Privacy Policy
What we collect, what we never keep, and who touches it.
- Effective
- September 15, 2026
- Last updated
- September 15, 2026
- Operator
- Artemius Labs LLC
CarePath is a documentation tool, not a healthcare provider. It does not practise medicine, diagnose, triage, prescribe, calculate doses or check interactions, and it never replaces a clinician's own judgment or instructions.
The short version: we store your account, we store de-identified case text and the comics made from it, and we go out of our way never to hold a patient identifier. We do not sell data, do not run trackers, and do not train models on your content.
Who we are and what this covers
Artemius Labs LLC operates CarePath. This policy covers the marketing site, the clinician application, and the reader page a patient opens from a share link.
For your organization’s own account data — who your members are, how they are billed — we are the controller. For the clinical material you put into the service we act as a processor on your instructions; your organization decides what goes in and who sees it. The Data Processing Addendum sets out those terms.
Write to support@carepath.com about anything in this policy. Postal address is at the bottom of this page.
Clinician and organization data
When you create an account or accept an invitation, we store:
- your name, email address, and password hash (or the fact that you sign in with Google);
- your credentials and specialty, if you provide them, and your role in each organization;
- your organization’s name, branding and members;
- billing contact details and subscription state (card data stays with Stripe — we never see the full number);
- an audit trail of actions that matter: approvals, edits, share links created and revoked, deletions, membership and plan changes.
We use this to run your account, enforce quotas and permissions, bill you, answer support requests, keep the service secure, and meet legal obligations. Our lawful bases are performance of the contract, our legitimate interest in operating and securing the service, and legal obligation.
The audit log is append-only by design: entries cannot be edited or deleted, by you or by us. That is a security feature, and it means audit entries survive account deletion.
Case content and de-identification
The core design rule: identifiers may pass through the system, but they are never stored in it.
- What you type, dictate or upload goes first to a separate de-identification service. It processes the text in memory, writes nothing to disk, logs only pre-approved fields, and has no endpoint that returns stored data.
- We store only the de-identified text, the comic generated from it, the artwork, and a report of which kinds of identifiers were removed and how many — never the identifiers themselves.
- Output that fails an independent second check is rejected rather than passed through. The database will not accept case text without a signed receipt from that service.
- Uploaded source documents are used to extract text and are not retained after processing.
No automated de-identification is perfect. You must not deliberately enter patient identifiers, and you are responsible for checking a comic before you approve it — see the Terms and the HIPAA notice.
We do not train models on your content. Case text and comics are not used to train or fine-tune our models or our vendors’ models.
Patients
Patients never create accounts, are never asked for an email address, and are never billed. Opening a shared comic records only the time and which comic was opened — enough for the clinic to know a link was used, and no more.
The reader page sets no analytics cookie, loads no third-party tracker, runs no session replay, and does not store an IP address, device identifier or browser fingerprint against the view. Share links are unlisted, expire, can be revoked instantly, and are excluded from search engine indexing.
How long we keep things
- Cases and comics — you choose, per case, whether to keep it in your library or have it deleted when its share link expires. Deleted content is removed from live systems promptly and falls out of backups on their ordinary rotation, at most 35 days.
- Account data — kept while the account exists, then deleted within 30 days of deletion, except where retention is required by law.
- Billing records — invoices and payment records are kept for as long as tax and accounting law requires, typically seven years.
- Audit log — retained for the life of the organization and, in de-identified form, afterwards. It never contained identifiers to begin with.
- Security logs — kept up to 90 days for intrusion detection and abuse investigation.
Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to the processing of your personal data, to receive a portable copy, and to withdraw consent.
- EEA / UK (GDPR). All of the above, plus the right to complain to your supervisory authority. We rely on contract, legitimate interests and legal obligation rather than consent for the processing described here.
- California (CCPA/CPRA). Rights to know, delete, correct and opt out. We do not sell or share personal information as those terms are defined, and we do not use sensitive personal information for inferring characteristics. We will not discriminate against you for exercising a right.
- Other US states and Canada, Australia, and elsewhere. We honour equivalent rights where they apply.
Exercise a right by writing to support@carepath.com from the address on your account. We respond within 30 days, or tell you why we need longer. If your request concerns clinical content held on behalf of a healthcare organization, we will forward it to that organization, which is the controller for it.
You can also manage most of this yourself: edit your profile, delete cases, revoke share links, and delete the organization from your account settings.
Where data is processed
Our infrastructure runs primarily in the United States. If you are outside the US, your data will be transferred there, to a country whose privacy laws may differ from your own.
For transfers out of the EEA, UK or Switzerland we rely on the European Commission’s Standard Contractual Clauses and the UK Addendum, together with the technical measures described on the Security page. A copy of the relevant clauses is available on request.
Security and breach notification
Data is encrypted in transit and at rest, row-level security isolates one organization from another, and access to production is limited and logged. The controls that are built and tested are described in detail on the Security page. No system is perfectly secure, and we do not claim otherwise.
If a breach affects your data, we will notify the affected organization without undue delay and in any event within 72 hours of becoming aware, with what we know, what we are doing, and what you should do. Report a suspected vulnerability or incident to support@carepath.com.
Children
CarePath accounts are for healthcare professionals aged 18 or over. We do not knowingly collect personal information from children as account holders. If we learn that a child has created an account, we delete it.
A comic may of course be written for a paediatric patient. That content passes through de-identification like any other, and no identifying information about the child is stored.
Changes to this policy
We will post any change here and update the date at the top. For material changes we will notify organization owners by email at least 30 days before they take effect. Continuing to use the service after that means you accept the updated policy.
Questions about this document
Write to us and we'll answer within 5 business days. Use the email address on your account so we can find you.
support@carepath.comArtemius Labs LLC1209 Mountain Road Pl NE, Ste RCheyenne, WY 82001United States