This Privacy Policy explains how Solace AI, Inc. (“Solace,” “we,” “us”) handles information in connection with our patient-intake and clinical-triage services (the “Services”). Solace serves healthcare organizations. Most patient health information we touch is handled as a Business Associate on behalf of a covered entity, and is governed first by the Business Associate Agreement (BAA) and HIPAA, not by this consumer-facing policy.
- Clinician & account data. Name, work email, organization, role and authentication metadata for the people who use Solace at a customer site.
- Patient PHI processed for covered entities. Intake responses, demographics, insurance details and related clinical data submitted during a visit, processed under the BAA. See the next section.
- Usage & telemetry. Log data, device and browser details, and aggregate performance and reliability metrics, used to operate and improve the Services.
- Cookies & similar technologies. Strictly necessary and analytics cookies as described below.
When Solace processes patient PHI, it does so as a Business Associate of the covered entity, strictly to deliver the Services and only as the BAA permits. The covered entity, not Solace, is the steward of the patient relationship and the primary point of contact for patient privacy rights.
- We do not sell patient PHI.
- We never use patient PHI to train or fine-tune AI models.
- Our AI plans and narrates over coded, de-identified metadata and slot tokens; raw identifiers are stripped before any model prompt, enforced by an automated leak-gate test in the build.
- To provide, secure, maintain and improve the Services.
- To authenticate users and protect against fraud and abuse.
- To communicate about your account, the Services and support.
- To meet legal, regulatory and contractual obligations, including those under the BAA.
We do not use patient PHI for advertising, and we do not use it to train models. Aggregate, de-identified usage metrics that contain no PHI may be used to improve the Services.
We rely on a small set of infrastructure subprocessors, each bound by contract and, where PHI is involved, by a BAA:
- Amazon Web Services (AWS). HIPAA-eligible cloud hosting, storage and key management, under AWS’s BAA.
- Anthropic, via AWS Bedrock. Model inference runs through Bedrock in covered regions under BAA; prompts contain only coded, de-identified metadata, never raw PHI.
A current list of subprocessors is available to customers on request.
We practice data minimization. Intake sessions are short-lived, and patient records and media carry an automatic TTL that expires them on schedule. Magic-link tokens are single-use and stored only as hashes. Account and contract data are retained for as long as your organization uses the Services and as required by law, then deleted or de-identified. PHI retention and disposal follow the terms of the BAA.
We protect data with customer-managed AWS KMS encryption in transit and at rest, secrets held in AWS Secrets Manager, passwordless magic-link sign-in with short-lived JWT sessions, role-scoped access with tenant-isolation checks, a CloudFront + WAF edge, SSRF guards on outbound calls, and an append-only audit log.
Depending on your jurisdiction, you may have rights to access, correct, delete, port or restrict the processing of your personal information. For patient PHI, individual rights requests are directed to and fulfilled by the covered entity that owns the patient relationship; Solace supports the covered entity in meeting them. For clinician and account data, contact us using the details below.
We use strictly necessary cookies to run the Services and limited analytics to understand performance and reliability. Where required, we obtain consent for non-essential cookies, and you can control cookies through your browser settings.
The Services are intended for healthcare organizations and their staff, not for direct use by children. Any pediatric PHI processed during a visit is handled as PHI under the BAA and the covered entity’s direction, not collected by Solace for its own purposes.
The Services are operated from, and data is processed in, the United States. If you access the Services from outside the United States, you understand that your information will be processed in the U.S., and where applicable we rely on appropriate safeguards for any cross-border transfer.
We may update this policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Services after an update means you accept the revised policy.
Questions about this policy or our data practices? Email privacy@solace.health. We respond within one business day.