and protects personal information through our apps, website, and related services. If you handle Protected Health Information, palmER applies the safeguards and use restrictions in the standardized Business Associate Agreement in Schedule A to our Terms of Service (the "BAA"). Once accepted as described in the Terms, the BAA governs the parties' obligations regarding PHI and controls any conflict with this Privacy Policy regarding PHI.
Personal information is any information about you which can be used to identify you. This includes your name and email address, device identifiers, payment details, and usage data. Separately, any patient information you submit through the services may constitute Protected Health Information (PHI) as defined at 45 CFR 160.103, and we apply the BAA's safeguards and use restrictions to it.
Please also review our Terms of Service. By using our services, you agree to be bound by both this Privacy Policy and our Terms of Service.
Information We Collect
We collect information in two categories: voluntarily provided and automatically collected.
Voluntarily provided is information you knowingly provide when using our services. Examples: account registration details, profile info, support requests, and content you upload or paste, including clinical text if you choose to handle PHI.
Automatically collected is information sent by your device while accessing our services. Examples: IP address, device and browser type, operating system, app version, pages and screens viewed, actions taken, timestamps, error and crash data.
Log and Device Data
When you access our services, we log technical and usage data such as IP, device type, app version, actions taken, date and time, and error details. This helps us operate, secure, and improve the services.
Account Security and HIPAA Compliance
Protecting health information and securing the services requires us to monitor how accounts are accessed and used. As part of our security program and our safeguards as a HIPAA Business Associate, we maintain audit logging and access controls and monitor account and system activity, consistent with the audit control and unique user identification requirements of the HIPAA Security Rule (45 CFR 164.312).
This monitoring relies on technical and behavioral measures, including device fingerprinting, IP address information, and analysis of how the service is used, together with signals such as concurrent or overlapping sessions, access from different devices or locations, and activity inconsistent with a single user. These measures help us safeguard protected health information and accounts, maintain a reliable audit trail, confirm that each account is used by a single, named individual as required by our Terms, verify eligibility for free trials and Discounted Pricing, and identify and investigate security incidents or misuse.
We carry out this processing on the basis of our legitimate interests in protecting the services and our users, to fulfill our obligations as a Business Associate, and to comply with applicable law and our Terms of Service.
Device Permissions
Our apps may request access to device capabilities you choose to use. What we can access depends on your device settings and the permissions you grant.
For example, ambient scribing, transcription, and related documentation features may require access to your microphone. When you choose to use these features, we may process audio, transcripts, derived text, and related clinical content to provide transcription, documentation generation, note generation, chart analysis, consult scripting, and related services. If that content includes Protected Health Information, it is handled in accordance with the BAA.
Audio from ambient scribing is ephemeral. It is transcribed and then immediately discarded after processing. No audio is ever stored on our servers or sent to any third party, and no one, including us, can listen to any encounter. The transcripts and derived clinical content generated from that audio are handled as described in this policy and, where they include Protected Health Information, in accordance with the BAA.
Our apps do not request access to your device location, and we do not collect precise geolocation.
You can manage device permissions through your device or browser settings. Some features may not function if required permissions are disabled.
Personal Information We May Request
We may ask for personal information, for example, when you register an account or when you contact us, which may include one or more of the following:
- Name
- Phone/mobile number
- Eligibility or training-status information (for example, an institutional or program email address, training program, role, or expected training completion date) when you request or hold Discounted Pricing
- Verification documents or links you submit to confirm eligibility for Discounted Pricing, such as a training badge, student ID, program letter, or a link to an official program page. We use these only to confirm eligibility and delete uploaded documents immediately after we complete verification.
Legitimate Reasons for Processing
We only collect and use your personal information where we have a legal basis (for example, performance of a contract, legitimate interests, consent, or legal obligation) and only what is reasonably necessary to provide and improve the services.
How We Collect and Use Information
We may collect personal information when you:
- Register for an account
- Use a mobile device or web browser to access our content
- Contact us by email, social media, or similar channels
- Mention us on social media
We may collect, hold, use, and disclose information to:
- Provide core features and services
- Customize or personalize your experience
- Operate and improve the services, apps, and related channels
- Authenticate users and authorize access
- Verify eligibility for free trials, Discounted Pricing, and other offers
- Provide support and incident response
- Meet legal and regulatory obligations and resolve disputes
- Prevent, detect, and investigate abuse, fraud, and security events
- Perform internal analytics about service performance and reliability
- De-identify data in accordance with 45 CFR 164.514 where permitted under the BAA
We do not sell personal information. We do not sell PHI.
Our software integrates with several third party services, each with its own privacy practices. These may include OpenAI, Anthropic, Amazon Web Services, Google Cloud Platform, Supabase, Stripe, RevenueCat, Encharge.io, Referly, and similar vendors for hosting, AI inference, authentication, communications, payments, and referral attribution. Where a provider may handle PHI, we execute a BAA and require appropriate safeguards. A current list of infrastructure and service subprocessors is available upon request at hipaa@palm-ER.com.
We may combine voluntarily provided and automatically collected information with data from trusted sources to improve the services. For example, with your permission we may combine support emails and account data to resolve issues faster.
Use of Artificial Intelligence (AI)
Our applications use third party AI services to assist with documentation generation, language processing, and clinical workflow automation. Some outputs you receive may be generated by large language models. These models generate text based on your input and are not intended to provide individualized clinical advice.
We require zero-retention or an equivalent no-logging configuration for PHI content processed by AI providers, and we prohibit providers from using your data for model training. We do not use your data to train or fine tune any AI or machine learning models.
HIPAA Compliance and PHI
When we create, receive, maintain, or transmit PHI on behalf of a Covered Entity through our services, we act as a Business Associate.
Business Associate relationship: We apply the BAA's safeguards and use restrictions to PHI submitted through the services. The BAA becomes effective when accepted by the Covered Entity, directly or through an authorized representative, as described in the Terms.
Our obligations as a Business Associate include:
- Using PHI only as necessary to provide the services and as permitted by applicable law and the BAA
- Implementing administrative, technical, and physical safeguards to protect PHI
- Reporting breaches of unsecured PHI in accordance with HIPAA requirements
- Making PHI available for access, amendment, and accounting as required
- Ensuring our subcontractors who handle PHI are bound by agreements no less protective than the BAA
Security standards: We maintain industry standard safeguards including encryption in transit using TLS 1.2 or higher, encryption at rest using AES-256, strict access controls, audit logging, and vulnerability management.
AI processing and retention: When PHI is routed to AI providers at your direction, we use providers and configurations designed to prevent retention and training. If a provider cannot meet those requirements for a given feature, we will not route PHI to that provider for that feature.
De-identification: We may de-identify PHI in accordance with 45 CFR 164.514. De-identified data is no longer PHI. We will not attempt to re-identify de-identified data or contact individuals whose information has been de-identified.
Breach and incident notification: We will notify the Covered Entity within 10 business days after becoming aware of a non-permitted use or disclosure of PHI or a Security Incident that requires notice under the BAA. If we determine that a Breach of Unsecured PHI occurred, we will provide written notice to the Covered Entity without unreasonable delay and no later than 30 calendar days after discovery, including the information required by 45 CFR 164.410(c).
Retention and deletion: Return, destruction, and retention of PHI are governed by the BAA. When the BAA or the applicable services relationship terminates, we will return PHI we maintain on the Covered Entity's behalf to the Covered Entity or, if the Covered Entity agrees, destroy it, except for PHI we need to retain for our proper management and administration or to carry out our legal responsibilities. We will continue to safeguard retained PHI under the same terms and return it to the Covered Entity or, if the Covered Entity agrees, destroy it when it is no longer needed for those purposes.
Your responsibilities: You are responsible for obtaining any required patient authorizations and consents, ensuring that you have a legal right to share PHI with us, and meeting your applicable legal obligations.
Security of Your Information
We protect personal information using commercially reasonable safeguards appropriate to the data we process. No method of transmission or storage is 100 percent secure. You are responsible for maintaining the confidentiality of your credentials.
How Long We Keep Information
We retain personal information only as long as necessary to provide the services, meet legal obligations, resolve disputes, and enforce agreements. For PHI, retention is governed by the BAA. When information is no longer needed, we delete it or de-identify it consistent with applicable law.
Verification documents submitted for Discounted Pricing are deleted immediately after we complete verification. We retain only the eligibility outcome and the details listed above, such as program and expected training completion date.
Children’s Privacy
Our services are not directed to children under 18, and we do not knowingly collect personal information from children under 18. If you believe a child provided personal information, contact us and we will delete it. If we become aware that PHI relating to a minor has been submitted without appropriate authority, we will handle it in accordance with the BAA and applicable law.
Disclosure of Personal Information to Third Parties
We may disclose personal information to:
- a parent, subsidiary, or affiliate of our company
- third party service providers for the purpose of enabling them to provide their services, including (without limitation) IT service providers, data storage, hosting and server providers, analytics, error loggers, debt collectors, maintenance or problem-solving providers, professional advisors, and payment systems operators
- our employees, contractors, and/or related entities
- our existing or potential agents or business partners
- credit reporting agencies, courts, tribunals, and regulatory authorities, in the event you fail to pay for goods or services we have provided to you
- courts, tribunals, regulatory authorities, and law enforcement officers, as required by law, in connection with any actual or prospective legal proceedings, or in order to establish, exercise, or defend our legal rights
- third parties, including agents or sub-contractors, who assist us in providing information, products, services, or direct marketing to you
- third parties to collect and process data
- an entity that buys, or to which we transfer all or substantially all of our assets and business
When we disclose PHI, we do so only as permitted by applicable law and the BAA. We also bind recipients to appropriate confidentiality and security obligations.
International Transfers of Personal Information
The personal information we collect is stored and/or processed in the United States, or where we or our partners, affiliates, and third party providers maintain facilities. Protected Health Information is stored and processed only in the United States.
The countries to which we store, process, or transfer your personal information may not have the same data protection laws as the country in which you initially provided the information. If we transfer your personal information to third parties in other countries: (i) we will perform those transfers in accordance with the requirements of applicable law; and (ii) we will protect the transferred personal information in accordance with this privacy policy.
Your Rights and Controlling Your Personal Information
Your choice: By providing personal information to us, you understand we will collect, hold, use, and disclose your personal information in accordance with this privacy policy. You do not have to provide personal information to us, however, if you do not, it may affect your use of our app or the products and/or services offered on or through it.
Information from third parties: If we receive personal information about you from a third party, we will protect it as set out in this privacy policy. If you are a third party providing personal information about somebody else, you represent and warrant that you have such person's consent to provide the personal information to us.
Marketing permission: If you have previously agreed to us using your personal information for direct marketing purposes, you may change your mind at any time by contacting us using the details below.
Access: You may request details of the personal information that we hold about you.
Correction: If you believe that any information we hold about you is inaccurate, out of date, incomplete, irrelevant, or misleading, please contact us using the details provided in this privacy policy. We will take reasonable steps to correct any information found to be inaccurate, incomplete, misleading, or out of date.
Non-discrimination: We will not discriminate against you for exercising any of your rights over your personal information. Unless your personal information is required to provide you with a particular service or offer (for example serving particular content to your device), we will not deny you goods or services and/or charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties, or provide you with a different level or quality of goods or services.
Notification of data breaches: We will comply with laws applicable to us in respect of any data breach.
Complaints: If you believe that we have breached a relevant data protection law and wish to make a complaint, please contact us using the details below and provide us with full details of the alleged breach. We will promptly investigate your complaint and respond to you, in writing, setting out the outcome of our investigation and the steps we will take to deal with your complaint. You also have the right to contact a regulatory body or data protection authority in relation to your complaint.
Unsubscribe: To unsubscribe from our email database or opt-out of communications (including marketing communications), please contact us using the details provided in this privacy policy, or opt-out using the opt-out facilities provided in the communication. We may need to request specific information from you to help us confirm your identity.
Analytics and Cookies
We use cookies and similar technologies to provide core functionality, remember settings, measure performance, and improve the services. You can control cookies through your browser. Some features may not function without certain cookies.
We self-host our website analytics. Usage data collected through this website is processed on infrastructure we control and is not shared with a third-party analytics provider.
If you arrive through a referral link, we use Referly (referly.so) to attribute that referral and administer our Referral Program. Referly sets a cookie that records the referral so the referring partner can be credited. See our Referral Program Agreement for details.
Additional Disclosures for Australian Privacy Act Compliance (AU)
Overseas Disclosure Under Australian Privacy Principle 8
If the Privacy Act 1988 (Cth) applies when we disclose personal information to an overseas recipient, we will take the reasonable steps required by Australian Privacy Principle 8 to help ensure the recipient does not breach the Australian Privacy Principles. In some circumstances, we may remain accountable under the Privacy Act for the overseas recipient's handling of that information. Exceptions may apply as provided by law.
Additional Disclosures for General Data Protection Regulation (GDPR) Compliance (EU)
Data Controller / Data Processor
We, palmER Worldwide LLC, located at the address provided in our Contact Us section, act in different roles depending on the information involved.
We are a Data Controller for the personal information we collect to operate our business and our accounts, including registration and profile details, billing and subscription information, eligibility and verification information, support correspondence, log and device data, and website analytics. For that information we determine the purposes and means of processing.
We are a Data Processor for the content you submit through the services, including clinical text, audio, and any PHI. We process that content on the documented instructions of the controller, which is you or the organization on whose behalf you use the services. That controller determines the purposes and means of processing, and PHI is also handled in accordance with the BAA.
Legal Bases for Processing Your Personal Information
We will only collect and use your personal information when we have a legal right to do so. In which case, we will collect and use your personal information lawfully, fairly, and in a transparent manner. As described in the Children's Privacy section above, our services are not directed to anyone under 18 and we do not knowingly collect personal information from anyone under 18, so we do not rely on parental or guardian consent under Article 8 of the GDPR.
Our lawful bases depend on the services you use and how you use them. This means we only collect and use your information on the following grounds:
Consent From You Where you give us consent to collect and use your personal information for a specific purpose. You may withdraw your consent at any time using the facilities we provide; however this will not affect any use of your information that has already taken place. When you contact us, you may consent to your name and email address being used so we can respond to your inquiry. While you may request that we delete your contact details at any time, we cannot recall any email we have already sent. If you have any further inquiries about how to withdraw your consent, please feel free to inquire using the details provided in the Contact Us section of this privacy policy.
Performance of a Contract or Transaction Where you have entered into a contract or transaction with us, or in order to take preparatory steps prior to our entering into a contract or transaction with you. For example, we need technical information about your device in order to provide the essential features of our apps.
Our Legitimate Interests Where we assess it is necessary for our legitimate interests, such as for us to provide, operate, improve and communicate our services. For example, we collect technical information about your device in order to improve and personalize your experience of our apps. We consider our legitimate interests to include research and development, understanding our audience, marketing and promoting our services, measures taken to operate our services efficiently, marketing analysis, and measures taken to protect our legal rights and interests.
Compliance with Law In some cases, we may have a legal obligation to use or keep your personal information. Such cases may include (but are not limited to) court orders, criminal investigations, government requests, and regulatory obligations. If you have any further inquiries about how we retain personal information in order to comply with the law, please feel free to inquire using the details provided in the Contact Us section of this privacy policy.
Where we act as a Data Controller, we rely on these bases as follows:
- Creating and authenticating your account, providing the services, managing your subscription, processing payments, and responding to support requests: performance of a contract.
- Security monitoring, audit logging, fraud and abuse detection, verifying eligibility for free trials and Discounted Pricing, and analyzing service performance and reliability: our legitimate interests, as described in the Account Security and HIPAA Compliance section above.
- Marketing communications, where consent is required: your consent, which you may withdraw at any time.
- Retaining records, responding to regulators, and meeting reporting duties: compliance with a legal obligation.
Where we act as a Data Processor for content you submit through the services, the controller establishes the legal basis for that processing and we act on that controller's instructions.
International Transfers Outside of the European Economic Area (EEA)
We will ensure that any transfer of personal information from countries in the European Economic Area (EEA) to countries outside the EEA will be protected by appropriate safeguards, for example by using standard data protection clauses approved by the European Commission, or the use of binding corporate rules or other legally accepted means.
Additional Rights Under the GDPR
Restrict: You have the right to request that we restrict the processing of your personal information if (i) you are concerned about the accuracy of your personal information; (ii) you believe your personal information has been unlawfully processed; (iii) you need us to maintain the personal information solely for the purpose of a legal claim; or (iv) we are in the process of considering your objection in relation to processing on the basis of legitimate interests.
Objecting to processing: You have the right to object to processing of your personal information that is based on our legitimate interests or public interest. If this is done, we must provide compelling legitimate grounds for the processing which overrides your interests, rights, and freedoms, in order to proceed with the processing of your personal information.
Data portability: You may have the right to request a copy of the personal information we hold about you. Where possible, we will provide this information in CSV format or other easily readable machine format. You may also have the right to request that we transfer this personal information to a third party.
Deletion: You may have a right to request that we delete the personal information we hold about you at any time, and we will take reasonable steps to delete your personal information from our current records. If you ask us to delete your personal information, we will let you know how the deletion affects your use of our apps, website or products and services. There may be exceptions to this right for specific legal reasons which, if applicable, we will set out for you in response to your request. If you terminate or delete your account, we will delete or de-identify personal information associated with your account within a reasonable period, generally within 7 days where feasible, except for information we need to retain for legal, security, billing, dispute-resolution, fraud-prevention, audit, backup, BAA, or other legitimate business purposes.
Additional Disclosures for California Compliance (US)
This section applies to California residents and supplements the disclosures above.
Protected Health Information that we handle as a HIPAA Business Associate is exempt from the California Consumer Privacy Act under Section 1798.145(c). That information is governed by HIPAA and the BAA rather than by this section.
Do Not Track
We do not currently respond to Do Not Track (DNT) signals because there is no consistent industry standard for compliance. However, we respect user privacy and allow you to control cookies and tracking through your browser and platform preferences.
Cookies and Pixels
At all times, you may decline cookies from our site if your browser permits. Most browsers allow you to activate settings on your browser to refuse the setting of all or some cookies. Accordingly, your ability to limit cookies is based only on your browser's capabilities. Please refer to the Analytics and Cookies section of this privacy policy for more information.
CCPA-permitted Financial Incentives, Where Applicable
To the extent any discount, promotion, or special pricing program we offer is considered a financial incentive under the CCPA, we will provide any required notice and obtain any required opt-in consent. Any such incentive will reasonably relate to the value of the personal information involved, and participation may be revoked as described in the applicable offer terms.
Discounted Pricing, including resident, trainee, student, fellow, educational, partner, or promotional pricing, may require information needed to verify eligibility, such as your role, training status, institutional affiliation, expected training completion date, or other documentation reasonably needed to confirm eligibility. Unless otherwise stated in the applicable offer terms, Discounted Pricing is provided based on eligibility criteria and is not offered in exchange for the sale or sharing of personal information.
California Notice of Collection
In the past 12 months, we have collected the following categories of personal information enumerated in the California Consumer Privacy Act:
- Identifiers, such as name, email address, and an ID or number assigned to your account.
- Commercial information, such as products or services history and purchases.
- Professional or employment-related information, such as training program, role, or eligibility details, when you request or hold Discounted Pricing.
- Audio, electronic, visual, thermal, olfactory, or similar information, such as audio processed through ambient scribing or a training badge, ID, or program letter you upload to verify eligibility for Discounted Pricing. Ambient scribing audio is transcribed and then immediately discarded, and is never stored. Uploaded verification documents are deleted immediately after verification.
- Internet activity, such as your interactions with our service.
- Geolocation data, such as the approximate location derived from your IP address, which we use to secure accounts, detect unauthorized use, and understand where our services are used. We do not collect precise geolocation, and our apps and website do not request access to your device location.
- Inferences, such as information about your interests, preferences and favorites.
For more information on information we collect, including the sources we receive information from, review the "Information We Collect" section. We collect and use these categories of personal information for the business purposes described in the "How We Collect and Use Information" section, including to provide and manage our services.
We disclose these categories of personal information to the categories of recipients listed in the "Disclosure of Personal Information to Third Parties" section. We retain each category for the period described in the "How Long We Keep Information" section, which sets out the criteria we use and our specific practice for verification documents.
Do not sell or share. We do not sell personal information or share it for cross-context behavioral advertising as defined by the California Consumer Privacy Act, as amended by CPRA.
Right to Know and Delete
If you are a California resident, you have rights to delete your personal information we collected and know certain information about our data practices in the preceding 12 months. In particular, you have the right to request the following from us:
- The categories of personal information we have collected about you;
- The categories of sources from which the personal information was collected;
- The categories of personal information about you we disclosed for a business purpose or sold;
- The categories of third parties to whom the personal information was disclosed for a business purpose or sold;
- The business or commercial purpose for collecting or selling the personal information; and
- The specific pieces of personal information we have collected about you.
To exercise any of these rights, contact us using the details provided in this privacy policy. To protect your information, we will take reasonable steps to verify your identity before responding, which may include confirming information you have already provided to us or asking you to respond from the email address associated with your account. An authorized agent may submit a request on your behalf if you give the agent written permission and we can verify that permission and your identity.
Shine the Light
Under California Civil Code Section 1798.83, known as "Shine the Light," if you live in California and your business relationship with us is mainly for personal, family, or household purposes, you may request information about the personal information we disclosed to third parties and affiliates for their own direct marketing purposes during the preceding calendar year.
To make this request, contact us using the details provided in this privacy policy with "California Privacy Rights Request" in the subject line, and include your name, street address, city, state, and ZIP code. You may make this request once per calendar year. We will respond with the categories of personal information disclosed and the names and addresses of the recipients. Not all personal information shared in this way is covered by Section 1798.83.
Business Transfers
If we or our assets are acquired, or in the unlikely event that we go out of business or enter bankruptcy, your information may be transferred as part of that transaction in compliance with applicable law and, for PHI, the BAA.
Limits of Our Policy
Our apps may link to external sites that are not operated by us. Please be aware that we have no control over the content and policies of those sites, and cannot accept responsibility or liability for their respective privacy practices.
Changes to This Privacy Policy
At our discretion, we may change our privacy policy to reflect updates to our business processes, current acceptable practices, or legislative or regulatory changes. Thus, you are advised to review this page for any changes. We will notify you of any changes by posting the new Privacy Policy on this page.
Contact Us
For any questions or concerns regarding your privacy and our policies, you may contact us at:
- Privacy Contact: privacy@palm-ER.com
- HIPAA Compliance Officer: hipaa@palm-ER.com
- Security Breach Reporting: security@palm-ER.com
palmER Worldwide LLC
8 The Green STE A
Dover, DE 19901
United States
You may also reach out using the contact form on our website.