Privacy Policy
This Privacy Policy describes how Veridax collects, uses, and safeguards information when you use veridax.ai. (Legacy Chrome-extension clinical-text processing is disabled in the current pilot.) For a technical explanation of how Protected Health Information (PHI) is handled, see our Privacy & Security page.
Information We Collect
Veridax is designed to collect as little information as technically necessary to operate the service.
Account information
When you create an account, our authentication provider (Clerk) stores your email address and a hashed password or federated sign-in identifier. We do not store your password directly.
Payment information
Subscription payments are processed by Stripe. Veridax never sees or stores your credit card number, CVC, or bank account details. Stripe returns only a subscription identifier, billing status, and the billing email address you provide at checkout.
Clinical notes submitted for audit
Clinical notes that you paste or upload are processed in-memory during a single audit request and then discarded. Before transmission to our servers, structured PHI (such as Social Security numbers, dates of birth, phone numbers, email addresses, Medical Record Numbers, NPIs, ZIP codes, and labeled patient names) is removed by client-side JavaScript running in your browser. Because this pass is pattern-based, identifiers in free-narrative text may not be caught; a second, server-side redaction pass then runs on the transmitted text. Do not enter PHI unless Veridax has enabled a PHI-authorized pilot environment.
Technical and usage information
Our hosting provider (Netlify) logs standard request metadata such as IP address, user agent, request timestamp, and response status. These logs do not contain the contents of your clinical notes.
How We Use Your Information
We use the limited information we collect only for the following purposes:
- Providing the audit service. Scrubbed clinical text is sent to our AI provider (Anthropic) to generate a compliance audit, and the result is returned to your browser.
- Authenticating your account. Email and credential data are used to sign you in and, for paid users, to enforce your subscription entitlement.
- Processing payments. Billing information is used by Stripe to charge your subscription and by Veridax to confirm whether your subscription is active.
- Operating and securing the service. Request logs are used to diagnose errors, prevent abuse, and maintain reliability.
- Customer support. If you email us, we use your email address and the content of your message to respond.
We do not use your clinical notes, audit results, or account information for advertising, resale, or AI model training.
Data Storage and Retention
Clinical notes
Clinical notes are never persisted to a Veridax database. Each audit runs inside a short-lived serverless function (Netlify Functions), which discards the note as soon as the response is returned. We maintain no patient database, no note archive, and no backup copies of submitted text.
Drafts
If you use the Save Draft feature, drafts are stored only in your browser's localStorage on the device where you saved them. They are not transmitted to or stored on Veridax servers. Clearing your browser storage or signing out and removing local data will remove saved drafts.
Account and billing data
Account records are retained by Clerk for as long as your account exists. Billing records are retained by Stripe in accordance with their terms and applicable financial recordkeeping law. Request logs are retained by Netlify according to their standard retention schedule. To delete your account or billing records, contact us at the email below.
Information Sharing and Disclosure
We do not sell, rent, or syndicate your information. We share limited information only with the following processors, strictly for the purpose of operating the service:
- Anthropic — receives scrubbed clinical text to generate audit results. Anthropic's terms prohibit using API inputs to train models.
- Stripe — receives payment information directly from you at checkout and returns subscription status to Veridax.
- Clerk — manages account authentication and stores your email and credential data.
- Netlify — hosts the Veridax website and serverless functions and maintains standard request logs.
We may also disclose information if required by law, valid legal process, or to protect the rights, property, or safety of Veridax, our users, or the public.
Cookies and Analytics
Veridax uses a minimal set of cookies and browser storage strictly necessary to operate the service:
- Session cookies set by Clerk to keep you signed in.
- localStorage entries used to store your drafts, free-tier audit counter, and signed access token after payment. These are stored only on your device.
Veridax does not use third-party advertising cookies, tracking pixels, or cross-site analytics tools. We do not build user profiles for marketing purposes.
Your Rights
You have the following rights with respect to your information, subject to applicable law:
- Access — request a copy of the account information we hold about you.
- Correction — update or correct inaccurate account information.
- Deletion — request deletion of your account and associated records.
- Portability — request that your account data be provided in a machine-readable format.
- Withdraw consent — cancel your subscription and stop using the service at any time.
Because Veridax does not store your clinical notes, there is no stored clinical content for us to return, correct, or delete on request — it is discarded at the moment of audit.
To exercise any of these rights, email us at the address below. We will respond within 30 days.
Contact Us
Questions, requests, or concerns about this Privacy Policy or our data practices can be sent to:
We respond to privacy inquiries within two business days.