Status: what Gale is today
This policy is in force today. It governs the real information we already hold about real people — the email address you left us, the question you typed into the chat, the phone number you gave us for a scheduling call. That information is not synthetic. It is described below and it is protected by this policy.
It also sets out, in advance, the terms that will govern your medical record once Gale begins serving real patients. That has not happened yet: today the clinical product runs on synthetic demonstration data — invented patients, invented charts, invented claims, no real money. We are publishing the second half of this policy early so that it can be read and challenged before anyone's chart is on the line, rather than after.
One thing follows, and we would rather you hear it from us: some real information about real people is already processed today. If you give us an email address to be told when care opens in your state, if you leave a phone number to ask for a scheduling call, or if you type a question into our chat, that is real information about a real person.
Which parts are in force now. The parts about visitors — the chat, screeners, searches, signups, the reading trail, our logs — are in force now, because we process that information now. The parts about patients — your chart, your notes, your claims — take effect on the day Gale begins serving real patients. Nothing below is aspirational: it is either in force now, or it is marked as taking effect then.
The short version
- We will never sell your information, and we will never use it for advertising or marketing. Ever. That covers de-identified information too. No third-party advertising or analytics tracker runs on any Gale page.
- Two different laws apply, depending on what the information is — not on who you are. HIPAA governs your medical record. Consumer-health-data law governs what you generate by reading, searching, screening, or using the chat. Both can be true of the same person on the same day. A third — California's CMIA — reaches across both.
- What leaves Gale: your chat messages go to Google's Gemini API — with your name, phone, email, address, dates and record numbers stripped out in your browser first, and the health content of your question intact. The same is true of the goal you type if you ask Gale to draft a plan from research papers you chose. Web visit audio goes to Google's Speech-to-Text service — covered by our healthcare agreement with Google — with names still spoken in it. Payments go to Stripe as an amount and a code — never a diagnosis.
- What we have not built yet: a self-service delete button and a data export. Each is named below rather than implied.
- Your visit note is yours to read — with one part still withheld today, which we treat as a defect to fix, not a policy to defend.
Everything below is the long form of these five things.
The two halves of Gale — and the laws that govern them
This is the single most important thing to understand about your information at Gale, and most privacy policies blur it.
Under HIPAA, Gale is software, and Gale does not practice medicine. Licensed clinicians practice medicine, under their own judgment, through their own professional practices. Gale is the practice's administrative-services contractor and, for HIPAA purposes, the practice's business associate. That distinction determines which law protects your information — and, as the next section explains, California draws the line in a different place, and we accept California's line.
Which law applies depends on what the information is, not on who you are. The same person can be a patient of a Gale practice and a reader of our health library. Their chart is protected health information; their chat, their searches and their screeners are consumer health data. Being a patient does not pull your chat inside HIPAA, and reading an article does not push your chart outside it. The Terms of Service and the Consumer Health Data Privacy Policy draw the line the same way.
| Information in your medical record | Information you generate on our public surfaces | |
|---|---|---|
| What it is | A visit, a chart, a note, a prescription, a claim, a bill — anything Gale holds for a clinician's practice | An article you read, a screener you ran, a symptom you searched, a question you typed into our chat — held by Gale for itself, before and outside any practice's record |
| Who holds the record | The clinician's practice — it is the HIPAA Covered Entity | Gale — for itself |
| What Gale is | The practice's Business Associate, under a written Business Associate Agreement. No such agreement is signed today — see the register below | A first party. No practice is involved |
| The law that governs | HIPAA — 45 CFR Parts 160 and 164 | Not HIPAA. State consumer-health-data law (Washington's My Health My Data Act, Nevada SB 370, Connecticut, Maryland, California), and — if Gale is a "vendor of personal health records," a predicate we have not yet established — the FTC Health Breach Notification Rule, 16 CFR Part 318. See "If something goes wrong" |
| A law that governs both | California's Confidentiality of Medical Information Act (CMIA), Cal. Civ. Code § 56 et seq. — which, under § 56.06(b), (d) and (e), deems a business offering an EHR, a mental-health digital service, or a reproductive- or sexual-health digital service a "provider of health care," regardless of HIPAA | ← the same row. The CMIA reaches across both columns |
| Who tells you about a breach | The practice tells you. Gale tells the practice. (45 CFR 164.410) | Gale tells you directly — and your state, and the FTC if that Rule reaches us. See "If something goes wrong" |
The same act can cross the line. A screener result you choose to send to a clinician starts as consumer health data and becomes part of your medical record. We tell you at the moment you cross it.
Being a business associate does not exempt Gale from consumer-health-data law. This is the point companies in our position most often get wrong, so we will name the authority. The FTC's rule does not apply to an entity "to the extent that it engages in activities as a business associate of a HIPAA-covered entity" (16 CFR 318.1(a)). Those words are load-bearing: the exclusion is scoped to the activity, not to the company. Reading an article on Gale is not a business-associate activity. Washington draws the line the same way: RCW 19.373.100 exempts protected health information and information intermingled with it — a data-scoped exemption, not an entity-scoped one.
So: when you read an article about panic attacks, run a GAD-7, and search for a therapist — even if you are already someone's patient — you have generated consumer health data, not PHI. HIPAA does not reach it. This policy does, and so does state law.
Washington's Attorney General takes the position that consumer health data must be described in a standalone policy with its own separate link. The statute itself, RCW 19.373.020(1)(b), requires only that we "prominently publish a link to [our] consumer health data privacy policy on [our] homepage." The words "separate and distinct," and the rule that such a policy may contain nothing beyond what the Act requires, come from the Attorney General's guidance, not from the statute. We follow the guidance, because the Attorney General is also the enforcer. That policy is here: Consumer Health Data Privacy Policy — it is the one that tracks the statute. This policy also describes the same information, in plainer terms, so you can see the whole picture in one place.
California treats us as a provider of health care — and we accept that
Under HIPAA, Gale is a business associate. Under California law, that is not the whole answer, and we are not going to hide behind the federal characterization.
California Civil Code § 56.06 — as amended effective January 1, 2024 — deems certain businesses to be a "provider of health care" subject to the CMIA, whether or not HIPAA applies to them:
- § 56.06(b) — a business offering software or hardware, including a mobile application, designed to maintain medical information. Gale ships an EHR.
- § 56.06(d) — a business offering a mental health digital service to a consumer "for the purpose of allowing the individual to manage the individual's information, or for the diagnosis, treatment, or management of a medical condition." Gale ships PHQ-9, GAD-7, ACEs, PC-PTSD-5 and AUDIT-C screeners, a mental-health article library, and a health chat.
- § 56.06(e) — a business offering a reproductive or sexual health digital service, on the same terms. Gale's article library and chat cover reproductive and sexual health.
We think the honest reading is that California deems Gale a provider of health care for our consumer surfaces, and that on the clinical side Gale is additionally a CMIA "contractor" under Civ. Code § 56.05. So rather than litigate the edges, we have made a decision:
We apply CMIA-grade controls to all consumer health data, in every state. We do not disclose medical information without an authorization that satisfies Civ. Code § 56.10 and § 56.11, and we do not treat the fact that you were "only reading an article" as a reason to protect the data less.
This matters to you, and not only in California: the CMIA carries a private right of action, with nominal damages of $1,000 without any proof of harm (Civ. Code §§ 56.35, 56.36(b)). We would rather build to the strictest standard that plausibly applies than discover later which one did.
Who we are, and what this policy covers
Gale Care Inc., a Delaware corporation. Gale Care Inc., c/o Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, USA.
This policy covers www.gale.care and the Gale applications. It does not replace:
- the Notice of Privacy Practices issued by your clinician's practice, which governs your medical record — Notice of Privacy Practices;
- the standalone Consumer Health Data Privacy Policy;
- the Terms of Service.
What we collect, where it comes from, and where it goes
These tables describe what the system actually does.
Before the tables, one thing you should not have to find in a table: your visit is recorded. When your clinician uses the scribe, the audio of your visit is captured so the note can be drafted — that is the point of it. You will be asked before recording starts, and you can say no; your clinician will type the note instead, and your care is unchanged. On the web, that audio goes to Google's Speech-to-Text service with your name still spoken in it, covered by our healthcare agreement with Google (see "An honest note about the scribe"). On iPhone it never leaves the device. Our software captures no video, ever.
When you are a patient of a practice that uses Gale (HIPAA applies)
| What | Where it comes from | Why | Where it goes | How long we keep it |
|---|---|---|---|---|
| Your record — name, date of birth, medical record number, home state, insurance, copay, care plan | You, at intake; your clinician | Treatment | Gale's database. Readable by your clinician, an administrator at your clinician's practice (not at Gale), and you | For as long as your clinician's state law requires them to keep a medical record — see "How long we keep things" |
| Your chart — conditions, medications, observations (real ICD-10, RxNorm, LOINC codes) | Your clinician | Treatment | Gale's database | Same as above |
| What you told us is wrong — the complaint and goals you type in your own words when you book | You | So your clinician is prepared for your visit | Gale's database, stored word-for-word, and Google's Gemini API, which uses your words to draft the agenda for your visit | Indefinitely today — no schedule is enforced. |
| Visit notes — the SOAP note (the standard visit note: what you said, what your clinician found, what they concluded, and the plan) | The scribe, then your clinician's edit | Treatment | Gale's database. See "Your record is yours" for an honest limit | Same as your record |
| Visit audio — on iPhone | Your clinician's phone microphone | To turn speech into text | Nowhere. It never leaves the phone. Transcription happens on the device | Not kept |
| Visit audio — on the web | Your clinician's browser microphone | To turn speech into text | To Gale's server and on to Google's Speech-to-Text service, with names still spoken in it. See the honest note below | Gale never stores it, and the service is covered by the Google Cloud BAA — Google is not enrolled in Speech-to-Text data logging, so the audio is not kept to improve Google's products |
| The visit transcript | Transcription | To draft the note | Stays in the clinician's browser. Never written to our database | Not kept |
| The de-identified transcript | Our on-device cleansing engine | Sent to the note-drafting model | The model sees placeholders ([NAME_1]), not names | Not kept as such |
| The key that puts the names back | The cleansing engine | So your clinician sees a readable note | Never leaves the browser. Never transmitted to us. | Discarded |
| Claims and bills | Your visit | Payment | Gale's database. Never sent to Stripe | Indefinitely today; no schedule enforced |
| Payments | Your card | Payment | Gale's database + Stripe — amount and an opaque ID only (a random code that means nothing to anyone who does not hold the key) | Indefinitely today; no schedule enforced |
| Appointments | Booking | Treatment, scheduling | Gale's database. No diagnosis, no score, no label | Indefinitely today; no schedule enforced |
| Consents you sign | You | Legal record | Gale's database, with a cryptographic fingerprint of the exact document you saw | Six years (45 CFR 164.530(j)(2)) |
| Documents you upload | You | Your record | De-identified on your device before upload. Then our database, and a summarizing model | Indefinitely today; no schedule enforced |
| Telehealth video | Your camera | The visit | Directly to your clinician, device to device. There is no video vendor. Our software captures no video at all | Never recorded |
| Telehealth audio | Your microphone | The visit, and the scribe | Device to device to your clinician. When your clinician uses the scribe, the audio is recorded in short chunks and sent for transcription — see "Visit audio — on the web" above. You are told first, and you can say no | Not stored by Gale |
| Engine signals | A de-identified write after a visit | To improve the tools clinicians use | Our database. The signal itself carries no name, no patient ID, no visit ID, no date, no free text, and no geography finer than a state — its region is a multi-state Census division and its top age band is "65 and older" | Kept indefinitely |
On "engine signals," and why we say they are one-way. The signal holds nothing that identifies you: a clinical area, a severity band, a class of intervention, a coarse age range, and a multi-state region. Nothing else.
And nothing points back at you. The signal is written and then deliberately orphaned — its identifier is not stored on your visit record, and it is not returned by any part of our software. There is no key, held by us or by anyone, that turns a signal back into a visit.
We rely on the de-identification standard described under "Research," below (45 CFR 164.514(c) permits a re-identification code only where the mechanism is not disclosed — the sounder answer was to have no mechanism at all).
When you are a visitor, not a patient (HIPAA does not apply)
| What | Where it comes from | Why | Where it goes | How long we keep it |
|---|---|---|---|---|
| Chat messages — health questions you type | You, signed in | To answer you | Google's Gemini API, and our database — both of them see the message with your name, phone, email, address, dates and record numbers already stripped out and replaced with placeholders, in your browser, before it is sent. The key that puts your real words back never leaves your device. The health content of the question is not stripped, because removing it would leave nothing to answer. See "The chat," below | 365 days, then a Firestore TTL policy deletes them. You can also delete them yourself, one at a time or all at once, from your profile — you do not have to wait or ask |
| Files you attach to chat | You | Context for the answer | Read into text in your browser and de-identified there; the placeholdered text is read once by Google's model, then discarded. The file itself is not uploaded | Not kept |
| Screener results — PHQ-9, GAD-7, ACEs, PC-PTSD-5, AUDIT-C, including the question about self-harm | You | So you can see your own result, and so the chat can draft talking points from it | Not saved to your account — our database rules block that for real accounts today. But being unsaved is not the same as being unsent: if the chat discusses your result, or you send it to a clinician, your score, your band, the talking points, and whether you endorsed the self-harm item are sent to Google's Gemini API — a general-purpose consumer endpoint we have no Business Associate Agreement with | Not saved, today |
| Symptom and care searches | You | To route you to the right kind of care | Routing runs on a keyword table on our own server — no AI model, and our search index is self-hosted, so there is no search vendor. But your IP address and the page you asked for do appear in our hosting logs — see "Web server logs." And there is a defect you should know about: in the care front door, the words you type about your health problem travel in the web address of the request, which means they land verbatim in our hosts' ordinary request logs. We are moving that text into the body of the request. Until we have, it is there. If you go on to book, the words you typed travel with the booking (see the patient table) | Not stored against your account |
| Care-gap signups — your email, state, care type | You | So we can email you when care opens in your state — because you asked us to | Our database. Nothing is sent today — see below | Indefinitely today — no schedule is enforced. |
| Scheduling requests — your email, phone, state, care type | You | So that a person at a practice can be asked to book you — once we are able to ask them | Our database, and nowhere else. Today the record is written with a structural never-send marker and is transmitted to no one — not to a practice, not to a vendor. No code reads it in order to contact anyone, and contacting a real person sits behind a legal switch that is off. Do not leave a phone number expecting a call back until this policy says otherwise | 180 days: a Firestore TTL policy deletes the record when its expiresAt passes. See "How long we keep things" |
| What you have been reading | Your browser | So your clinician can see the topics you have been reading — but only if you decide to show them | Kept in your browser: a local list of at most 20 topics from the last 90 days. No cookie, no third-party collector. It leaves your browser only if you switch on the reading-trail toggle when you book care. Then the list of topics — not the web addresses — travels to Gale with your booking, appears in your visit brief for the clinician you named, and the topic titles are sent to Google's Gemini API to refine your pre-visit agenda. The switch is off unless you turn it on | 90 days in your browser, or until you clear it. The shared copy lives in your visit brief — indefinitely today; no schedule enforced |
| Product measurements | Your browser | To see where our funnel breaks | Our own server. The server strips every field except a short allow-list. No user ID, no email, no free text | Indefinitely today; no schedule enforced |
| Web server logs | Every request | Running the site | Vercel (web) and Google Cloud Run (API): IP address, browser, and the page you asked for — which can reveal what you were reading | Per our hosts' defaults; no Gale schedule enforced |
If you are a clinician we contacted
We source publicly listed clinician information from NPPES, the federal provider registry, and we build outreach lists using SignalHire and PhantomBuster. Our public provider pages carry only registry facts — name, NPI, specialty, city and state. No license numbers, no street addresses, no scores.
Clinicians have the same rights as everyone else. California's business-to-business carve-out expired on January 1, 2023. Your business contact information is still personal information about a natural person: you may access, correct, and delete the outreach record we hold about you, on the same terms as any other person, using the methods under Contact.
One more thing we keep about you, and you should know it. When Gale places a call to your office on a patient's behalf, we keep an operational record keyed to your NPI — whether the call was answered, whether you are taking new patients, whether the number is dead. It is identified as to you, so we will not pretend it is de-identified data. It is denied to every client in our database rules, it renders on no surface, and we will not publish it: a handful of calls against a registry of self-reported, stale phone numbers is not evidence about your practice. If we ever intend to show it, that will require its own published policy defining thresholds, staleness, and how you dispute it.
Removal. If you want your page removed, write to legal@gale.care. We tombstone the NPI so it is not re-published on a later data refresh. Removal is handled by a person, not a form — there is no self-serve removal button today — and we will confirm when it is done.
If you are a provider who connects an AI assistant to your practice
Gale can connect your practice to an AI assistant you choose — Claude.ai today, ChatGPT as a next step — over a standard protocol (MCP), so you can set up your practice by talking instead of filling out forms. This is optional, off by default, and revocable at any time from Settings → Connected AI.
What that connection can do: read and write your own practice settings — services, rates, hours, payer targets. What it can never do: move money, submit a claim, sign or attest anything, or touch a patient record. Those actions do not exist on this connection — structurally, not merely as policy.
What leaves Gale is structured practice fields only — never patient information, never free text about a person. The tools this connection calls accept typed business values and reject anything else before it is ever stored.
Your AI assistant is outside Gale's walls. The destination for what your practice data becomes once it is in that conversation is your chosen AI vendor — Anthropic (Claude.ai) or, once available, OpenAI (ChatGPT) — not Gale. What you type into it, and how that vendor stores, trains on, or retains it, is governed by that vendor's own terms, not ours. Read them before you connect.
This is your own business-configuration data — services, prices, hours — not a patient record, so it carries no PHI to begin with. That is also why no Business Associate Agreement covers this connection: there is nothing on it that HIPAA reaches. It is not a Gale subprocessor in the sense the register below uses the word — it is a tool of your choosing, sitting outside Gale, that you point at your own account.
If you connect your own AI to your Gale record
You can connect the AI you already use — Claude.ai today, ChatGPT over the same connection — to your own Gale record, at mcp.gale.care. This is optional, off by default, consented one permission at a time, and revocable in one tap from your settings. Nothing about your care changes if you never touch it.
What crosses is minimized and pseudonymized before it leaves Gale. Your AI can read your visit letters, the measures you entered, your upcoming appointments — with your name, contact details, and record numbers replaced by placeholders we cannot reverse, because we discard the key; dates coarsened to "this week" or a year; no clinician names; and nothing risk-shaped, which our software refuses structurally rather than remembers to omit. If you allow the further permissions: it can read our public health articles and the titles of what you saved; it can read short, mechanical summaries of your Gale chats — never the full text of them; and it can save notes back into your own library shelf — never into your medical record, and never to your clinician unless you separately and explicitly share the note inside Gale yourself.
Your AI is outside Gale's walls, and we will not pretend otherwise. Sending your own record to your own AI is your right — the law calls it a patient-directed disclosure, and once you exercise it, our healthcare agreements do not follow the copy. The AI you connect is not a Gale subprocessor and is under no Business Associate Agreement with us: what it retains, what it trains on, and how long it keeps what it saw are governed by that vendor's terms, not ours. Gale cannot control any of that — and Gale cannot even see which kind of chat you are in (an incognito chat or a regular one), so the product tells you this in a standing notice instead of implying a control we do not have.
Revoking the connection stops all future access the moment you do it — every live connection dies in the same tap. It cannot recall what an AI already saw. And one more honest limit: the scrubbing is measured, not perfect — free text can describe you in ways no engine catches — so we say "minimized and pseudonymized," and we will not tell you the connection is anonymous.
Your complete record stays yours without any third party. The full-fidelity copy — nothing minimized, nothing replaced — is downloadable in-app, to you alone. It is never served over the AI connection.
If you build a plan from research papers
In the Gale app you can say what you are trying to do in your own words, look through research papers about it, tick the ones you want, and ask Gale to draft a plan from those papers. Here is where the words go, because that is the part a privacy policy owes you.
What leaves your device: your goal, and your later messages in that conversation — with your name, contact details, dates and record numbers replaced by placeholders on your own device first. The scrubbed text goes to Gale's own research index (below). Then that text, together with the abstracts of the papers you ticked, goes to Google's Gemini model on Vertex AI — the same model and the same healthcare agreement of 13 July 2026 that covers the chat. The health content of what you typed is not stripped, for the same reason it is not stripped in the chat: there would be nothing to work from.
The research index is ours, not a vendor's. The shelf of papers runs on Gale's own server, inside Gale's own Google Cloud project. No search company receives your query, because there is no search company — the only outside party involved is Google, hosting our servers, under the same healthcare agreement that covers the rest of our database. That server sees the scrubbed query text and nothing else — no name, no account, no record number — it is sent from our own backend rather than from your device, and it keeps no log of what was searched.
And the people whose research this is never learn anything about you. The shelf was assembled ahead of time, in bulk, from public research sources — the National Library of Medicine's PubMed and PMC Open Access collections, and the medRxiv preprint server. Gale does not call those services when you search. They receive nothing about you, ever — not your query, not the fact that you searched. Where those papers come from, and the licences they carry, is in Terms of Service Section 13.5.
What is kept, and what is not. Until you press Create, the draft exists only on your device — no plan, no step and no reminder is written to our servers, and you can delete it in one tap. If you do create the plan, we keep a provenance record with it: which papers it was drawn from, when, and by which model. The conversation is kept like any other conversation in the app, you are told so on the screen, and you can delete it there.
If your AI-data switch is off, this feature does not run at all. It says so plainly and offers to build the plan by hand instead. It does not quietly proceed without the switch.
It is not medical advice, and the app says so on the draft itself. Terms of Service Section 4.3 is the full statement.
The subprocessor register
Every vendor, what reaches it, and whether the agreement that would let real patient information flow to it has been signed. One has been: the Google Cloud HIPAA agreement of 13 July 2026, which covers the database, the model on Vertex AI, and transcription — the three that see the most. The other rows say No, and they do not all mean the same thing by it: some vendors are not switched on, one can never be under contract, one sits outside HIPAA entirely, and some are live in production without one. There is no blanket answer, so the table gives you one per vendor.
| Vendor | What reaches it | BAA signed? | Live today? |
|---|---|---|---|
| Google Cloud / Firebase | The database itself — accounts, records, files. Everything | ✅ Yes — signed 13 July 2026 (the Google Cloud HIPAA Business Associate Addendum). It covers the services on Google's HIPAA-eligible list, which is what our database, sign-in, file storage and servers run on | Yes — production |
| Google Gemini (on Vertex AI) | Chat text; the complaint and goals you type in your own words when you book; the topic titles from your reading trail, if you shared it; chart context for clinician tools; insurance-card images; document text; your screener score, its band, the talking points drafted from it, and whether you endorsed the PHQ-9 self-harm item; visit summaries; and, if you build a plan from research: the goal you typed, your later messages in that conversation, and the abstracts of the papers you chose — all scrubbed of your identifiers on your own device first | ✅ Yes — covered by the agreement signed 13 July 2026. Until that day we sent this text to Google's consumer AI endpoint, which the healthcare agreement does not cover. We moved it the same day to Vertex AI, the version of the same model that is covered. We are telling you it used to be otherwise rather than presenting the fix as though it had always been true | Yes |
| Google Cloud Speech-to-Text (transcription) | Raw visit audio from the web scribe, with names still spoken in it | ✅ Yes — covered by the Google Cloud HIPAA BAA signed 13 July 2026 (it replaced Modal, which had none) | Yes — production |
Google public STUN (stun.l.google.com) | Your IP address, at the start of a telehealth visit — used to find a direct path to your clinician. No audio or video passes through it | No — and none is possible. It is a free public endpoint with no contract of any kind | Yes — production |
| Stripe | Amount in cents, currency, and opaque IDs. Clinical detail structurally cannot enter | Not required — a payment processor is outside HIPAA under the payment-processing exemption (42 U.S.C. § 1320d-8). Confirmed with counsel. This holds only because we send Stripe nothing but payment data — see below | Test mode only. No live money |
| Twilio (voice, SMS) | Phone numbers; live call audio; message bodies carrying logistics only — a name and a link. Never a diagnosis, score, or band | No | Not in use. Built so that if it is not switched on, nothing is sent |
| OpenAI (Realtime, voice calls only) | Live call audio and the scope you consented to — name, date of birth, callback number, insurance, care type, times. No chart, no history | No | Not in use — same fail-closed design |
| Mailgun (email) | Email address + a logistics body | No | Not in use — same fail-closed design |
| Vercel (web hosting) | Every web request: IP, browser, and the URL you asked for | No | Yes — production |
| Google Cloud Run (API hosting) | Every API request | ✅ Yes — covered by the Google Cloud HIPAA BAA signed 13 July 2026. Cloud Run is on Google's HIPAA-eligible Covered Products list, the same agreement that covers the database | Yes — production |
| SignalHire, PhantomBuster | Clinician business contact data. Never patient data | No | Credential-gated |
| Serper.dev (search-results observation, added 20 July 2026) | Generic public-search queries — "therapist in Oakland" — and the city being searched, used to observe where clinician profiles rank. Never your data: no patient, consumer, or account information — and not even the clinician's name. Matching results to clinicians happens on our own servers, after the answer comes back | Not required — nothing that reaches it is health information or personal information. That is engineered, not promised: the probe builder can only compose queries from templates and city strings | Key provisioned; first observation run pending |
| Clearinghouse / EDI (insurance-claim transmission) | Insurance claims | No | Not connected. Sandbox only |
| School-claims clearinghouse, Carelon Behavioral Health | School-linked referral and claim data | No — and no LEA Data Use Agreement is signed | Not connected |
| Video vendor | — | — | There isn't one. Telehealth video is device-to-device between you and your clinician |
| Search / embeddings vendor | — | — | There isn't one. Our health search and the research-paper shelf behind plans both run on our own servers, in our own Google Cloud project (the Google Cloud Run row above). Your search text reaches no search vendor, that service keeps no log of what was searched, and the public research sources the shelf was built from receive nothing about you |
Four flows deserve to be called out rather than buried in a row.
What Stripe can and cannot see
Stripe is the only vendor above that does not need a Business Associate Agreement, and we want to be exact about why, because "our payment company says it doesn't need one" is not on its own a reason to trust anybody.
The law. A company that only processes payments — authorizing a card, clearing it, settling it, moving the money — is outside HIPAA's reach for that activity (42 U.S.C. § 1320d-8). It is not a business associate, and Stripe does not sign these agreements. Our counsel confirmed this reading.
The catch, which is the part that matters. That exemption protects payment data. It does not protect a payment company that gets sent something else. If we put your diagnosis, your procedure code, or the reason for your visit into a field on a payment — a description line, a receipt, a label — that information would be health information sitting at a company with no agreement covering it. The exemption would be ours to lose, not Stripe's, because we would be the ones who sent it.
So we made it impossible rather than promising not to. Every payment leaving Gale passes through a single gate. The gate accepts an amount, a currency, and a meaningless identifier — a random code. It rejects any field that is not on a short permitted list, so a "description" cannot even be attached. It rejects any value containing a space, an @, or a slash — which is what a name, an email address, a date, and a phone number look like. And it scans what is left for the shape of a date of birth, a Social Security number, a diagnosis code, and a procedure code, and refuses those too. A separate automated check reads our own source code and proves no payment can go around the gate.
What Stripe therefore holds: an amount, a currency, a random code, and your card details, which they need in order to be a payment company. What Stripe never holds: why you came.
Your invoice — the document that says what the visit was — stays with us. It is never sent to Stripe.
Telehealth is device-to-device, and that cuts both ways. Your video and audio go straight to your clinician — no vendor holds your visit. But to find that direct path, your device and your clinician's device each contact Google's public STUN service, which sees your IP address and never sees your call. Our own servers carry only the connection-setup messages, not that contact. A direct connection also means your device and your clinician's device exchange IP addresses. That is how a direct connection works, and we would rather tell you than let you discover it.
Our hosts see the path of every page you request. A URL like /conditions/generalized-anxiety-disorder is, read plainly, health information about the person who asked for it, and it sits in a hosting log at Vercel and Google Cloud Run. We have not solved this, and we are not going to describe it as solved.
The AI model now runs under the healthcare agreement. Until 13 July 2026 we sent this text to Google's consumer AI endpoint, which our agreement with Google does not cover. On the day we signed that agreement we moved to Vertex AI — the same model, on the version Google's healthcare agreement does cover — because signing an agreement that does not reach the endpoint you are actually using protects nobody. What is sent is unchanged; who is bound by it is not.
Advertising, marketing, and sale — what we will never do
Read this as a covenant, not a description of current practice.
Gale will never sell your information. Gale will never use it for advertising or marketing. Gale will never share it for cross-context behavioral advertising. Not now, and not under any future version of this policy.
Those three sentences are the point of this section. The rest is how we hold ourselves to them.
And they cover de-identified information too. Once information is de-identified, the law stops protecting it and we could lawfully sell it. We will not. We do not sell, license, or trade the de-identified signals our engine retains — not to a drug company, not to an insurer, not to a data broker, not to anyone. That is the loophole a promise like this usually leaves open, and we are closing it on purpose. The Terms of Service and the practice's Notice of Privacy Practices close it in the same words.
Sale. Federal law defines "sale" of health information broadly — any disclosure where we receive payment, direct or indirect, in exchange for it (45 CFR 164.502(a)(5)(ii)). That prohibition binds business associates directly, not merely through our contract with the practice. Under Washington law, "sell" is broader still: an exchange of consumer health data for "monetary or other valuable consideration" (RCW 19.373.010). We do not do either, and we never seek the authorization that RCW 19.373.070 would require.
Advertising and marketing. We take no payment from any third party to communicate with you, and we build no advertising profiles.
One thing that is not marketing, and we would rather name it than have you find it. If you sign up to be told when care opens in your state, we will email you — because that is the thing you asked us for. We would send it only to people who asked, we would send nothing else, and you could stop it in one click. We take no payment from anyone to send it, and we will not use your care type to sell you anything else. Today we send nothing at all — no message of any kind reaches a real person, and the register below says so.
We are not neutral, and you should know how we earn. Gale is paid by the clinician's practice, not by you. We are going to state the fee exactly, because a friendlier description of it would be false: on a self-pay visit Gale charges the practice 8% of the transaction, all-in (card processing included) — or 3.5% when your clinician brought you to Gale as their own patient; on an insurance claim, the fee is a fixed billing cost of $2.50 plus 15% of the amount the claim pays. Each of these scales with the size of the transaction — a larger professional fee pays Gale a larger platform fee. It is never charged to you. So we have an interest in your finding care, and an interest in the care you find being billed.
Here is the line we hold anyway: no clinician can pay for placement, ranking, or a recommendation. There is no sponsored slot on Gale and there never will be. That is why we think a suggestion of a clinician falls within the exception at 45 CFR 164.501 for a communication that "direct[s] or recommend[s] alternative treatments, therapies, health care providers, or settings of care to the individual" — an exception available only where no one has paid us to make it. Read the counsel note below before you rely on that characterization: our fee is paid by the very practices a suggestion may describe, and whether that is "financial remuneration" is genuinely contestable.
We place no third-party advertising or analytics trackers on any page. No Google Analytics. No Meta pixel. No Segment, PostHog, Amplitude, Hotjar, or Mixpanel. Our web application ships five runtime dependencies — Firebase, Next.js, React, React DOM, and a PDF reader — and not one of them is an analytics package. We run an automated tracker scan (evals/pixel_gate.py) over every compiled file in a production build, against a deny-list of tracker hosts, and we run it against every release.
Our own measurement is first-party and server-side. The only place our web application sends a measurement is our own server, and that server strips every field that is not on a short allow-list before writing it. There is no user ID, no email address, no free text, and no durable device identifier in it. The per-tab session key is a random value held in your browser tab and discarded when you close it — it is never linked to your account.
We set no tracking cookies. The complete list of what we store in your browser: your sign-in session (held by Firebase, not in a Gale cookie); your font-size and text-highlight preferences; the local list of topics you have read; some sidebar and tutorial state; a draft of your care search; and, if you arrived from a clinician-referral link, a single first-party token that is deleted the moment you sign up — and expires on its own after 90 days if you never do. That token appears only on the pages where clinicians apply to join; on the pages where you seek care, Gale sets no cookie at all. None of it is a third-party cookie. None of it is an advertising identifier.
We could ask you to authorize marketing. We could ask you to authorize a sale. Federal law provides a form for each — 45 CFR 164.508(a)(3) and 45 CFR 164.508(a)(4) — and Washington provides a third, at RCW 19.373.070. We never will. You will not find those forms on Gale, because they do not exist here.
If Gale is acquired, or fails
A promise that dies with the company is not a promise.
If Gale is acquired, merges, or its assets are sold — including in a bankruptcy — your information transfers only to a successor that assumes this policy in full, including the three commitments above. We will not permit your information to be sold as an asset to a buyer who has not accepted them. We will tell you before any transfer happens.
Two limits on that promise, because a promise with a hidden edge is worse than none:
- It runs to the information Gale holds for itself — your chat, your searches, your screeners, your signups. If no successor accepts the commitments, that information is destroyed rather than transferred, and you may delete it first.
- It does not, and cannot, mean your medical record is destroyed. That record belongs to your clinician's practice, not to Gale, and state law requires the practice to keep it for years. If the practice is acquired, the record generally transfers to the new owner; federal law treats that as a health care operation and does not call it a sale (45 CFR 164.501, "Health care operations," ¶(6)(iv)). The practice's Notice of Privacy Practices says the same thing, in the same words, and commits the practice to telling you first.
Research and model training — we do neither, and here is the commitment
Gale does not conduct research on your health information, and does not use it to train any model. Not identifiable information, not your notes, not your chat, not your screener answers. This is a present-tense statement of fact, not an aspiration.
We had drafted an authorization to permit research, and we withdrew it. An earlier version of these documents published a signed, revocable permission that would have allowed a practice to disclose identifiable records to Gale for research aimed at improving care. It is withdrawn. Nobody was ever asked to sign it and nobody signed it. It is not in use, it is not published, and there is no form anywhere in this product that would let you consent to research even if you wanted to.
Why we withdrew it rather than kept it in reserve. The contract that governs how Gale handles a practice's patient information — the Business Associate Agreement — does not currently permit Gale to use that information for research, and until 23 July 2026 it did not permit de-identification at all. One narrow permission now exists and it is not research: de-identified, aggregated benchmarks with structural floors (no identity, no cell under 25 practices, never for training, never for advertising) — Terms of Service Section 11.5 describes it in full. We could have papered over that with a patient-facing consent form. We would rather fix the contract first and ask you second. Until the agreement is amended, research is not something we are entitled to do, so we are not going to describe it as something we might.
What this means in practice, stated as a bright line:
- No model is trained on your information. Not the scribe, not the chat, not the tools your clinician uses.
- Your clinician's corrections are not a training label. The system learns nothing from them today.
- No de-identified extract of your record is studied, analysed, or used to improve a model.
- Nothing is sent to any vendor for the purpose of improving that vendor's models.
If this ever changes, you will not find out by reading a quietly-updated policy. It would require: the Business Associate Agreement amended to permit it; a separate, specific, revocable authorization that you sign; and a rewrite of this section. Refusing would never affect your care — that is a promise we keep whether or not there is anything to refuse.
One honest note about how the software works. Operating the care loop still produces internal, de-identified records — a clinical area, a severity band, a coarse age range, a multi-state region, with no name and nothing that points back to you. They exist because the software runs on them. They are not used to train anything and they are not studied. We are telling you they exist rather than letting you discover them.
Substance-use records are protected more strictly
If your care includes substance-use treatment from a practice that is a federally assisted Part 2 program, a stricter federal rule applies to those records: 42 CFR Part 2. Under it, your records generally cannot be disclosed without your written consent — including to a parent — and they cannot be used against you in a court, administrative, or legislative proceeding without your consent or a court order issued after notice and an opportunity to be heard. Where Part 2 and HIPAA disagree, Part 2 wins.
Your record is yours
You can read your chart — your problems, your medications, your labs, your visit notes.
One part is not yet shown to you: your clinician's Assessment, the "A" of the SOAP note. We are treating that as a defect to fix, not a policy to defend — see the note below. Today, a patient's chart read tells you that an assessment exists and invites you to review it with your clinician; it does not hand you the text.
Beyond that, two deliberate exceptions, which we name rather than hide.
First exception — the risk model. Our engine produces internal risk output. Our database rules structurally prevent a patient or family member from reading a risk label or score. This is deliberate: a risk tier is a modeling artifact, not a clinical finding, and a family should not meet it in a portal without a clinician in the room.
Second exception — the adolescent confidentiality firewall. See the next section.
Children, teens, and guardian access
Gale serves families. That creates a problem we take seriously and have not finished solving.
In nearly every state, a minor may consent alone — without a parent — to certain categories of care: outpatient mental health, reproductive and sexual health, testing and treatment for sexually transmitted infections, and substance-use treatment. Where a minor consents alone, the minor controls that part of the record — not the parent. In California, Health & Safety Code § 123115 goes further: a parent is not entitled to those records, and a clinician may separately withhold records where access would harm the minor's safety, well-being, or the clinical relationship.
Our commitment: a guardian's access to an adolescent's record is not automatic, and will be restricted for the categories a minor may consent to alone under the law of their state.
Two things follow, and both are commitments:
- The minor keeps full access to their own record. The firewall restricts a guardian's proxy view — never the patient's own view of their own chart.
- The guardian keeps access to everything that is not a protected category. Over-blocking a parent is as much a failure as under-blocking one, and we will not use confidentiality as an excuse to give a family less of their record than they are owed.
COPPA. The Children's Online Privacy Protection Rule, 16 CFR Part 312, requires verifiable parental consent before we knowingly collect personal information online from a child under 13.
When care reaches you through your school
Some care reaches a family through a school referral. That channel has its own posture, and it is not the same as either half above.
- A school never reads the treatment chart, and a clinical encounter never writes a school education record. The boundary between FERPA and HIPAA is kept structural, not remembered.
- School referral data is governed by the school district's Data Use Agreement, not by this policy alone, and it is never silently merged into your medical chart.
- A school-linked encounter de-identifies into engine signals exactly as any other does: no student ID, no district ID.
None of this is live for any real student today. No LEA Data Use Agreement is signed, and neither the school-claims clearinghouse nor Carelon Behavioral Health is connected. They are named in the register above so that their absence is visible.
The chat, and a flow you should know about
Our consumer chat answers health questions. You should know five things about it:
- Your identifiers are stripped out before the message leaves your browser — the health content is not. Your name, phone number, email address, street address, dates and record numbers are replaced with placeholders like
[NAME_1]on your own device, and Google — and our own database — see only the placeholdered text. The key that turns the placeholders back into your real words never leaves your device and is never sent to us; it is why the conversation reads back to you normally. Two consequences you are entitled to weigh: open the same chat on another device and you will see the placeholders, and anyone using your browser can read your chat in plain form. Clear your browser's site data to destroy the key. The engine is measured, not perfect — see "An honest note about the scribe" for the numbers it is held to — and free text can still describe you in ways no engine catches ("my son's school"). Do not treat the chat as anonymous.
- The health content of what you type is sent to Google. Specifically, to Google's Gemini model on Vertex AI, which is covered by the healthcare agreement we signed with Google on 13 July 2026. (Before that date it went to Google's consumer AI endpoint, which that agreement does not cover. We moved it.) Stripping identifiers is not stripping content: if you ask the chat about a symptom, the symptom goes to Google. It has to, or there is nothing to answer. The agreement governs what Google may do with it; it does not stop it being sent.
- If you run a screener and then ask us about it, your result goes to Google too — your score, your band, the talking points, and whether you endorsed the PHQ-9 self-harm item. We would rather say that than let "we don't save it" do the work of "we don't send it." Today that path is open only to demonstration accounts. Before it opens to a real person, that endpoint must move to a HIPAA-eligible one.
- If you ask us to search the web for an answer, your query goes to Google Search.
- Your chat messages are kept for 365 days, then deleted automatically by a Firestore TTL policy. You can also delete them yourself, one at a time or all at once, from your profile — you do not have to wait or ask.
If you tell the chat you are in danger. The chat will show you the 988 Suicide & Crisis Lifeline. No one at Gale is alerted, and no one calls anyone — the chat is not a monitored crisis service and you should not rely on it as one. If you are in immediate danger, call 988 or 911. What you typed is stored, and goes to Google with the rest of the conversation, exactly as described above.
The chat is not a doctor, it is not your medical record, and no covered entity is involved in it. It is exactly the kind of consumer health data that Washington's Act was written about.
Our lawful basis for sending it. Washington's Act permits us to share consumer health data "to the extent necessary to provide a product or service that the consumer has requested" (RCW 19.373.030(1)(b)(ii)). Answering the question you typed is the service you requested, and that is the basis we rely on. It is a narrow lane, and we will not stretch it: it does not cover analytics, product improvement, model training, or research.
An honest note about the scribe
Our scribe removes identifying details from the visit transcript on the clinician's own device, before the note-drafting model ever sees it. It is measured against a benchmark, and we will give you the numbers rather than an adjective:
- Direct identifiers — your name, Social Security number, medical record number, phone, email, address, full dates, account and plan numbers — are removed with 100% recall on our benchmark. That is a must-never-leak gate: a single miss fails the build.
- Across all eighteen categories of identifying detail, our benchmark requires at least 95% recall. That means a small fraction of indirect identifying detail can survive into the text the drafting model sees. We measure it, we publish the gate, and we do not claim it is perfect.
- The benchmark runs on synthetic transcripts. Real-world recall on live clinical speech is not yet measured.
And it does not work the same way on every device:
- On iPhone, transcription happens entirely on the device. The audio never leaves the phone. This is the version of the promise that is fully true.
- On the web, the audio goes to Google's Speech-to-Text service to be turned into text — and the names are still in the audio when it goes. De-identification happens after the text comes back, before the note-drafting model sees it. That service is covered by the Google Cloud HIPAA BAA we signed on 13 July 2026, and Gale is not enrolled in Google's Speech-to-Text data-logging program, so the audio is not kept to improve Google's products. (Until that day this path used Modal, which had no agreement with us; Modal is retired.)
We do not store visit audio. We are not going to tell you it is "deleted after transcription," because there is no deletion step to point at — it is never written to our storage in the first place.
Your rights
We grant every right below to every user, regardless of where you live. Building a matrix of which right you get in which state reads like a company looking for the floor.
⚠️ Read this before the table. We cannot yet receive a rights request. There is no privacy inbox and no named privacy contact anywhere in Gale's product or code today, and there is no deletion endpoint, no export endpoint, and no appeal intake. Until those exist, this section describes what you will be able to do, not what you can do now. We would rather say that than point you at a button that does not exist. See the blocking note below.
| Right | What it means | Who it runs against |
|---|---|---|
| Know and access | Confirm what we hold about you, and get a copy — including a list of every third party and affiliate we shared your consumer health data with, and a way to contact each of them. Washington law requires that list; we give it to everyone | Gale (consumer data); your clinician's practice (your medical record) |
| Correct | Fix what is wrong. On the clinical side this is HIPAA's right to amend (45 CFR 164.526) | Gale (consumer data); the practice (your medical record) |
| Delete | Have it deleted. Your chat messages you can delete yourself, from your profile. Everything else we would still do by hand, and we cannot yet promise deletion from backups. Your medical record is a separate matter: your clinician is legally required to keep it | Gale |
| Portability | Get your information in a usable, portable form. Not built. There is no patient or consumer export today | Gale |
| Withdraw consent | As easily as you gave it | Gale |
| Opt out of sale, sharing, and targeted advertising | We do none of these, so there is nothing to opt out of. We say so plainly rather than offering you a switch that controls nothing | Gale |
| Limit the use of sensitive information | Granted — though it changes little in practice, because we already use sensitive information only to give you the service you asked for | Gale |
| Appeal | If we refuse a request, you may appeal — and if we deny the appeal, we will give you a way to complain about us to your state Attorney General. No appeal intake exists yet | Gale |
| No retaliation | Exercising any of these rights costs you nothing | Gale |
| Global Privacy Control | There is nothing for a GPC signal to turn off. GPC exists to switch off sale, sharing, and targeted advertising. Gale does none of these, for anyone — so a GPC signal changes nothing about how we treat you, with or without the signal. If we ever introduce a use that GPC could switch off, we will honor it, and we will say so here first | Gale |
Authorized agents. You may authorize someone else — an agent, a lawyer, a family member — to make a request on your behalf. We will ask for proof that you authorized them, and we may ask you to confirm it directly.
Timing — consumer requests. We respond within 45 days, extendable once by another 45 days if we tell you why within the first 45. Verifying who you are does not stop that clock.
Timing — your medical record. Different and faster deadlines apply, and they run against your clinician's practice, not against Gale:
- 30 days to give you a copy of your record (45 CFR 164.524(b)(2)), extendable once by 30.
- 60 days to act on a request to amend it (45 CFR 164.526(b)(2)), extendable once by 30.
- In Texas, an electronic copy of an electronic health record is due within 15 business days (Tex. Health & Safety Code § 181.102).
We build to the shortest applicable deadline.
The honest limits on deletion — read this part.
- Your medical record generally cannot be deleted on request. HIPAA contains no deletion right, and state law requires clinicians to retain medical records for years. The right to delete attaches to your consumer data — your chat transcripts, your care-gap signup, your scheduling request — not to a treatment record your clinician is legally obliged to keep.
- One deletion control does exist, and it is real. A saved screener result can be deleted by the person who saved it — our database rules permit the owner, and only the owner, to delete it. (Today, saving a screener is limited to demonstration accounts, so this control is waiting for the surface it protects.) This is the pattern we intend to generalize to chat, which needs it most.
- Screeners and searches are not retained at all today — so there is very little to delete, and the exposure is correspondingly small. That is not luck; it is the architectural answer, and we are most of the way to it.
Automated tools, and the risk model
Gale's engine produces risk output that helps clinicians triage. Three things about it:
- You cannot see it, and neither can your family — see "Your record is yours."
- Does it affect your care? No — all clinical decisions belong to the provider. The engine's output is advisory to a clinician and gates no care decision.
- You may opt out. Under every state comprehensive privacy law, you may opt out of profiling that produces legal or similarly significant effects — and "similarly significant effects" is commonly read to include the provision or denial of health care. You can opt out of the risk model from your Profile — the switch is yours to set, we honor it, and your care will not change because you set it.
Security
Your information is encrypted in transit and at rest.
Beyond that, some of what protects your information is not a policy but a property of how the system is built:
- You cannot be given a role you should not have. Roles are assigned by our server after verifying your identity token. A client cannot assign itself one.
- No client can write to a money record. Claims, invoices, payouts, superbills, and consent signatures are all write-denied to every client. Only our server can write them.
- Clinical detail structurally cannot enter Stripe. Every payment payload passes a single narrow gate that permits an allow-list of fields, rejects any value containing a space, an
@, or a slash, and scans for the shape of a date, a Social Security number, a diagnosis code, or a procedure code. A separate automated check proves the gate cannot be bypassed. - Nothing in our file storage is public. The default rule is deny.
- We cannot accidentally contact you. Every outbound message passes one gate that fails closed on three separate conditions, and message bodies carry logistics only — a name and a link. Never a diagnosis, a score, or a band.
- Access to a shared visit summary is audited in an append-only log, and a shared link locks after three failed attempts.
Who at Gale can see your record
Only our support team — and automated support systems acting under their direction — can read patient records in production, and only the minimum necessary to operate the service and answer your requests. Engineers do not read production patient data in the ordinary course.
We are not dressing this up: a small number of Gale support staff can read records in order to operate the system — no more than necessary, and never for any purpose but running the service and helping you.
Speech, and the limits we put on it
Two parts of Gale turn speech into text: the scribe, which drafts a clinician's note during a visit, and the voice search on our public site, which lets a visitor say what is going on instead of typing it.
The scribe requires a signed-in clinician. Drafting a clinical note is an act a named, licensed provider owns (see "Gale does not practice medicine"), and our software will not do it for an anonymous request. Until 13 July 2026 it would have: the two parts of our software that transcribe audio and draft the note accepted requests from anyone, without checking who was asking. That is fixed — the note-drafting step now refuses any request that does not carry a valid clinician's credential, and the transcription step requires one whenever it is used for care.
The public voice search stays open, on purpose, and is capped. A visitor who has not signed in can still speak a symptom into the search box, because requiring an account to find care would exclude exactly the people least able to type one. That path carries a search query, not a medical record. We cap how much audio any single request may send.
What you should take from this: audio is relayed to Google's Speech-to-Text service, which transcribes it and is covered by the Google Cloud HIPAA Business Associate Agreement we signed on 13 July 2026. On iPhone the transcription happens entirely on your own device and reaches no vendor at all.
Every member of our workforce who can reach patient information is trained on state and federal PHI law before they begin, tailored to their role — see the Texas standard below, which we apply everywhere.
Texas imposes a direct obligation, and we meet it. Texas Health & Safety Code § 181.101 makes Gale itself a Texas "covered entity" (Texas defines that term far more broadly than HIPAA, and it reaches Gale directly, not merely through a BAA): training on state and federal PHI law, tailored to the employee's scope of employment, completed not later than the 90th day after the employee is hired (§ 181.101(b)); retraining within one year of any material change in the law (§ 181.101(c)); and a signed employee attestation retained until the sixth anniversary of the date it is signed (§ 181.101(d)). Every employee associated with a patient in Texas has completed this training. (There is no biennial refresh requirement in the current statute.)
How long we keep things
We are going to be direct about how long we keep things.
We enforce automatic deletion for the consumer information you generate here. A Firestore time-to-live policy — a rule the database runs, not a script we might forget — deletes chat transcripts after 365 days, and care-gap signups and scheduling requests after 180 days, acting on an expiresAt timestamp on each record. Categories not covered by that policy follow the criteria in the table below; your clinical record follows the separate, law-mandated schedule, and de-identified engine signals are kept indefinitely because they are no longer your information.
This is what Cal. Civ. Code § 1798.100(a)(3) requires: we both disclose the retention period and do not keep personal information "for longer than is reasonably necessary" for the disclosed purpose.
The full schedule, and the criteria behind the categories that do not carry a fixed number:
| Category | The criterion |
|---|---|
| Clinical records (chart, notes, claims) | Retained for the period your clinician's state law requires — commonly 6–10 years for adults; for minors, generally to the age of majority plus a term of years |
| Consents and authorizations | Six years (45 CFR 164.530(j)(2), to which 45 CFR 164.508(b)(6) refers) |
| Security documentation and audit records | Six years (45 CFR 164.316(b)(2)) |
| Chat transcripts, screeners, searches, care-gap signups, scheduling requests | Chat transcripts: 365 days. Care-gap signups and scheduling requests: 180 days. Both enforced by a Firestore TTL policy, deletable sooner on request. Screeners and searches are not retained at all. |
| Engine signals (de-identified) | Indefinitely. They are no longer your information |
| Web server logs | Per our hosts' defaults; no Gale schedule enforced |
If something goes wrong: breach notification
The two halves of Gale are notified differently, and we would rather you know which one you are in.
If the breach involves your medical record (the HIPAA side): Gale notifies your clinician's practice — the covered entity — without unreasonable delay and no later than 60 days after we discover it (45 CFR 164.410). The practice then notifies you, and where the law requires, the media and the Secretary of Health and Human Services.
If the breach involves your consumer information — what you typed into the chat, a screener you ran, an email you left us — Gale notifies you directly:
- You: without unreasonable delay and no later than 60 calendar days after we discover it (16 CFR 318.4(a)).
- The Federal Trade Commission: if the breach reaches 500 or more people, contemporaneously with the notice to you; if it reaches fewer than 500, in an annual log filed no later than 60 days after the end of the calendar year (16 CFR 318.4(b), 318.5(c)). We are not going to promise you a 60-day FTC notice that the rule does not require and we would not give.
- Prominent media in any state where 500 or more residents are affected (16 CFR 318.3(a)(3), 318.5(b)).
- The content of that notice is prescribed by 16 CFR 318.6.
We are also subject to the breach-notification statute of every state where an affected person lives — for example, Cal. Civ. Code § 1798.82 and RCW 19.255.010 — each with its own clock and its own duty to notify the state Attorney General. Where a state's deadline is shorter than the federal one, the shorter deadline is the one we meet.
The FTC's definition of a breach is broader than HIPAA's. It reaches any acquisition of your health information without your authorization — including an unauthorized disclosure, not only a hack. That is the rule the FTC used against companies that leaked health data through advertising pixels. We place no advertising pixels.
International transfers
Gale operates in the United States and stores information in the United States. We do not currently offer the service outside the United States.
Changes to this policy
Three commitments in this policy are not amendable:
- We will never sell your information.
- We will never use it for advertising or marketing.
- We will never share it for cross-context behavioral advertising.
Every other part of this policy can change with notice. These cannot. If we ever wanted to change them, we would have to obtain your affirmative, separate, opt-in consent — and this document is our commitment that we will not ask.
For everything else: we will post a new version here with a new effective date. Where a change is material and it concerns your medical record, the new practice does not begin until the new notice is in effect — we cannot change what we do and update the document afterward.
Washington law is stricter still, and we will follow it: we may not collect, use, or share a new category of consumer health data, or use it for a new purpose, without first updating the Consumer Health Data Privacy Policy and obtaining your affirmative consent before the new processing begins (RCW 19.373.020(1)(c)–(d)).
We review and update this policy at least once every 12 months (Cal. Civ. Code § 1798.130(a)(5)).
We keep prior versions available.
Contact
Email: legal@gale.care. This is the address for any privacy request — to see what we hold about you, to correct it, to delete it, to take it elsewhere, or to appeal a decision. A person reads it.
By post: Gale Care Inc., c/o Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, USA
Gale Care Inc. is a Delaware corporation.
Privacy officer: Bill Nguyen, CEO — reachable at legal@gale.care.
Complaints. You may complain to us and you may complain about us — to your state Attorney General, and, for a matter concerning your medical record, to the U.S. Department of Health and Human Services, Office for Civil Rights. We will not retaliate against you for doing so. If we refuse a request and you appeal, and we deny the appeal, we will hand you the way to reach your Attorney General ourselves.
Appendix A — California disclosures (Cal. Civ. Code § 1798.130(a)(5))
This appendix restates the tables above in the statutory taxonomy of Cal. Civ. Code § 1798.140(v). It adds no new processing; it is the compliance layer for the plain-English document above.
| Statutory category (§ 1798.140(v)) | Do we collect it? | Source | Business purpose | Categories of third parties it is disclosed to | Retention criterion |
|---|---|---|---|---|---|
| (A) Identifiers — name, email, phone, IP, account ID | Yes | You; your clinician; NPPES (clinicians) | Providing the service; care coordination; security | Cloud hosting; email delivery; telephony | Per the retention table above |
| (B) Customer records (Civ. Code § 1798.80(e)) — name, address, insurance, payment data | Yes | You | Treatment, payment, operations | Cloud hosting; payment processor | Medical-record retention periods |
| (C) Protected classifications — age, sex, and, where clinically relevant, other characteristics | Yes, clinically | You; your clinician | Treatment | Cloud hosting | Medical-record retention periods |
| (D) Commercial information | Payments and invoices only | Your visit | Payment | Payment processor | Per the retention table above |
| (E) Biometric information | No | — | — | — | — |
| (F) Internet or network activity — pages requested, first-party product measurements | Yes | Your browser | Running the site; fixing the funnel | Cloud hosting | Indefinitely today; no schedule enforced |
| (G) Geolocation | State only. No precise geolocation | You | Matching you to licensed clinicians | Cloud hosting | Per the retention table above |
| (H) Audio, electronic, visual — visit audio; telehealth audio/video | Yes (audio); video is never captured | Your microphone | The visit; drafting the note | Transcription provider (web only) | Not stored by Gale |
| (I) Professional / employment information | Clinicians only | NPPES; enrichment vendors | Provider outreach | Enrichment vendors | On request, deleted |
| (J) Education information | No | — | — | — | — |
| (K) Inferences — the engine's risk output | Yes | Derived | Clinical triage | None. It is disclosed to no third party | Per the retention table above |
| (L) SENSITIVE personal information — health, mental-health, and sexual-health data; precise identifiers | Yes — this is the core of what we hold | You; your clinician | Only to provide the service you requested, and for treatment. Never for advertising, marketing, or profiling to infer characteristics | Cloud hosting; the Gemini API (chat, screeners, briefs); transcription (web audio) | Per the retention table above |
Categories of personal information SOLD or SHARED in the preceding 12 months: NONE. We have sold no personal information and shared none for cross-context behavioral advertising. We never will.
Categories DISCLOSED for a business purpose in the preceding 12 months: all categories marked "Yes" above are disclosed to the service providers named in the subprocessor register, for the purposes stated there. That register — not a category list — is the operative disclosure.
Sensitive personal information. We use and disclose it only for the purposes permitted by Cal. Civ. Code § 1798.121 and 11 CCR § 7027 — performing the service you asked for, security, and safety. We do not use it to infer characteristics about you.
Methods for submitting requests. Email legal@gale.care, or write to us at the postal address under "Contact," above.
California ordinarily requires two or more methods, including a toll-free telephone number — but a business that operates exclusively online and has a direct relationship with the consumer need only provide an email address (Cal. Civ. Code § 1798.130(a)(1)(A)). Gale operates exclusively online. We give you a postal address anyway.
Authorized agents. See "Your rights," above.
Financial incentives. We offer none. We do not pay you for your data and we do not charge you more for withholding it.
Related documents
- Consumer Health Data Privacy Policy — the standalone Washington My Health My Data policy, covering the information you generate as a visitor rather than as a patient.
- Notice of Privacy Practices — issued by your clinician's practice, which is the covered entity for your medical record.
- Terms of Service.