This policy is published by Geach Technologies, LLC, trading as ChartVoyant (“ChartVoyant”, “we”, “us”), of Cleveland, Tennessee. It describes how we handle information collected through this website and the public demo, and — in section 11 — the mobile numbers and consent behind the appointment-reminder texts that practices send through ChartVoyant.

1. What this policy does not cover

It does not cover protected health information (PHI). When ChartVoyant processes PHI on behalf of a medical practice, it does so as a business associate under a signed business associate agreement (BAA), and that agreement — together with the practice’s own Notice of Privacy Practices — governs, not this policy. Nothing here grants us any right to use PHI beyond what a BAA permits.

Do not enter real patient information, real PHI, or anything confidential into the public demo.

2. What we collect

  • Demo sign-up details. When you request access to the live demo we collect the name and email address you enter, and — only if you choose to give them — your job title, phone number, and organization.
  • Request metadata. With that sign-up we record your IP address and browser user-agent string, for rate limiting and abuse prevention. They are kept on the sign-up record.
  • Misdirected-fax reports. If you use our fax-reporting page to tell us a fax reached you in error, we keep what you enter — the reference from the cover sheet, the receiving fax number, and any name, organization, phone, email, and message you provide — along with your IP address and user-agent. Please describe only what you need to; do not copy the patient’s information into the message box.
  • Server logs. Our web servers keep standard request logs (IP address, timestamp, URL requested, response status, user-agent) for security and operations.
  • Support tickets. If you use the public support page to open a ticket we keep the name, email, and the description you enter, and — only if you choose to give them — a practice name and callback phone, along with your IP address for rate limiting. Please describe only the product problem; do not include patient information.
  • Email and phone. If you write or call us, we keep that correspondence so we can respond and follow up.
  • Text-message program. If you are a patient of a practice that uses ChartVoyant and you opt in to appointment texts, we process your mobile number, your text consent, the texts sent to you and your replies, and their delivery status — see section 11.

Apart from the fax-report and support-ticket forms above, we do not ask for, and you should not send us, health information, Social Security numbers, or payment card numbers through this website.

3. Cookies, and what we deliberately do not run

This page sets one cookie: cv_demo, placed on .chartvoyant.com for 30 days after you complete the demo sign-up form. It is an access gate — it is what lets demo.chartvoyant.com know you signed up — and it is set Secure, HttpOnly, and SameSite=Lax. Inside the demo, one further cookie (cv_demo_session) is set on demo.chartvoyant.com so that a refresh returns you to your own private copy of the sample data; it holds an opaque identifier and nothing else. Practice users who log into the product receive a session cookie (cv_session) for the duration of their session. That is every cookie we set.

We run no analytics, no advertising or tracking pixels, no social-media trackers, and no third-party fonts or scripts on this page. Every asset it loads is served from our own domain. We do not track you across other websites, and there is therefore nothing for a Do Not Track or Global Privacy Control signal to switch off.

4. How we use it

To open demo access and provide the demo; to reply to you; to contact you about ChartVoyant early access if you asked us to; to keep the site secure and available; and to meet legal obligations. That is the whole list.

5. What we never do

We do not sell personal information. We do not share it with advertisers, data brokers, or list vendors. No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. We do not train AI models on it, and we do not permit any provider we use to train on it. We do use an AI assistant internally to help us run our own systems, and in the course of that your sign-up or fax-report details may be processed by our AI provider on our behalf.

6. Who else can see it

Only service providers who help us run the site and product — hosting and cloud infrastructure, email delivery, and the AI provider behind our internal operations assistant — and only as needed to do that work. Any vendor that could encounter PHI is additionally covered by a BAA before any patient data reaches it. We may disclose information where the law requires it, or to protect our rights or the safety of others. If the business is ever sold or merged, information may transfer as part of that transaction, subject to this policy.

7. Where it lives, and for how long

Information is stored on infrastructure operated by our hosting and email providers; tell us if you need to know where a particular system is hosted and we will confirm it. Demo sign-up records are kept while we have an active or prospective relationship with you and for a reasonable period afterward; server logs sit on a rolling window and are overwritten as new logs arrive. You can ask us to delete your sign-up record at any time.

8. Security

Traffic to and from this site and the product is encrypted in transit and at rest. Each practice’s data is separated from every other practice’s at the database layer. Two-step sign-in is required: staff sign in with a password plus a second factor. Every view and every change inside the product is written to an append-only, hash-chained audit trail that cannot be edited or deleted, including by us.

Production hosting is Amazon Web Services under a signed business associate agreement. Every vendor that can encounter PHI — hosting, the AI model provider, the claims clearinghouse, and fax and messaging transport — is under a BAA before any patient data reaches it. No system is perfectly secure and we do not claim otherwise.

If a breach of unencrypted personal information occurs, we notify affected Tennessee residents as required by T.C.A. § 47-18-2107, and — where PHI is involved — as required by the HIPAA Breach Notification Rule.

How we back up production, copy recovery points off-site, and run across availability zones is on the Security page.

9. Your choices

Write to info@chartvoyant.com to ask what we hold about you, to correct it, to get a copy, or to have it deleted; to unsubscribe from any email we send; or to withdraw demo access. We honor these requests regardless of where you live, and we will not treat you differently for making one. We will respond within 45 days. To clear the cv_demo cookie yourself, delete cookies for chartvoyant.com in your browser.

10. Children

This website is for healthcare professionals and is not directed to children. We do not knowingly collect personal information from anyone under 18 through it.

11. Text messages (SMS)

Practices that use ChartVoyant can send their patients appointment reminders and visit updates by text, under the SMS Terms. Texting is optional: a patient opts in by ticking an unticked box when creating a patient portal account, or by telling the practice’s staff, and consent is never a condition of an account or of care.

  • What we collect: the mobile number on the patient’s chart; the text consent (yes or no, when, and how it was given); the texts sent and any replies; and delivery status from the messaging provider.
  • How we use it: only to send the texts the patient agreed to, to answer HELP, and to honor STOP immediately and permanently until the patient replies START. It is never used for marketing.
  • Who else sees it: only the practice and the messaging provider and wireless carriers that deliver the texts, under a BAA where patient information is involved.

No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

A patient’s mobile number and text consent are also part of the practice’s own records, governed by its BAA with us and its Notice of Privacy Practices.

12. Changes

We will post any revision here and update the effective date above.

13. Contact

Geach Technologies, LLC (trading as ChartVoyant), Cleveland, Tennessee · info@chartvoyant.com · (762) 887-8412. A mailing address is available on request.