Privacy Notice

Last updated: August 15, 2026

1. Introduction

Optimize AI Tech ("Optimize AI", "we") builds Medical Copilot, a Clinical Documentation & Coding Intelligence platform for healthcare organizations. This notice explains what information we process, why, and the rights available to you. It covers both visitors to this website and the data we process on behalf of our healthcare clients through the Medical Copilot platform.

2. Data We Process on Behalf of Healthcare Clients

Medical Copilot processes clinical encounter documentation on behalf of healthcare organizations, under written agreements with those organizations. Where United States law applies, we act as a Business Associate under HIPAA and execute Business Associate Agreements with our clients. If a Business Associate Agreement, client agreement, or data-processing agreement applies and conflicts with this notice, that agreement controls for the covered client data.

We follow strict data minimization. To perform documentation and coding review, the platform processes:

We do not deliberately collect or store patient names, addresses, contact details, social security or national identity numbers, or medical record numbers. Where clinical free text, audio, transcripts, or encounter materials supplied by a client contain identifying details, that information is protected with the same safeguards as all clinical data.

3. Ambient Documentation, Audio, and Consent

When a healthcare client enables ambient scribe or encounter-listening features, Medical Copilot may process audio or conversation content from an encounter to generate draft transcripts, summaries, notes, documentation suggestions, coding-related context, or other encounter-support output. Audio processing may be transient during a live session. Temporary encrypted transcripts, draft notes, session artifacts, or processing logs may be retained only as needed to provide, secure, troubleshoot, audit, or support the service, and according to the applicable client agreement, Business Associate Agreement, product configuration, or retention setting.

The healthcare client is responsible for determining when patient notice, patient consent, participant consent, staff consent, or other authorization is required for recording, transcription, ambient listening, or AI-assisted documentation, and for obtaining and documenting that notice or consent before using ambient features. Medical Copilot may provide consent prompts, status indicators, logs, configuration settings, or other consent-support tooling, but those tools support the client's workflow and do not replace the client's legal responsibility.

Ambient output is draft documentation support. The client is responsible for clinician review, editing, approval, and inclusion in the medical record. The service does not have autonomous clinical authority and does not independently diagnose, treat, prescribe, order care, submit claims, or make final clinical, coding, billing, or payer-submission decisions.

Encounter audio or transcripts may include information from patients, clinicians, interpreters, family members, caregivers, trainees, and other participants. The client is responsible for addressing the rights and expectations of those participants under applicable law and policy.

4. Safeguards

All clinical data is protected through:

5. Artificial Intelligence Processing

Medical Copilot uses artificial intelligence to analyze documentation and suggest clarifications, draft notes, summaries, and codes. AI output is advisory: it is reviewed and confirmed by qualified professionals at the client before any use, and every recommendation carries its source text and rationale where supported by the applicable feature. We do not use identifiable protected health information from client clinical data to train generalized models for other clients, and processing by any technology subcontractor takes place under data-protection agreements consistent with this notice and any applicable Business Associate Agreement.

We may use de-identified, aggregated, or operational information to maintain security, measure system performance, improve reliability, evaluate accuracy, troubleshoot issues, and improve the service, subject to applicable agreements and law. We minimize data used for these purposes and do not use identifiable client PHI for generalized model training unless expressly permitted by the applicable written agreement and law.

6. Website Data We Collect Directly

On this website we collect:

7. How We Use Information

8. Data Retention

Clinical data processed for clients is retained according to the client agreement, Business Associate Agreement, product configuration, and applicable healthcare regulations, and is returned or deleted when the agreement ends. Ambient audio may be processed transiently, while encrypted transcripts, draft notes, session artifacts, logs, and audit records may be retained temporarily or for the period configured or agreed for clinical, support, audit, compliance, or legal purposes. Website enquiry data is kept only as long as needed to handle the enquiry and any resulting relationship.

9. Legal Frameworks and Your Rights

We align our practices with the privacy laws of the markets we serve, including HIPAA in the United States, the EU and UK GDPR, the Saudi Personal Data Protection Law (PDPL), the UAE Personal Data Protection Law, and applicable US state privacy laws such as the California Consumer Privacy Act.

Depending on the law that applies to you, you may have the right to:

For patient data processed on behalf of a healthcare client, requests should be directed to that healthcare organization, which controls the data; we support our clients in fulfilling them.

10. Contact Information

For privacy-related inquiries, contact our Data Protection Officer at: privacy@medcopilot.co