Privacy Policy

Last Updated: August 24, 2026

LynxFlow Health is a remote patient monitoring platform. It handles protected health information, and it is built to meet HIPAA requirements: access is scoped by role, every access to patient data is written to an audit log, and sensitive fields are encrypted at rest.

1. Information we collect

  • Account information — name, email address, the role you hold, and the facility or organisation you belong to.
  • Health information — patient records and the readings transmitted by connected devices, together with device identifiers and status.
  • Billing information — for individual subscribers, subscription status and a payment reference held by Stripe. We do not receive or store full card numbers.
  • Files you upload — images or PDFs you attach to a question in AI Analytics.
  • Access records — the audit log described below, which includes IP address, browser user agent, and the path accessed.

2. How we use information

We use it to operate the monitoring service: to present readings to the clinicians responsible for a patient, to run the reports and analytics you request, to send service email such as invitations and scheduled summaries, to process subscription payments, and to secure the platform and meet our regulatory obligations. We do not sell personal information, and we do not use it for advertising.

3. AI Analytics and de-identification

When you ask AI Analytics a question, the platform builds a briefing from the records you are authorised to see and replaces patient identifiers with opaque tokens before anything leaves our systems. The AI provider receives the tokenised text — for example "PT-001" — never the patient's name. Identifiers are restored in the answer only after it returns, and only for you.

Files you attach are streamed to the provider to answer your question and are never written to our storage or database; only the filename, type, and size are recorded alongside the message. Every AI Analytics query that touches patient records is written to the audit log.

4. Who we share information with

We share information with service providers who process it on our behalf, under contract and only for the purposes above:

  • our cloud hosting and database provider;
  • the manufacturer of your connected monitoring devices;
  • our transactional email provider;
  • Stripe, for subscription billing;
  • our AI provider, which receives de-identified text as described above.

We also share information with your own clinicians, facility, and organisation as the platform's role model requires, and where the law obliges us to.

5. Security and audit logging

Access is scoped by role and enforced server-side, not merely hidden in the interface. Sensitive fields are encrypted at rest, traffic is encrypted in transit, and every access to patient data is recorded in an audit log capturing who accessed what, when, and from where. Audit records are retained for six years in line with HIPAA requirements. No system is perfectly secure, but these controls are actively maintained and reviewed.

6. Cookies

We use only essential cookies, for secure login and session management. There are no analytics, advertising, or tracking cookies. See the Cookie Policy for the full list.

7. Your rights

You may request access to the personal information we hold about you, ask for corrections, and ask for deletion where we are not required to retain it. If your record is held by a healthcare provider using the platform, that provider is the custodian of your health record and we will direct your request to them. Contact us at the address below to make a request.

8. Retention

We keep account and health information for as long as your account is active and afterwards for as long as we are required to. Audit logs are retained for six years. Files attached to AI Analytics questions are not retained at all.

9. Contact

Privacy questions and requests can be sent to support@lynxflowhealth.com.