Privacy
Privacy Policy
Last updated:
The short version
QME Copilot is a desktop application. Medical records you process with it stay on your Mac. We never receive, store, or transmit the contents of any case file, page, or extracted fact. We collect only the minimum information required to bill you, deliver your license, support the product, and keep our license server running.
What we do not collect
- The contents of any PDF, document, or file you process with QME Copilot.
- Patient names, dates of birth, diagnoses, or any protected health information.
- Page counts, file names, hashes, or metadata derived from your records.
- Extracted facts, generated drafts, or any portion of the Review of Records output.
- Telemetry about which features you use within the app, which buttons you click, or how long you spend on a case.
What we do collect
Account & billing data
- Email address. Used to deliver your license, activation links, billing receipts, and product update notices.
- Billing information. Processed and stored by Stripe. We never see or store your full card number. We retain Stripe's customer ID and the metadata Stripe shares (last 4 digits, billing country, subscription status).
- License-claim events. When you activate a seat, our license server records the activation timestamp, the email tied to the seat, and a non-reversible hardware fingerprint used to bind the license. This fingerprint cannot be used to identify your machine to any third party.
License heartbeats
The desktop app may periodically check in with our license server to confirm your subscription is active. Heartbeats include only: your license ID, the version of the app, and the timestamp. They never include any information about the cases you process. Heartbeats can be disabled in offline-license mode for institutional deployments.
Support correspondence
If you email us, we retain the email thread for as long as needed to resolve your question and reasonable record-keeping thereafter. Please do not include patient information in support emails. If you need to share a problematic case, we'll provide a redaction process.
Website analytics
[Configure before launch] We use a privacy-respecting, cookieless analytics tool (e.g., Plausible or Fathom) on the marketing site to count page views and referrers. We do not use Google Analytics, Facebook Pixel, or any tracking that builds cross-site profiles of you.
HIPAA & PHI
QME Copilot is a desktop application that does not receive, transmit, or store protected health information on your behalf. Because no PHI flows through our infrastructure, we are not a HIPAA Business Associate by default. The HIPAA security posture of your Mac (full-disk encryption, access controls, screen lock, etc.) governs the records you process locally.
For institutional deployments where a Business Associate Agreement is required, contact us. We have an offline-license deployment mode and a BAA we can execute when our processing scope expands beyond the local desktop.
Cookies
The marketing site uses no third-party tracking cookies. The license-claim page and account portal may set a single first-party session cookie required for sign-in security. We do not sell, share, or commercialize cookie data.
Third-party processors
- Stripe — payment processing and subscription management.
- Email delivery provider [Postmark / Resend / etc. — fill in] — transactional email for license activation and billing receipts.
- Hosting [Cloudflare Pages / Vercel / etc. — fill in] — hosts this marketing site and the license server.
Your rights
You can request a copy of the data we hold about you, ask us to correct it, or ask us to delete it (subject to legal retention requirements for billing records). Email hello@qmecopilot.com. We respond within 30 days. California residents have additional rights under CCPA / CPRA — please reference those rights in your request and we will honor them.
Children
QME Copilot is a professional tool for licensed Qualified Medical Evaluators. It is not directed to anyone under 18 and we do not knowingly collect data from children.
Changes to this policy
If we materially change how we handle your data, we will notify you by email at the address tied to your license at least 14 days before the change takes effect. The current version of this policy will always be available at this URL with the "Last updated" date.
Contact
Questions, requests, or concerns: hello@qmecopilot.com.