Privacy Policy
Effective date: August 2, 2026
Notfyr (“Notfyr,” “we,” “us,” or “our”) provides voice-first shift notes and care documentation tools for direct support professionals (DSPs), caregivers, and the home-care and residential provider organizations that employ them (collectively, the “Services”). This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit our website, use our web or mobile applications, or otherwise interact with us (collectively, the “Service”). This Privacy Policy is intended for a United States audience.
If you are a direct support professional or caregiver using Notfyr on behalf of a care provider organization, that organization (your employer or the agency you work with) is typically the “Covered Entity” or “Business Associate” under the Health Insurance Portability and Accountability Act (“HIPAA”), and Notfyr acts as a service provider or business associate to that organization with respect to protected health information (“PHI”) contained in care notes. Where we act as a business associate, our handling of PHI is governed by a Business Associate Agreement (“BAA”) with the applicable organization, in addition to this Privacy Policy.
1. Information we collect
We collect the following categories of information:
- Account and contact data: name, email address, phone number, job title/role, employer or organization name, and login credentials when you register, request early access, or are added to an organization’s Notfyr account.
- Care note and voice data: voice recordings, transcriptions, shift notes, tags to care goals, timestamps, and related metadata that you or your organization create through the Services. This category may include protected health information about the individuals your organization supports, which we process on behalf of, and at the direction of, your organization.
- Usage and device data: device type, browser type, operating system, IP address, general location (such as city or region), log data, and information about how you interact with the Service.
- Communications data: emails, support requests, and other messages you send us.
- Payment data: billing contact information and limited transaction details. Full payment card information is collected and processed directly by our payment processor and is not stored on our servers.
2. Cookies and tracking technologies
We use cookies and similar technologies on our website and application for essential functionality, remembering your preferences, and limited analytics. We do not use advertising or cross-site tracking cookies. For details, see our Cookie Policy.
3. How we use your information
- Provide, operate, secure, and improve the Services.
- Process voice recordings into transcriptions and structured care notes, and route notes to the appropriate supervisor, team, or record.
- Create and manage accounts, and authenticate users on behalf of care provider organizations.
- Communicate with you about your account, product updates, security notices, and support requests.
- Analyze aggregated, de-identified usage trends to understand how the Service is used and to develop new features.
- Detect, investigate, and prevent fraud, abuse, and security incidents.
- Comply with legal obligations, respond to lawful requests, and enforce our agreements, including our Terms of Service and any applicable Business Associate Agreement.
We do not use care note content, voice recordings, or other PHI to train general-purpose artificial intelligence models, and we do not sell personal information or PHI.
4. How we share your information
We do not sell your personal information. We disclose information only as described below and, with respect to PHI, only as permitted by HIPAA and any applicable Business Associate Agreement:
- Your organization. If you use Notfyr as an employee, contractor, or affiliate of a care provider organization, we share the notes and information you create with that organization and the supervisors or reviewers it designates.
- Service providers. Trusted third parties that help us operate the Services, such as cloud hosting, transcription, analytics, and email delivery providers. Currently, we use Amazon Web Services (AWS), including Amazon Simple Email Service (SES), for infrastructure and email delivery. Service providers that may access PHI are bound by appropriate confidentiality and, where required, Business Associate Agreement obligations.
- Legal and safety. When required by law, regulation, subpoena, or other legal process, or to protect the rights, property, or safety of Notfyr, our customers, or others.
- Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality protections and, for PHI, continued compliance with HIPAA.
- With your consent. For any other purpose disclosed to you at the time of collection or with your consent.
5. HIPAA and protected health information
Where care notes or related content constitute PHI under HIPAA, Notfyr provides administrative, technical, and physical safeguards designed to protect that information, consistent with the HIPAA Security Rule and any Business Associate Agreement in place with the applicable care provider organization. Your organization (as the Covered Entity or upstream Business Associate) remains responsible for ensuring its own use of the Services, including staff training and access management, complies with HIPAA and other applicable healthcare laws. Requests relating to PHI, including access, amendment, or accounting of disclosures, should generally be directed to your care provider organization in the first instance.
6. Data retention and security
We retain personal information and care note data for as long as necessary to provide the Services, comply with legal and contractual obligations (including any applicable Business Associate Agreement or recordkeeping requirements), resolve disputes, and enforce our agreements. We implement administrative, technical, and physical safeguards designed to protect your data, including encryption of data in transit and at rest, access controls, and audit logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
7. Your rights and choices
Depending on your location and role, you may have the right to access, correct, delete, or restrict processing of your personal information, and to opt out of certain uses. To exercise these rights, contact us using the information below. If your request relates to PHI created by or for a care provider organization, we may direct you to submit your request to that organization, which controls the underlying records.
State privacy rights. Residents of states with comprehensive privacy laws (such as California, Colorado, Connecticut, Virginia, and others) may have additional rights, including the right to know, access, correct, and delete personal information, and to opt out of the sale or sharing of personal information for targeted advertising. We do not sell or share personal information for cross-context behavioral advertising. You may exercise applicable state privacy rights by contacting us at privacy@notfyr.co. We may need to verify your identity before responding.
8. International data transfer
We are headquartered in the United States, and the Services are designed for use by U.S.-based care provider organizations. Any information we collect is processed and stored in the United States, and, where applicable, by service providers operating in the United States.
9. Children’s privacy
The Service is intended for use by adult care professionals and is not directed to children. We do not knowingly collect personal information directly from children under 18. Care notes may reference minors receiving care solely as part of the documentation created by a care provider organization, and such information is handled in accordance with this Privacy Policy and applicable law.
10. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the revised policy on our website and updating the effective date above. Your continued use of the Service after changes become effective constitutes acceptance of the revised policy.
11. Contact us
If you have questions or concerns about this Privacy Policy or our privacy practices, please contact us at privacy@notfyr.co. For support questions, contact support@notfyr.co.
This Privacy Policy is provided as a template and should be reviewed by qualified legal counsel before use.