Legal

Privacy Policy

Effective date: June 4, 2026  ·  Cleryn LLC  ·  Questions: contact@cleryn.ai

1. Introduction

Cleryn LLC ("Cleryn," "we," "us," or "our") operates cleryn.ai and provides an AI-assisted compliance review platform for sleep diagnostic centers ("Services"). This Privacy Policy explains how we collect, use, store, and protect information in connection with the Services.

This policy applies to all users of the Services, including authorized staff at sleep diagnostic centers ("Customers") who access the platform on behalf of their organizations. It does not apply to information collected by third-party services linked from our platform.

Note on HIPAA. Cleryn acts as a Business Associate under HIPAA with respect to Protected Health Information ("PHI") submitted through the Services. Our obligations regarding PHI are governed primarily by the Business Associate Agreement ("BAA") executed with each Customer, and by HIPAA's Privacy and Security Rules. This Privacy Policy supplements — but does not replace — those obligations.

2. Information We Collect

2.1 Account Information

When you create an account or request access, we collect:

2.2 Documents and Protected Health Information

The core function of the Services requires Customers to upload physician documents (PDFs, scanned faxes, or images) that may contain PHI, including patient names, dates of service, diagnosis codes, and clinical notes. Uploaded documents are processed in memory solely to generate the compliance review described in the BAA and are never written to persistent storage. The resulting review report is returned to you at processing time and is not retained on Cleryn's systems — what Cleryn keeps is a patient-free activity record (date, payer, study type, compliance score, and which checklist requirements were missing), as described in Section 4.3.

AI analysis is performed using Claude models hosted within Google Cloud's Vertex AI service, under Cleryn's Google Cloud HIPAA Business Associate Agreement. PHI is not sent to any third-party AI provider outside Google Cloud. Cleryn does not use PHI to train, fine-tune, or improve AI models, for marketing purposes, or for any use outside the scope of the BAA.

2.3 Usage and Technical Data

We automatically collect certain technical information when you use the Services, including:

3. How We Use Your Information

Data typeHow we use it
Account informationTo manage your account, process payments, send service communications, and confirm coverage region eligibility
PHI in uploaded documentsSolely to perform the compliance review and return results to you — no other use
Review resultsTo display compliance reports to authorized users within your organization and to calculate usage for billing
Usage dataTo monitor service performance, detect abuse, and improve the platform
Contact information from access requestsTo follow up on access requests and notify you of regional availability

We do not sell, rent, or share your personal information or PHI with third parties for their marketing purposes.

4. PHI Handling and Data Retention

4.1 Transmission

All data transmitted between your browser and Cleryn's servers is encrypted in transit using TLS 1.2 or higher. Uploaded documents are transmitted directly to Cleryn's processing service running on Google Cloud and are held in memory only for the duration of the review.

4.2 Data at Rest

Raw uploaded documents are not written to persistent storage, so no copy of the original document exists at rest. Review results are likewise not stored — they are delivered to your screen and your systems at processing time. The patient-free activity records Cleryn does store in Firestore are encrypted at rest by Google Cloud using AES-256. Because no patient information is stored at rest, a breach of Cleryn's database cannot expose patient records.

4.3 Retention Schedule

DataRetention periodDeletion method
Raw uploaded documents (PHI)Not retained — processed in memory onlyDiscarded automatically when the review request completes; never written to persistent storage
EMR export data (optional feature; full patient demographics)Not retained — extracted transiently during the review and delivered directly to your workstation; the export file exists only on your systemsNever written to Cleryn storage; removed from the stored review result before saving
Compliance review results (checklists, patient identifiers, clinical summaries)Not retained — returned to you at processing time only; no result content or patient identifier (not even a hashed name) is storedNever written to Cleryn storage
Review activity records (patient-free: date, payer, study type, score, missing checklist requirements, claim outcome)90 days from review dateAutomatic TTL deletion via Firestore
Anonymous audit and outcome recordsRetained indefinitely as HIPAA-required audit documentation — structured metadata only (payer, study type, scores, claim outcome); contains no patient names, hashes, or free textDeliberately durable (HIPAA §164.316 documentation evidence)
Account recordsDuration of account, plus up to 6 years where required for HIPAA documentationManual deletion upon written request, subject to legal retention obligations
Operational logs (PHI-free)Up to 6 years (HIPAA documentation retention)Automatic expiration via Google Cloud log retention

Upon termination of your account, the activity records above are deleted according to the schedule (there are no stored documents or review results to delete — they only ever existed on your systems). Account information is retained for the period required by applicable law and our BAA obligations.

5. Sub-Processors and Third-Party Service Providers

Cleryn uses the following sub-processors to provide the Services. Each sub-processor with access to PHI has executed appropriate data processing agreements.

ProviderPurposePHI accessAgreement
Google CloudInfrastructure, database, authentication, compute, and AI inference via Vertex AI (Claude models hosted within Google Cloud)YesGoogle Cloud HIPAA BAA (signed)
StediReal-time insurance eligibility checks (270/271 transactions) — member details entered by center staff pass through Stedi to the payer in transit only and are never stored by ClerynYes (transit only)Stedi HIPAA BAA (signed)
StripeSubscription billing — practice name, billing contact, and payment method held on Stripe-hosted pages; no patient information is ever shared with StripeNoStandard service terms
FormspreeAccess request form submission (prospect contact details only)NoStandard privacy terms

Google Cloud and Stedi are the only sub-processors with access to PHI, and each operates under a signed HIPAA Business Associate Agreement. Stedi's access is transit-only: eligibility details pass through to the insurance payer during a staff-initiated check and are never retained on Cleryn's systems. If Cleryn adds vendors in the future, this list will be updated before they are used. We will notify you of any material changes to our sub-processor list that involve PHI access.

6. Cookies, Local Storage, and Tracking

Cleryn does not set tracking cookies and does not use third-party advertising trackers, pixels, or analytics services that share your data with third parties. Firebase Authentication maintains your signed-in session using browser storage (not a tracking cookie). The application also stores a small amount of non-PHI data in your browser's local storage: your workspace preferences (such as practice name and default study type) and, for the folder-automation feature, a one-way-hashed memory of already-processed files so documents aren't reviewed and billed twice — file names themselves are not stored. We may use Google Cloud's built-in logging and monitoring for performance and error tracking, which does not include PHI.

7. Data Security

Cleryn implements administrative, technical, and physical safeguards designed to protect your information against unauthorized access, alteration, disclosure, or destruction. These measures include:

No system is perfectly secure. In the event of a breach involving your PHI, Cleryn will notify you as required under our BAA and applicable law.

8. Your Rights

Depending on your jurisdiction, you may have rights regarding your personal information, including the right to access, correct, or delete data we hold about you. To exercise these rights, contact us at contact@cleryn.ai.

Requests relating to PHI of your patients must be handled by you as the covered entity. Cleryn will assist you in fulfilling patient rights requests as required under the BAA.

9. Children's Privacy

The Services are intended for use by healthcare professionals and are not directed to individuals under the age of 18. We do not knowingly collect personal information from children.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by notice within the Services at least 14 days before the changes take effect. Your continued use of the Services after the effective date constitutes acceptance of the updated policy.

11. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at:

Cleryn LLC
2654 W Horizon Ridge Pkwy, Ste B5, PMB# 305
Henderson, NV 89052
contact@cleryn.ai