Notice of Privacy Practices
This notice describes how medical information about you may be used and disclosed, and how you can get access to this information. Please review it carefully.
Google API Services disclosure → what Google user data RafaNest accesses, and how it is used, shared, protected, retained, and deleted.
Who this notice covers
RafaNest provides the software your clinic uses to schedule appointments, keep records, communicate, and (where enabled) take payments. Your clinic is the “covered entity” responsible for your care; RafaNest acts as its “business associate” under a signed agreement. This notice explains how protected health information (PHI) is handled within the platform and the rights you have under HIPAA.
How your information is used
Your PHI is used to provide care and run the clinic: booking and managing appointments, maintaining your clinical records, sending you appointment confirmations and reminders, processing payments you authorize, and, where your clinician uses it, producing visit summaries with an AI scribe. Some clinics also offer an AI booking assistant on their public booking page — clearly labeled as automated — that can check availability and schedule appointments but is not permitted to give medical information. We do not sell your information, and we do not use it for marketing without your separate, explicit consent.
When information is disclosed
PHI may be disclosed to: your treating clinician and authorized clinic staff; service providers that operate the platform under HIPAA Business Associate Agreements (for example, our cloud, email, and text-message providers); and others when you direct us to or when the law requires it (for example, public-health or legal obligations). Every disclosure to an outside provider is recorded in an accounting you can request.
How your information is protected
PHI is encrypted in transit (TLS) and at rest. Clinical record content is additionally encrypted at the application layer with per-patient keys. Access is restricted by role and is logged in a tamper-evident, append-only audit trail. AI transcription and summarization run inside Amazon Web Services under a HIPAA Business Associate Agreement, so your audio and notes are not shared with any outside AI vendor.
Uses that require your authorization
Uses and disclosures other than those described in this notice will be made only with your written authorization. You may revoke that authorization at any time, in writing, except to the extent we have already acted in reliance on it. We do not sell your PHI, and we do not use or disclose it for marketing without your separate authorization.
Washington and other state consumer health data laws
Some states, including Washington’s My Health My Data Act, regulate “consumer health data” more broadly than HIPAA does — including data collected before any treatment relationship exists, such as browsing a booking page. RafaNest does not use advertising or analytics trackers of any kind anywhere in the product: no pixel, ad network, or data broker ever receives information about you, whether or not you have booked an appointment, and RafaNest does not use geofencing near health-care locations to identify or target anyone. You may withdraw consent for how RafaNest handles your consumer health data, and request that it be deleted, at any time, using the contact details in Changes & contact below — these rights apply in addition to, not instead of, the HIPAA rights described elsewhere in this notice.
Recording consent
If your clinician records a session to generate a visit summary, they must confirm you were informed and consented before recording. Some states require that all parties consent to a recording. You may decline; tell your clinician if you do not wish to be recorded.
Google Calendar integration
If your clinician connects their Google account, appointments you book are mirrored into their Google Calendar so their schedule stays in one place. Only the appointment type, your first name (if the clinician enables that option), and the location are written — never your clinical notes. Full details of what Google data RafaNest accesses are in the Google API Services disclosure below.
Your rights
You have the right to: inspect and obtain a copy of your information; request a correction (amendment) to it; receive an accounting of disclosures made to outside parties; request restrictions on certain uses or disclosures; request that we communicate with you by a particular means or at a particular location (confidential communications); obtain a paper copy of this notice on request, even if you agreed to receive it electronically; and request that your account and personal data be closed and deleted, subject to the retention periods the law requires. You can exercise the access, amendment, and accounting rights from your patient portal.
Data retention
Clinical records are never silently deleted. They are kept in a tamper-evident, append-only form and retained for at least as long as any law that applies to your clinic requires. When you ask us to close your account from your patient portal, your identifying profile details are removed right away: your name is replaced with a placeholder, your email and phone number are cleared, and your login is disabled. For accounts that have been closed for a long time, we also periodically remove the remaining identifying details from the retained record so it can no longer be traced back to you. Audio captured for an AI visit summary is transient: it is deleted from storage once the visit summary has been generated and is not retained afterward. If your clinician records a video visit, the recording is stored temporarily for playback and automatically deleted no later than 7 days after the visit; it is not retained afterward.
Breach notification
If a breach affecting your unsecured PHI occurs, you will be notified without unreasonable delay and no later than 60 days after discovery, consistent with the HIPAA Breach Notification Rule. Where required, regulators and, for large breaches, media outlets are also notified.
Our duties
We are required by law to maintain the privacy of your PHI, to give you notice of our legal duties and privacy practices, to notify you following a breach of your unsecured PHI, and to abide by the terms of the notice currently in effect. We reserve the right to change this notice and to make the revised terms effective for all PHI we maintain; the current version is always available here, and material changes are posted here.
Changes & contact
To exercise a right, ask a question, or file a privacy complaint, contact the RafaNest Privacy Officer at privacy@rafanest.com or +1 (720) 984-8634, or contact your clinic directly. Filing a complaint will not affect the care you receive. You also have the right to complain to the U.S. Department of Health and Human Services, Office for Civil Rights, without retaliation.
Google API Services disclosure
This section applies to practitioners who connect a Google account to RafaNest, and describes RafaNest’s access to Google user data under the Google API Services User Data Policy. It governs Google user data exclusively and takes precedence for that data over the general practices described above, which concern patient health information held in the clinic’s records and not data obtained from Google APIs. In particular, the uses described above — treatment and clinic operations, payment processing, disclosures permitted or required by law, and marketing with separate consent — do not apply to Google user data, which is used only for the two features named below.
Data access — what Google user data RafaNest accesses
A practitioner may connect their Google account so that RafaNest keeps their Google Calendar in step with their RafaNest schedule. RafaNest then accesses exactly two things. (1) Calendar events on the connected account’s own primary calendar (the calendar.events scope): RafaNest creates, updates, and deletes the appointment events it puts there, and — only while the practitioner turns on the optional “let my Google events block my booking slots” setting — reads the start and end times of the events already on that calendar. That read returns times only: RafaNest does not store, display, or transmit the title, description, attendees, location, or any other content of a practitioner’s pre-existing Google events. (2) The connected account’s email address (the userinfo.email scope), so the settings page can show which Google account is currently linked and the practitioner can tell that they connected the right one.
Data use — how that data is used
The calendar write access is used for one user-facing feature: mirroring RafaNest appointments into the practitioner’s Google Calendar, and keeping that mirror correct when an appointment is rescheduled or cancelled. The busy-time read is used for one user-facing feature: hiding times the practitioner is already busy from the slots patients can book, so a personal commitment on their Google Calendar does not get double-booked. The email address is used only to label the connection in the settings UI. Google user data is used solely to provide and improve these user-facing features, and for no other reason. Specifically, it is never used for marketing or promotional messaging of any kind — including where a patient has consented to marketing about their care — never for advertising, profiling, or lending or credit decisions, never for research, analytics, benchmarking, or product statistics, never to process payments, and never to train AI/ML models. It is never sold or rented, and RafaNest does not disclose it under the general permitted-disclosure practices described elsewhere in this notice; the only exception is a narrowly scoped disclosure that a specific law compels, which has not occurred to date.
Data transfer — what is shared and with whom
RafaNest does not share, sell, or transfer Google user data to data brokers, advertisers, or any other third party. The data stays between the practitioner’s Google account and RafaNest’s own infrastructure on Amazon Web Services, which acts solely as RafaNest’s hosting provider under a signed agreement and does not receive the data for any purpose of its own. The only outward transfer is back to Google itself, when RafaNest writes or removes an appointment event on the practitioner’s calendar at their direction.
Data protection — how it is secured
The Google refresh token is encrypted with AES-256-GCM before it is stored, and is decrypted only in memory for the duration of a single sync call. All traffic to and from Google runs over TLS. Access to the connection is scoped to the practitioner who created it and is enforced on every request; administrative access is restricted by role and recorded in an append-only, tamper-evident audit log. The underlying database and object storage are encrypted at rest.
Data retention and deletion
RafaNest does not keep a copy of the practitioner’s Google Calendar. Busy times read for slot calculation are used to answer that one availability request and are never written to the database. The only Google data retained is the encrypted refresh token, the connected account’s email address, and the Google event id of each appointment RafaNest itself created, all of which exist solely to keep the sync working. When the practitioner clicks Disconnect in settings, the stored token is deleted immediately and RafaNest can no longer reach the calendar; deleting the RafaNest account removes the remaining connection fields as well. A practitioner can also revoke RafaNest’s access at any time from their Google Account permissions page.
AI and machine learning — Limited Use
RafaNest’s AI features (visit-summary drafting, transcription, and the booking assistant) run entirely on Amazon Bedrock and Amazon Transcribe inside RafaNest’s own AWS account, under the same HIPAA Business Associate Agreement that covers the rest of the platform. No third-party AI vendor is used, and no Google user data is sent to any external AI service. Amazon Bedrock does not use inputs or outputs to train any model, and prompts are not retained. Google user data is not used to develop, improve, or train any foundational or generalized AI/ML model. For completeness: when a practitioner has enabled busy-time blocking and asks the booking assistant which slots are open, the assistant is given the resulting list of free times, which is derived in part from the practitioner’s Google busy times. No Google event content is ever included, and that derived data is processed only within the isolated AWS environment described above and is never used for model training.
Limited Use compliance statement
RafaNest’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
Effective August 24, 2026. Your clinic may provide an additional practice-specific notice.