Privacy Policy
Last updated: June 18, 2026
Overview
InBasket AI (“we,” “us”) provides a smart EHR and care-operations platform to healthcare organizations. This policy explains what information we collect, how we use it, and the choices you have. When we process patient health information, we generally do so on behalf of our healthcare-organization customers and under their instructions.
Information we collect
- Account & contact information — name, work email, organization, role, and country/region you provide (for example, when requesting pilot access).
- Usage information — basic logs and analytics about how the platform is used, for security, reliability, and improvement.
- Customer & patient data — clinical and operational records that customers enter or generate in the platform, which may include personal and health information about patients.
How we use information
- To provide, secure, support, and improve the platform.
- To set up and administer pilots and accounts, and to communicate with you about them.
- To meet legal, regulatory, and contractual obligations.
Health information
For patient health information that customers process in the platform, the healthcare organization is the controller/covered entity and we act as a processor/service provider. We handle that information only as needed to provide the service and as instructed by the customer, with appropriate technical and organizational safeguards. Specific obligations are governed by the agreement (and, where applicable, a data-processing or business-associate agreement) with each customer.
How we share information
- With service providers who help us operate the platform, under confidentiality and security obligations.
- At the direction of the customer who controls the data.
- Where required by law, or to protect rights, safety, and the integrity of the service.
Data security
We use reasonable technical and organizational measures to protect information, including access controls, tenant isolation, encryption in transit, and audit logging. The platform is designed to run self-contained — including in offline, on-premise settings — which can reduce exposure for organizations with limited connectivity. No system can guarantee absolute security.
Data retention
We retain information for as long as needed to provide the service, comply with legal obligations, resolve disputes, and enforce agreements. Customer and patient data are retained and deleted according to the customer’s instructions and the applicable agreement.
Your rights and choices
Depending on your location and role, you may have rights to access, correct, or delete personal information, or to object to or restrict certain processing. For patient data held on behalf of a healthcare organization, please direct requests to that organization; we will support them as required.
International transfers
Information may be processed in countries other than where it was collected. Where required, we put appropriate safeguards in place for cross-border transfers.
Children’s privacy
The platform is intended for use by healthcare organizations and their workforce. Where the platform is used to manage care for minors, it is done by clinicians under the controlling organization’s authority and policies.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the “last updated” date and, where appropriate, through additional notice.
Contact
Questions about this policy or your information? Reach us through our contact form and we’ll respond as soon as we can.