InBasket AI

Privacy Policy

Last updated: June 18, 2026

Overview

InBasket AI (“we,” “us”) provides a smart EHR and care-operations platform to healthcare organizations. This policy explains what information we collect, how we use it, and the choices you have. When we process patient health information, we generally do so on behalf of our healthcare-organization customers and under their instructions.

Information we collect

  • Account & contact information — name, work email, organization, role, and country/region you provide (for example, when requesting pilot access).
  • Usage information — basic logs and analytics about how the platform is used, for security, reliability, and improvement.
  • Customer & patient data — clinical and operational records that customers enter or generate in the platform, which may include personal and health information about patients.

How we use information

  • To provide, secure, support, and improve the platform.
  • To set up and administer pilots and accounts, and to communicate with you about them.
  • To meet legal, regulatory, and contractual obligations.
We do not sell personal or health information, and we do not use patient health information for advertising.

Health information

For patient health information that customers process in the platform, the healthcare organization is the controller/covered entity and we act as a processor/service provider. We handle that information only as needed to provide the service and as instructed by the customer, with appropriate technical and organizational safeguards. Specific obligations are governed by the agreement (and, where applicable, a data-processing or business-associate agreement) with each customer.

How we share information

  • With service providers who help us operate the platform, under confidentiality and security obligations.
  • At the direction of the customer who controls the data.
  • Where required by law, or to protect rights, safety, and the integrity of the service.

Data security

We use reasonable technical and organizational measures to protect information, including access controls, tenant isolation, encryption in transit, and audit logging. The platform is designed to run self-contained — including in offline, on-premise settings — which can reduce exposure for organizations with limited connectivity. No system can guarantee absolute security.

Data retention

We retain information for as long as needed to provide the service, comply with legal obligations, resolve disputes, and enforce agreements. Customer and patient data are retained and deleted according to the customer’s instructions and the applicable agreement.

Your rights and choices

Depending on your location and role, you may have rights to access, correct, or delete personal information, or to object to or restrict certain processing. For patient data held on behalf of a healthcare organization, please direct requests to that organization; we will support them as required.

International transfers

Information may be processed in countries other than where it was collected. Where required, we put appropriate safeguards in place for cross-border transfers.

Children’s privacy

The platform is intended for use by healthcare organizations and their workforce. Where the platform is used to manage care for minors, it is done by clinicians under the controlling organization’s authority and policies.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the “last updated” date and, where appropriate, through additional notice.

Contact

Questions about this policy or your information? Reach us through our contact form and we’ll respond as soon as we can.