GDPR, CCPA, and HIPAA compliant โ governing how we collect, use, and protect your data.
MentraNote Inc. ("MentraNote", "we", "us", or "our") is the operator of the MentraNote EHR platform โ an AI-powered electronic health record and practice management system for mental health professionals. Our registered address is in the State of Delaware, United States.
This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our platform. By using MentraNote, you consent to the practices described in this Policy.
| Purpose | Legal Basis (GDPR) |
|---|---|
| Provide and operate the platform | Contract performance |
| Process payments and subscriptions | Contract performance |
| Comply with HIPAA and legal obligations | Legal obligation |
| Send service notifications and account alerts | Legitimate interest |
| Improve platform features and AI models (anonymized data only) | Legitimate interest |
| Respond to support requests | Legitimate interest |
| Detect and prevent fraud or unauthorized access | Legitimate interest |
We do not sell your personal information or PHI. We may share data only in the following limited circumstances:
HIPAA Notice: MentraNote operates as a HIPAA Business Associate. PHI entered into the platform is governed by our Business Associate Agreement (BAA) and HIPAA regulations. PHI is never used for advertising, sold to third parties, or shared without appropriate authorization.
MentraNote uses PHI solely to provide the services you have contracted for, for treatment, payment, or healthcare operations as permitted under HIPAA, and as required by law.
AI model training on PHI is strictly prohibited. Any AI improvement uses only aggregated, anonymized, de-identified data meeting the requirements of 45 C.F.R. ยง164.514.
We retain your data for as long as your account is active or as needed to provide the Service. After account termination:
You can request a full data export at any time from your account settings before termination.
Depending on your jurisdiction, you may have the following rights:
To exercise your rights, contact us at privacy@mentranote.com. We will respond within 30 days.
MentraNote uses essential session cookies required for secure authentication (JWT tokens stored in HttpOnly cookies). We do not use advertising cookies, third-party tracking pixels, or behavioral analytics tools that would share your data with advertisers.
You may configure your browser to block cookies, but this may affect platform functionality.
MentraNote implements HIPAA-required administrative, physical, and technical safeguards, including:
MentraNote stores data on servers located in the United States. If you access the platform from outside the United States, your data will be transferred to and processed in the US. We ensure such transfers comply with applicable privacy laws, including the GDPR Standard Contractual Clauses where applicable.
MentraNote is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us immediately at privacy@mentranote.com.
We may update this Privacy Policy periodically. Material changes will be communicated via email to the address associated with your account and/or a prominent notice in the platform at least 30 days before taking effect. Continued use of the platform after the effective date constitutes acceptance of the updated Policy.
For privacy inquiries, data subject requests, or to report a potential breach:
EU residents may also lodge a complaint with their local supervisory authority.