PRIVACY
Privacy Policy
This policy explains what ABA NoteFlow AI collects, where information is processed, and the controls available to you.
Effective August 19, 2026
Information you provide
ABA NoteFlow AI receives the account information needed to identify your login, administer access, enforce note allowances, and support billing. You may also enter treatment details to request a draft. Do not enter names, initials, exact service dates, addresses, contact details, record numbers, insurance information, assessment files, or other information that could identify a client.
AI drafting
After you confirm that identifying information was removed, the treatment-detail fields needed for drafting are sent through the NoteFlow server to OpenAI to generate an editable draft. NoteFlow does not intentionally send client-profile fields, payment-card information, or assessment files with that request.
Information stored by NoteFlow
The server stores account identifiers, your self-reported professional role, usage counts, access status, feedback status when enabled, and billing references needed to operate the service. Generated note drafts, session-form fields, and client profiles are not stored in the NoteFlow server database.
Information stored on your device
Client profiles and professional-profile details other than your selected role are encrypted and stored in the browser on the device where you created them. They may be removed by deleting a profile, deleting your account from that browser, or clearing the browser’s site data. Anyone with access to your unlocked device and browser session may still be able to use the app, so protect your device.
Service providers
Clerk supports account authentication, Stripe supports checkout and subscription management, Cloudflare supports application hosting and operational storage, and OpenAI provides note generation. Those providers process limited information needed for their role and may retain records under their own terms or legal obligations. NoteFlow does not receive your full payment-card number.
Extension permissions and page data
The optional Chrome extension uses browser permissions to open its side panel, identify the current tab, show its right-click drafting command, copy a completed draft, and read or insert content only on a website you approve. It receives website content and form data only when you initiate a read or insertion action. Extracted fields are displayed for review, approved website access can be removed, and temporary form and insertion-target information is cleared when the panel closes. NoteFlow does not sell extension data, use it for advertising or credit decisions, or permit humans to read captured page content except when specifically authorized by you for support, required for security, or required by law. Page information is used only to provide the extension’s disclosed note-drafting workflow. Browser permissions do not make clinical information appropriate to send to AI; you remain responsible for removing identifiers.
Retention and deletion
You may permanently delete your NoteFlow account from the Account screen. This removes the login and NoteFlow usage and billing-reference records associated with it and clears local profiles in that browser. Stripe and other providers may keep transaction or security records they are independently required to retain.
Security and limitations
NoteFlow uses HTTPS, authenticated access, server-side secrets, security headers, and restricted application flows. No system can promise absolute security. NoteFlow has not completed a formal HIPAA compliance program and should not be used to transmit protected health information.
Questions
For privacy or account questions, email support@abanoteflow.com. Do not include client or session information in a support request.
