Privacy Policy
Last updated: July 13, 2026
1. Scope
This Privacy Policy describes how EchoReview AI ("we", "us") collects, uses, and shares information when you use our website, marketing pages, pilot application form, and the EchoReview AI research-preview platform (collectively, the "Service").
PHI processed under an executed Business Associate Agreement (BAA) is governed by that agreement and by HIPAA, not solely by this policy.
2. Information We Collect
- Account information: name, email, organization, role, hashed password, sign-in provider identifiers.
- Pilot application data: hospital name, contact details, program metadata, notes you submit.
- Study data: de-identified echocardiography files you upload, cardiologist annotations, addendums, audit-trail metadata.
- Usage data: IP address, user-agent, timestamps, feature interactions, error diagnostics.
- Communications: messages you send us, email delivery events (bounces, complaints, unsubscribes).
3. How We Use Information
- Provide, secure, and improve the Service.
- Authenticate users, enforce access controls, and maintain audit trails.
- Respond to pilot applications and support requests.
- Send transactional and account emails (confirmations, alerts, account notices).
- Comply with legal obligations and enforce our Terms.
We do not sell personal information. We do not use PHI to train models except as expressly permitted by an executed BAA and DUA.
4. Legal Bases (GDPR)
Where GDPR applies, we process personal data on the bases of contract performance, legitimate interests (product security, service improvement, direct B2B outreach in response to inbound inquiries), consent (where required), and legal obligation.
5. Subprocessors
We use a small number of vetted subprocessors to run the Service:
- Supabase (via Lovable Cloud) — authentication, database, storage, edge functions. US region.
- Cloudflare Workers — application hosting and edge compute.
- Mailgun — outbound transactional email delivery.
- Google Gemini / OpenAI (via Lovable AI Gateway) — AI inference for preliminary echocardiography impressions on de-identified inputs.
Each subprocessor is contractually bound to confidentiality and appropriate security controls. A current list is available on request.
6. Data Retention
- Account and organization data: retained while your account is active plus 90 days after deletion request.
- Study data: retained per your organization's configuration or the pilot DUA; deleted within 30 days of contract termination unless legally required to retain.
- Audit logs: retained for at least 6 years to support HIPAA compliance where applicable.
- Email logs: retained for 12 months for deliverability and suppression tracking.
7. Security
The Service is built on HIPAA-eligible infrastructure with encryption in transit (TLS 1.2+) and at rest, row-level security (RLS) for data isolation, role-based access controls, MFA support, and append-only audit logging. See our Trust and Compliance pages for details.
8. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, delete, port, or restrict processing of your personal data, and to object to certain processing. To exercise these rights, email contact@echoaireview.com. We will respond within 30 days.
9. Cookies
We use strictly necessary cookies for authentication and session management. We do not currently use advertising or cross-site tracking cookies.
10. Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from them.
11. International Transfers
Data is primarily processed in the United States. If you access the Service from outside the US, you consent to that transfer.
12. Changes
Material changes to this policy will be posted here with an updated date. Continued use after changes constitutes acceptance.
13. Contact
Data protection questions: contact@echoaireview.com