Legal
Privacy Policy
Last updated September 3, 2026
Ezren is a practice-management and electronic health record (EHR) tool for mental-health clinicians. Clinicians use Ezren to store and manage information about their clients, including protected health information (PHI). This policy explains what we collect, how we use it, who we share it with, and the choices you have.
Prototype notice. Ezren is currently in an early / prototype stage. Except where you have a signed Business Associate Agreement (BAA) with us, you should not enter real client PHI — use test data only. See our Terms for details.
1. Our role — who controls the data
For information about a clinician’s own account (name, email, billing), Ezren acts as the controller. For information a clinician enters about their clients — the PHI in the EHR — the clinician (or their practice) is the covered entity and controller, and Ezren acts as a service provider / business associate that processes that data only on the clinician’s instructions and to provide the service.
2. Information we collect
We collect the following categories of information:
- Account & practice data — your name, email, password (stored hashed), practice name, team members, and settings.
- Client / patient data (PHI) — everything a clinician records about a client: demographics, contact details, appointments, session notes, treatment plans, documents, intake and consent forms, and secure messages.
- Session audio & transcripts — where you use recording or transcription, the audio you upload or capture and the transcript produced from it.
- Billing & payment data — subscription and invoice records, and, for practices that collect client payments, payment amounts and methods. Card and bank details are handled directly by our payment processor; we do not store full card numbers.
- Support requests — when you report an issue or ask a question from the in-app Support tab, the category, subject, and description you write, along with the page you filed it from and your browser user-agent as diagnostic context. Please describe issues generally and avoid including client names or other PHI.
- Usage & technical data — IP address, browser/device information, and log and audit records of actions taken in the app.
3. How we use information
- To provide, operate, secure, and support the Ezren service.
- To perform the features you invoke — scheduling, note-taking, transcription, AI-assisted drafting, messaging, telehealth, billing, and reporting.
- To send transactional messages such as appointment reminders and account notices.
- To respond to your support requests and diagnose and fix problems you report.
- To monitor errors and keep the service reliable — technical and diagnostic data (not PHI) is sent to our error-monitoring subprocessor for this purpose.
- To maintain audit trails and meet our security and legal obligations.
We do not sell your data or your clients’ data, and we do not use PHI for advertising. We do not use your clients’ PHI to train AI models, and our AI provider does not train on the content you submit through the API.
5. AI features
When you ask Ezren to draft a progress note or explain insurance benefits, the relevant text you submit is sent to our AI provider (Anthropic’s Claude API) to generate the output, then returned to you. This content is used only to produce your result; it is not used to train models. AI output is a draft aid only — you are responsible for reviewing and approving anything you keep in a clinical record.
6. How we protect data
Ezren is built with health-data security in mind:
- Encryption of data in transit (TLS) and at rest.
- Row-level security so each practice can only reach its own data, plus role-based access controls and optional multi-factor authentication.
- An append-only, hash-chained audit log recording access to patient data, with full version history and tamper-evidence (supporting HIPAA §164.312 technical safeguards).
- Encrypted backups with a documented, tested recovery process: we publish internal targets for how quickly data is restored and how much may be lost, and we rehearse the restore on a schedule rather than assuming it works.
No system is perfectly secure, but we work to protect your information and to notify you of a breach affecting your data as required by law.
7. Data retention
We keep account and clinical data for as long as your account is active and as needed to provide the service. You can export your data at any time. On request or account closure we will delete or return your data within a reasonable period, except where we must retain records to meet legal, tax, or audit-integrity obligations.
Deletion applies to our live systems first. Encrypted backup copies, which exist so your records can be recovered after a failure, are not edited selectively — doing so would break the integrity protections above. Deleted data therefore persists in backups until they age out on their normal schedule, which is up to 90 days. When we restore a copy of the database to test or perform a recovery, that copy is access-restricted and destroyed once the recovery is verified.
8. Your rights and choices
Depending on where you and your clients live (e.g. under HIPAA, GDPR, or U.S. state privacy laws), you or your clients may have rights to access, correct, export, or delete data. Because clinicians control their clients’ records, client requests are generally directed to the treating clinician; Ezren will assist clinicians in fulfilling them. To exercise your own rights, contact us at privacy@ezrenhealth.com.
9. International data transfers
Our providers process data primarily in the United States (Whereby may also process telehealth media in the European Union). If you access Ezren from outside these regions, your data may be transferred to and processed there under appropriate safeguards.
10. HIPAA and Business Associate Agreements
Where Ezren handles PHI on behalf of a covered entity, it does so as a business associate under a BAA. If your use of Ezren involves real PHI, contact us at legal@ezrenhealth.com to put a BAA in place before entering that data.
11. Children’s data
Ezren is a professional tool for clinicians, not intended for direct use by children. A clinician may record information about a minor client as part of treatment; that data is handled under this policy and the clinician’s own legal obligations.
12. Changes to this policy
We may update this policy as Ezren evolves. When we make material changes we will revise the “last updated” date above and, where appropriate, notify you. Continued use of the service after a change means you accept the updated policy.
13. Contact us
Questions about this policy or your data? Email privacy@ezrenhealth.com.