Privacy policy
Last updated 22 September 2026.
The short version
NoteFix QA reads the visit note being written so it can show what a reviewer would send back. To do that, the wording of that note is sent to our server and checked. The note is not written to our database or our logs. Nothing is sold, and there is no advertising or tracking in the product.
What the extension runs on
The extension is configured to run only on the visit documentation pages of the system it supports. It is not granted access to other sites in the browser. It loads with the note page and does nothing until a check is requested.
What is sent when a check runs
- The contents of the fields on the note being checked, including the narrative text.
- A random identifier for that installation, and the version of the extension. It is not a name and it is not linked to an account.
It travels over an encrypted connection to our server, which runs in our own Amazon Web Services account in a US region. The analysis is performed through Amazon Bedrock, using a Claude model from Anthropic. The findings are returned to the clinician. The note's text is not written to our database and not written to our logs.
Zero data retention is enabled on our Bedrock account. AWS describes that setting as meaning no request or response data is written to durable storage by AWS, or shared with the model provider. Amazon separately states that content sent to Bedrock is not used to train models. We have not turned on Bedrock's optional invocation logging, which is the feature that would write prompts and responses into logs of our own.
What we keep
- A record that a check happened. The identifiers of the rules that fired, how long the check took, the installation identifier and the version. No note content.
- A one-way fingerprint of the note, so that checking the same note three times counts as one note rather than three. The note cannot be reconstructed from it.
- Feedback from approved testers. Feedback and messaging are switched on only for testers who help improve the checks; other users never see them. If a tester tells us a flag was wrong, we keep what they wrote. If they tick the box to attach the field the flag came from, we keep that field's text so the rule can be corrected. The panel says so before it is sent.
Patient names and patient numbers are removed automatically from feedback before it is stored. That is a safeguard against habit rather than a substitute for keeping identifiers out of the box in the first place. Everything we retain expires after six months.
What stays on the clinician's computer
To notice that a visit repeats the previous one, the extension remembers a few values from notes the clinician has opened themselves: distance, assist level, device, strength. Narrative text is kept only as a one-way hash, and the patient is identified only by a salted hash, so nothing readable about a patient is written to disk. It stays in that browser on that computer, is not synced to a Google account, and expires after 60 days.
What we do not collect
- No account, no password, no payment details.
- No advertising identifiers, no analytics, and no tracking across sites.
- No browsing history, and nothing from any page outside the note itself.
Who can see it
Stored feedback is reachable only by the person who operates the service, through a separate credential, and only for the purpose of correcting a check. The clinician using the extension sees their own notes in their own browser. Data collected by NoteFix QA is not sold, rented, or handed to anyone for their own purposes. The third parties involved are the providers that run the service on our behalf: Amazon Web Services, and Resend for the inquiry form.
Protected health information
A visit note can contain protected health information. Before NoteFix QA is used on real patient notes under an agency's name, we would put a business associate agreement in place with that agency and review the data flow described here with whoever owns compliance on their side. We do not claim any certification, audit, or accreditation.
This website
Reading this site sends nothing to anyone else. There are no analytics, no advertising cookies, and no third-party scripts, and the typefaces are served from this site rather than from a font provider.
The inquiry form
If you use the form, what you type in it (your name, email address, and anything you add about your organization, role, interest or situation) is posted to our own endpoint and emailed to us through Resend, an email delivery provider, so that we can reply. Your address is set as the reply-to so that a reply reaches you.
We do not add form submissions to a mailing list and do not send marketing email. The message reaches our inbox and stays there; the contents are deliberately kept out of our application logs. Please do not put patient information in it, and the form says so next to the message box.
Changes and contact
If this policy changes in a way that affects what we collect, the date at the top changes and the change is described here. Questions, or a request to delete feedback that was sent, go to hello@notefixqa.com.