Privacy Policy
Last updated: August 2026
1. Core Commitment: 100% Zero PHI Data Retention
phiReports.health is architected from the ground up to operate without retaining, storing, selling, or indexing Protected Health Information (PHI) or Personally Identifiable Information (PII). When you use our service to generate clinical notes, SOAP documentation, consultation letters, procedure reports, or ISBAR medical handovers, all clinical patient data (including names, medical record numbers, dates of birth, diagnostic measurements, and clinical notes) exists solely in your browser's local RAM.
2. Ephemeral In-Memory PDF Compilation
When you request a PDF download or in-memory preview, your browser transmits the document payload over an encrypted TLS 1.3 connection to our serverless rendering instance. The server compiles the binary vector PDF in volatile memory and streams the bytes back to your client. The payload and compiled buffer are purged from memory immediately upon completion of the stream. No disk files or database records are created.
3. Local Browser Storage for Clinic Customizations
Any clinic logos or electronic signatures you upload/draw are saved exclusively in your browser’s local web storage (localStorage) on your own device. They are never uploaded to a persistent cloud database.
4. Payment Processing Separation (Stripe)
Financial transactions for Pay-As-You-Go credit bundles are processed securely through Stripe, Inc. Stripe collects and processes payment method details exclusively for financial settlement. Stripe never has access to any clinical notes, patient names, diagnostic measurements, or medical records generated on phiReports.health.
5. Cloud Infrastructure & Edge Network Sub-Processors
To maintain high availability, low latency, and zero-compromise encryption, phiReports.health utilizes enterprise cloud infrastructure providers operating under strict sub-processor data protection standards:
- Google Cloud Platform (Google LLC / Alphabet Inc.): Hosts our containerized serverless application via Google Cloud Run in SOC 2 Type II and ISO 27001-certified US data centers. Compute execution occurs in hardware-isolated, ephemeral Linux containers where memory is flushed immediately upon response completion.
- Cloudflare, Inc.: Provides global Anycast DNS routing, automated TLS 1.3 encryption, and DDoS edge protection. Cloudflare proxy rules are configured with strict
no-storecache-bypass policies on all document rendering endpoints (/api/*), preventing edge caching of document streams.