Privacy Policy

Last updated: 2026-10-09 (version 2026-10-09)

This Privacy Policy explains how SafeBridge collects, uses and shares information in connection with its website and cloud medical imaging platform (the "Service").

1. Two kinds of information

Account and website information about people who visit the website, request a trial or use the Service on behalf of an organization. SafeBridge is the controller of this information.

Customer Data, including medical images and protected health information ("PHI") that customers send to the Service. SafeBridge processes Customer Data on behalf of the customer as its business associate and only as described in the customer's agreement and the Business Associate Agreement.

2. Information we collect

3. How we use information

4. How we share information

We share information with service providers that help us run the Service, such as Google Cloud (hosting and storage), Google (sign-in and email delivery) and team messaging tools used to notify staff of new signup requests, under agreements that restrict their use of the information. Providers that handle PHI do so under business associate or equivalent agreements.

We may disclose information if required by law or to protect rights, safety and security, or in connection with a merger or sale of the business. Customer Data is disclosed only as the customer directs or as the Business Associate Agreement permits.

5. Google sign-in

We use Google sign-in to verify your email address. We receive your email address, name and account identifier, and do not receive your Google password. Your use of Google is governed by Google's own privacy policy.

6. Security

We use encryption in transit and at rest, access controls, audit logging and tenant-level separation of customer storage. No system is perfectly secure. We will notify affected customers of breaches of PHI as described in the Business Associate Agreement.

7. Retention

Signup records are kept while needed to administer your request and account and for legitimate business and legal purposes. Customer Data is retained for as long as the customer's account is active and under the customer's retention settings. Storage is versioned with a retention period, so deleted objects may remain in storage until that period ends. After termination, Customer Data is returned or destroyed as described in the Business Associate Agreement. Audit logs may be retained for longer for security and compliance.

8. Your choices and rights

Depending on where you live you may have rights to access, correct or delete personal information. Patients should contact the healthcare provider that holds their records, as SafeBridge processes PHI on that provider's behalf and will forward patient requests to the relevant customer. For account information, email support@safebridge.io.

9. International users

The Service is hosted in the United States. By using it you understand that information is processed there.

10. Children

The website and signup are not intended for individuals under 18.

11. Changes and contact

We may update this policy by publishing a new version with a new date and will notify account contacts of material changes. Questions: support@safebridge.io.