Skip to content

Callpost Privacy Policy

Effective date: October 6, 2026

The short version: Callpost helps healthcare practices run their front office and business. When we handle patient information, we do it as the practice's business associate under HIPAA, under a signed Business Associate Agreement, and only to provide our service. We never sell personal information, never use patient information for advertising, and never use it to train AI models.

1. Who we are and what this policy covers

Callpost, LLC ("Callpost," "we," "us") provides an AI-powered practice operations platform for healthcare practices, including chiropractic, dental, physical therapy, massage therapy and veterinary practices (each a "Practice"). The platform answers calls, texts and web chats, schedules visits, sends reminders and forms, helps clinicians prepare and document visits, processes payments through our payment partner, and supports a practice's finances and marketing (the "Service"). Our AI assistant within the Service is called Hartley.

This policy explains how we handle information about:

  • Practices and their staff who hold accounts ("Authorized Users"), and visitors to callpost.ai; and
  • Patients and clients of Practices, and people who contact a Practice through the Service ("Patients").

2. Our two roles

For patient information, we act for the Practice. When a Patient calls, texts or chats with a Practice through the Service, completes forms, or is seen by a clinician who uses the Service, the Practice decides how that information is used. For Practices that are covered entities under the Health Insurance Portability and Accountability Act ("HIPAA"), Callpost is a business associate, and our handling of protected health information ("PHI") is governed by our Business Associate Agreement ("BAA") with the Practice. If this policy and a BAA conflict on PHI, the BAA controls.

The Practice's own Notice of Privacy Practices describes how the Practice uses and discloses PHI and the rights Patients have. Patients who want to access, correct or ask about their health information should contact their Practice. We will help the Practice respond as our BAA requires.

For account and business information, we act for ourselves. We are responsible for information about Practices and Authorized Users that we collect to run our business, such as account, billing and support information, and for information about visitors to our website.

Veterinary records are not PHI under HIPAA. We protect information that veterinary Practices entrust to us with the same safeguards we apply to PHI.

3. Information we handle

For Practices (as their business associate):

  • Patient identifiers and contact details: name, phone number, email, address, date of birth.
  • Scheduling and communications: appointment history, call recordings and transcripts where the Practice enables them and required notices or consents are given, text and chat messages, voicemails.
  • Health information the Patient or Practice provides: intake and consent forms, reason for visit, health history, visit recordings and transcripts (only with the consent the Practice collects), clinical note drafts and signed notes, care plans and home-care instructions.
  • Payment information: payment methods are collected and stored by our payment processor, Stripe. Callpost stores only a token, the card brand, the last four digits and the expiration date. We never store full card numbers.

About Practices and Authorized Users (for ourselves):

  • Account details: practice name, staff names, work email and phone, roles and permissions.
  • Billing details for the Callpost subscription (processed by Stripe).
  • Support conversations and product feedback.
  • Security and usage data: sign-in events, IP address, device and browser type, pages used, and audit logs.

Website visitors: information you submit (for example, a demo request) and basic analytics. We use only essential and analytics cookies on our website; we do not use advertising cookies. We do not currently respond to "Do Not Track" signals. Our analytics never run inside the parts of the Service that display PHI.

4. How we use information

We use PHI only as our BAA permits: to provide the Service to the Practice, to maintain and secure it, to provide support the Practice requests, and as required by law. We apply HIPAA's "minimum necessary" standard.

We use account and business information to create and manage accounts, bill for the Service, provide support, keep the Service secure, communicate about the Service, improve it, and comply with law.

We do not:

  • sell personal information or PHI, or share it for cross-context behavioral advertising;
  • use PHI for marketing, or let anyone else do so;
  • use PHI or Patient conversations to train AI models, ours or anyone else's; or
  • let our service providers use PHI for their own purposes.

De-identified information. Where our BAA with a Practice permits it, we may create information that has been de-identified under HIPAA's standards (45 CFR 164.514) to measure and improve the Service, for example to test that Hartley books visits accurately. De-identified information cannot reasonably be used to identify a Patient, and we do not attempt to re-identify it. A Practice may opt out by contacting privacy@callpost.ai.

5. Artificial intelligence

The Service uses AI to answer calls and messages, schedule visits, prepare patient briefs, draft clinical notes, summarize business performance and answer staff questions.

  • Clinicians stay in charge. AI-drafted clinical content is a draft until a licensed clinician reviews and signs it. Clinical reference answers are provided only to Practice staff, are labeled as reference for the clinician's judgment, and are not shown to Patients.
  • Patients are told. Hartley identifies itself as the Practice's AI assistant. It does not give Patients medical advice and directs emergencies to 911.
  • Recording requires consent. Visit recording works only after the Practice records the Patient's consent, and the Practice controls whether calls are recorded.
  • No automated decisions with legal effect. The Service does not make decisions about Patients that produce legal or similarly significant effects without a person's involvement.
  • AI providers are bound. Our AI provider processes information under a BAA, does not use it to train models, and retains it only as needed to provide and secure its service.
  • Web searches carry no patient details. When Hartley searches the web to answer a staff question, identifying information is removed from the search first.

6. Who we share information with

We disclose information only to:

  • Service providers (subprocessors) that help us run the Service, under written agreements that limit their use of information and, where they handle PHI, under a BAA: Anthropic (AI processing), Supabase (database and file storage), Vercel (application hosting), Surge (voice and text messaging), Stripe (payments), Google (optional sign-in and calendar connection), and our email delivery provider. A current list is available at privacy@callpost.ai, and we will notify Practices before adding a subprocessor that handles PHI.
  • The Practice and the Authorized Users it permits.
  • Others at the Practice's direction, such as an integration the Practice connects.
  • Legal and safety recipients, when required by law or legal process, or to protect the rights, safety and security of Patients, Practices, Callpost or the public, and in the case of PHI only as HIPAA and our BAA allow.
  • A successor, in a merger, acquisition or sale of assets, subject to this policy and existing BAAs.

7. Security

We protect information with administrative, physical and technical safeguards designed to meet the HIPAA Security Rule, including:

  • encryption in transit (TLS 1.2 or higher) and at rest;
  • row-level access controls that keep each Practice's data separate, role-based permissions within each Practice, and two-step sign-in for administrators;
  • automatic sign-out after inactivity, and append-only audit logs of access to and changes to patient records;
  • signed clinical notes that cannot be altered, only amended;
  • limited Callpost staff access: our staff see only aggregate, de-identified information about Practices by default. Viewing patient details requires a documented reason, expires after 60 minutes, is logged, is visible to the Practice, and can be set to require the Practice's approval.

No system is perfectly secure, but we continuously monitor and improve our safeguards.

8. Breach notification

If we discover a breach of unsecured PHI, we will notify the affected Practice without unreasonable delay and within the time required by our BAA and 45 CFR 164.410, and we will provide the information the Practice needs to meet its obligations. We will notify Practices and Authorized Users of other security incidents affecting their personal information as required by applicable law.

9. Retention, export and deletion

We keep information while a Practice's account is active. A Practice can export its data at any time in standard formats (CSV and JSON, plus recordings and documents in their original formats). When an account ends, we keep data for 30 days so the Practice can export it, then return or destroy PHI as our BAA requires. Backups are retained no longer than 90 days and are not actively processed. Where returning or destroying PHI is not feasible, or law requires us to keep information, we extend this policy's protections to it for as long as we keep it.

10. Your choices and rights

Patients: your health information rights under HIPAA (to access, amend, receive an accounting of disclosures, and request restrictions) are exercised through your Practice. You can stop text messages from a Practice at any time by replying STOP.

Practices and Authorized Users: you can access and update account information in Settings, export data at any time, and contact privacy@callpost.ai with requests.

California residents: PHI handled under HIPAA is exempt from the California Consumer Privacy Act. For other personal information we hold about you, you may request to know, delete or correct it, and you will not be discriminated against for doing so. We do not sell or share personal information, and we use sensitive personal information only to provide the Service. Send requests to privacy@callpost.ai; we will verify your identity before responding. An authorized agent may submit a request on your behalf with your written permission.

11. Children

Practices may treat minors, and we handle minors' information on behalf of Practices under the same protections as all PHI. Our website and accounts are for businesses and are not directed to children; we do not knowingly collect personal information from children for our own purposes.

12. Where we process information

Callpost and its subprocessors store and process information in the United States. The Service is intended for Practices located in the United States.

13. Changes to this policy

We will post any changes here with a new effective date. For material changes we will notify account owners by email at least 30 days before they take effect. Changes never reduce the protections of a signed BAA.

14. Contact us

Callpost, LLC Privacy: privacy@callpost.ai Security reports: security@callpost.ai General: support@callpost.ai