Privacy
policy.
Last updated · August 20, 2026
Spriggan AI is committed to protecting your privacy. This policy explains how we collect, use, disclose, and safeguard your information when you use our AI receptionist services — voice, SMS, and the AI Scribe.
01 Information we collect
We may collect the following types of information:
- Personal information. Name, phone number, email address, date of birth, mailing address.
- Health information. Appointment details, prescription refill requests, insurance information, and other healthcare-related information you provide during calls.
- Communication data. Call recordings, transcripts, SMS/text messages, and voicemails.
- Visit recordings & transcripts. When a clinician starts an AI Scribe session in the Spriggan app, the in-room visit conversation is recorded through the device microphone and transcribed to draft clinical documentation. See “AI Scribe & AI processing” below.
- Device information. Phone number, carrier information, and device identifiers when you interact with our services.
- Usage data. Information about how you interact with our services — call times, durations, service preferences.
02 SMS / text messaging data
When you opt in to receive SMS messages from Spriggan AI, we collect and process:
- Your mobile phone number
- Your consent status and opt-in/opt-out history
- Message content and delivery status
- Timestamps of messages sent and received
Message types
All messages are sent by Spriggan AI and are limited to appointment reminders and confirmations, clinic location and directions, and patient intake form links related to your healthcare appointments.
Frequency. Typically 1–10 messages per month. Frequency varies based on your appointment schedule.
Opt-out. Reply STOP at any time to unsubscribe. Reply HELP for assistance. Message and data rates may apply.
No sale or sharing. We do not sell, rent, or share your mobile phone number with third parties for their marketing purposes. Phone numbers and message content are handled in accordance with HIPAA and applicable privacy laws.
Carrier support. Supported carriers include AT&T, T-Mobile, Verizon, Sprint, Boost, Virgin, US Cellular, MetroPCS, Cricket, and others. Carriers are not liable for delayed or undelivered messages.
03 How we use your information
We use the information we collect to:
- Provide AI-powered receptionist services to healthcare providers
- Schedule, confirm, reschedule, and cancel appointments on your behalf
- Process prescription refill requests
- Send appointment reminders and billing notifications via SMS or voice
- Facilitate communication between you and your healthcare provider
- Verify insurance eligibility
- Improve and optimize our services
- Comply with legal and regulatory requirements
04 AI Scribe & AI processing
Clinics using Spriggan can document in-person visits with our AI Scribe. A clinician starts and stops every session — recording never happens automatically. During a session, the in-room conversation is captured through the clinician's device microphone and processed as follows:
- Transcription. Audio is streamed to Google Cloud Speech-to-Text — operating under a Business Associate Agreement within our HIPAA-covered cloud environment — and converted to a text transcript.
- Clinical documentation. The transcript is processed by Google's Gemini models via Vertex AI, running in our own cloud environment under the same Business Associate Agreement, to draft a SOAP note and suggest medical billing codes.
- Clinician review. AI-drafted documentation is reviewed and edited by the treating clinician before it becomes part of the patient record.
These AI service providers act as our subcontracted business associates. They are contractually prohibited from using your audio, transcripts, or health information to train their models or for any purpose other than providing the service to us.
05 HIPAA compliance
Spriggan AI is fully committed to compliance with the Health Insurance Portability and Accountability Act (HIPAA). We operate as a Business Associate under HIPAA and enter into Business Associate Agreements (BAAs) with all healthcare providers who use our services.
Protected Health Information (PHI). Any health information we collect on behalf of healthcare providers is treated as PHI and handled in accordance with HIPAA. We implement administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of PHI.
Minimum necessary standard. We only access, use, and disclose the minimum amount of PHI necessary to accomplish the intended purpose.
06 Data security
We implement industry-standard security measures to protect your information, including:
- Encryption of data in transit and at rest (AES-256)
- Secure, access-controlled data centers
- Regular security audits and vulnerability assessments
- Employee training on data privacy and security
- Multi-factor authentication for system access
- Audit logging of all PHI access
07 Third-party service providers
We work with trusted third-party service providers who assist us in operating our services. These providers are contractually obligated to protect your information and comply with applicable privacy laws. Our service providers include:
- Telecommunications providers for voice and SMS services
- Cloud hosting providers
- Payment processors
- Analytics providers (using de-identified data only)
- AI service providers for speech-to-text and clinical-note drafting (Google Cloud, under a Business Associate Agreement — see “AI Scribe & AI processing” above)
All third-party providers who handle PHI have signed Business Associate Agreements with us.
08 Data retention
We retain your information for as long as necessary to provide our services and comply with legal obligations:
- PHI. Retained in accordance with HIPAA and our agreements with healthcare providers (typically 6 years minimum).
- SMS / call records. Retained for the duration of your relationship with the healthcare provider plus any legally required retention period.
- Consent records. Retained for as long as required to demonstrate compliance with applicable regulations.
09 Your rights
You have the following rights regarding your information:
- Access. Request access to the personal information we hold about you.
- Correction. Request correction of inaccurate information.
- Deletion. Request deletion of your information (subject to legal retention requirements). Users of the Spriggan mobile app can also delete their account directly in the app — open the Account sheet on any tab and choose Delete account. This removes your sign-in identity; clinical records remain with your healthcare provider as required by law.
- Opt-out. Opt out of SMS by replying STOP.
- HIPAA rights. Exercise your rights under HIPAA, including requesting an accounting of disclosures.
To exercise any of these rights, contact us at support@spriggan.ai.
10 Children's privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us.
11 Cookies & website analytics
Our public marketing website uses a small number of first-party cookies — set under our own domain — to remember your preferences and to understand how visitors use the site so we can improve it. We do not use cookies to sell your data or to track you across other websites for advertising.
- Preference cookie. A single cookie that remembers your cookie-banner choice so we don't ask again.
- Product analytics. We use PostHog to measure aggregate, de-identified site usage (such as pages viewed and navigation paths). These requests are routed through our own domain; PostHog acts as a contracted processor and does not receive your information for its own purposes. This applies to our marketing website only — not to any patient-facing or PHI-bearing systems.
- Your control. You can clear or block these cookies through your browser's settings, or contact us at support@spriggan.ai to opt out of analytics. The site remains fully functional either way.
12 Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the “Last Updated” date. We encourage you to review this policy periodically.
13 Contact
Questions about this Privacy Policy or our privacy practices?