Privacy Policy
Your health information deserves clear rules — not fine print you have to decode.
This Privacy Policy explains how AiraMed collects, uses, shares, retains, and protects personal information when you use our website, product, and related services.
Effective: September 8, 2026 Last updated: September 15, 2026
Who operates AiraMed
AiraMed is operated by I Rise UP, LLC (“AiraMed,” “we,” “us,” or “our”), located in Columbus, Ohio, United States. This policy applies to the AiraMed website, the AiraMed product, and related services we provide under the AiraMed name, including pilot programs with healthcare organizations.
Privacy questions and privacy requests can be sent to privacy@airamed.com or submitted through our contact form.
Information we collect
The information we collect depends on how you use AiraMed. It may include:
- Account and contact information, such as name, email address, phone number, password or sign-in credentials, organization, role, and communication preferences.
- Device, log, and usage information, such as device type, operating system, app or browser version, IP address, approximate location derived from IP address, timestamps, feature use, crash data, and security-event data.
- Recordings, transcripts, prompts, messages, summaries, and other content you choose to create or provide.
- Uploaded documents or images, such as visit notes, after-visit summaries, or other health materials already in your possession.
- Health-related information contained in recordings, transcripts, uploads, prompts, messages, or other user-provided content. This can include information about a medical condition, treatment, medication, appointment, or care plan.
- Support communications and feedback, including the content of emails, contact-form messages, and related correspondence.
- Website technical information created when your browser loads our site, including information received by the font service described below.
We do not require a Social Security number to use AiraMed. We do not use recordings to create a biometric identifier or to identify a person by voiceprint.
Sources of information
We collect personal information from:
- You, when you create an account, record a conversation, upload a file, type a prompt or message, contact us, or otherwise use AiraMed.
- Your device, automatically, as needed to operate, secure, and troubleshoot the website or product.
- Service providers that process information on our behalf, such as communications, transcription, hosting, authentication, or support tools, when they return results or status information to us.
- A healthcare organization or pilot partner, if they invite you, help create access, or share limited enrollment details such as your name, email address, role, or program affiliation. A partner does not need to send AiraMed your full medical record for you to use the product, and we do not request one unless a specific program requires it and you or the partner provide it.
How we use information
We use personal information to:
- Provide and operate AiraMed, including accounts, recordings, transcripts, summaries, explanations, document questions, and multilingual features where supported.
- Process the content you submit so we can return the output you requested.
- Secure accounts, authenticate users, prevent abuse, and detect security events.
- Provide support and communicate with you about your account, a request, a pilot, or a service change.
- Maintain, troubleshoot, and improve service reliability in ways permitted by law and our contracts.
- Meet legal, regulatory, and contractual requirements.
AI and patient data
AiraMed does not use recordings, transcripts, uploaded health information, prompts, messages, or other user-provided health content to train its own or third-party artificial intelligence models.
We configure our model providers, logging pathways, and production workflows so that this content is used to provide the service to you — not as training material. If that practice ever changes, we will update this policy before the change takes effect and, where required, notify you.
Service providers
We use specialized companies to operate AiraMed. They receive only the information needed to perform their function. They may store that information for as long as needed to deliver the service and to meet their own security, abuse-prevention, or legal obligations. They are not permitted to use recordings, transcripts, uploaded health information, prompts, messages, or other user-provided health content for their own advertising, or to train their own or third-party AI models.
We require written contractual safeguards for these providers. Where AiraMed acts for a HIPAA covered entity or business associate and a business associate agreement is required, we put one in place. Some providers process information in the United States and in other countries where they operate.
Twilio may receive phone numbers, call or message metadata, and audio needed to connect or deliver a communications feature. Twilio processes this information to provide telephony or messaging and may store it as needed to complete delivery, prevent abuse, and meet legal obligations. Twilio is not authorized to use AiraMed user health content for its own advertising or model training.
Deepgram may receive audio you record or upload in order to produce a transcript. Deepgram processes that audio to return text. We do not authorize Deepgram to retain that audio or transcript as training data for its own models.
Our artificial-intelligence processing provider receives transcripts, prompts, messages, and the uploaded text or images needed to generate a summary, explanation, or other requested output. The provider processes that content to return a result. We configure the provider not to use this content to train its models.
ElevenLabs may receive text — and limited voice-setting information — when AiraMed generates spoken audio. ElevenLabs processes that input to return audio. We do not authorize ElevenLabs to use user-provided health content to train its models.
Our hosting provider stores account information and the content you save in AiraMed, including recordings, transcripts, summaries, and uploads, so the product can operate. The host processes this information as infrastructure and is not permitted to use it for its own purposes beyond providing that infrastructure.
Our authentication provider may receive your email address, credential or single-sign-on tokens, and session data in order to sign you in and protect your account. It stores this information as needed to authenticate you and detect unauthorized access.
Security and reliability tools may receive technical logs, IP addresses, device data, and error traces. We use these to operate, secure, and troubleshoot the service. We do not use health content in logs except as needed to diagnose a specific problem, and we do not use logs to train AI models.
When you contact us, your name, email address, and message are received in our support inbox so we can respond. Support messages are stored as business correspondence. Please do not include more sensitive medical information than is necessary for us to help you.
We do not operate a public vendor directory. If a healthcare organization needs additional vendor detail for a pilot or contracting review, it can request that information from us.
Sale, advertising, and profiling
AiraMed does not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use advertising cookies, advertising pixels, or data brokers.
We do not use personal information to profile you for advertising, or to make automated decisions that produce legal or similarly significant effects, such as eligibility for care, insurance, housing, or employment. AI-generated summaries and explanations are created to help you understand information you already have. They are not used as a hidden score about you.
De-identified and aggregated information
We may create de-identified or aggregated information that cannot reasonably be used to identify you, such as counts of feature use or reliability metrics. We use that information to operate, secure, and improve AiraMed. We do not attempt to re-identify it except as permitted by law to test that our de-identification works.
De-identified or aggregated information is not a way around our AI-training rule. We do not use recordings, transcripts, uploaded health information, prompts, messages, or other user-provided health content to train AI models, even after removing obvious identifiers.
How long we keep information
We keep personal information only for as long as the category below requires. If a legal hold, security investigation, dispute, or contract requires a longer period, we keep only what is needed for that purpose and then delete or de-identify it.
Kept in your account until you delete the recording or close the account. After deletion or closure, we remove it from production systems within 30 days.
Kept in your account until you delete them or close the account. After deletion or closure, we remove them from production systems within 30 days.
Documents and images remain until you delete them or close the account. After deletion or closure, we remove them from production systems within 30 days.
Kept while your account is open. After you close the account, we delete or de-identify it within 30 days, except limited records we must keep as described below.
Kept for up to 12 months, or longer if needed to investigate a security event or meet a legal requirement.
Kept for up to 24 months after the request is resolved, unless a longer period is required to handle a related legal or security matter.
Encrypted backups may retain a deleted copy until the backup rotates, which occurs within 90 days.
Deletion and account closure
You can delete individual recordings, transcripts, summaries, and uploads from your AiraMed account. You can close your account in account settings, or by emailing privacy@airamed.com and asking us to close it.
After we verify a deletion or account-closure request, we remove the applicable information from production systems within 30 days. Encrypted backup copies may remain for up to 90 days until those backups rotate. We may retain limited information when we are legally or contractually required to do so, or when we need it to prevent abuse, resolve a dispute, enforce our Terms, or complete a transaction you asked us to finish. We do not continue using retained health content to provide AiraMed back to you after the account is closed, except as required by law.
Closing an account deletes the account holder’s AiraMed content subject to the limits above. It does not delete information a healthcare organization or another person lawfully keeps in their own records.
Recordings that include other people
An AiraMed recording may capture more than the account holder. It may include a clinician, nurse, caregiver, interpreter, family member, or another person in the room or on the call.
If you use a recording feature, you are responsible for obtaining any consent required by applicable recording and privacy laws before you record. Those laws vary by location. Using AiraMed does not, by itself, mean that legal consent requirements have been met.
This Privacy Policy is not a substitute for the in-app consent workflow. Follow the prompts in the product, and do not record a healthcare conversation unless recording is permitted and any required consent has been obtained.
Children’s privacy
AiraMed is intended for adults. You must be at least 18 years old to create an account.
AiraMed is not directed to children under 13, and we do not knowingly collect personal information from children under 13 for their own accounts. If we learn that we have collected personal information from a child under 13, we will delete it.
A parent, legal guardian, or other authorized caregiver who is 18 or older may use their own AiraMed account in connection with a minor’s care if they have legal authority to do so. That adult is responsible for obtaining any consent required to record or upload information about the minor, and for the content they submit.
Cookies and analytics
The public AiraMed website does not use advertising cookies, analytics cookies, or advertising pixels. We do not run Google Analytics, Meta Pixel, or similar advertising or analytics SDKs on this site.
The website loads fonts from Google Fonts. Google may receive your IP address, browser type, and the font files your browser requests. That is a technical request to display the site, not an advertising tracker we control.
The website contact form submits directly to AiraMed. It does not share form submissions with third parties.
The AiraMed product does not use advertising cookies or advertising SDKs. It may collect device and usage information needed to operate the product, including crash reports, security logs, and feature-performance data. We use that information to keep the service working and secure. We do not use it for cross-context behavioral advertising.
Your browser or device may let you block cookies or clear stored data. Blocking technical storage can affect sign-in or other product functions.
How we protect information
We use administrative, technical, and physical safeguards designed to protect personal information. Those safeguards include encryption in transit and at rest, authentication and access restrictions, monitoring, audit logging for relevant system activity, and an incident-response process.
No method of transmission or storage is completely secure. We do not claim that information is 100% protected from every risk. If we believe a security event affects your information, we will respond as described in Breach notification.
HIPAA and other health privacy laws
Not every health application, user, transaction, or piece of health information is governed by HIPAA. HIPAA coverage depends on whether AiraMed is acting on behalf of a covered entity or business associate. Where we act for a HIPAA covered entity or business associate, the applicable agreements and legal requirements may govern that processing. Other information may be governed by different privacy laws.
This policy describes AiraMed’s role. It does not state that all information you submit is “HIPAA protected.”
Even when HIPAA does not apply, AiraMed may still be covered by other laws. Those can include the Federal Trade Commission Act, the FTC Health Breach Notification Rule, and state consumer-health or consumer-privacy laws. The FTC Health Breach Notification Rule can apply to many health apps that fall outside HIPAA. We treat user-provided health content as sensitive information whether or not a particular interaction is a HIPAA transaction.
International data transfers
I Rise UP, LLC is located in the United States. If you use AiraMed from another country, your information is transferred to and processed in the United States. Some service providers may also process information in other countries where they operate.
Where a transfer requires additional safeguards, we use contracts and other appropriate measures permitted by applicable law. If you are in a country with data-transfer rules, you can contact privacy@airamed.com for more detail about the safeguards that apply to your information.
Legal disclosures and business transfers
We may disclose personal information if we believe in good faith that disclosure is required by law, regulation, legal process, or governmental request; to protect the rights, safety, or property of AiraMed, our users, or others; or to enforce our Terms or other agreements.
If I Rise UP, LLC is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, personal information may be transferred as part of that transaction. We will continue to protect the information as described in this policy and will notify you of a change in control or of a new policy that applies, as required by law.
Your choices and rights
You can access and update certain account information in the product. You can delete content and close your account as described above. You can also choose not to record, not to upload a file, or not to submit a prompt.
Depending on your location, you may have additional rights under US state privacy laws or other applicable law. Those rights can include the right to:
- Know and access the personal information we hold about you.
- Correct inaccurate personal information.
- Delete personal information, subject to legal exceptions.
- Receive a copy of certain information in a portable format.
- Opt out of the sale of personal information or the sharing of personal information for cross-context behavioral advertising. AiraMed does not sell personal information or share it for that purpose.
- Limit the use and disclosure of sensitive personal information. We use sensitive health information to provide AiraMed and to secure the service, not to infer characteristics for advertising.
- Withdraw consent where processing is based on consent, including by stopping a recording or deleting content.
- Appeal our decision on a privacy request, where your state gives you that right.
- Authorize an agent to submit a request on your behalf, where applicable law allows it.
We will not discriminate against you for exercising a privacy right.
California and other US state residents
If you are a resident of California or another US state with a comprehensive consumer privacy law, the categories of personal information we collect are those listed in Information we collect. We collect them for the purposes in How we use information, from the sources in Sources of information, and we disclose them to the service-provider categories in Service providers and as described in Legal disclosures and business transfers.
We do not sell personal information or share it for cross-context behavioral advertising, so we do not offer a “Do Not Sell or Share” opt-out for a practice we do not perform. If that ever changes, we will provide a required opt-out method and update this policy first.
If your state recognizes consumer health-data rights that go beyond this section, email privacy@airamed.com and we will handle your request under the law that applies to you.
How to make a privacy request
To access, correct, delete, or export information, or to close your account, use the in-product controls where available, email privacy@airamed.com, or submit the privacy request form. Do not include more sensitive medical information than is necessary for us to respond.
We may need to verify your identity before completing a request. For account-related requests, we typically verify using the email address on the account and, if needed, additional information reasonably necessary to confirm that you are the account holder. We will not fulfill a request if we cannot verify the requester.
If you use an authorized agent, we may require proof of your written authorization and may still need to verify your identity, unless applicable law says otherwise.
We respond to verifiable requests within 45 days, or sooner if a specific law requires a shorter period. If we need more time, we will tell you why and how long we expect the extension to take, as permitted by law.
If we deny a request and applicable law gives you a right to appeal, email privacy@airamed.com with the subject line “Privacy appeal.” We will review the decision and respond in writing. If you still disagree, you may contact your state attorney general or other privacy regulator, where available.
Breach notification
If we become aware of a breach of personal information that requires notice under applicable law — including the FTC Health Breach Notification Rule where it applies, HIPAA breach-notification rules where they apply, or a state breach law — we will notify affected individuals and any required regulators. We will do so without unreasonable delay and within the time those laws require.
Notice may be provided by email to the address on your account, in the product, or by another method permitted by law. The notice will describe the incident, the types of information involved to the extent we can determine them, the steps we are taking, and how you can reach us.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will change the “Last updated” date above. If a change is material, we will provide additional notice, such as an email to the address on your account, an in-product message, or a notice on this page, as appropriate and as required by law.
The updated policy applies to information we already have and to information we collect after the effective date of the update, unless the notice says otherwise or applicable law requires a different approach.
Contact us about privacy
I Rise UP, LLC
Columbus, Ohio, United States
Privacy email: privacy@airamed.com
You can also use the contact form and choose “Privacy request.” Do not include more sensitive medical information than is necessary for us to respond.