Legal
Cleryn LLC ("Cleryn," "we," "us," or "our") operates cleryn.ai and provides an AI-assisted compliance review platform for sleep diagnostic centers ("Services"). This Privacy Policy explains how we collect, use, store, and protect information in connection with the Services.
This policy applies to all users of the Services, including authorized staff at sleep diagnostic centers ("Customers") who access the platform on behalf of their organizations. It does not apply to information collected by third-party services linked from our platform.
Note on HIPAA. Cleryn acts as a Business Associate under HIPAA with respect to Protected Health Information ("PHI") submitted through the Services. Our obligations regarding PHI are governed primarily by the Business Associate Agreement ("BAA") executed with each Customer, and by HIPAA's Privacy and Security Rules. This Privacy Policy supplements — but does not replace — those obligations.
When you create an account or request access, we collect:
The core function of the Services requires Customers to upload physician documents (PDFs, scanned faxes, or images) that may contain PHI, including patient names, dates of service, diagnosis codes, and clinical notes. Uploaded documents are processed in memory solely to generate the compliance review described in the BAA and are never written to persistent storage. The resulting review report is returned to you at processing time and is not retained on Cleryn's systems — what Cleryn keeps is a patient-free activity record (date, payer, study type, compliance score, and which checklist requirements were missing), as described in Section 4.3.
AI analysis is performed using Claude models hosted within Google Cloud's Vertex AI service, under Cleryn's Google Cloud HIPAA Business Associate Agreement. PHI is not sent to any third-party AI provider outside Google Cloud. Cleryn does not use PHI to train, fine-tune, or improve AI models, for marketing purposes, or for any use outside the scope of the BAA.
We automatically collect certain technical information when you use the Services, including:
| Data type | How we use it |
|---|---|
| Account information | To manage your account, process payments, send service communications, and confirm coverage region eligibility |
| PHI in uploaded documents | Solely to perform the compliance review and return results to you — no other use |
| Review results | To display compliance reports to authorized users within your organization and to calculate usage for billing |
| Usage data | To monitor service performance, detect abuse, and improve the platform |
| Contact information from access requests | To follow up on access requests and notify you of regional availability |
We do not sell, rent, or share your personal information or PHI with third parties for their marketing purposes.
All data transmitted between your browser and Cleryn's servers is encrypted in transit using TLS 1.2 or higher. Uploaded documents are transmitted directly to Cleryn's processing service running on Google Cloud and are held in memory only for the duration of the review.
Raw uploaded documents are not written to persistent storage, so no copy of the original document exists at rest. Review results are likewise not stored — they are delivered to your screen and your systems at processing time. The patient-free activity records Cleryn does store in Firestore are encrypted at rest by Google Cloud using AES-256. Because no patient information is stored at rest, a breach of Cleryn's database cannot expose patient records.
| Data | Retention period | Deletion method |
|---|---|---|
| Raw uploaded documents (PHI) | Not retained — processed in memory only | Discarded automatically when the review request completes; never written to persistent storage |
| EMR export data (optional feature; full patient demographics) | Not retained — extracted transiently during the review and delivered directly to your workstation; the export file exists only on your systems | Never written to Cleryn storage; removed from the stored review result before saving |
| Compliance review results (checklists, patient identifiers, clinical summaries) | Not retained — returned to you at processing time only; no result content or patient identifier (not even a hashed name) is stored | Never written to Cleryn storage |
| Review activity records (patient-free: date, payer, study type, score, missing checklist requirements, claim outcome) | 90 days from review date | Automatic TTL deletion via Firestore |
| Anonymous audit and outcome records | Retained indefinitely as HIPAA-required audit documentation — structured metadata only (payer, study type, scores, claim outcome); contains no patient names, hashes, or free text | Deliberately durable (HIPAA §164.316 documentation evidence) |
| Account records | Duration of account, plus up to 6 years where required for HIPAA documentation | Manual deletion upon written request, subject to legal retention obligations |
| Operational logs (PHI-free) | Up to 6 years (HIPAA documentation retention) | Automatic expiration via Google Cloud log retention |
Upon termination of your account, the activity records above are deleted according to the schedule (there are no stored documents or review results to delete — they only ever existed on your systems). Account information is retained for the period required by applicable law and our BAA obligations.
Cleryn uses the following sub-processors to provide the Services. Each sub-processor with access to PHI has executed appropriate data processing agreements.
| Provider | Purpose | PHI access | Agreement |
|---|---|---|---|
| Google Cloud | Infrastructure, database, authentication, compute, and AI inference via Vertex AI (Claude models hosted within Google Cloud) | Yes | Google Cloud HIPAA BAA (signed) |
| Stedi | Real-time insurance eligibility checks (270/271 transactions) — member details entered by center staff pass through Stedi to the payer in transit only and are never stored by Cleryn | Yes (transit only) | Stedi HIPAA BAA (signed) |
| Stripe | Subscription billing — practice name, billing contact, and payment method held on Stripe-hosted pages; no patient information is ever shared with Stripe | No | Standard service terms |
| Formspree | Access request form submission (prospect contact details only) | No | Standard privacy terms |
Google Cloud and Stedi are the only sub-processors with access to PHI, and each operates under a signed HIPAA Business Associate Agreement. Stedi's access is transit-only: eligibility details pass through to the insurance payer during a staff-initiated check and are never retained on Cleryn's systems. If Cleryn adds vendors in the future, this list will be updated before they are used. We will notify you of any material changes to our sub-processor list that involve PHI access.
Cleryn does not set tracking cookies and does not use third-party advertising trackers, pixels, or analytics services that share your data with third parties. Firebase Authentication maintains your signed-in session using browser storage (not a tracking cookie). The application also stores a small amount of non-PHI data in your browser's local storage: your workspace preferences (such as practice name and default study type) and, for the folder-automation feature, a one-way-hashed memory of already-processed files so documents aren't reviewed and billed twice — file names themselves are not stored. We may use Google Cloud's built-in logging and monitoring for performance and error tracking, which does not include PHI.
Cleryn implements administrative, technical, and physical safeguards designed to protect your information against unauthorized access, alteration, disclosure, or destruction. These measures include:
No system is perfectly secure. In the event of a breach involving your PHI, Cleryn will notify you as required under our BAA and applicable law.
Depending on your jurisdiction, you may have rights regarding your personal information, including the right to access, correct, or delete data we hold about you. To exercise these rights, contact us at contact@cleryn.ai.
Requests relating to PHI of your patients must be handled by you as the covered entity. Cleryn will assist you in fulfilling patient rights requests as required under the BAA.
The Services are intended for use by healthcare professionals and are not directed to individuals under the age of 18. We do not knowingly collect personal information from children.
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by notice within the Services at least 14 days before the changes take effect. Your continued use of the Services after the effective date constitutes acceptance of the updated policy.
If you have questions about this Privacy Policy or our data practices, contact us at:
Cleryn LLC
2654 W Horizon Ridge Pkwy, Ste B5, PMB# 305
Henderson, NV 89052
contact@cleryn.ai