Legal

Privacy Policy

Effective date: June 4, 2026  ·  Cleryn LLC  ·  Questions: contact@somniq.live

1. Introduction

Cleryn LLC ("Cleryn," "we," "us," or "our") operates cleryn.ai and provides an AI-assisted compliance review platform for sleep diagnostic centers ("Services"). This Privacy Policy explains how we collect, use, store, and protect information in connection with the Services.

This policy applies to all users of the Services, including authorized staff at sleep diagnostic centers ("Customers") who access the platform on behalf of their organizations. It does not apply to information collected by third-party services linked from our platform.

Note on HIPAA. Cleryn acts as a Business Associate under HIPAA with respect to Protected Health Information ("PHI") submitted through the Services. Our obligations regarding PHI are governed primarily by the Business Associate Agreement ("BAA") executed with each Customer, and by HIPAA's Privacy and Security Rules. This Privacy Policy supplements — but does not replace — those obligations.

2. Information We Collect

2.1 Account Information

When you create an account or request access, we collect:

2.2 Documents and Protected Health Information

The core function of the Services requires Customers to upload physician documents (PDFs, scanned faxes, or images) that may contain PHI, including patient names, dates of service, diagnosis codes, and clinical notes. Uploaded documents are processed in memory solely to generate the compliance review described in the BAA and are never written to persistent storage. The resulting review report — which contains reduced identifiers and a one-way hashed patient name — is retained as described in Section 4.3.

AI analysis is performed using Claude models hosted within Google Cloud's Vertex AI service, under Cleryn's Google Cloud HIPAA Business Associate Agreement. PHI is not sent to any third-party AI provider outside Google Cloud. Cleryn does not use PHI to train, fine-tune, or improve AI models, for marketing purposes, or for any use outside the scope of the BAA.

2.3 Usage and Technical Data

We automatically collect certain technical information when you use the Services, including:

3. How We Use Your Information

Data typeHow we use it
Account informationTo manage your account, process payments, send service communications, and confirm coverage region eligibility
PHI in uploaded documentsSolely to perform the compliance review and return results to you — no other use
Review resultsTo display compliance reports to authorized users within your organization and to calculate usage for billing
Usage dataTo monitor service performance, detect abuse, and improve the platform
Contact information from access requestsTo follow up on access requests and notify you of regional availability

We do not sell, rent, or share your personal information or PHI with third parties for their marketing purposes.

4. PHI Handling and Data Retention

4.1 Transmission

All data transmitted between your browser and Cleryn's servers is encrypted in transit using TLS 1.2 or higher. Uploaded documents are transmitted directly to Cleryn's processing service running on Google Cloud and are held in memory only for the duration of the review.

4.2 At-Rest Encryption

Raw uploaded documents are not written to persistent storage, so no copy of the original document exists at rest. Review results stored in Firestore are encrypted at rest by Google Cloud using AES-256.

4.3 Retention Schedule

DataRetention periodDeletion method
Raw uploaded documents (PHI)Not retained — processed in memory onlyDiscarded automatically when the review request completes; never written to persistent storage
Compliance review results90 days from review dateAutomatic TTL deletion via Firestore
Patient name within resultsStored as SHA-256 hash only — plain-text name exists only in the encrypted result payloadDeleted with review result at 90 days
Account and billing recordsDuration of account plus 7 yearsManual deletion upon written request, subject to legal retention obligations
Usage logs90 days rollingAutomatic rotation

Upon termination of your account, raw documents and review results are deleted according to the schedule above. Account information is retained for the period required by applicable law and our BAA obligations.

5. Sub-Processors and Third-Party Service Providers

Cleryn uses the following sub-processors to provide the Services. Each sub-processor with access to PHI has executed appropriate data processing agreements.

ProviderPurposePHI accessAgreement
Google CloudInfrastructure, database, authentication, compute, and AI inference via Vertex AI (Claude models hosted within Google Cloud)YesGoogle Cloud HIPAA BAA (signed)
StripePayment processingNoStripe standard DPA
Resend / PostmarkTransactional emailNoStandard DPA
FormspreeAccess request form submissionNoStandard privacy terms

We will notify you of any material changes to our sub-processor list that involve PHI access.

6. Cookies and Tracking

Cleryn uses Firebase Authentication, which sets a session cookie to maintain your logged-in state. We do not use third-party advertising trackers, pixels, or analytics services that share your data with third parties. We may use Google Cloud's built-in logging and monitoring for performance and error tracking, which does not include PHI.

7. Data Security

Cleryn implements administrative, technical, and physical safeguards designed to protect your information against unauthorized access, alteration, disclosure, or destruction. These measures include:

No system is perfectly secure. In the event of a breach involving your PHI, Cleryn will notify you as required under our BAA and applicable law.

8. Your Rights

Depending on your jurisdiction, you may have rights regarding your personal information, including the right to access, correct, or delete data we hold about you. To exercise these rights, contact us at contact@somniq.live.

Requests relating to PHI of your patients must be handled by you as the covered entity. Cleryn will assist you in fulfilling patient rights requests as required under the BAA.

9. Children's Privacy

The Services are intended for use by healthcare professionals and are not directed to individuals under the age of 18. We do not knowingly collect personal information from children.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by notice within the Services at least 14 days before the changes take effect. Your continued use of the Services after the effective date constitutes acceptance of the updated policy.

11. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at:

Cleryn LLC
2654 W Horizon Ridge Pkwy, Ste B5, PMB# 305
Henderson, NV 89052
contact@somniq.live