Privacy Policy

Effective August 1, 2026. This page is maintained by ChiroReports LLC to explain what ChiroReports collects, what it deliberately does not collect, and what you can control.

The short version

  • We collect the account information needed to run your subscription and your reports.
  • Patient names and dates of birth stay in your own browser. They are not transmitted to our servers, and they are not sent to any AI model.
  • Uploaded imaging reports are redacted in your browser before anything is sent to us.
  • We do not sell your information, and we do not use your content to train AI models.
  • You choose how long saved report drafts are kept, and you can delete them.

What we collect

Account information. Your email address, and the clinic and provider details you enter in Settings, such as clinic name, provider name and title, medical director name, logo image, and signature image.

Billing information. Your subscription status, plan, renewal dates, invoice history, and report credit balance. Card numbers are handled entirely by our payment processor and never reach our servers.

De-identified report content. When you save a report, we store the clinical text with patient identifiers replaced by placeholders such as [PATIENT] and [DOB], plus which tool created it and when.

Support messages. If you email support or use the contact form, we keep the conversation so we can answer it and follow up.

Affiliate information. If you join the affiliate program, we keep your payout email, referral link activity, commission records, and the signup IP address of accounts referred through your link, which we use to detect self-referral and fraud.

Basic technical logs. Request and error logs generated by our hosting and backend, used to keep the service working and secure.

What stays on your device and is never sent to us

The patient name and date of birth you enter into the local identity panel are stored only in your browser's local storage. They are merged into the report in your browser at the moment of preview, print, or export. We never receive them, so we cannot see them, and they are not part of any backup we hold.

When you upload an imaging report PDF to the X-Ray & MRI Translator, the file is opened and read in your browser. Names, dates of birth, record numbers, dates, phone numbers, and social security numbers are stripped and replaced with tokens before any content leaves your device. We do not store the uploaded file itself. Full detail is on the Security & HIPAA page.

Because identifiers stay on your device, clearing your browser data or switching computers will clear the stored patient identities. Settings includes an export and import tool so you can move that local data yourself.

How we use what we collect

  • To create your reports and apply your clinic branding to them.
  • To run billing, subscriptions, report credits, and affiliate payouts.
  • To send you service email: welcome and onboarding, payment problems, cancellation confirmations, support replies and follow-ups, and affiliate program information.
  • To answer support requests and improve the product.
  • To detect fraud and abuse, and to meet legal obligations.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

Service providers we use

We use a small number of providers to operate the service. Each receives only what it needs to do its job:

  • Hosting, database, and authentication - stores your account, settings, and de-identified report drafts, encrypted in transit and at rest.
  • Payment processing - handles cards, subscriptions, invoices, and affiliate payouts. They hold your payment details, not us.
  • Transactional email - delivers the service emails described above.
  • AI processing - receives only de-identified clinical text when a report needs AI assistance. Many reports are generated by our own rule engine and involve no AI call at all. Prompt content is not used to train models and is not retained beyond the request.

We may also disclose information where required by law, to protect our rights, or as part of a business transfer, in which case this policy continues to apply to the transferred data.

Cookies and similar technology

  • Session storage keeps you logged in. Without it the app cannot function.
  • Local storage holds your patient identity entries and interface preferences on your device.
  • Affiliate referral cookie records which affiliate link brought you to the site, for up to 60 days, so the referral can be credited correctly.

We do not run third-party advertising trackers on the site.

How long we keep things

  • Report drafts are kept according to the auto-delete window you choose in Settings. When that window passes, the draft is deleted automatically. You can also delete any draft yourself at any time.
  • Account and billing records are kept while your account is open and afterward for as long as we need them for tax, accounting, and legal purposes.
  • Support conversations are kept so we can maintain context on your requests.
  • Locally stored patient identities are kept until you clear them, since they live on your device and not with us.

Your choices and requests

You can access and correct your account details in Settings, set your report retention window, export or clear your local patient data, manage your subscription and invoices through the billing portal, and unsubscribe from non-essential email using the link in any message. Essential emails about billing and account security will still be sent while your account is active.

To request a copy of the information we hold about you, or to ask us to delete your account and its data, email support@chiroreports.app. We will verify the request against your account email before acting on it.

Security

Traffic between your browser and ChiroReports uses TLS, stored account data is encrypted at rest, and access to backend data is restricted by row-level rules so accounts cannot read one another's records. No system is perfectly secure, so keep your own login credentials and devices protected. If you believe you have found a vulnerability, please report it to support@chiroreports.app rather than disclosing it publicly, and we will respond.

Children and international use

ChiroReports is a professional tool and is not directed to children, and we do not knowingly collect information from anyone under 18. The service is operated from the United States. If you use it from elsewhere, your information will be processed in the United States.

Changes and contact

If we change this policy we will post the update here with a new effective date, and we will notify account holders of material changes. Questions can go to support@chiroreports.app. This page describes our own practices and is not legal advice about your practice's obligations.

See also our Terms of Service and Security & HIPAA pages.