Your Privacy

Privacy Policy

How ClinicalEdge collects, uses, and protects your personal and health information.

Last updated: July 16, 2026

Functional Glow Institute ("we," "us," or "our") operates ClinicalEdge, a clinical reasoning and patient care platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform. By using ClinicalEdge, you agree to the practices described in this policy.

Information We Collect

Account Information: Your name, email address, and role (provider or patient) when you register or are invited to the platform.

Patient Intake Data: Health history, symptoms, lifestyle information, lab results, and uploaded documents submitted through intake forms or the patient portal.

Clinical Case Data: De-identified case aliases, biomarker entries, clinical matrices, and AI-generated analyses created by providers for educational and clinical reasoning purposes.

Usage Data: Subscription status, token usage counts, and interaction logs necessary for billing and service delivery.

Audit Data: Timestamped records of data access, modifications, and exports for compliance and security monitoring.

How We Use Your Information

Clinical Care: To generate AI-assisted treatment plans, care plans, after-visit summaries, and lab interpretations that providers use in patient care.

Platform Operations: To manage your subscription, track token usage, process payments via Stripe, and deliver email notifications.

Communication: To send care plan notifications, appointment reminders, and support responses to registered users.

Security & Compliance: To maintain HIPAA-compliant audit trails, detect potential data breaches, and enforce retention policies.

HIPAA Compliance & Data Security

ClinicalEdge is designed with healthcare data protection as a core principle. We implement the following safeguards:

  • Role-Based Access Control: Only authorized administrators can access patient records. Patients can view their own data.
  • Data Masking: Sensitive patient fields are masked in administrative views where full access is not required.
  • Session Timeout: Automated session expiration after 15 minutes of inactivity.
  • Admin 2FA: Two-factor verification required for sensitive administrative actions.
  • Audit Logging: All access to patient data is logged with actor, timestamp, and action type.
  • Breach Detection: Automated hourly monitoring for unusual data access patterns.

Data Retention

Patient health records are retained for a minimum of 7 years in accordance with healthcare record retention requirements. An automated nightly policy review flags records approaching retention thresholds.

Clinical case data created by providers (case aliases, biomarker trends, matrices) is retained for the lifetime of your account and can be deleted at any time by the creator.

Audit logs are retained indefinitely for compliance and security investigation purposes.

Your Data Rights

Patients have the following rights regarding their personal health information:

  • Access: Request a copy of your health records stored on the platform.
  • Correction: Request amendments to inaccurate or incomplete information.
  • Deletion: Request that your data be deleted, subject to medical record retention requirements.
  • Restriction: Request limitations on how your data is used or shared.

To exercise any of these rights, submit a data request through the patient portal or contact us directly using the information below.

Data Sharing & Third Parties

We do not sell your personal or health information. Data is shared only in the following circumstances:

  • AI Processing: De-identified clinical data is sent to our AI service provider to generate treatment plans and analyses. No patient names, dates of birth, or direct identifiers are transmitted.
  • Payment Processing: Billing is handled by Stripe. We do not store full credit card numbers — only transaction metadata.
  • Email Delivery: Care plan and appointment notifications are sent via our email service provider to registered patient email addresses.
  • Legal Compliance: If required by law, we may disclose information to authorized authorities.

AI Tools & Educational Disclaimer

ClinicalEdge provides AI-powered clinical reasoning tools for educational and decision-support purposes. AI-generated content — including treatment plans, lab interpretations, and peptide recommendations — is not a substitute for professional medical judgment.

Providers are responsible for verifying all AI-generated recommendations against current clinical guidelines before applying them to patient care. All AI tools require authentication and token-based access, ensuring usage is attributable and monitored.

Contact Us About Privacy

If you have questions about this Privacy Policy, want to exercise your data rights, or need to report a privacy concern, reach out to us:

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated revision date.

© 2026 Functional Glow Institute · ClinicalEdge