Legal
Privacy Policy
Last updated: August 16, 2026
ATTENDING AI exists to give your provider your complete health story before your visit — nothing more. This policy explains, in plain language, what information COMPASS and this website collect, how it is used and protected, and the choices you have. We do not sell personal data, and we do not use it for advertising.
1. Who we are
ATTENDING AI LLC was founded by Dr. Scott Isbell, a practicing family physician. We operate this website (attendingai.health) and COMPASS — the Clinical Orientation and Multi-symptom Patient Acuity Screening System — a pre-visit assessment that captures your health story in a guided conversation, together with a portal where your provider reviews it before your visit.
2. What information we collect
- Symptom and assessment responses. What you tell COMPASS during a pre-visit assessment: your symptoms in your own words, your answers to follow-up questions, and relevant history you choose to share (for example, medications, allergies, or family history).
- Optional photos. If you choose to upload a photo (for example, of a rash or wound) to help your provider prepare, we collect that image. Uploading photos is always optional.
- Contact information. If you reach out through the contact options on this website — for example, to ask about a pilot or request a demo — we collect what you submit, such as your name, email address, and organization.
- Security and audit logs. Our systems record access events (who accessed what, and when) to protect your information and meet HIPAA audit requirements. These logs are operational, not marketing data.
- Mobile app information. If you use the ATTENDING AI mobile app: your account details (name and email), a push-notification token if you allow notifications, and — only if you enable crash detection and only when an alert actually fires — your device's location, so it can be shared with your emergency contacts. Your sign-in credentials are stored in your device's secure keychain, and the app keeps a local, encrypted audit log of access to your health information that syncs to our systems. The app never collects your location in the background or outside an emergency alert.
3. How we use your information
We use assessment information for one purpose: preparing your provider for your visit. COMPASS organizes what you share into a clinical summary so your provider already knows your story before you walk in — and so you never have to repeat it.
If you start COMPASS through a clinic link: your responses are shared with the clinic you selected, and only that clinic. This mirrors the consent you give in the app:
We use contact-form submissions only to respond to your inquiry. We do not use any of your information for advertising, and we do not sell it — see Section 7.
4. AI processing
COMPASS uses AI to help organize what you share into a clear summary for your provider. Text and images you submit are processed by Azure OpenAI services running within Microsoft Azure — the same HIPAA-eligible cloud environment where your data is stored. Two commitments matter here:
- No patient data is used to train AI models — not ours, and not Microsoft's or OpenAI's. Your information is processed to prepare your visit summary and nothing else.
- AI output supports — never replaces — clinical judgment. Everything COMPASS prepares is reviewed by your licensed provider, who makes every clinical decision. COMPASS does not provide medical advice or diagnosis — it exists to give your provider better information so they can make a more accurate decision.
If we ever engage an additional AI provider, it will be held to the same two commitments under a signed HIPAA Business Associate Agreement before any health information reaches it, and this policy will be updated to name the change. In the mobile app, AI processing additionally requires your explicit, revocable permission before your first assessment (see Section 9).
5. How your information is stored and protected
HIPAA-compliant. Encrypted. Audited. Specifically:
- Encrypted at rest in Microsoft Azure, using strong encryption (AES-256).
- Encrypted in transit using TLS 1.2 or higher on every connection.
- Role-based access — only the people who need your information to prepare your visit can see it.
- Audit trails — every access to health information is logged with user, timestamp, and context.
6. How long we keep your information
Health information handled on behalf of clinics is retained for a minimum of six years, consistent with HIPAA documentation requirements (45 CFR 164.530(j)) and our agreements with the clinics we serve. Encrypted backups follow the same protections. Contact-form submissions are kept only as long as needed to handle your inquiry and our business records. When retention periods end, data is securely deleted.
7. What we never do with your data
- We do not sell personal data — to anyone, for any reason.
- We do not use your information for advertising, and we do not share it with advertisers or data brokers.
- We do not use patient data to train AI models.
8. Cookies and analytics
This website sets no cookies and runs no analytics or advertising trackers. One technical note for completeness: our pages load fonts from Google Fonts, which means your browser requests font files from Google's servers (transmitting your IP address as part of any web request). The COMPASS application uses only the strictly necessary session storage required for an assessment to function — nothing for tracking.
9. Your rights and choices
You can request access to, correction of, or deletion of your personal information by contacting us (Section 12). We will respond consistent with applicable law and our retention obligations described in Section 6.
Deleting your mobile app account
If you have an ATTENDING AI mobile app account, you can delete it directly in the app: Settings → Delete Account. Deletion is immediate and cannot be undone — your sign-in credentials, sessions, and the personal identifiers on your account (name, email, phone) are permanently removed, and logging in again becomes impossible. One important carve-out: clinical information already shared with your clinic remains part of your medical record, which your clinic is required by law to retain (see Section 6). Deleting your app account does not — and legally cannot — delete your medical record; requests about the record itself go to your clinic.
Withdrawing AI processing permission
In the mobile app, you can withdraw your permission for AI processing at any time in Settings. Withdrawal stops future AI processing (COMPASS assessments become unavailable until permission is granted again) but does not affect information already shared with your care team.
If you used COMPASS through your clinic, your clinic is the HIPAA "covered entity" responsible for your medical record, and its Notice of Privacy Practices also applies. For requests about your medical record itself, your clinic is often the fastest path — and we support clinics in fulfilling those requests.
10. Children's privacy
COMPASS is not directed to children. Assessments for minors should be completed by, or under the supervision of, a parent or legal guardian in connection with the child's care at a clinic. We do not knowingly collect personal information directly from children under 13 outside of that clinical context. If you believe a child has submitted information to us in error, contact us and we will delete it.
11. Changes to this policy
When we update this policy, we will post the revised version on this page and update the "Last updated" date above. Material changes that affect how patient information is handled will be communicated to the clinics we serve.
12. How to contact us
The most reliable way to reach us is the contact section on our home page. You may also write to attendingai@gmail.com.
This page describes our privacy practices in plain language; it is informational and is not legal advice.
