Legal

Privacy Policy

Last updated: June 1, 2026

1. Who we are

AuditHalo is a clinical supervision compliance platform operated by Medipyxis. For any privacy questions, contact us at info@audithalo.com.

2. What we collect

  • Account information — name, email address, password (bcrypt-hashed, never stored in plaintext), role, state, and license type.
  • Organization data — practice name, billing contact, and subscription status.
  • Supervision records — session dates, durations, session types, hour totals, and e-signature metadata (signer name, role, timestamp, IP address, intent confirmation).
  • Evidence packages — the sealed, SHA-256-hashed JSON records generated at signing. These are immutable once created.
  • Supervision session content — if you use the AI session notes feature, you submit a supervision transcript for processing. We do not store the raw transcript after processing completes. The generated structured note is stored as part of the session record.
  • Usage and log data — server logs, IP addresses, and pages visited, used for security monitoring and debugging.

3. What we do not collect

AuditHalo is a supervision compliance tool, not a clinical records system. Supervision notes document the supervisory relationship — counselor development, competencies, and professional growth — not client information. We do not collect or store patient or client records of any kind.

4. How we use your data

  • Providing and operating the AuditHalo platform
  • Evaluating supervision hours against encoded state board rules
  • Generating, sealing, and storing evidence packages
  • Sending transactional emails (invitations, signature requests, billing receipts)
  • Processing payments through Stripe
  • Security monitoring and error debugging
  • Improving the platform based on aggregate usage patterns (never individual records)

We do not sell your data. We do not use your data to train AI models.

5. Third parties we share data with

  • Neon — Postgres database, US-East-1, encrypted at rest
  • Vercel — application hosting, US-East, receives request logs
  • Stripe — payment processing; AuditHalo does not store card numbers
  • Resend — transactional email delivery
  • OpenAI — processes supervision transcripts for AI session notes via the standard API; content is not retained and not used for model training
  • Sentry — anonymized error monitoring

We do not share your data with licensing boards or any government entity except as required by law.

6. Data retention

  • Account and organization data: retained while your account is active and for 90 days after deletion
  • Supervision records and evidence packages: retained for 7 years from creation (matching most state board record-retention requirements)
  • Raw transcript content: deleted after AI processing completes — not stored
  • Audit log entries: 7-year retention

7. Your rights

You may request to:

  • Access a copy of the data we hold about you
  • Correct inaccurate data
  • Delete your account and associated data (subject to retention requirements above)
  • Export your supervision records

To make any of these requests, email info@audithalo.com.

8. Security

Passwords are bcrypt-hashed. Sessions are stored in HttpOnly cookies scoped to app.audithalo.com. All traffic uses TLS 1.3. Data at rest is encrypted by our cloud providers. We monitor for unauthorized access and will notify affected users in the event of a breach as required by law.

9. Children

AuditHalo is a professional platform for licensed clinicians. We do not knowingly collect data from anyone under 18.

10. Changes to this policy

We update the “Last updated” date when this policy changes. For material changes, we'll notify you by email at least 14 days before the change takes effect.

11. Contact

info@audithalo.com