Introduction
SOAPBox AI, operated by Simplicity Group Advisors, LLC ("Company," "we," "us"), is committed to protecting your privacy and the privacy of your clients. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our Service. We understand the sensitive nature of healthcare documentation and have designed our practices to support HIPAA compliance requirements.
Notice at Collection
When you create or use an account, we collect identifiers and professional account information, device and security information, product-usage information, and billing identifiers when you purchase a paid service. We use this information to create and secure your account, provide and support the Service, process billing, prevent abuse, and meet legal obligations. Clinical information is collected only when an authorized user chooses to enter or transmit it through an enabled workflow.
We do not sell personal information or share it for cross-context behavioral advertising. Retention varies by data type and is described in the Data Retention section below. Contact alec@slpsoapbox.com before creating an account if you need this notice in another accessible format.
Information We Collect
Account Information
When you create an account, we collect your name, email address, professional credentials, specialty, and practice information. If you sign up via Google OAuth, we receive your name, email, and profile photo from Google.
Protected Health Information (PHI)
Our core service processes audio recordings of therapy sessions. This audio may contain PHI. We also generate and store transcripts, SOAP notes, plans of care, and other clinical documentation that may contain PHI. All PHI is encrypted at rest and in transit.
Payment Information
Payment processing is handled by Stripe, Inc. We do not store credit card numbers or bank account details on our servers. We retain Stripe customer and subscription identifiers to manage your billing.
Usage and Analytics Data
We collect anonymized usage data including feature usage, session counts, error logs, and performance metrics. This data does not contain PHI and is used to improve the Service.
Audit Logs
For HIPAA compliance, we maintain audit logs of all access to PHI, including user identity, timestamp, action performed, and resource accessed. Audit logs do not contain PHI content.
How We Use Your Information
- To provide the Service: processing audio, generating transcripts, creating SOAP notes and clinical documentation
- To manage your account, authentication, and authorization
- To process subscription payments and manage billing
- To send transactional notifications (account changes, billing receipts)
- To maintain audit trails as required by HIPAA
- To improve and optimize the Service based on anonymized usage patterns
- To detect and prevent fraud, abuse, or security incidents
- To comply with legal obligations and respond to lawful requests
Third-Party Processors
We use infrastructure, transcription, artificial-intelligence, communications, billing, and diagnostic providers to operate the Service. The provider used for a particular request depends on the features and integrations enabled for your organization. A provider that may process PHI is not approved for that production workflow until the applicable contractual and technical safeguards are in place, including a BAA where required.
Our provider inventory distinguishes SoapBox subprocessors from non-PHI service providers and customer-connected services. Contact alec@slpsoapbox.com for the current reviewed inventory or to receive notice of material provider changes.
Data Security
We implement industry-standard security measures:
- All data encrypted in transit using TLS 1.2 or higher
- Audio recordings and transcripts encrypted at rest using AES-256 encryption
- Database connections encrypted and access restricted by IP
- Passwords hashed with bcrypt (12 rounds)
- Session tokens and JWTs with cryptographic signing
- CSRF protection on all mutating API endpoints
- Rate limiting on authentication endpoints
- Regular security assessments and dependency auditing
HIPAA Compliance
SOAPBox AI is designed to support HIPAA compliance for covered entities and their business associates. We implement administrative, physical, and technical safeguards to protect PHI including:
- Access controls with role-based permissions and multi-tenant isolation
- Comprehensive audit logging of all PHI access
- Encryption of PHI at rest and in transit
- Automatic session timeout and token expiration
- Data backup and disaster recovery procedures
We enter into Business Associate Agreements (BAAs) with covered entities as required by HIPAA. Contact alec@slpsoapbox.com to request a BAA.
Data Retention
Retention varies by organization configuration and applicable legal, contractual, and operational requirements. Our current product defaults and controls are:
- Clinical documentation (transcripts, SOAP notes): The default retention setting is approximately 7 years (2,555 days), configurable per organization. This product default does not mean that HIPAA itself requires a seven-year medical-record retention period.
- Audio recordings: Encrypted at rest; configurable auto-deletion after export (default 5 days)
- Account information: Retained while needed to provide the Service and afterward only as required by contractual obligations, legal holds, security, financial-record rules, and the approved account-deletion process
- Audit logs: Retained according to our security and compliance policy; the current baseline is 7 years.
- Payment records: Retained as required by tax and financial regulations
Your Rights
Depending on where you live and the law that applies, you may have rights to access, correct, delete, restrict, object to processing of, or receive a portable copy of personal information associated with your SoapBox account. These rights may be limited by identity-verification requirements, another person's rights, legal holds, contractual obligations, and applicable record-retention laws.
Patient and clinical information
SoapBox generally processes patient PHI on behalf of the healthcare practice that uses the Service. Requests concerning a patient record should normally be directed to that practice. We assist the practice with access, amendment, accounting, and other requests as required by the applicable BAA and law; we do not independently decide whether a patient record should be changed or deleted.
To exercise these rights, contact us at alec@slpsoapbox.com. We will verify the request, identify the applicable role and law, and respond within the legally required period.
California Privacy Rights (CCPA/CPRA)
If the CCPA or CPRA applies to SoapBox and your information, California residents may have rights to know, correct, or delete personal information and to limit or opt out of certain uses or disclosures. We do not sell personal information or share it for cross-context behavioral advertising. The Notice at Collection above describes the categories and purposes involved. Submit a request at alec@slpsoapbox.com.
International Privacy
Availability of the Service and applicable privacy rights depend on location. Before a customer uses SoapBox to process personal data governed by the EU GDPR, UK GDPR, or another international privacy law, the customer should contact us to confirm availability, processing locations, the parties' controller and processor roles, and whether a Data Processing Addendum or transfer mechanism is required. We do not treat this general policy as a substitute for an executed DPA.
Cookies and Tracking
We use essential cookies for authentication (session cookies) and security (CSRF tokens). We do not use third-party advertising cookies or tracking pixels. Our anonymized analytics do not track individual users across websites.
Chrome Extension Data Handling
This section applies when SoapBox AI for Fusion is first distributed through the Chrome Web Store. The extension uses your existing SoapBox login to retrieve notes and patient records you are authorized to access. It handles names, record and account identifiers, note text, search input, authentication cookies and, when you choose Record, microphone audio. Recent notes and search results are held in panel memory. Patient searches are sent to SoapBox; searches within loaded notes remain local. Your first-use responsibility acknowledgment is remembered in your Chrome profile.
The extension checks the active tab's address and reads supported Fusion note fields to preserve existing content when appending selected SOAP text. It does not extract or verify a Fusion patient profile, collect a browsing-history list, or send Fusion field content back to SoapBox. Fusion handles imported content under your practice's arrangements with that service. You remain responsible for choosing the correct patient, reviewing the note, and confirming its save.
Microphone recording begins only when you choose Record and grant Chrome permission. It continues if the side panel closes and is indicated by the toolbar badge. Audio is encrypted in this Chrome profile while recording and uploaded when you choose Stop & save or retry recovery. Unsaved local audio remains after logout or restart until successfully saved and cleaned up, or explicitly discarded; there is no automatic time-based purge. Recovery is available only to the original SoapBox user and organization. Discard deletes local recovery, not previously uploaded server audio. Clearing extension data or uninstalling can make unsaved audio unrecoverable.
The production extension sends authenticated requests to app.slpsoapbox.com. A separate beta build uses staging.slpsoapbox.com and synthetic data only. The extension does not contact artificial-intelligence providers directly. The SoapBox service processes audio and notes through its configured providers and records security and audit metadata as described elsewhere in this policy.
Chrome Web Store Limited Use
SoapBox AI for Fusion uses data obtained through the extension only to provide or improve its described clinical-documentation features. Our use of information received through Chrome and its extension APIs complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. We do not sell extension user data or use or transfer it for personalized advertising, creditworthiness, or lending decisions. Transfers and human access are limited to the circumstances allowed by that policy and described in this Privacy Policy.
Children's Privacy
The Service is intended for licensed healthcare professionals and is not directed at children under 13. We do not knowingly collect personal information from children under 13. The Service may process clinical data about minor patients as part of therapy documentation; this data is PHI and is protected accordingly.
Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email or in-app notification at least 30 days before they take effect when this policy or applicable law requires advance notice. The "Last updated" and "Effective date" labels above distinguish publication from effectiveness.
Contact Us
For questions about this Privacy Policy, data practices, or to exercise your rights:
SOAPBox AI — Privacy
Simplicity Group Advisors, LLC
Email: alec@slpsoapbox.com