Last updated: August 25, 2026
At Bolder AI Care, privacy is fundamental to the trust placed in us. This Privacy Policy explains how Bolder-I LLC d/b/a Bolder AI Care ("Bolder AI Care", "we", "us") handles information collected through our public website and information processed through the Bolder AI Powered Care software (the "Service").
We have divided this policy into two parts, because visiting our website is different from having your information processed through the Service by a healthcare professional. Part One covers our website. Part Two covers the software, which is used by healthcare staff to record, transcribe, and review patient exams and therefore processes protected health information ("PHI"). When we process PHI, we do so on behalf of the healthcare providers and organizations that use the Service, as described in Section 13.
This part applies to visitors of our public website. If you are a patient whose information was processed through the Service by your healthcare provider, see Part Two.
When you visit our website, we may automatically collect limited technical information, which may include your Internet Protocol address, browser and device information, the pages you visit, the date and time of your visit, and information about how you interact with the website.
We may also collect information you choose to provide, such as your name, email address, telephone number, company or organization, and any questions or comments you submit through a form.
Please do not submit medical information through a general website contact form unless Bolder AI Care or your healthcare provider has specifically instructed you to do so.
We use information collected through the website to respond to inquiries and requests; to communicate with interested customers, healthcare professionals, and partners; to operate, maintain, and secure the website; to understand website activity and improve our services; and to meet applicable legal and regulatory obligations.
Within the Bolder AI Powered Care application itself, we use only the browser storage strictly necessary to operate the Service — tokens stored in your browser to keep you signed in, and local storage for the exam recordings and their transcripts while a visit is in progress. The application does not use advertising cookies, analytics cookies, tracking pixels, or other third-party tracking technologies.
Exam audio is recorded by your browser and stays on the device you recorded it on. Each clip is held in that browser's local storage, where you can play it back or delete it.
Our public website may use cookies and similar technologies to operate and secure the site and to understand how it is being used. You may be able to limit or remove cookies through your browser settings, although doing so may affect certain website features.
Bolder AI Care does not sell your personal information. We do not provide your personal information to unrelated companies for their own advertising or marketing purposes. Information may be processed by carefully selected service providers that support our website or business operations, but only for authorized purposes and subject to appropriate confidentiality and data-protection requirements.
You may contact us in writing to ask that we access, correct, or delete personal information maintained in our website or business-contact systems. After verifying your identity, we will honor an eligible request within the time required by applicable law.
In some circumstances we may need to retain limited information to comply with legal obligations, maintain security records, prevent fraud, resolve disputes, or document that a request was completed. To make a request, use the contact details in Section 19. You may raise a privacy concern without fear of retaliation.
This part applies to information processed through the Service on behalf of a healthcare provider.
Bolder AI Powered Care helps healthcare professionals collect, organize, review, and understand information relevant to the care of their patients. It is intended to support healthcare professionals and does not replace the professional judgment of a qualified healthcare provider. Your healthcare provider remains responsible for evaluating the information presented by the software and for decisions regarding your diagnosis, treatment, and care.
Depending on the services being provided, Bolder AI Care may process health information on behalf of your healthcare provider. When we act as a business associate under the Health Insurance Portability and Accountability Act ("HIPAA"), we handle PHI in accordance with applicable HIPAA requirements and our written agreement with the healthcare provider. See Section 13.
Account information. When you create an account we collect your email address and the role you register under (such as Organization Administrator, Physician, Nurse Practitioner, Physician Assistant, Registered Nurse, Licensed Practical Nurse, Medical Assistant, or Medical Receptionist), together with the organization you belong to. Authentication is handled by Amazon Cognito.
Patient information (PHI). To support a visit, the Service processes patient information entered into or imported by the Service — such as name, date of birth, contact and demographic information, patient and encounter identifiers, dates associated with care, medical history and records, symptoms, medications, diagnoses, treatment information, clinical observations, and medical measurements and device readings.
Visit information (PHI). During and after a visit, the Service processes the transcript of the exam, vitals, the chief complaint, information supplied by your healthcare provider, and the documentation produced from the visit (such as patient summaries, SOAP notes, exam findings, and suggested billing codes). What reaches Bolder AI Powered Care is text: the transcript of each clip, the vitals and chief complaint you enter, and the patient and encounter identifiers the visit is filed under. These travel over an encrypted connection to our AWS US West (Oregon) environment, where checking the patient out hands the transcript and visit context to Amazon Bedrock to draft the note, summary, exam findings, and suggested billing codes.
The exam audio is not in that list. The recording is never uploaded. Bolder AI Powered Care has no way to receive an audio file: the audio is turned into text on your own device, and only that text is sent to us. What we receive, and therefore all we can process, disclose, or produce in response to a request, is the text. Section 12 describes how the audio is handled.
Technical information. Limited operational data (such as error diagnostics) needed to run and secure the Service, and an access log recording which users viewed or changed which records. We do not include patient-record content in application logs.
The exact information processed depends on the services requested by your healthcare provider and the manner in which the software is used.
Bolder AI Care processes health information only for authorized healthcare and operational purposes, including organizing information for review by your healthcare provider; identifying potentially relevant patterns, measurements, or changes; preparing summaries, reports, or other clinical-support information; helping healthcare professionals assess and coordinate care; operating, securing, testing, and supporting the software; and meeting applicable legal, regulatory, contractual, and patient-safety requirements.
Bolder AI Care does not sell your health information, does not share it with third parties for their own purposes, and does not use PHI for targeted advertising. Information generated by the software is provided to your healthcare professional for review; Bolder AI Care does not independently diagnose a condition, prescribe treatment, or make final healthcare decisions.
The healthcare provider's EMR is the system of record. The official, permanent patient record is created and retained in the provider's own HIPAA-compliant systems, in accordance with the provider's medical-record retention practices and legal obligations. Nothing in this Section deletes, alters, or shortens the retention of information that has been transferred to or incorporated into that record.
Separately, the Service is designed to minimize the amount of patient information retained in our systems. Temporary copies of transcripts, medical measurements, generated documentation, and other patient information processed by the Service are deleted from Bolder AI Care-controlled systems within 24 hours after processing and secure delivery to the healthcare provider. Deletion is automatic. We do not retain long-term backups of PHI.
Exam recordings are not part of this. The recording is not part of what Bolder AI Powered Care holds or deletes — it never leaves your browser. What is deleted on that schedule is the text we received: the transcript and the drafted output. Because the recording never reaches us, it is not on our deletion schedule — and we cannot retrieve or restore it. It stays in the browser that made it until the clip is deleted or that browser's site data is cleared, and it is not available from another browser or another device.
Accounts without an EMR connection. Where an account is being evaluated and no EMR has been connected yet, there is no delivery target and therefore no external system of record for that visit. For those accounts, temporary copies are instead deleted within 7 days, so that information is not lost before it can be exported. A longer retention period may be arranged in writing as part of EMR integration. Once the EMR connection is live, the within 24 hours period in the preceding paragraph applies.
Limited technical records that do not contain patient-record content — including the access log described in Section 8 — may be retained beyond this period when necessary for cybersecurity, system integrity, audit, incident investigation, or compliance purposes.
Account information (as distinct from patient and visit information) is retained for as long as your account exists. Where an account or organization is closed, records that we are required to retain for medical-record, audit, or legal-compliance purposes are preserved rather than erased.
With separate and affirmative authorization from the relevant patient or authorized party, Bolder AI Care may retain selected information beyond the standard deletion periods described in Section 10 to evaluate, train, test, and improve the quality, safety, accuracy, and reliability of our software.
Participation is voluntary. A decision not to participate will not affect your care or your relationship with your healthcare provider, and this program does not modify the default automatic deletion described in Section 10.
Before using the information, Bolder AI Care will remove or transform identifying details using appropriate de-identification procedures. We will not knowingly attempt to re-identify properly de-identified information, sell it, or use it for targeted advertising.
Upon written request, and while the information can still be linked to your authorization, you may review the information selected for de-identification and request that it be removed. You may also withdraw your authorization for future use. Once information has been irreversibly de-identified, combined with other data, or incorporated into a system in a way that no longer allows us to identify your individual contribution, it may no longer be possible to locate, review, or delete your specific information. This limitation will be explained before your authorization is obtained.
De-identified information will be used only for approved purposes related to quality improvement, patient safety, research, and the development of healthcare technology. Appropriate privacy and security safeguards continue to apply.
We use Amazon Web Services (AWS) as our infrastructure and processing provider. AWS services support authentication (Amazon Cognito), storage (Amazon S3), the application backend (Amazon API Gateway and AWS Lambda), and the generation of clinical documentation (Amazon Bedrock). We have entered into a HIPAA Business Associate Agreement with AWS covering the handling of PHI. We do not use any other third-party subprocessor to process patient information.
Speech-to-text runs on your own device. Speech-to-text runs on your own device, inside the browser, using a Whisper speech-recognition model that Bolder AI Powered Care loads into a background worker. There is no transcription server and no speech-to-text vendor involved.
The recording is never uploaded. Bolder AI Powered Care has no way to receive an audio file: the audio is turned into text on your own device, and only that text is sent to us.
The first time a browser transcribes, it downloads the speech-recognition model files from the public Hugging Face model hub and caches them for later visits. That is a one-way download of the model itself — no audio, no transcript, and no patient information is sent with it.
If transcription fails, the recording is unaffected — it is saved and playable before transcription even starts. The clip is marked as failed, no text is sent for it, and nothing from it reaches the drafted note. Record the passage again to add a transcript, or continue without one; if no clip in a visit produced a transcript, there is nothing for checkout to process and the Results tab stays empty.
When we create, receive, maintain, or transmit PHI on behalf of a covered entity, we act as a Business Associate as defined by HIPAA, and our handling of PHI is governed by the applicable Business Associate Agreement ("BAA") with that organization. We are prepared to enter into a BAA with covered-entity and business-associate customers — see Section 6 of the Terms of Service.
We maintain signed Business Associate Agreements with our own subcontractors and infrastructure providers that may handle PHI on our behalf — including Amazon Web Services, which provides the infrastructure described in Section 12 — and require them to apply safeguards consistent with our obligations to you.
We use administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of the information we process, including encryption in transit and at rest, role-based access controls, organization-level data isolation, an access log, automatic session timeout, and the automatic deletion described in Section 10.
Access is limited to authorized individuals and service providers who require it to perform approved functions, and those individuals and organizations are subject to confidentiality, security, and data-protection obligations. Although no electronic system can guarantee absolute security, we are committed to maintaining safeguards appropriate to the sensitive nature of health information.
Information is stored and processed in the United States using AWS data centers in the AWS US West (Oregon) region.
Your healthcare provider generally controls the official medical record and is responsible for responding to requests involving that record. To request access to, correction of, or deletion of information contained in your medical record, please contact your healthcare provider directly. Medical records may be subject to legal retention requirements and may not always be eligible for deletion.
Your healthcare provider may also give you a separate HIPAA Notice of Privacy Practices, which explains how the provider may use and disclose your health information and describes your rights regarding the provider's medical records. That notice governs the provider's handling of those records. For questions about your own account with us, use the contact details in Section 19.
The Service is intended for use by healthcare staff and is not directed to children, and we do not knowingly create accounts for children under 13. (This concerns account holders; information about patients, who may be minors, is handled as PHI under the terms above.)
We may update this Privacy Policy as our services, technologies, or legal obligations change. When we make changes, we will update the "Last updated" date above and provide any additional notice required by law.
For questions about our privacy practices, to make a request under Section 6, or to request more detailed privacy or legal documentation, contact us at support@bolder-i.com. We will respond directly or, when appropriate, arrange for a response from our privacy or legal counsel.