Privacy Policy
- We collect only what is needed to run your account and the features you use.
- The text of the clinical notes you review is sent to us to be analyzed and is not stored, unless you choose to be supervised by a colleague (see Peer supervision).
- Patient and treatment-plan records you enter are stored encrypted and are only visible to your account.
- The browser extension reads a page only when you click its icon and press Capture, and never changes the page.
- We do not sell your data, show ads, or use it to train AI models.
1. Who we are
AbaAiCheck (“AbaAiCheck”, “we”, “us”) provides a service that helps Registered Behavior Technicians (RBTs), Board Certified Behavior Analysts (BCBAs) and ABA agencies review session notes for documentation quality and CPT-code compliance. The service consists of the website at abaaicheck.com, the web app at app.abaaicheck.com, the API at api.abaaicheck.com, and the AbaAiCheck browser extension (together, the “Service”).
The Service is intended for professionals. When you enter information about your clients, you are the one who decides what to submit, and AbaAiCheck processes it on your behalf to provide the Service.
2. Information we collect
| Category | What it includes | Why |
|---|---|---|
| Account | First and last name, email address, your language preference, a salted hash of your password (we never store the password itself), your role, registration date, and, if you sign in with Google, your Google account identifier. | To create your account, sign you in and secure it. |
| Patient and plan records | What you choose to enter or upload: client name, date of birth, diagnosis, and behavior-intervention-plan details (dates, target behaviors, replacement programs, clinical profile). | To compare your notes against the client’s plan. |
| Clinical notes (transient) | The note text you submit for review, and the text of plan documents (PDF/DOCX) you upload to extract plan data. | To generate the analysis. See section 4: this content is not stored, except for the peer-supervision history you choose to share. |
| Settings | Your language and audit preferences. | To personalize the Service. |
| Usage counts | How many notes you have reviewed and when you last did, plus daily totals. Counts only, never content. | To operate, secure and improve the Service. |
| Phone number and legal acceptance | Your phone number, and a record that you accepted the Terms of Service and Business Associate Agreement (yes/no, date and time, and the version accepted). | To contact you about your account and security, and to keep an audit record of your agreement for legal compliance. Required to use the analysis. |
| Agency quote requests | If you request an agency quote: agency name, contact email, EHR subdomain and team size range. | To calculate your price, set up your agency account after payment and follow up on your request. Card details are handled only by Stripe. |
| Detailed audit records for your agency (optional) | Only if you choose to share them from Settings: for audits you run under your agency’s EHR domain after you accept, the client name, the CPT code, the full AI analysis (which may quote short excerpts of your note) and your supervisor’s review status. Never the full note text or your supervisor’s comments. | To let your agency’s administrators review documentation quality for the clinicians who chose to share. See Sharing detailed records with your agency. |
| EHR-domain quality metrics | For each note you review, the EHR subdomain it came from (for example clinic.my-ehr.com), the date, CPT code, quality score and number of errors and warnings. Never the note text. | To show your agency administrators quality and compliance metrics for specialists who work under the agency’s EHR domain. This sharing is disclosed when you register; agency administrators must first prove they own the domain, and specialists who did not accept it are shown only as anonymous totals. |
| Note fingerprints | For the “Cloned Note Detection” setting: a set of irreversible numeric hashes of each note you review (up to the last 60 notes, kept up to 180 days). The note text cannot be reconstructed from them. | To warn you when a new note is more than 80% similar to a previous one. If your agency turns on Cross-Employee Clone Detection, a new note is also compared with the fingerprints of other clinicians of the same agency (no note text is ever shared). You can turn the setting off; contact us to delete them. |
| Subscription and usage | Your plan (Free, Individual or Pro), the number of notes you review each month (a counter only, never the note text) and, if you subscribe, identifiers that link your account to Stripe. Payments are processed by Stripe: we never see or store your card number. | To apply your plan’s monthly limit and manage your subscription. |
| Professional profile | If you complete it: your role (RBT, BCBA, BCaBA or other), your certification number and, optionally, your NPI. An NPI may be checked against the public NPPES registry to confirm it belongs to your name. | To limit reviews to the CPT codes of your role and to match the provider named in a note with your account. |
| Sign-in security | The network address (IP) and browser type of your sign-ins, and which browser holds your active session. The provider name written in a note is compared with your account name in your browser or on our server and is not stored. | To keep one active session per browser and network and prevent an account from being shared. |
| Agency and source website | The website domain of the page where you press “Review Now” (for example an agency’s EHR address), counted per month, and, for agency accounts, the member emails registered by the agency administrator. | To confirm that the agency has an active subscription and that you belong to it. |
| Contact messages | If you use the contact form: your name, email address, organization (optional) and message. Please do not include patient information in it. | To reply to your enquiry. |
| Administrator actions | A log of account-management actions taken by administrators (for example, a role change or suspension). | Accountability and security. |
| Technical data | Standard web-server and security logs: IP address, time, requested address and browser type. | Security, abuse prevention and troubleshooting. |
We do not collect your browsing history, and we do not collect precise location, financial or payment information.
3. How we use information
- To provide, maintain and secure the Service, and to authenticate you.
- To analyze the notes you submit and show you the results.
- To prevent fraud and abuse, including rate limiting of sign-in and analysis requests.
- To respond to your requests and to communicate important service or security information.
- To meet legal obligations.
We do not sell personal information, share it for advertising, or use the content of notes or patient records to train AI models.
4. Clinical notes and patient data
Notes you review
When you press “Validate” or “Analyze”, the note text is sent to our servers over an encrypted connection, analyzed, and the result is returned to you. We do not save the note text and our logs do not record it. We keep only a counter that a note was reviewed, plus a one-way fingerprint of the patient name used to count how many different patients you reviewed in the month (your plan limit); the name itself is not kept in that counter.
Sharing detailed records with your agency (optional)
If you use AbaAiCheck under an agency, the agency’s administrators see only quality metrics by default (date, CPT code, score and counts of errors and warnings). Nothing more is shared unless you choose to. In Settings you can opt in to share detailed records: from the moment you accept, for audits you run under the agency’s EHR domain, we keep the client name, the CPT code, the AI analysis result (score, ABC breakdown, replacement skills, warnings; it may quote short excerpts of your note) and your supervisor’s review status, encrypted at rest, and the agency’s administrators can see them and download the PDF report. We do not keep or share the full note text or your supervisor’s comments. Audits you run outside the agency’s EHR domain are never shared. You can stop at any time: access ends immediately and the detailed records kept for the agency are deleted; they are also deleted if you leave the agency. If we change the text of this consent, we ask you again before sharing continues.
Peer supervision (optional)
A colleague on the Pro plan can invite you to be supervised. Nothing is shared unless you accept. Once you accept, we keep a read-only history of the notes you review from that moment (date, patient name, score and note text), encrypted at rest and visible only to that supervisor. You can choose Remove Supervisor in Settings at any time: access ends immediately and the shared history is deleted. Without a supervisor we keep no note text.
Patient and plan records
Records you create (or extract from an uploaded plan) are stored so you can reuse them. They are encrypted at rest and are only accessible from your account. Other users cannot see them, and the in-app administrator dashboard shows only account-level details and counts, never patient details or notes.
Uploaded plan documents
PDF and DOCX files you upload to pre-fill a plan are read in memory to extract fields and are not stored. You review and confirm the extracted data before anything is saved.
Minimum necessary. Enter only the information you need. Where possible, avoid full names or other direct identifiers in notes you submit for review.
5. AI processing and service providers
Analysis is produced either by our own rules engine or, when enabled, with the help of a third-party AI provider. Every result in the app is labeled to show which one was used (“AI analysis” or “Local test analysis”). When AI analysis is used, the note text (and, for automatic plan extraction, the text of the uploaded plan) is sent to the AI provider, currently Anthropic, through its API solely to produce your result. We ask the provider to process it only to return the response to us.
We also rely on the following providers to run the Service:
- Hosting provider — runs the servers where the Service and its encrypted data are hosted.
- Cloudflare — provides DNS, TLS, network security and performance services, and may collect privacy-oriented usage analytics for our sites.
- Google — only if you choose “Continue with Google”. Google tells us your email address and account identifier; we never receive your Google password. Loading the sign-in button connects your browser to Google’s servers, which apply Google’s own privacy policy.
These providers process information only as needed to provide their services to us. We do not permit them to use it for their own advertising.
6. The browser extension
The AbaAiCheck extension shows the review results in your browser’s side panel while you work in your EHR or other web system.
| Permission | What we use it for |
|---|---|
sidePanel | To display the AbaAiCheck panel. |
activeTab and scripting | To read the text of the current tab only after you click the extension icon and press “Review Now” (or “Capture note from this page”). It reads your selected text, the field you are editing, the largest text field on the page or, if there is none, the visible text of the page. It never modifies the page and does not run in the background on other sites. |
identity | To open the AbaAiCheck sign-in page in a browser window when you press “Continue with Google”. The extension does not ask for your Google email or profile: you sign in on app.abaaicheck.com and receive only a one-time code that the extension exchanges for your AbaAiCheck session. |
storage | To keep you signed in (your session token and email) and remember your last CPT code and patient. Note text is never stored in the extension. |
Access to *.officepuzzle.com | So the extension can read the note when your EHR shows it inside a frame from another address. Nothing is read until you click the extension icon and press “Review Now” (or “Capture note from this page”); there are no scripts running on the page in the background. |
Access to api.abaaicheck.com | To sign you in and send the note you chose to analyze. |
The text you capture is sent to AbaAiCheck only when you press “Review Now” or “Analyze note”. The extension has no analytics, no advertising and no remote code.
Limited Use. The use of information received through the extension adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. We use that information only to provide and improve the note-review features you request; we do not transfer it to third parties except as needed to provide those features (see section 5), to comply with law, or for security purposes; we do not use it for advertising or credit decisions; and no person reads it except with your consent, for security or abuse investigation, or to comply with law. Because notes are not stored, there is nothing to read after the analysis is returned.
7. Security
- All traffic is encrypted in transit with HTTPS/TLS.
- Account, patient and settings data are encrypted at rest (AES-256-GCM).
- Passwords are stored only as salted hashes.
- Access to your records is limited to your account, and sign-in and analysis requests are rate limited.
- Sessions expire automatically, and an administrator can suspend an account, which takes effect immediately.
No system is perfectly secure. If we become aware of a breach affecting your information, we will notify you as required by applicable law.
8. Retention and deletion
We keep account and patient records for as long as your account is active. You can delete individual patient records at any time in the app. To delete your account and all associated data, contact us (see section 15); we will act on verified requests without undue delay and in any case within 30 days, except where the law requires us to keep certain information. Standard security logs are kept only as long as needed for security and troubleshooting.
9. Your choices and rights
Depending on where you live, you may have the right to access, correct, delete or obtain a copy of your personal information, to object to or restrict certain processing, and to withdraw consent. You can change your password and preferences in Settings. To exercise any right, contact us; we may need to verify your identity first. You may also complain to your local data-protection authority.
10. HIPAA and agreements
AbaAiCheck is built with technical safeguards suited to sensitive health information, such as encryption in transit and at rest and access controls. However, we do not claim any certification, and whether your use of the Service complies with HIPAA or other laws also depends on your own practices and agreements. If your organization is a covered entity and needs a Business Associate Agreement (BAA), contact us before submitting protected health information.
11. Cookies and local storage
We do not use advertising or cross-site tracking cookies. The web app keeps your sign-in token in your browser’s session storage, which is cleared when you close the tab. Cloudflare and Google may set their own technical cookies or identifiers when their components load on our pages.
12. Children
The Service is for adult professionals and is not directed to children. Information about children who receive services is entered by their providers, who are responsible for having the right to do so.
13. International processing
Our providers may process information in countries other than your own. Where required, we rely on appropriate safeguards for such transfers.
14. Changes to this policy
We may update this policy as the Service evolves. We will change the date at the top and, for material changes, notify you in the app or by email.
15. Contact
Questions, requests or privacy concerns: abaaicheck@gmail.com