Nextvisit AI Inc ("Nextvisit," "we," "us," or "our") values your privacy and is committed to protecting the personal information you share with us. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, platform, applications, and services (collectively, the "Service"). References to "Nextvisit Inc" in legacy materials refer to our subsidiary company.
This Privacy Policy describes our practices under applicable U.S. federal and state laws, including the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CTDPA), the Utah Consumer Privacy Act (UCPA), the Health Insurance Portability and Accountability Act (HIPAA), the Health Information Technology for Economic and Clinical Health Act (HITECH), and the New York SHIELD Act. It also describes how we handle personal information in services that use AI and machine learning.
By using our Service, you agree to the practices described in this Privacy Policy. If you do not agree, please refrain from using the Service.
1. Intended Use in the United States Only
The Nextvisit Service is intended solely for users located within the United States. We do not support users outside the United States, and the Service is not designed to comply with international privacy laws, such as GDPR (General Data Protection Regulation). By using the Service, you confirm that you are a resident of the United States and will access it only within U.S. territories.
2. Information We Collect
We collect and process information to provide and improve our Service. This includes information you actively provide, data collected automatically, and information obtained from third parties.
a. Information You Provide
Depending on your user role, you may provide us with:
- Personal Identifiable Information (PII): Examples include your name, email address, phone number, and billing information when you register, make a purchase, or interact with the Service.
- Protected Health Information (PHI): If you are a healthcare provider or process patient data through Nextvisit, we may process PHI as defined under HIPAA.
- Account Information: Professional credentials, practice or clinic details, team member directories, and roles.
- User-Generated Content: Transcriptions, notes, uploaded files, and other data entered into the platform.
- Payment Information: Credit card details and billing information for payment processing.
b. Information Collected Automatically
When you use our Service, we automatically collect:
- Device Information: IP address, browser type, operating system, device type, and geographical location.
- Usage Data: Features accessed, timestamps, crash logs, clickstream data, and performance metrics.
- Cookies and Tracking Technologies: We use cookies, web beacons, and similar technologies to improve your experience (see Section 8: Cookies and Tracking Technologies).
c. Information From Third Parties
We may receive data from trusted third-party sources, including:
- Identity Verification Services: To validate accounts and comply with legal requirements.
- Third-Party Service Providers: Such as payment processors, server hosting providers, and AI partners.
- Publicly Available Sources: Information from public databases or directories to verify healthcare-related entities.
3. User Categories and Access Levels
Our platform provides different roles to ensure appropriate access to data:
Practice/Clinic Owner
Full administrative access to practice data, including patient records and team activity. Responsible for managing billing, user roles, and overall compliance.
Administrators
Access to patient data, practice settings, and analytics as assigned by the Owner. Manage provider and staff accounts.
Providers
Access to patient records, clinical tools, and transcription services. Limited administrative permissions based on role assignments.
Staff
Task-level access to specific patient or workflow data as assigned by the Owner or Administrator. No access to administrative or billing data.
4. How We Use Your Information
We use your information for the following purposes:
a. Core Service Delivery
Enable account setup and management; provide transcription, clinical documentation, and analytics tools; and process payments and manage subscriptions.
b. Service Improvement
Analyze usage trends and technical performance, improve platform features, and evaluate accuracy and quality. Users are included in internal evaluations by default. Model training using patient or provider information requires explicit opt-in, as described in Section 5.
c. Regulatory Compliance
Adhere to HIPAA, HITECH, and other healthcare privacy regulations, and respond to legal or regulatory inquiries.
d. Security and Fraud Prevention
Monitor for suspicious activity, unauthorized access, or security risks, and investigate and mitigate fraudulent behavior.
e. Communication
Send transactional emails, service updates, and notifications, and provide marketing communications (with an opt-out option).
5. AI and Machine Learning
We use a combination of proprietary in-house models and third-party large language models (LLMs) to power our AI features. Our AI and subprocessor disclosures describe providers, model selection by feature, and data handling in more detail.
a. AI Partners
- Anthropic, OpenAI, Google, xAI: Language models for clinical documentation, review, chat, and other AI features.
- Cloudflare AI Gateway, OpenRouter: Our primary AI gateways, used with Nextvisit's own API keys and provider connections.
- Deepgram: Our primary voice and transcription provider, with SpaceX/xAI text-to-speech and speech-to-text services as a fallback.
- Perplexity: Search using non-PII inputs only.
We maintain Business Associate Agreements (BAAs) and agreements with our AI gateways, model providers, and AI providers. Provider and model selection changes with the task, selected mode, and available services. See the provider disclosures for the current list and processing roles.
OpenAI is covered by our signed BAA. SpaceX/xAI is covered through OpenRouter's subprocessor arrangements; a direct agreement with xAI is in progress.
b. How Data Is Handled
Redaction depends on the workflow. We replace selected identifiers with bracketed tags, and review steps check for identifying information missed in earlier passes. Some workflows remove patient and provider identifiers; others retain provider information and clinically relevant patient details. Some diagnostics use a filter-only redaction pass. Replacing identifiers does not by itself establish de-identification under HIPAA. See our redaction practices.
We use zero data retention (ZDR) with providers where supported. Otherwise, provider retention is 30 days in most cases, depending on the model, process, and applicable agreement. See provider retention and Section 11 for the distinction between provider processing and Nextvisit's stored records.
Requests and storage containing patient information or other PII are restricted to the United States, including AI processing, gateway routing, and fallbacks. Tasks without patient information or other PII, such as medication research and insurance remittance-address searches, can use providers globally.
c. Voice and Audio Data
Nextvisit does not store voice data or voiceprints from real-time transcription features. For audio upload or legacy audio recording methods, Nextvisit may store anonymized voice data after 30 days. We do not create or retain biometric identifiers from voice data. These statements concern Nextvisit's audio storage; provider processing follows the retention practices described above.
d. Model Training
As of 2026, we do not train models on patient or provider information without explicit opt-in. When a provider and patient opt in, eligible training data is limited to data created directly on the Nextvisit platform and goes through our full PII redaction process. Data from third-party authentication services and connected sources, including Google Accounts, Google Calendar, and EHRs, is excluded even when training is enabled. See our training disclosures.
Our default requires consent from both the provider and patient. Consent requirements depend on the applicable state, region, and locality. Contact our Help Center for consent, training information, opt-in, or withdrawal requests. Withdrawal excludes the information from future training. It does not reverse completed training or remove the information's effects from a Nextvisit model already trained on it.
e. Internal Evaluations
Users participate in internal evaluations by default. We evaluate data, including transcripts and LLM traces, solely to monitor accuracy, service quality, performance, and progress against our mission. Evaluation is separate from model training and does not constitute training opt-in. Trace and evaluation records are used internally; external reporting is limited to aggregate performance metrics. Retention varies by workflow. See our evaluation disclosures for the related data handling practices.
Access follows least-privilege and need-to-know controls under the CTO's oversight. Support access to detailed information requires explicit provider confirmation through a user-initiated request. Senior engineers with higher levels of trace access are based in the United States.
Opt-outs from traces and internal evaluations are available under enterprise or custom agreements. Submit requests through our help center. Some services are unavailable with these restrictions.
f. Provider Restriction Requests
To request that a specific provider or subprocessor be excluded from your use of Nextvisit, submit a request at our help center. We try to accommodate requests where feasible; availability is not guaranteed. See provider restriction requests.
6. Third-Party Integrations
We work with trusted third-party providers to deliver secure and reliable services:
Infrastructure Providers
- Amazon Web Services, Google Cloud Platform, Microsoft Azure, DigitalOcean: Hosting and server infrastructure. Sensitive data is stored with partners covered by a BAA and/or an appropriate agreement.
- Cloudflare: Content delivery network and security services.
- Backblaze: Encrypted data backup and storage.
Development and Deployment
- Laravel LLC (Forge, Envoyer, Spark, Cloud): Application deployment, server management, and billing infrastructure. Our BAA covers Laravel Cloud, which is not intended to receive patient information; the agreement is maintained as a precaution against incidental exposure.
Payment Processors
- Stripe: Handles secure payment processing and subscription billing.
Communications and Messaging
- Telnyx: Phone, fax, SMS messaging, two-factor authentication (2FA), and communications services.
- Twilio (planned): We have a signed BAA, but no current service uses Twilio.
- Customer.io, Mailgun, SendGrid: Email delivery and messaging automation platforms.
Claims and Insurance
Claim.MD and Stedi: Claims and insurance services covered by our BAAs with these providers.
Monitoring, Marketing, and Analytics
- Mixpanel, Segment: Product analytics and customer data platform.
- Google Analytics: Website and usage analytics.
- Apollo.io, HubSpot: Marketing, sales outreach, and customer relationship management. These tools are used for prospect and existing customer communications only and do not process patient data.
Diagnostics and Real User Monitoring
Traces, diagnostics, and real user monitoring (RUM) data are stored in US data centers. The destination depends on the service and support needs:
- Nextvisit-hosted or support-managed Sentry, storage buckets, or databases.
- Sentry US hosted services for Nextvisit GO and the Help Center, covered by our Sentry BAA.
- Datadog's HIPAA-compliant services in US data centers.
- Laravel Nightwatch, for non-PII diagnostics.
Support can enable or disable RUM and other diagnostics based on a user's issue or request. Users can opt out of RUM through our help center. Trace and evaluation opt-outs require an enterprise or custom agreement, and some services are unavailable with those restrictions. See our diagnostic disclosures for the related redaction practices.
AI/ML Services
- Anthropic, OpenAI, Google, xAI: Language model processing for documentation, analysis, and chat.
- Cloudflare AI Gateway, OpenRouter: Primary AI routing through Nextvisit's API keys and provider connections.
- Helicone: A legacy AI gateway retired from routine use and retained as a fourth-level failover, covered by our BAA.
- Deepgram, SpaceX/xAI: Voice and transcription, with Deepgram used primarily and SpaceX/xAI as a fallback.
- Perplexity: Search using non-PII inputs only.
Security and Compliance
- Ceel.io: Security and compliance management, including SOC 2, HIPAA, and other regulatory compliance programs.
Productivity and Support Services
- Airtable: Data management and workflow automation.
- Nextvisit-hosted help center and documentation: AI features primarily use OpenAI and Anthropic through OpenRouter.
- Google Workspace: Internal email and documents.
- Neon: Infrastructure for some Help Center and support services.
Google Workspace and Neon are not intended to receive patient information. We maintain BAAs with these providers as a precaution against incidental exposure.
We ensure all third-party integrations comply with data protection laws and execute Business Associate Agreements (BAAs) where required.
7. SMS/Text Messaging Data
Protection of Your Mobile Information
Your mobile information will not be sold or shared with third parties for promotional or marketing purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
Limited Sharing for Service Delivery
We will not share your opt-in to an SMS campaign with any third party for purposes unrelated to providing you with the services of that campaign. We may share your Personal Data, including your SMS opt-in or consent status, with third parties that help us provide our messaging services, including but not limited to platform providers, phone companies, and any other vendors who assist us in the delivery of text messages.
Your Rights
You may opt out of SMS communications at any time by replying "STOP" to any message. Your consent to receive SMS messages is not a condition of using our Service. Message and data rates may apply based on your mobile carrier plan.
8. Cookies and Tracking Technologies
Why We Use Cookies
Cookies and similar technologies allow us to keep you logged in during your session, analyze feature usage and platform performance, and customize your experience based on preferences.
Types of Cookies
- Essential Cookies: Required for the platform to function properly.
- Performance Cookies: Help us understand how users interact with the Service.
- Preference Cookies: Store user settings and preferences.
Managing Cookies
You can control cookies through your browser settings or by contacting us for assistance. Some features may not work properly if essential cookies are disabled. See our Cookie Policy for full detail.
9. How We Protect Your Data
We implement security measures, including:
- Encryption: AES-256 encryption for data at rest and TLS 1.2+ for data in transit.
- Access Controls: Role-based permissions and support for multi-factor authentication.
- Monitoring: Regular security assessments, audits, and intrusion detection.
Despite these measures, no online service can guarantee absolute security. You use our Service at your own risk.
10. Data Breach Notification
In the event of a data breach involving your personal information, we will notify affected individuals and relevant regulatory authorities as required by applicable law, including HIPAA, the New York SHIELD Act, and applicable state breach notification laws. Notifications will be provided without unreasonable delay and, where required, within the timeframes mandated by law. Breach notifications will include a description of the incident, the types of information involved, steps we are taking to address the breach, and recommendations for affected individuals to protect themselves.
11. Data Retention and Deletion
Retention Policy
Clinical data retention follows applicable legal requirements. Model training using patient or provider information remains subject to the explicit opt-in and source restrictions in Section 5.
For AI provider processing, we use ZDR where supported. Otherwise, providers retain data for 30 days in most cases, depending on the model, process, and applicable agreement. This provider retention period does not set a deletion deadline for Nextvisit's clinical records, diagnostics, backups, or other stored data. See our retention disclosures.
RUM data is retained for 30 days. Trace and evaluation data retention varies by workflow. These records are used internally; external reporting is limited to aggregate performance metrics.
After an evaluation, our usual practice is to retain results and calculations without PII. The handling and retention of identifiable evaluation material varies by workflow.
Deletion Requests
You may request that we delete your personal data by contacting us at privacy@nextvisit.ai. Certain information may need to be retained for legal or compliance reasons.
12. We Do Not Sell Your Personal Information
Nextvisit does not sell, rent, or trade your personal information to third parties for monetary or other valuable consideration. This applies to all categories of personal information we collect, including information covered under the CCPA, CPRA, and other applicable state privacy laws. We do not engage in the "sale" or "sharing" of personal information as those terms are defined under California law.
13. Your Privacy Rights
Depending on your state of residence, you may have the following rights:
- Access your personal data.
- Correct inaccuracies in your data.
- Request deletion of personal data, where legally permissible.
- Opt out of marketing communications.
- Opt out of the sale or sharing of personal information (though we do not sell your data).
- Request portability of your data.
- Appeal a decision regarding your privacy request.
California residents may exercise rights under the CCPA/CPRA, including requesting disclosure of data collection practices. Virginia, Colorado, Connecticut, and Utah residents have similar rights under their respective state privacy laws. To exercise any of these rights, please contact us at privacy@nextvisit.ai.
14. Children's Privacy
The Nextvisit platform is not intended for use by individuals under the age of 18. We do not knowingly collect personal information directly from minors. However, healthcare providers using our platform may enter clinical data about patients of any age as part of their professional practice. Such data is processed in accordance with HIPAA and applicable healthcare privacy regulations.
15. Updates to This Policy
We may update this Privacy Policy from time to time. When changes are made, we will post the updated policy on our website. You will be notified via email or platform alerts for significant changes.
16. Contact Information
For questions or concerns, please contact us:
Email: privacy@nextvisit.ai
Mail:
Nextvisit AI Inc
C/O Ryan Yannelli
108 W 39th St
Ste 1006 #1120
New York, NY 10018