Practicepicnic (“Practicepicnic”, “we”, “us”, or “our”) operates the practicepicnic.com website and the app.practicepicnic.com application (together, the “Service”).
What This Policy Covers, and What It Doesn’t:
This policy covers information about visitors to our website and about the practitioners and staff who hold accounts with us.
This policy does not cover Protected Health Information. When you use Practicepicnic to manage your practice, the client records, clinical documentation, session audio, and other health information you store with us are Protected Health Information (“PHI”) that we process on your behalf as your business associate under HIPAA. Our handling of PHI is governed by our Business Associate Agreement with you, not by this policy. Nothing in this policy permits us to use PHI for marketing, analytics, product development, or artificial intelligence training.
If you are a client of a practice that uses Practicepicnic, your health information is governed by your provider’s Notice of Privacy Practices, not by this policy. Please contact your provider with questions about your records.
Definitions:
Service means the practicepicnic.com website and the app.practicepicnic.com application.
Personal Data means information that identifies, relates to, or could reasonably be linked with an identifiable individual, excluding PHI.
Usage Data means data collected automatically by the Service or its infrastructure, such as the duration of a page visit.
Cookies are small files stored on your device. See our Cookie Policy.
Types of Data We Collect:
Personal Data. When you create an account or contact us, we may collect your email address, first and last name, phone number, mailing address, practice name and details, and billing information.
Usage Data. We may collect information about how the Service is accessed and used, including IP address, browser type and version, pages visited, time and date of visit, time spent on pages, device identifiers, and diagnostic data.
Cookies. We use cookies as described in our Cookie Policy. Analytics and advertising cookies are used only on our public marketing website, never inside the application.
How We Use Data:
We use collected Personal Data to:
- Provide and maintain the Service
- Notify you about changes to the Service
- Provide customer support
- Process payments and manage your subscription
- Monitor usage and detect, prevent, and address technical and security issues
- Improve the Service
- Send you news, offers, and information about our products, where you have not opted out
You may opt out of marketing communications at any time using the unsubscribe link in any marketing email.
Artificial Intelligence Features:
The Service includes features that transcribe session audio and generate draft clinical documentation.
We do not use your data to train artificial intelligence models. We do not use Personal Data, PHI, session audio, transcripts, or clinical documentation to train, fine-tune, or improve any artificial intelligence or machine learning model, and we do not permit our vendors to do so.
Session audio is transcribed by a model running on our own infrastructure and is not sent to any third-party transcription service. The resulting transcript is processed using Amazon Web Services under a Business Associate Agreement to produce a draft note. AWS does not use inputs to or outputs from these services to train its models and does not share them with model providers. Session audio is retained only as long as needed to produce a transcript and note.
Google Calendar Integration (Google user data):
If you choose to connect Google Calendar to Practicepicnic, we will request access to your Google Calendar data through Google OAuth in order to provide two-way calendar sync between Practicepicnic and Google Calendar.
Data we access
When the integration is enabled, Practicepicnic may access the following Google Calendar data, limited to the OAuth scopes you authorize:
- Your calendar list (for example: calendar names and identifiers)
- Calendar events and event details needed for syncing (for example: title, start/end time, description, location, attendees, and event identifiers)
How we use Google Calendar data
We use Google Calendar data only to provide the calendar sync features you enable, including:
- Displaying relevant Google Calendar events inside Practicepicnic
- Creating, updating, or deleting Google Calendar events based on changes you make in Practicepicnic
- Creating, updating, or deleting Practicepicnic calendar items based on changes detected in Google Calendar
- Keeping a consistent mapping between events in both systems so the sync works reliably
What we store
To operate the integration, we may store:
- OAuth tokens required to maintain your Google Calendar connection (stored securely)
- Sync metadata required to keep events matched between systems (for example: Google Calendar IDs, event IDs, and timestamps)
We do not store your Google account password.
Retention and deletion
We delete the Google Calendar integration data we store (including OAuth tokens and sync metadata) within 24 hours of you disconnecting Google Calendar from Practicepicnic (or revoking access). We may retain limited copies in encrypted backups, which are deleted within 30 days.
Sharing / transfers
We do not sell Google user data. We do not share Google Calendar data with third parties except:
- With service providers we use to host and operate Practicepicnic (for example, infrastructure hosting), strictly as needed to provide the Service; and/or
- When required to comply with law, enforce our policies, or protect our rights and users.
Your choices and controls
- You can disconnect Google Calendar at any time from Practicepicnic settings. After disconnection, Practicepicnic stops accessing your Google Calendar data and stops syncing.
- You can also revoke Practicepicnic’s access from your Google Account settings.
Limited Use
- Practicepicnic’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide or improve the user-facing calendar sync features described above.
- We do not use Google user data for advertising.
- We do not sell Google user data.
Service Providers:
We use third-party companies to help operate the Service. They have access to information only to perform tasks on our behalf and are contractually obligated not to use it for any other purpose. Where they handle PHI, we have a Business Associate Agreement in place.
| Provider | Purpose | BAA |
|---|---|---|
| Amazon Web Services | Application and database hosting; AI note generation via Amazon Bedrock | Yes |
| Twilio | SMS and voice appointment reminders | No. No PHI is sent to this provider |
| Mailgun | Transactional and notification email delivery | No. No PHI is sent to this provider |
| Stripe | Payment processing | No. Payment processors and financial institutions are exempt from the HIPAA Privacy Rule per HHS guidance. We share only the limited information needed to process transactions and no health information. |
| Google (Calendar) | Optional two-way calendar sync, at your election | N/A. Access is limited to calendar data you authorize |
| Google Analytics, Google Ads | Analytics and advertising on our public marketing website only. Not used inside the application | No. No PHI is processed |
Session audio transcription runs on our own infrastructure and involves no third-party provider.
Sharing and Disclosure of Personal Data:
We do not sell Personal Data, and we never sell or share PHI.
We may disclose Personal Data:
- To service providers, as described above
- In connection with a merger, acquisition, or asset sale, with notice to you before your Personal Data becomes subject to a different privacy policy. Any transfer of PHI would remain subject to HIPAA and our Business Associate Agreement
- To comply with a legal obligation or a valid request by a public authority
- To protect and defend our rights or property, investigate possible wrongdoing, protect the personal safety of users or the public, or protect against legal liability
Your Choices:
You may opt out of marketing email at any time using the unsubscribe link in any such message.
If you would like to access, correct, or delete the Personal Data we hold about you, contact us and we will help. Note that health records stored in the Service are PHI; requests about client records should go to the practice that holds them, not to us.
You can control cookies through your browser settings and through the opt-out mechanisms described in our Cookie Policy.
Do Not Track. We do not respond to Do Not Track browser signals, as no common standard for them exists.
Data Retention:
We retain Personal Data for as long as your account is active and as needed to provide the Service. After account closure we retain account and billing records as required for tax, accounting, and legal purposes, and delete the remainder in the ordinary course.
Retention and deletion of PHI is governed by the Terms and Conditions and the Business Associate Agreement. Copies of data may persist in encrypted backups for a limited period after deletion and remain protected until removed.
Security:
We protect Personal Data and PHI using encryption in transit and at rest, role-based access controls, and authentication requirements, and we restrict access to what is necessary to operate and support the Service.
No method of transmission or electronic storage is completely secure. While we use commercially reasonable means to protect your information, we cannot guarantee absolute security.
If a breach of PHI occurs, we will notify affected customers in accordance with our Business Associate Agreement and 45 C.F.R. 164.410.
Geographic Scope:
The Service is offered to practitioners in the United States. Our systems are located in the United States, and information you provide is processed there. We do not offer the Service to individuals in the European Economic Area, the United Kingdom, or Switzerland.
Children’s Privacy:
The Service is a professional tool for licensed practitioners. Account holders must be at least 18. We do not knowingly collect Personal Data directly from children. Where a practice stores records of minor clients, that information is PHI governed by the Business Associate Agreement and the practice’s own obligations.
Changes to This Privacy Policy:
We may update this policy. We will post the new version on this page with an updated version identifier, and will notify you before a material change takes effect. Prior versions are available on request. Please review this policy periodically.
Contact Us:
If you have any questions about this Privacy Policy, please contact us.
Practicepicnic is the registered trade name of Blobbackup, LLC, an Iowa limited liability company. Mail may be sent to Practicepicnic, c/o Blobbackup, LLC, 15920 Hickman Rd, Ste 400 #448, Clive, IA 50325.