Legal
Last updated: July 1, 2026
Scryber, Inc. ("Scryber," "we," "our," or "us") is committed to protecting the privacy and security of the information we handle. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data when you use our platform and services.
If you are a patient whose information was processed through a healthcare provider using Scryber's tools, please contact your provider directly — they are the covered entity responsible for your PHI under HIPAA.
Account Information: When you register, we collect your name, email address, practice name, specialty, NPI number, and billing information.
Clinical Session Data: When you use Transcryber, audio from clinical encounters is processed to generate SOAP notes and billing codes. Audio is not stored beyond the processing session unless explicitly retained for review by the clinician.
Usage Data: We collect log data including IP addresses, browser type, pages accessed, and feature usage to maintain and improve the Services.
Communications: If you contact us, we retain records of that correspondence.
We use the information we collect to:
We do not use protected health information (PHI) to train AI models, sell data to third parties, or use clinical data for advertising purposes.
Scryber acts as a Business Associate under HIPAA for covered entities. We maintain appropriate administrative, physical, and technical safeguards for PHI as required by the HIPAA Security Rule. A Business Associate Agreement (BAA) is available and must be executed before PHI is processed through our platform. To request a BAA, contact support@scryber.ai.
We do not sell your personal information. We may share information in the following limited circumstances:
We retain account and usage data for as long as your account is active or as needed to provide the Services. After account termination, we retain data for up to 7 years to comply with healthcare recordkeeping requirements and applicable law, unless a shorter period is required by a BAA or applicable regulation. You may request deletion of non-clinical data by contacting us.
We implement industry-standard security measures including AES-256 encryption at rest, TLS 1.3 encryption in transit, zero-trust access architecture, role-based access controls, and multi-factor authentication. For a full overview of our security posture, see our Security page.
We use essential cookies to maintain your session and preferences. We do not use third-party advertising cookies. You can manage cookie preferences through your browser settings, though disabling essential cookies may affect platform functionality.
Depending on your jurisdiction, you may have rights to access, correct, delete, or restrict processing of your personal information. To exercise these rights, contact us at support@scryber.ai. We will respond to verifiable requests within 30 days.
For PHI access requests related to clinical records, please contact your healthcare provider directly.
The Services are intended for healthcare professionals and are not directed to individuals under 18. We do not knowingly collect personal information from minors. If you believe a minor's information has been submitted, contact us immediately.
We may update this Privacy Policy periodically. We will notify you of material changes via email or in-app notice at least 14 days before the changes take effect. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy.
If you have questions, concerns, or requests regarding this Privacy Policy or your data, please contact us: