Legal
Privacy policy
What information Rebrief handles, why it handles it, and the choices you have — for visitors to this site, for the practices that use Rebrief, and for the patients whose records we process on those practices' behalf.
01Scope of this policy
Rebrief is built and operated by Stat Labs Incorporated (“Stat Labs,” “Rebrief,” “we,” “us”), a company headquartered in Montreal, Quebec, Canada. Rebrief is an AI documentation and agent platform for dental practices: it transcribes appointments, drafts clinical documentation for clinician review, charts, and operates alongside a practice’s management system.
This policy covers three situations, and it treats them differently:
- Site visitors — people who browse www.rebrief.ai, use the Ask AI search, or reserve a demo. We are responsible for this information.
- Practice users — dentists, hygienists, and staff who hold Rebrief accounts. We are responsible for their account, billing, and usage information.
- Patient information— clinical records, transcripts, and documentation we process on behalf of a dental practice. The practice is the custodian and controller of this information; Rebrief processes it only as the practice’s service provider, under this policy and any agreement between us and the practice — including a business associate agreement where one applies. If those agreements conflict with this policy, the agreements control for that information.
If you are a patient of a practice that uses Rebrief, your practice’s own privacy notice governs your care records; this policy describes how we handle them on your practice’s behalf.
02Information we collect
From practice users
- Account information — name, email address, role at the practice, and clinic details, provided at signup or through an invitation.
- Consent records — your acceptance of the Terms of Service, this policy, and, where applicable, a business associate agreement, recorded and version-tracked at signup.
- Billing information — payments are processed by Stripe on its hosted checkout. Rebrief never sees or stores your full card number — only the last four digits, your plan, and billing status.
- Support and correspondence — messages you send us by email or through in-app live support.
Patient information processed for practices
- Records synced from, or written to, the practice’s management system — patient demographics, appointments, clinical and practice notes, odontograms and periodontal charting, and appointment history.
- Appointment transcripts — the live transcript produced during a recorded appointment and the refined transcript produced when it ends. Transcript text persists with the clinical note; the audio does not (see below).
- AI-generated content — drafted clinical notes, per-patient summaries, and documents prepared for clinician review.
- Phone and messaging data— when a practice uses the AI receptionist: caller identity, caller phone number, and the live call transcript. When a staff member sends a supervised SMS: the message content and the patient’s number.
Appointment audio
Audio is handled more strictly than anything else we touch. During a recorded appointment, audio is streamed for live transcription, and a compressed copy is held only in the clinician’s browser memory — it is never written to disk or to storage. When the clinician ends the appointment, that in-memory copy is sent once for a higher-accuracy re-transcription and note refinement, and it is permanently deleted as soon as that step confirms. That deletion is by design and cannot be reversed. If the refinement step fails, the copy remains only in the browser’s memory so the clinician can retry ending the appointment; it is deleted when a retry succeeds, and it is gone in any case when the page is closed, because it exists nowhere else. What persists from a visit is text — the clinical note and its transcript — never the recording.
Collected automatically
- Usage and analytics events, described in Cookies and analytics below.
- Audit and security logs — every read and write in the platform is logged and attributable.
Diagnostics, recordings, and workflow learning
The Rebrief Bridge — the component that runs inside the practice — keeps three diagnostic and learning channels. All three are on by default, and the practice can turn any of them off at any time in the app’s settings:
- Diagnostics telemetry — operational events and error reports — task outcomes, timings, and error categories — sent to Rebrief so we can monitor and fix the service. These events carry no patient content.
- Diagnostic recordings— when Rebrief’s automation runs or fails, the Bridge keeps an encrypted recording of the automation’s screen interactions, which may show patient information as it was displayed in the practice’s management system. Rebrief staff can retrieve a specific recording to diagnose a problem; every retrieval is access-logged, recordings are encrypted end to end, they delete automatically after a bounded period, and they are hosted with our Canadian processor (Appwrite, in the Toronto region — see the subprocessor table below).
- Workflow demonstration capture— the Bridge observes how staff operate the practice management system — which controls are used and how staff navigate; the content of what staff type is never stored — so it can learn and automate the practice’s workflows. When the screen channel is enabled, screenshots are processed under the same encrypted, access-logged regime as diagnostic recordings. The practice, as the employer and custodian of its systems, consents to this observation on behalf of staff use of clinic systems; we provide notice text practices can share with their staff.
03How we use information
We use the information described above to:
- Provide the service— transcribe appointments, draft and refine clinical documentation, chart, sync with the practice’s management system, answer questions grounded in the practice’s own records, operate the AI receptionist, and send messages a staff member has approved.
- Operate accounts and billing — authentication, role-based access, subscription management, invoices, and receipts.
- Communicate — transactional email such as onboarding and clinic invitations, support replies, and notices about the service.
- Improve and secure the product — product analytics, debugging, and the prevention of abuse and fraud.
- Meet legal obligations — including record-keeping and responses to lawful requests.
AI processing
Rebrief’s core features are performed by AI systems, and we want that to be plain rather than implied. Speech from recorded appointments is transcribed to text; that text is used to produce draft clinical notes, refinements, per-patient summaries, in-app answers, and generated documents; and a practice’s own records can be searched — using a combination of third-party AI providers, which are listed with their purposes in the subprocessor table below. Every AI-drafted note or document is exactly that — a draft: it is presented to the treating clinician, who reviews and approves documentation before it becomes part of the patient record.
Customer data is not used to train models— not ours, and not anyone else’s.
04Protected health information and our role as a business associate
The dental practice — not Rebrief — is the custodian of its patients’ records. Under Canadian privacy law the practice is the organization accountable for patient personal information and, under provincial health-information statutes such as Ontario’s PHIPA, the health information custodian; Rebrief acts as its service provider or agent. For practices subject to HIPAA in the United States, the practice is the covered entity and Rebrief acts as a business associate.
We offer a business associate agreement to every practice; acceptance is recorded and version-tracked at signup. Where a business associate agreement or other data-processing agreement is in place, it governs protected health information and prevails over this policy for that information.
Rebrief writes clinical documentation into the practice’s own management system — the practice’s notes and documents remain in its PMS, where they were written all along. Each practice’s data lives in its own isolation boundary; one clinic’s records never mingle with another’s, and access is always scoped to the authenticated user’s own clinic.
06Data retention
- Appointment audio is never retained. See Information we collect for the full lifecycle.
- Practice and patient data held in Rebrief are retained while the practice’s account is active. If a subscription is cancelled, the practice reverts to the free Starter plan and its account, notes, and patient data stay intact — nothing is deleted on cancellation alone.
- Documentation written to the practice’s management system lives in the PMS under the practice’s own retention rules. Clinical record-retention periods are set by the practice and its regulators, not by Rebrief.
- Practices can permanently delete documents in the app — that deletion cannot be undone — and can request deletion of their data by contacting us. We honor deletion requests unless retention is required by law or a different arrangement is set out in the practice’s agreement with us.
- Consent records — acceptance of these documents — are retained as compliance evidence.
07Security
Our security posture is described in detail on the security page and at the trust center. The standing commitments:
- Encryption everywhere — data is encrypted in transit and at rest. There is no configuration in which it is not.
- Isolation per clinic— each practice’s data lives in its own isolation boundary.
- Access control— single sign-on through the practice’s identity provider, role-based permissions (clinical, front desk, billing), and audit trails: every read and write is logged and attributable.
- On-premise Bridge — the component that operates the practice management system runs inside the practice. PHI never persists in cleartext, and nothing leaves the building that the job did not require.
- No training — customer data is not used to train models.
- Frameworks — we maintain SOC 2-aligned security, availability, and confidentiality controls that are independently examined; HIPAA-aligned safeguards for protected health information, with business associate agreements for every practice; and practices consistent with GDPR and PIPEDA principles.
Breach notification
If we learn of a breach of security safeguards involving personal information, we will notify the affected practices without undue delay, provide the information they need to meet their own obligations to patients and regulators, and keep a record of the incident — consistent with PIPEDA’s breach-of-safeguards requirements and, where a business associate agreement applies, the notification terms of that agreement.
Responsible disclosure
If you believe you have found a security issue in any Rebrief product, write to compliance@rebrief.ai. We respond quickly, keep you informed, and credit researchers who disclose responsibly.
08International data transfers
Rebrief’s primary hosting is in Canada: both the platform and this website run in Appwrite Cloud’s Toronto region. Some of our service providers process information in the United States — including Anthropic, Deepgram, Groq, Voyage AI, Render, Stripe, Mixpanel, Loops, and Vapi — so information, including patient information routed to those providers, leaves Canada in the course of providing the service.
While information is in another jurisdiction, it is subject to the laws of that jurisdiction and may be accessible to its courts and authorities under lawful access regimes. We hold our providers to protection comparable to this policy through contractual and technical safeguards, and we limit what each provider receives to what its purpose requires.
09Your rights and choices
If you are a patient
Your dental practice is the custodian of your records. To access or correct your health information, to ask how it was collected, or to request its deletion, contact your practice directly — we support practices in fulfilling these requests. Rebrief cannot alter or release a patient record except on the practice’s instructions.
If you are a practice user or a site visitor
- You can review and update your account information in the app’s settings.
- You can ask us for access to, correction of, or deletion of the personal information we hold about you at hello@rebrief.ai.
- You can opt out of non-essential email using the unsubscribe link in any such message. Transactional notices about your account continue while the account exists.
Under applicable law
PIPEDA gives individuals the right to access and correct personal information an organization holds about them, to withdraw consent subject to legal and contractual restrictions, and to complain to the Office of the Privacy Commissioner of Canada. Provincial health-information laws — such as Ontario’s PHIPA — give patients corresponding rights against their health information custodian, which is the practice. For information subject to the GDPR, we honor data subject rights, data minimization, and EU processing requirements.
11Children's privacy
This website and Rebrief accounts are for dental professionals and their staff. They are not directed at children, and we do not knowingly collect personal information from children for our own purposes. Patient records processed on behalf of a practice may include information about minors; that information is processed solely on the practice’s instructions, under the consents and authority the practice holds as custodian of the record.
12Changes to this policy
We may update this policy as the product and the law evolve. When we do, we will post the new version here and update the dates above. For material changes that affect practices, we will give notice in the app or by email before the change takes effect. Acceptance of this policy is recorded and version-tracked, so a practice can always tell which version it agreed to.
13Contact
Privacy questions, access requests, and complaints: hello@rebrief.ai — we route privacy matters to the person accountable for them. Security reports: compliance@rebrief.ai. Signed-in users can reach live support directly inside the app. Our security posture is documented at trust.rebrief.ai.
If we cannot resolve a concern, individuals in Canada may contact the Office of the Privacy Commissioner of Canada or their provincial privacy regulator.
Questions about how we handle data? Ask us live.