Privacy Policy

Last updated: May 2026 · Pending attorney review
Note: This is a preliminary privacy policy for beta testing purposes. A formal, attorney-reviewed privacy policy will be published prior to public launch. This document describes our current data practices accurately.

Who We Are

Chrysalis Clinical Intelligence is a clinical documentation assistance tool built for licensed healthcare providers. We generate structured clinical notes from visit transcripts using artificial intelligence. We are not an Electronic Health Record (EHR) system.

What Data We Collect

Account information: When you sign up, we collect your email address and optionally your name. We do not collect payment information directly — billing is handled by third-party processors.

Patient data: Patient names, dates of birth, encounter types, insurance information, and visit transcripts entered into Chrysalis are stored in a secure database to generate clinical notes. This data constitutes Protected Health Information (PHI) under HIPAA.

Generated notes: AI-generated clinical notes are stored associated with the patient record. All notes are clearly marked as AI-generated and require provider review and attestation.

Usage data: We collect aggregate usage metrics (number of notes generated, features used) to improve the service. We do not sell this data.

How We Use Your Data

Patient data and transcripts are used solely to generate clinical documentation for your practice. We do not use patient data to train AI models. We do not share patient data with third parties except as required to operate the service (cloud infrastructure providers).

Your email address may be used to send service-related communications. We do not send marketing emails without your consent.

HIPAA and Data Security

Chrysalis is designed with HIPAA-compliant infrastructure. All data is encrypted in transit (TLS 1.2+) and at rest. We maintain access logs for audit purposes.

Business Associate Agreement (BAA): A BAA is available upon request for Practice and Enterprise subscribers. Using Chrysalis with real patient data requires a signed BAA. Contact us to request one before entering PHI into the system.

Data Retention

Patient records and generated notes are retained for the duration of your active subscription plus 30 days. You may request deletion of your data at any time by contacting us. We comply with applicable state and federal records retention requirements.

Third-Party Integrations

Chrysalis optionally integrates with Tebra EHR via the SMART on FHIR standard. When you authorize this integration, Chrysalis accesses read-only patient demographics, medications, allergies, and conditions from Tebra. This access is governed by your authorization and can be revoked at any time. We do not store Tebra access tokens beyond your active session.

Your Rights

You have the right to access, correct, or delete your account data and any patient data entered into Chrysalis. To exercise these rights, contact us at the address below.

Contact

For privacy questions, data deletion requests, or BAA inquiries:
Chrysalis Clinical Intelligence
Email: privacy@chrysalisapp.dev
Site: chrysalisapp.pages.dev

Changes to This Policy

We will post updates to this policy on this page with a revised date. Continued use of Chrysalis after changes constitutes acceptance of the updated policy.