Privacy policy
Last updated August 8, 2026
Template notice. This page describes how the software handles data as built. It is not legal advice and it is not a finished privacy policy for your organisation. Have counsel review it against your actual practices, jurisdictions, and business associate agreements before you publish it.
Two kinds of data
Bosshh handles two categories that are worth keeping separate: information about agency staff and prospects who use this website, and protected health information about patients, which agencies process inside the application.
Website and demo requests
When you submit the demo form we store the name, work email, agency, role, agency size, phone number, stated interests, and message you provide, along with the page you submitted from, your IP address, and the time. We use it to respond to your enquiry and to follow up about Bosshh. Please do not put patient information in that form.
The site sets one cookie, for your session. There is no third-party analytics, advertising, or tracking script, and the Content Security Policy blocks requests to other origins.
Patient information inside the application
Where an agency uses Bosshh to process patient records, the agency is the covered entity and controls that data. Bosshh processes it on the agency's instructions and for the purposes the agency configures. The application stores:
- patient demographic, insurance, and clinical records the agency enters or imports;
- referral documents the agency uploads, and the structured data extracted from them;
- visit audio recordings and their transcripts;
- generated drafts, the evidence cited for each item, and the signed final records;
- an audit log of who accessed or changed which record, and when.
Subprocessors and model providers
Generating a draft requires sending the relevant clinical text to a large language model API. Transcription, when enabled, may send audio to whichever provider the agency configures — or to no third party at all, if the agency uses local transcription or manual entry. Each agency should confirm that every provider it enables is covered by an appropriate business associate agreement before processing real patient data.
Retention and deletion
Clinical records are retained according to the agency's own retention schedule, which is typically set by state and payer requirements rather than by us. Demo request records are kept while a commercial conversation is active and then deleted. Audit log entries are append-only and retained for the period the agency's compliance programme requires.
Security
The controls the application implements are described in detail on the security page. In summary: agency-scoped access, role-based permissions, session and CSRF protection, prepared statements throughout, uploads stored outside the web root, a strict content security policy, and an audit log covering reads as well as writes.
Your choices
To see, correct, or delete information we hold about you as a website visitor or prospect, email privacy@bosshh.example. If you are a patient asking about your own health records, contact your home health agency directly — they hold and control that record, and they are the right party to answer.
Changes
If this policy changes materially we will update the date above and, where the change affects existing customers, tell them directly rather than relying on this page.