Privacy Policy

Last updated September 30, 202612 min read

At a glance

Short versions to help you find your way. The full text below is what applies.

  • We don’t sell your data. The only advertising use is measuring whether our own ads lead to sign-ups.§2
  • Data is stored on AWS in the United States, encrypted at rest and in transit.§9
  • Clinical notes are encrypted a second time inside the app, so stored notes are unreadable without the application key.§9
  • By default, AI Scribe audio is deleted when the note is signed. Transcripts go 90 days after signing, unless shared to the client’s portal.§8
  • Card details stay with Stripe and are never stored on Stillpoint’s servers.§1
  • Clients can ask to see, correct, or delete their data. We answer verified requests within 30 days.§12

This policy explains what information 1581572 B.C. Ltd. d/b/a Stillpoint Technologies (“Stillpoint,” “we,” “us,” or “our”) collects, how we use it, and your rights regarding your data. We recommend reviewing this page periodically as we update it to reflect new features and practices.

§1Information we collect

Account information. When you create a Stillpoint account, we collect your name, email address, phone number (optional), and practice details such as your practice name and timezone.

Client information. When clients book appointments through your booking page or an embedded booking form, we collect the following on behalf of the practitioner:

  • Full name
  • Email address
  • Phone number (if provided)
  • Booking details (service, date, time)
  • Appointment history
  • Session preferences and notes

This data is stored on behalf of the practitioner and shared with them to manage appointments and provide their services.

Family member information. Clients may add family members or dependents to their account and book appointments on their behalf. We collect the same information (name, email, phone) for dependents as for primary clients.

Clinical records. If you use Stillpoint’s clinical notes features, we store the content of session notes, SOAP notes, and note templates that you create. All clinical content is encrypted at rest using AES-256 encryption. This data is stored solely on your behalf and is not accessed by Stillpoint for any purpose other than providing the service.

AI-generated clinical content. If you use the AI Scribe feature, audio from clinical sessions may be recorded, transcribed, and used to generate structured session notes. Audio recordings are transcribed by Microsoft Azure OpenAI Service under Microsoft’s HIPAA Business Associate Agreement, and clinical note generation is powered by AWS Bedrock (Anthropic Claude). Audio recordings are stored encrypted in HIPAA-eligible storage. By default, audio is deleted when the note is signed, or 7 days after recording if the note is never signed; a practice can instead choose to have audio deleted 7 or 30 days after recording, whether or not the note is signed. Section 8 describes how long transcripts are kept.

Video visits. If you hold a session through Stillpoint’s built-in video visits, the audio, video, and in-call chat are carried by the Amazon Chime SDK under our AWS Business Associate Agreement. Media is encrypted in transit and is not recorded by Stillpoint. We retain only metadata about the session (participants, join and leave times, and connection quality) so practitioners can confirm attendance and we can troubleshoot call quality. Recording a session for note generation is a separate, opt-in action (see AI Scribe below).

Billing and invoicing data. Stillpoint stores invoice records, insurance claim details, procedure codes, and related billing information that you enter. This data is used to generate invoices and manage claims within the platform.

Payment information. All payment data is processed securely by Stripe. We do not store credit card numbers, bank account details, or other financial information on our servers.

Stored payment methods. With your authorization, practitioners may store a payment method on file via Stripe for future charges, including recurring session fees, no-show fees, and autopay. Card details are held securely by Stripe and never stored on Stillpoint servers.

Website content. If you use our hosted website feature, we store the text, images, and configuration you provide to build and display your practice website.

Usage data. We collect standard server logs including IP addresses, browser type, and timestamps. We use Google Analytics to understand how visitors interact with our marketing site and our sign-up and practice setup pages. See Section 4 for details on analytics cookies.

§2How we use your information

We use the information we collect to:

  • Provide and operate the Stillpoint scheduling platform
  • Store and display clinical notes and records on your behalf
  • Generate and manage invoices and insurance claims
  • Provide practice analytics and reporting
  • Process payments through Stripe Connect
  • Send appointment confirmations and reminders via email
  • Send SMS notifications for bookings and cancellations (when enabled)
  • Host video visits between practitioners and their clients
  • Host and display your practice website (when published)
  • Respond to support requests
  • Improve the reliability and performance of our service

We do not sell your data. We do not use your data for advertising, except to measure whether our own ads lead to sign-ups, as described in Section 3.

§3Third-party services

Stillpoint relies on a small number of trusted third-party services to operate. Each provider receives only the data necessary to perform its function. The full list of the providers that process practice and client data, with change notice, is maintained at withstillpoint.com/subprocessors; practices in the United Kingdom, Australia, and New Zealand are covered by our Data Processing Agreement. Stillpoint runs on Amazon Web Services in the United States (us-east-1, N. Virginia), so data from Canadian and other international practitioners and their clients is transferred to and stored in the United States. While it is there, it may be accessible to courts, law enforcement and national security authorities in the United States under US law.

Amazon Web Services (AWS)Under our BAA
The infrastructure Stillpoint runs on, in the United States (us-east-1, N. Virginia). AWS provides application hosting (ECS Fargate), our application database including all protected health information (RDS PostgreSQL), authentication and sign-in (Cognito), file and document storage (S3), content delivery (CloudFront), transactional email (SES), video visits (Chime SDK), and AI processing for clinical, website, and practice-setup features (Bedrock, running Anthropic Claude). The one exception is audio transcription for the AI Scribe, which runs on Microsoft Azure under a separate Business Associate Agreement, described below. Data is encrypted at rest with KMS-managed AES-256 encryption and in transit with TLS. Every AWS service listed here is on the AWS HIPAA Eligible Services list and operates under our Business Associate Agreement. Privacy policy
Stripe
Payment processing (PCI-DSS compliant). Stripe receives client payment details directly and Stillpoint never handles or stores card data. Privacy policy
Twilio
SMS delivery for appointment notifications. No clinical detail and no patient identifiers are placed in a message body: sends are limited to scheduling facts and a secure link, enforced in code rather than by contract, so protected health information does not transit this vendor. Privacy policy
Google Analytics

Anonymized usage analytics on our marketing site and our sign-up and practice setup pages, including when an account is created and when a practice finishes setup. Completed sign-ups are also used to measure our Google Ads. Google Analytics collects data such as pages visited, button clicks, device type, and browser information using cookies. No personally identifiable information is sent to Google Analytics. You can opt out using the Google Analytics opt-out browser add-on. Privacy policy

Google Fonts
Typography loaded on booking pages and hosted websites. Google may collect usage data when fonts are served. Privacy policy
Microsoft AzureUnder Microsoft’s BAA
Clinical audio transcription for the AI Scribe feature is processed through the Azure OpenAI Service. Audio is transcribed under Microsoft’s HIPAA Business Associate Agreement and is not used to train any models. Privacy policy
Stedi

Healthcare data clearinghouse used for insurance eligibility verification and claim submission. When a practitioner performs an eligibility check, patient information (name, date of birth, member ID, and provider details) is transmitted to Stedi to verify insurance coverage. When a practitioner submits a claim, the claim, including patient, diagnosis, procedure, and provider details, is transmitted to Stedi, which forwards it to the insurance payer once the practice’s claim submission enrollment with that payer is active. Privacy policy

Google CalendarOptional
Optional calendar integration. When connected, appointment data (times, service names, client names) is synced between Stillpoint and Google Calendar. Privacy policy
Microsoft (Outlook Calendar)Optional
Optional calendar integration. When connected, appointment data is synced between Stillpoint and Microsoft 365 via the Microsoft Graph API. Privacy policy
Google Maps Platform

Used for address autocomplete when a practice or client enters an address, such as a practice location or a client’s home address. Address input is sent to Google’s Places API. Privacy policy

Google Sign-InOptional

Optional sign-in with a Google account. When you choose it, Google confirms your identity and shares your name and email address with Stillpoint. Privacy policy

Meta (Facebook and Instagram)

The Meta Pixel runs on our marketing site and our sign-up and practice setup pages. It uses cookies to record page views and actions such as a founding program application or a completed sign-up, so we can measure our own Facebook and Instagram advertising. It loads for every visitor and does not receive practice or client records. Separately, Meta is used for an optional social publishing integration: when a practice connects a Facebook Page or Instagram account, the posts and media the practice schedules are sent to Meta for publishing. Privacy policy

§4Cookies and authentication

Stillpoint uses cookies for authentication and session management. We set authentication cookies across the .withstillpoint.com domain to enable seamless login between your dashboard, booking pages, and hosted website.

We also use Google Analytics cookies to collect anonymized usage data on our marketing site and our sign-up and practice setup pages. These cookies help us understand how our platform is used so we can improve it. Google Analytics does not collect personally identifiable information.

The same pages load the Meta Pixel, which sets Meta advertising cookies so we can measure our own Facebook and Instagram ads (see Section 3). Other than the Meta Pixel, we do not use advertising cookies or participate in any ad networks.

§5Hosted websites

If you publish a hosted website through Stillpoint, your website is served at a .withstillpoint.com subdomain or your own custom domain. Standard web server logs (IP address, browser, timestamps) are collected from visitors to your website. No tracking scripts or analytics are added by Stillpoint.

Stillpoint does not add its own analytics or tracking scripts to practitioner-hosted websites. However, practitioners may optionally add their own Google Analytics tracking ID in the website editor. If a practitioner enables Google Analytics, visitor data on that hosted website will be collected by Google in accordance with Google’s privacy practices. Google Fonts may be loaded for typography. Custom domains are served through Amazon CloudFront, with TLS certificates issued by AWS Certificate Manager.

§6Embedded booking forms

Your booking form can be embedded on third-party websites via an iframe. Data collected during the booking process (name, email, phone, notes) is transmitted to and processed by Stillpoint regardless of where the form is embedded.

Payment information entered within an embedded booking form is handled directly by Stripe. Authentication cookies may be set within the iframe for session management.

§7SMS and email communications

Stillpoint sends transactional messages on behalf of practitioners, including booking confirmations, appointment reminders, and cancellation notices. Practitioners also receive notifications when clients book or cancel.

Practitioners can control notification preferences (email and SMS) from the Settings page. Client reminders can be disabled by setting the reminder lead time to zero. Emails are sent via Amazon SES and SMS messages are sent via Twilio.

In addition to transactional messages, Stillpoint may send automated marketing communications on behalf of practitioners, including re-engagement campaigns for lapsed clients, birthday messages, review requests, welcome sequences for new clients, and no-show follow-up messages. These messages are sent based on practitioner-configured automation rules.

Clients may manage their email preferences through the client portal or by using the unsubscribe link included in automated messages. Stillpoint complies with CAN-SPAM and CASL requirements for all automated email communications.

§8AI features and clinical data

Stillpoint offers AI-powered features that process clinical data:

AI Scribe. The AI Scribe feature lets practitioners dictate, or record a session with their client’s consent. Audio is transcribed using Microsoft Azure OpenAI Service (under Microsoft’s HIPAA Business Associate Agreement), and notes are drafted by AWS Bedrock (Anthropic Claude). Neither provider uses the audio, transcripts or notes to train its models. Audio recordings are stored encrypted. By default, audio is deleted when the note is signed, or 7 days after recording if the note is never signed; a practice can instead choose to have audio deleted 7 or 30 days after recording, whether or not the note is signed. Transcripts are stored encrypted and deleted 90 days after the note is signed. When a client asks for their transcript, the practitioner can review it and share it to the client’s portal; the transcript and the copy shared are then kept for one year after it was last shared or withdrawn. Practitioners are responsible for obtaining their client’s consent before recording a session.

How long AI Scribe keeps thingsA summary of the paragraph above, to help you find your way. The paragraph is what applies.
WhatDeleted
Audio, by defaultWhen the note is signed, or 7 days after recording if it is never signed
Audio, if the practice chooses7 or 30 days after recording, whether or not the note is signed
Transcript90 days after the note is signed
Transcript shared to the client’s portalOne year after it was last shared or withdrawn

Clinical note expansion. Practitioners may use AI to expand brief clinical notes into full SOAP format. Note content is sent to AWS Bedrock (Anthropic Claude) for processing. All AI processing occurs within HIPAA-eligible AWS infrastructure under our Business Associate Agreement.

AI practice assistant (Clio). The Clio assistant helps with scheduling, navigation, and practice management, and can take actions on your behalf such as booking an appointment or creating a client record. To do that, Clio reads and writes practice data including client names, contact details, dates of birth, and appointment history. Clio does not have access to clinical notes, session content, or intake form responses.

Clio runs on Anthropic Claude via AWS Bedrock, under our AWS Business Associate Agreement. It does not send your data to any provider outside that agreement, and your conversations are not used to train any model. If Bedrock is unavailable, Clio returns an error rather than falling back to a provider not covered by a BAA.

AI website copy. Practitioners may use AI to generate content for their practice website. Practice information (name, services, descriptions) is sent to AWS Bedrock for content generation.

§9Data security

All data is encrypted in transit (HTTPS/TLS) and at rest. Stillpoint stores all practice data, including protected health information such as intake forms, medical history, medications, allergies, insurance records, consent records, and uploaded health documents, on a HIPAA-eligible AWS RDS PostgreSQL database in the United States (us-east-1, N. Virginia), with uploaded documents in Amazon S3. Both use KMS-managed AES-256 encryption at rest and TLS in transit, with database and infrastructure audit logging via the PostgreSQL pgaudit extension and AWS CloudTrail. Stillpoint additionally maintains an application-level audit trail for access to protected health information, recording the acting user, the record, and the time.

Clinical notes, including SOAP notes and note templates, carry a second layer of protection: they are encrypted at the application layer with AES-256-GCM (a unique key per environment, with a fresh initialization vector per field) before being written to the database, so the stored values are unreadable without the application key even to someone holding the database itself. The same application-layer encryption protects secure messages, stored insurance identifiers, and connected-calendar access tokens.

Authentication is provided by Amazon Cognito. Data is separated between practices by two different controls depending on the data involved. General application data is read through a restricted database role governed by row-level security policies that scope each request to your practice. Protected health information is read through a separate, dedicated data-access layer in which practice scoping and audit logging are enforced in application code rather than by row-level security.

Payment information is processed by Stripe (PCI-DSS compliant) and never stored on Stillpoint servers. All API communication occurs over HTTPS.

§10Data retention

Account and practice data (including clinical notes, invoices, and insurance claims) is retained for as long as your account is active. If you request account deletion, we will remove your data within a reasonable timeframe, except where retention is required by law (for example, payment records and billing documentation). Server logs are retained for a limited period for debugging and security purposes.

§11Your rights (practitioners)

As a practitioner, you have the right to:

  • Export your data (including client records and clinical notes) at any time from your practice settings
  • Request deletion of your account and data
  • Opt out of SMS notifications from your settings
  • Unpublish your hosted website at any time

For any privacy-related requests, contact us at help@withstillpoint.com.

§12Client data rights

If you are a client who has booked an appointment through Stillpoint, you may contact us at help@withstillpoint.com to:

  • Request information about the data we hold about you
  • Request corrections to your personal information
  • Request deletion of your data, subject to the practitioner’s recordkeeping obligations

We will respond to verified requests within 30 days.

§13Client portal

Stillpoint provides a client portal where clients can:

  • View and manage upcoming appointments
  • Join video visits
  • Access billing information and payment history
  • Complete intake forms
  • Manage family members and dependents
  • Leave reviews for practitioners
  • Set communication preferences

The client portal requires authentication. Data displayed in the portal is limited to information relevant to the client’s relationship with their practitioner.

§14Contact

For privacy questions or concerns, reach us at help@withstillpoint.com. You may also reach us by mail at PO Box 5121, Victoria PO 9, BC V8R 6N4, Canada.

Questions about the Privacy Policy?

1581572 B.C. Ltd. d/b/a Stillpoint Technologies
PO Box 5121, Victoria PO 9, BC V8R 6N4, Canada
help@withstillpoint.com

History

  1. AI Scribe audio retention now reads the same everywhere and a shared transcript is kept a year from when it was last shared or withdrawn. Discloses the Meta Pixel, which measures our own ads, and that Google Analytics covers our sign-up and practice setup pages. The vendor list adds claim submission through Stedi, Google Sign-In, and Meta. Dashes became parentheses in two places, with no change in meaning.
  2. AI Scribe retention rewritten (audio deleted at signing, transcripts after 90 days, shared transcripts kept a year), and data held in the United States may be accessible to US authorities.
  3. Named the contracting entity: 1581572 B.C. Ltd. d/b/a Stillpoint Technologies.
  4. Linked the new sub-processor list and the Data Processing Agreement.
  5. SMS delivery moved back to Twilio.
  6. SMS delivery moved to AWS End User Messaging, and the last OpenAI features moved to AWS Bedrock.
  7. Rewritten for Stillpoint’s move to Amazon Web Services.

Related