Logo of Express Chart Note

Express Chart Note

Legal

Privacy Policy

We are committed to protecting your privacy and the confidentiality of patient health information. This Policy explains exactly what data we collect and how we use it.

Last updated: Effective:

Summary: Express Chart Note collects account details, clinical documentation you enter, and payment metadata. We use bcrypt password hashing, encrypted tokens, and HTTPS. We never sell your data or use PHI for advertising. If you are a HIPAA Covered Entity, please request a Business Associate Agreement (BAA) before entering patient data.

1. Overview

Express Chart Note ("Service"), operated by Code Frenetics ("Company", "we", "us", or "our"), is committed to protecting the privacy of healthcare professionals and, indirectly, the patients whose data is processed through the Service. This Privacy Policy explains how we collect, use, store, disclose, and protect information when you access or use Express Chart Note.

By using the Service you acknowledge that you have read and understood this Privacy Policy and agree to its terms. If you do not agree, please discontinue use of the Service.

2. Information We Collect

We collect several categories of information depending on how you interact with our Service:

2.1 Account & Registration Data

When you create an account we collect personal details including:

  • First name and last name
  • Email address (used as your unique identifier)
  • Contact number
  • Practice or clinic address
  • Date of birth
  • Account type (administrator or standard user)
  • Profile image (optional, if uploaded)

2.2 Authentication & Security Data

To secure your account we collect and process:

  • Hashed passwords — passwords are never stored in plain text; we use bcrypt hashing.
  • One-time passwords (OTPs) sent to your email for two-factor login verification and password resets.
  • JSON Web Tokens (JWTs) used for session management; tokens are encrypted before storage.
  • Login state and session timestamps.

2.3 Clinical Documentation Data (PHI)

The core function of Express Chart Note is to help healthcare professionals create and organise patient chart notes. Through the Wizard and related modules, you may enter and store:

  • Patient complaints and presenting symptoms
  • System review notes
  • Physical examination findings
  • Assessments / clinical impressions
  • Treatment plans
  • Patient history records
  • Location and clinic identifiers linked to records

This data may constitute Protected Health Information ("PHI") as defined under HIPAA. See Section 5 for details on how we handle PHI.

2.4 Subscription & Payment Data

Payment processing is handled exclusively by Stripe. We do not store raw credit card numbers or full payment card details on our servers. We do collect and retain:

  • Stripe session IDs and payment status
  • Subscription plan name (e.g., Solo Monthly, Group Yearly)
  • Subscription expiry dates
  • Number of permitted users under group plans
  • Phone number provided at checkout
  • Subscription owner flag for group accounts
  • Random invite code for group plan member linking

2.5 Communication Data

When you submit a contact or support request via the in-app "Contact Us" form, we collect the message content, your email address, and any other details you choose to provide.

2.6 Usage & Technical Data

We may automatically collect technical information such as IP addresses, browser type, operating system, and usage timestamps to maintain and improve the Service.

3. How We Use Your Information

We use collected information for the following purposes:

  • Account management — creating and managing your account, authenticating logins, and sending OTP verification emails.
  • Service delivery — enabling you to create, store, retrieve, and print clinical chart notes and associated templates (complaints, examinations, assessments, treatment plans, histories).
  • Subscription management — processing payments through Stripe, activating or deactivating subscription plans, tracking expiry dates, and managing group-plan membership via invite codes.
  • Security & fraud prevention — detecting unauthorised access, enforcing single-session login policies, verifying identities via OTP, and protecting against abuse.
  • Customer support — responding to contact requests, bug reports, and general enquiries.
  • Service improvement — analysing usage patterns (in aggregate and in anonymised form) to improve features and performance.
  • Legal compliance — meeting our obligations under applicable law, including HIPAA, HITECH, and other healthcare privacy regulations.

We do not use your clinical documentation data or PHI for marketing, advertising, or any purpose unrelated to providing the Service.

4. How We Share Your Information

We do not sell your personal information or PHI to any third party. We may share information only in the following limited circumstances:

  • Stripe (Payment Processor) — payment data is transmitted to Stripe to process subscription transactions. Stripe operates under its own privacy policy and PCI-DSS compliance framework.
  • Email service providers — we use a transactional email service to deliver OTP verification emails and password reset links. Only your email address and the OTP content are shared with this service.
  • MongoDB (Database hosting) — your data is stored in MongoDB. Any cloud-hosted MongoDB service we use is bound by appropriate data processing agreements.
  • Legal requirements — we may disclose information if required to do so by law, court order, or government regulation, or if we believe disclosure is necessary to protect our rights or the safety of users.
  • Business transfers — in the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. You will be notified via email and/or a prominent notice on our website.

All third-party processors are required to use your information only as directed by us and in compliance with applicable privacy laws.

5. Protected Health Information & HIPAA

Express Chart Note is designed to assist healthcare professionals who may be subject to the Health Insurance Portability and Accountability Act ("HIPAA") and the Health Information Technology for Economic and Clinical Health Act ("HITECH").

If you are a Covered Entity or Business Associate as defined under HIPAA, you must execute a Business Associate Agreement (BAA) with Code Frenetics before entering any PHI into the Service. Please contact us at legal@expresscharnote.com to request a BAA.

We implement the following safeguards in relation to PHI:

  • Access controls — data is accessible only to authenticated users holding a valid encrypted token. Session management enforces single concurrent login per user by default.
  • Encryption in transit — all data transferred between your browser and our servers is encrypted using HTTPS/TLS.
  • Password hashing — user passwords are hashed with bcrypt and are never stored or transmitted in plain text.
  • Token encryption — authentication tokens are encrypted before storage in the database.
  • No PHI in analytics or advertising — clinical data is never used for advertising, profiling, or shared with analytics platforms.

You, as the healthcare professional, remain responsible for ensuring that the patient data you enter complies with applicable laws and regulations in your jurisdiction.

6. Data Retention

We retain your account information and clinical data for as long as your account is active or as needed to provide the Service. Specifically:

  • Active accounts — all data is retained for the duration of your subscription and any applicable trial period.
  • Expired or cancelled subscriptions — accounts suspended for non-payment for more than 60 days may be terminated and associated data permanently deleted in accordance with our Terms of Service.
  • Deleted accounts — upon account deletion request, we will remove your personal data within a reasonable period, except where retention is required by law.
  • Payment records — Stripe session IDs and transaction metadata are retained as required for financial record keeping and fraud prevention.

You may request deletion of your account and data at any time by contacting us at support@expresscharnote.com.

7. Data Security

We take the security of your information seriously. Our technical and organisational measures include:

  • HTTPS/TLS encryption for all data in transit.
  • bcrypt password hashing — passwords are salted and hashed; we cannot recover your plain-text password.
  • Encrypted JWT tokens stored in the database to prevent session hijacking.
  • OTP-based two-factor authentication (optional or mandatory per administrator configuration).
  • Single-session login enforcement — the system detects if an account is already logged in from another location and prompts accordingly.
  • Server-side authorisation middleware that validates login tokens on every protected API request.
  • Token expiry of 10 days, after which re-authentication is required.

Despite these measures, no method of electronic transmission or storage is 100% secure. We encourage you to use strong, unique passwords and to log out of the Service when using shared devices.

8. Cookies & Local Storage

Express Chart Note uses browser local storage to maintain your authenticated session (storing your encrypted token and minimal user profile data). We do not currently use third-party tracking cookies or advertising pixels.

We may use essential session cookies required for basic website functionality. These cookies do not track you across third-party websites and are deleted when you log out or close your browser.

9. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal information:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — request correction of inaccurate or incomplete data. You can update most profile information directly in the app.
  • Erasure — request deletion of your account and associated data, subject to legal retention obligations.
  • Portability — request an export of your data in a commonly used machine-readable format.
  • Restriction — request that we restrict the processing of your data in certain circumstances.
  • Objection — object to our processing of your data where we rely on legitimate interests as the legal basis.

To exercise any of these rights, please contact us at privacy@expresscharnote.com. We will respond within 30 days.

10. Children's Privacy

The Service is intended solely for use by healthcare professionals who are at least 18 years of age. We do not knowingly collect personal information from individuals under 18. If you believe we have inadvertently collected such information, please contact us immediately and we will take steps to delete it.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by posting the revised Policy on this page and updating the "Last Updated" date below.

Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated Privacy Policy. We encourage you to review this Policy periodically.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please reach out to us:

© 2026 Code Frenetics · Express Chart Note · All rights reserved.