Skip to content
Sofya
reasoningcontinuous careintegrationssecuritynewsroomtalk to usenespt
talk to us
reasoningcontinuous careintegrationssecuritynewsroomenespt
privacy

Privacy Policy

How Sofya handles website, interaction, and clinical information — with different rules for the public site and authorized institutional care environments.

Effective · August 1, 2026

The privacy boundary in plain language

  • Optional analytics starts only after your choice and does not receive visible clinical content.
  • The public composer does not create a persistent medical record, but audio and files require transient processing.
  • Identifiable clinical data belongs in an authorized institutional environment with the required agreements.
  • We do not sell clinical content or use it for targeted advertising.
On this page
  1. 01Scope and privacy roles
  2. 02Information we process
  3. 03The public composer and clinical data boundary
  4. 04AI transparency, explanation, and human review
  5. 05Purposes and legal bases
  6. 06Browser storage, analytics, and experiments
  7. 07Service providers, disclosures, and no sale of clinical data
  8. 08Retention and deletion
  9. 09Security and incidents
  10. 10International transfers
  11. 11Brazilian privacy rights
  12. 12United States privacy supplement
  13. 13United States consumer health data notice
  14. 14Patients, minors, and professional responsibility
  15. 15Updates, questions, and requests
01

Scope and privacy roles

This Policy covers sofya.med, the public interactive experience, communications with Sofya, and Sofya services that link to it. It does not replace a hospital, clinic, professional, research sponsor, or other institution’s privacy notice.

For the public website and direct business communications, Sofya generally determines why and how data is processed. In an institutional deployment, the healthcare organization generally determines the care purpose and Sofya processes data under its instructions, a data processing agreement, a business associate agreement when applicable, and the institutional privacy notice. The actual contract and law determine each party’s role.

The relevant corporate entities are Sofya Tecnologia Ltda. · CNPJ 46.163.535/0001-84 · Rua Padre Adelino, 2074, 12º andar, conjunto 121, Quarta Parada, São Paulo, SP 03303-000, Brazil and Sofya AI Inc. · Florida document P25000007209 · 2 S Biscayne Blvd, Suite 2450, Miami, FL 33131, United States. The order form or institutional agreement identifies the entity responsible for a specific contracted service.

02

Information we process

Depending on how you use the service, we may process the following categories:

  • Browser and device data, such as language, privacy choice, page path, referral information, device type, approximate network information, and security logs.
  • Business contact data you provide, such as name, work email, organization, role, and message.
  • Public composer content, such as case text, voice audio and transcript, selected document contents and filenames, and the resulting structured text.
  • Institutional clinical data made available under contract, which may include patient identifiers, notes, medications, allergies, results, images, coded data, and professional actions.
  • Usage and feedback data about feature operation, errors, performance, and user choices, subject to the clinical data boundary below.
  • Legal acceptance data stored in the browser, limited to the accepted Terms version and acceptance timestamp.
03

The public composer and clinical data boundary

The no-account composer is designed not to save a persistent clinical record. Text remains available in the page for the session. Audio is streamed to the transcription service, and selected documents are sent to the document-extraction service so the requested result can be returned. This is transient service processing, not local-only processing.

Case text, audio, transcripts, document contents or filenames, patient identifiers, and generated clinical outputs are not sent to marketing analytics. Unless a separate authorized program and agreement expressly says otherwise, Sofya does not use identifiable public-composer clinical content to train a general-purpose model.

Use synthetic or properly de-identified cases on the public site. Identifiable patient data should be submitted only through an institutional environment expressly authorized for that purpose. Closing the page or clearing it does not erase data lawfully retained by an institutional controller or required security record.

04

AI transparency, explanation, and human review

When Sofya uses AI to transcribe, structure, retrieve, summarize, suggest, or generate content, the interface or surrounding experience identifies the AI-assisted nature of the task and provides material context about its purpose and limitations. Where available and appropriate, outputs may also expose sources, provenance, confidence, uncertainty, or items that still require verification.

AI output is not a silent or sole basis for a consequential clinical decision. The authorized professional must review the relevant patient context, may reject or correct an output, and remains responsible for the final judgment and communication with the patient. Feedback and correction paths may be provided to improve the specific workflow under the governing agreement.

Transparency does not require Sofya to disclose security controls, model weights, trade secrets, another person’s confidential information, or details that would make the service less safe. We provide meaningful information proportionate to the use, risk, applicable law, and contractual setting.

05

Purposes and legal bases

We process data to deliver the requested feature; authenticate and support authorized users; maintain security, reliability, and auditability; respond to communications; meet contractual and legal duties; prevent misuse; and improve the service using data permitted for that purpose.

Where the LGPD applies, the legal basis depends on the context and may include consent, performance of a contract or requested procedures, compliance with a legal or regulatory obligation, regular exercise of rights, protection of life or physical safety, health protection by authorized actors, legitimate interests that do not override rights, or another basis permitted by law. Sensitive health data is processed only under a basis specifically allowed for sensitive data.

Brazilian General Data Protection Law (LGPD) ↗ANPD guidance on controller and processor roles ↗
06

Browser storage, analytics, and experiments

Essential browser storage remembers language, the privacy decision, and whether the current version of the Terms was accepted. The acceptance record contains only the Terms version and timestamp — not a name, email, identity, case, audio, transcript, filename, or generated output. It remains until replaced by a later version, cleared from the browser, or no longer needed, and it is not used for marketing.

Optional Google Analytics 4 measurement starts only after you allow it; optional browser storage may then keep an anonymous experiment assignment. Measurement covers pages and actions using identifiers, locale, path, placement, device, and related technical data — not visible clinical content. If analytics is allowed, acceptance events may include only the Terms version and the type of action that opened the notice, never clinical content.

You may allow or reject optional measurement through the privacy controls at the bottom of the site and may clear browser data. Essential storage remains available because it is needed to remember your choice and operate the site.

07

Service providers, disclosures, and no sale of clinical data

We may disclose data to vetted providers that support hosting, security, transcription, document processing, communications, analytics after consent, and professional services; to an authorized healthcare organization; or when required to protect rights, safety, or comply with law. Providers receive only the access needed for their role and are bound by appropriate contractual and security duties.

Sofya does not sell clinical content or PHI, does not use it for targeted advertising, and does not disclose it to data brokers. A corporate transaction may involve a controlled transfer subject to confidentiality, applicable notice, and the same legal protections.

08

Retention and deletion

We retain personal data only for the period reasonably needed for the stated purpose, institutional instructions, security, legal obligations, dispute handling, and backup cycles. Public-composer content is designed for transient processing and not as a stored medical record. Analytics, communications, and security records follow their configured schedules.

Institutional clinical data follows the healthcare organization’s retention policy, applicable health-record law, and the contract. Deletion requests may be limited when retention is required by law, needed to establish or defend legal claims, or controlled by the healthcare organization rather than Sofya.

09

Security and incidents

We use administrative, technical, and organizational safeguards proportionate to the data and deployment, including access controls, encryption in transit, environment separation, monitoring, and incident procedures. No system is risk-free, so users must also protect credentials, devices, exports, and local copies.

We investigate suspected incidents and provide notices to affected organizations, individuals, and authorities when required. For US services outside HIPAA that meet the relevant definitions, the FTC Health Breach Notification Rule may apply; HIPAA-regulated environments follow the applicable HIPAA and contractual process.

FTC Health Breach Notification Rule ↗
10

International transfers

Sofya operates across jurisdictions and may process data in countries other than where it was collected. We use the contractual, organizational, and legal safeguards required for the applicable transfer, including institutional data-location commitments where agreed. A public website visit may involve global infrastructure even when clinical deployments have stricter location controls.

11

Brazilian privacy rights

When the LGPD applies and Sofya is responsible for responding, you may request confirmation and access, correction, information about sharing, portability where regulated, anonymization, blocking or deletion when legally available, withdrawal of consent, review of qualifying automated decisions, and information about the consequences of withholding consent. You may also petition the ANPD.

We may need to verify identity and clarify the request. If an institution controls the clinical record, we will direct or transmit the request to that institution as appropriate.

12

United States privacy supplement

HIPAA applies only when the legal requirements for a covered entity or business associate relationship are met. In those deployments, the healthcare organization’s Notice of Privacy Practices and the business associate agreement govern PHI. Patients generally exercise access, amendment, accounting, or restriction rights through the covered healthcare organization.

Residents of states with applicable privacy laws may have rights to know or access, correct, delete, obtain a copy, limit certain uses of sensitive data, opt out of sale or sharing, and appeal a denied request. These rights depend on the law’s scope and exceptions. We do not discriminate against a person for exercising a privacy right.

California residents may have rights under the CCPA, where it applies. Sofya does not sell or share public-composer clinical content for cross-context behavioral advertising. Requests can be sent to privacy@sofya.ai, and an authorized agent may submit a request where the law permits.

HHS: covered entities and business associates ↗California Consumer Privacy Act ↗
13

United States consumer health data notice

Where a state consumer health data law applies to information outside HIPAA, the consumer health data we may collect is the case text, audio, transcript, selected document content, structured result, and related inferences that a person directly provides or requests through the public composer. We collect it from the user and from the requested transcription or document-processing function only to provide that function, maintain security, and comply with law.

We may share that data only with processors needed to provide the requested function, an authorized healthcare organization, or a person legally entitled to receive it. The processor categories are described under “Service providers, disclosures, and no sale of clinical data.” We do not sell consumer health data and do not use geofencing to identify or infer that a person is seeking healthcare services.

Where available, a consumer may request access, correction, deletion, withdrawal of consent for future collection or sharing, or an appeal of a denied request by writing to privacy@sofya.ai. We verify the requester and apply statutory exceptions. If a healthcare organization controls the record, it remains the appropriate contact for that record.

Washington My Health My Data Act ↗
14

Patients, minors, and professional responsibility

The public site is directed to professionals and institutional audiences, not children. Do not submit a minor’s or dependent person’s identifiable data unless you have authority and the approved environment supports that use.

A professional or institution that enters patient information remains responsible for required notices, consents or other legal bases, minimum-necessary use, record governance, and responding to the patient. Patient-facing explanations should remain understandable and preserve access to a human professional.

15

Updates, questions, and requests

We may update this Policy as services and laws change. We will publish the effective date and provide additional notice when a material change requires it.

Send privacy questions or rights requests to privacy@sofya.ai. Describe the service and relationship involved, but do not include unnecessary patient information in email. We will verify and respond under the applicable law and may coordinate with the responsible healthcare organization.

Related documentRead the Terms of Use →
Contact privacy →

Medicine is decision.

Every consultation makes the next one better.

Sofya

A second clinical look during the consultation and between visits.

platformreasoninginteroperabilityinstitutional deployment
contentpublicationsnewsroom
trustsecurityterms of useprivacy
companybrandcontact
© 2026 sofya · são paulo · miami · www.sofya.medenespt
Privacy under your control.

We use optional measurement to improve the site and test experiences. Nothing beyond the essentials loads without your permission.