Data handling

The current boundary is deidentified operational data.

chatIR does not currently accept PHI. This page describes the operating boundary for diagnostic conversations today and the questions settled before an organization transfers a full export.

What chatIR accepts today

Approved, deidentified operational incident data. Before an engagement begins, we review a representative sample and agree on the fields that may be supplied.

What chatIR does not currently accept

Protected health information. Do not send patient names, dates of birth, medical record numbers, clinical narratives that identify a patient, or other PHI.

Work underway

chatIR is building the contractual and technical safeguards needed to support PHI, including BAAs with applicable vendors. The current boundary remains in place until that work is complete.

How the diagnostic uses the record

The supplied record is mapped and analyzed to produce the customer's diagnostic. Material findings remain connected to supporting records and are reviewed by a human before delivery.

Before transfer

Data scope, transfer method, retention, deletion, access, and contractual terms are confirmed for the engagement before the full export is accepted.

Public site analytics

Optional analytics is off by default. Analytics preferences at the bottom of public pages lets you enable Google Analytics and first-party marketing measurement or turn them off. Your browser remembers your choice for 180 days. Global Privacy Control and Do Not Track keep optional analytics off. Approved campaign labels and query-free public paths are measured only after consent; advertising signals and automatic cross-site cookie linking are disabled. Analytics cookies last for the browser session. Authentication and security storage needed to use the product are separate.

Session replay and private pages

Session replay is disabled. Google Analytics is limited to public marketing pages. Vercel Web Analytics and Speed Insights are not loaded. Hosting and security logs remain necessary to operate the service.

This is a public description of current practice, not a privacy policy, BAA, data processing agreement, or substitute for the terms governing a customer engagement. Those documents are being reviewed separately.

Questions about a proposed dataset can go to hello@chatir.io.