Privacy

How PepProto handles the data a clinic and its patients put into the platform.

Summary, not a contract. This page describes how PepProto is built. It is not a counsel-reviewed policy and does not replace the agreements a clinic signs before deployment — including a Business Associate Agreement. For the executed documents, contact hello@pepproto.com.

Whose data this is

Clinical information belongs to the clinic and its patients. PepProto processes it on the clinic’s instruction to run the platform — it is not sold, rented, or used to advertise, and it is not used to train third-party models.

What is collected

Account details for providers and staff; intake answers, treatment plans, tasks, lab results, documents and messages entered by a clinic or its patients; and operational logs needed to run and secure the service. Marketing forms on this site collect only the contact details you type into them.

Tenant isolation

Every clinical record is scoped to a clinic and isolated at the database level by row-level security, so one clinic’s staff cannot read another’s rows. Patients see only their own record.

Subprocessors

The platform runs on Supabase (database, authentication and file storage), Vercel (hosting) and Anthropic (the model behind AI drafting). AI drafts are generated from clinical data on request; no content is shared with a model provider for training.

Access, correction and deletion

Patients should contact their clinic, which controls their record. Clinics can reach hello@pepproto.com for export or deletion of a workspace.

Not an EMR · AI requires provider review