Version 2026-09-30.2 · published 2026-09-30 · current version

SHA-256 of the exact text: ec096c1a79d98bcd9b4b8276389585a72afd3058d29778b07a4caaf6904d7e2e

GaviaMed AI Quality Agent — Beta Privacy Notice

Version: 2026-09-30.2

Published: September 30, 2026

1. Who handles the data

GaviaMed LLC operates GaviaMed AI Quality Agent. Contact jasper@gaviamed.com for privacy questions, access or deletion requests, correction requests, or to appeal a privacy-request decision where applicable.

2. Data and purposes

We handle account identity and authentication information to provide access; documents, context, findings, discussions, and redlines to perform and preserve your reviews; usage, credit, and payment records to administer billing; and limited operational and security records to keep the Service functioning and prevent abuse.

We also record affirmative agreement acceptance: your authenticated account identifier, verified email at acceptance, server-recorded date and time, agreement and notice versions and their content hashes, the assent wording, and your recorded affirmative acknowledgments. If you provide an organization name for the agreement, it is included in that record. This supports evidence of the agreement and its administration. The acceptance feature does not collect document content, IP addresses, passwords, or payment-card details.

Application error reporting is designed to use fixed error codes, generated reference identifiers, and validated status codes rather than raw document content. Hosting and external providers may maintain their own operational records. We do not represent that all third-party logging has been independently audited.

3. Confidential handling and recipients

Customer content is used for the limited service purposes in the Terms. We do not sell customer document content, use it for advertising, or use it to train GaviaMed's own models.

Lovable and its cloud infrastructure support hosting, authentication, database, and file storage. OpenAI processes the review context supplied for AI work, which may include uploaded content and discussion history relevant to the workflow. Stripe processes payments when enabled; GaviaMed does not need your full card number. If you choose a third-party sign-in provider, that provider also handles the sign-in.

Authorized personnel and providers may access data as reasonably needed to deliver, support, secure, and administer the Service, comply with law, or address abuse. The app's Owner dashboard is limited to operational, billing, and agreement-administration information and does not expose customer document content. Privileged infrastructure access remains technically possible.

We may disclose information where legally required, to protect rights or safety, or to a successor that assumes appropriate obligations in a business transfer. Processing may occur in locations used by our providers; no customer-selected residency or specific regional restriction is currently promised.

4. Security and beta limitations

The current architecture relies on managed cloud security, private storage, account access controls, and provider-managed encryption rather than customer-exclusive control of all decryption keys. It does not make content inaccessible to all infrastructure administrators or processing providers. Customer-controlled encryption is not integrated with document reviews. No SOC 2 audit of GaviaMed, HIPAA-ready offering, end-to-end encryption, zero-knowledge design, or OpenAI zero data retention is claimed.

New document processing is currently subject to the hold shown in the app. Existing data remains governed by its actual storage and processing arrangements. Please do not submit patient-identifiable health data, PHI requiring a business associate agreement, credentials, or other data prohibited by the Terms.

5. Retention, deletion, and your choices

Saved reviews and files are retained to let you reopen and download them. Account, billing, security, and agreement records may be retained as needed for service operation, dispute handling, fraud prevention, and legal obligations. The duration depends on the record's purpose and applicable requirements; there is not currently a published automatic deletion timetable for every record type.

You can download available originals and redlines through your account. Contact us to request access, correction, deletion, or account closure. We will verify authority and respond as required by applicable law. Some records may be retained where permitted or required for legal, security, or financial purposes. Backups and provider systems may follow different retention schedules. We do not promise immediate deletion from every copy or provider system.

The Service has not been approved for OpenAI zero data retention. Provider retention and processing requirements still apply. Do not rely on the app as your only document repository.

We process requests and explain denials or available appeals as required by the laws that apply. Acknowledging this notice does not waive statutory rights or consent to unrelated marketing. We do not use customer document content for sale, targeted advertising, or decisions producing legal or similarly significant effects about individuals.

6. Changes and contact

Material changes will be communicated in the app or through account contact information as appropriate. Accepted policy versions remain available in the app, and a copy of your acceptance records can be requested through jasper@gaviamed.com. A new acknowledgment records notice of an updated policy; it does not retroactively authorize broader use of previously supplied content.

GaviaMed LLC — jasper@gaviamed.com

All versions of the Privacy Notice