Skip to content

Legal

Privacy Policy

What information Terra collects, how it is used to document visits, which subprocessors handle it, how long it is kept, and the rights you have.

Last updated

On this page (13 sections)

This policy explains how Terra handles information on our website, useterra.si, and in the Terra application at app.useterra.si. We have written it to match how the product actually works. Where the product's behavior is described in more detail in our Help Center or Compliance center, we link to it.

Who we are

Terra is a clinical documentation workspace operated by {{LEGAL_ENTITY}}, {{COMPANY_ADDRESS}} ("Terra", "we", "us"). You can reach us about privacy at hello@useterra.si and about security at security@useterra.si.

Two different roles

Terra handles two kinds of information, and our role differs for each.

  • Patient information in the app. When a clinic or clinician (our "customer") uses Terra to document care, the patient information they enter is protected health information (PHI) under HIPAA. The customer is the covered entity and decides how that information is used. Terra processes it only on the customer's behalf, as a business associate, under a Business Associate Agreement. If you are a patient, the privacy notice of your clinician or practice governs your information, and requests about it should go to them first. We will help them respond.
  • Account, billing and website information. For information about the people who use Terra (names, emails, sign-in records, billing contacts) and about visitors to our website, Terra decides how it is used and is responsible for it under this policy.

Information we collect

Account information

  • Name, email address, optional pronouns and credentials (for example "MD").
  • Your password, stored only as a bcrypt hash of a SHA-256 pre-hash. We never store or see your password in readable form.
  • If you use Google sign-in, the identifier of your Google account and its verified email. We do not receive your Google password.
  • Practice memberships, roles and permissions, and invitations.

Practice information

  • Practice name, description, logo and login address.
  • Sites, care teams, templates, writing-style settings and text shortcuts.

Clinical content (PHI, processed for our customers)

  • Patient demographics entered by the practice, such as name, date of birth, MRN and pronouns.
  • Visit context, transcripts, note drafts, signed notes, amendments, co-signatures and coding worksheets.
  • Audio recordings that a clinician chooses to upload or capture, and the transcripts made from them.
  • Documents uploaded to a patient's chart and the text extracted from them.
  • Reviewed facts such as allergies, medications and problems.
  • Questions asked in record chat and evidence research, and the answers.

Live transcription audio is not stored by Terra. During a live session, audio streams from the clinician's browser directly to our speech-recognition subprocessor. Terra stores only the finalized text turns.

Usage and billing information

  • Credit balances, estimates, reservations and charges for each request, with the model and rate used.
  • Your Stripe customer reference, plan, invoices and payment status. Card details are collected and held by Stripe; we do not receive full card numbers.

Security and technical information

  • Session records: device and browser (user agent), sign-in method, creation and last-use times.
  • IP addresses, used in memory to limit repeated sign-in attempts and kept in our hosting provider's standard request logs.
  • An audit history of actions in the workspace, such as sign-ins, invitations, signatures, amendments and access changes.

Website information

  • Messages you send through our contact form (name, email, practice and message), which are delivered through Netlify Forms.
  • Standard request logs kept by our website host. Our website does not use advertising or analytics cookies. See the Cookie Policy.

How we use information

We use information to:

  1. Provide the service: run visits, transcription, drafts, chat, coding suggestions and evidence research, and keep the records your practice creates.
  2. Keep it secure: authenticate users, enforce roles and patient access, detect abuse and keep audit history.
  3. Bill accurately: estimate, reserve and settle credits, and process subscriptions and top-ups.
  4. Support you: answer questions and fix problems you report.
  5. Communicate: send account emails (verification, password reset, welcome) and important service notices.
  6. Meet legal obligations and enforce our Terms of Service.

We do not sell personal information or PHI, use it for advertising, or use PHI to train AI models.

How AI processing works

Terra sends clinical content to an AI or speech provider only to perform a task a clinician started, and only what that task needs:

  • Drafts use the sources listed in the quote the clinician sees before confirming. The encounter header gives age at the date of service, pronouns and visit type, never the patient's name, MRN or date of birth.
  • Code suggestions send the saved note, and the transcript only when the clinician includes it.
  • Evidence research sends only search queries the clinician approves, after a privacy check that removes names, exact dates and ages, record numbers and contact details. These queries go to public sources (NCBI PubMed and PubMed Central, DailyMed, openFDA and MedlinePlus), which receive no account details, cookies or identity from Terra.
  • Requests to AI providers are made with provider-side storage disabled, with no tools or conversation history, under API terms that do not permit training on customer data.

Every output is a proposal for clinician review. Nothing is signed, submitted or sent to a patient automatically.

Subprocessors and sharing

We share information only with service providers that help us run Terra, under contracts that limit their use of it, and, for PHI, under a business associate agreement. The current list, with what each provider receives and where, is on the Compliance center. In summary:

  • Google Cloud: application hosting, storage and Gemini AI models.
  • OpenAI: AI models for drafting, chat, coding suggestions and file transcription.
  • AssemblyAI: live speech recognition.
  • MongoDB Atlas: database hosting.
  • Stripe: payments and invoices (no PHI).
  • Netlify: our marketing website and its contact form (no PHI).
  • Google Workspace: account email such as verification and password reset (no PHI).

We may also disclose information when required by law, to protect the rights and safety of patients, users or the public, or as part of a merger or acquisition, in which case PHI remains subject to the BAA. We will tell customers about legal requests for their data unless the law forbids it.

How long we keep information

  • Clinical records are kept for as long as the customer's account is active, because they are the customer's medical records. Signed notes and their history are never silently changed or deleted.
  • Raw audio can be removed under a practice's audio retention policy, configurable from 1 to 3,650 days after clinician review, with a recovery window and legal hold. Transcripts and signed notes are kept.
  • Original document files can be retired after review; the reviewed text is kept.
  • Account information is kept while your account is active and for up to {{ACCOUNT_RETENTION}} afterwards for security and legal purposes.
  • Billing records are kept as long as tax and accounting law requires.
  • Backups are kept for {{BACKUP_RETENTION}} and expire on their own schedule, so deleted data can remain in a backup until it expires.

When a customer's agreement ends, they can export their records for {{EXPORT_WINDOW}}. After that we delete or de-identify the customer's data, except where the law requires us to keep it, as set out in the BAA.

Security

We protect information with encryption in transit (TLS) and at rest, signed short-lived session tokens, hashed passwords and secrets, role- and patient-level access controls, integrity hashes on signed notes and an audit history. Details are on the Compliance center. If we learn of a breach of unsecured PHI, we notify the affected customer as required by HIPAA and our BAA.

Your rights and choices

  • Users can view and update their profile in the app, end sessions, and ask us for a copy of their account information, a correction or deletion by writing to hello@useterra.si. Deleting your account removes your membership; records you signed remain part of the practice's medical records.
  • Patients should contact their clinician or practice to access, correct or receive a copy of their records. As a business associate, we support practices in responding.
  • Depending on where you live, you may have additional rights under state privacy laws, such as to know, access, correct or delete personal information, and to appeal a decision. We honor these for information we control. Information governed by HIPAA is handled under HIPAA.
  • You can opt out of non-essential emails at any time. Account and security emails are part of the service.

We will not discriminate against you for exercising your rights.

Children

Terra is a professional tool for clinicians and practice staff and is not directed to children. Records of patients who are minors are entered and controlled by their practice as PHI.

Where information is stored

Terra stores and processes information in the United States. If you use Terra from elsewhere, your information is transferred to the United States.

Changes to this policy

We will post any change here with a new "last updated" date, and we will email account owners about material changes before they take effect.

Contact

{{LEGAL_ENTITY}}, {{COMPANY_ADDRESS}}. Email hello@useterra.si. For security matters, security@useterra.si.