This Privacy Policy (the "Policy") applies to the applications, websites, and electronic communications on which it appears (the "Platform"). The Policy describes how Nightingale Technology LLC (referred to herein as "Nightingale Technology", "Nightingale", or "we" or "us" or "our") uses the Personal Information that we collect, receive, maintain, and store about you. Please read this Policy carefully, by interacting with us through the Platform you consent to this Policy.
Note: this Policy does not cover our collection, use, or disclosure of Protected Health Information ("PHI") as defined by the Health Insurance Portability and Accountability Act of 1996, the Health Information Technology for Economic and Clinical Health Act and the regulations promulgated therein.
Notwithstanding the foregoing, Section 7 (Patient Detection — Screen Recording Data) describes how the Superchart desktop application processes on-screen content, which may include PHI. That Section is provided for transparency and applies in addition to — and not in place of — HIPAA and the agreements that govern our handling of PHI.
We collect a range of Personal Information. "Personal Information" is information that identifies, relates to, describes, or is reasonably capable of being associated with or linked to an individual.
We collect Personal Information directly from you (for example, when you register an account or correspond with us), from third parties (such as business partners, analytics providers, and search information providers), and passively through tracking tools like cookies, pixels, and web beacons.
Separately from the collection described above, the Patient Detection feature of the Superchart desktop application processes on-screen content entirely on your device; this content is never collected by, or transmitted to, Nightingale. See Section 7 (Patient Detection — Screen Recording Data).
We may combine Personal Information we obtain online with information collected offline, information from third party sites, and information across devices.
We use your Personal Information to respond to requests and inquiries, communicate with you for transactional purposes, improve our Platform, ensure security, protect against fraud, and for marketing purposes as permitted by law.
We may share your Personal Information in the following circumstances:
Notwithstanding anything in this Section, screen recording data processed by the Patient Detection feature of the Superchart desktop application is never shared with, sold to, disclosed to, or made accessible to any third party under any circumstances. See Section 7 (Patient Detection — Screen Recording Data).
We collect Personal Information about users over time using cookies, web beacons, pixels, and flash cookies. We also use analytics services such as Google Analytics. You can control cookies through your browser settings. For more information about cookies, visit allaboutcookies.org.
We may use required cookies, performance-related cookies, functionality-related cookies, and targeting-related cookies. You can usually find cookie settings in the options or preferences menu of your browser.
The Superchart desktop application (available for macOS and Windows) includes an optional feature called "Patient Detection." When Patient Detection is enabled, the application captures the contents of your screen and uses on-device optical character recognition (OCR) for a single purpose: to determine whether a patient displayed on your screen (for example, in your electronic health record system) matches a patient you are authorized to access, so that the application can offer you a shortcut to that patient's chart.
Collection and use. Captured screen images and recognized text are processed entirely on your device and exist only in memory while matching is performed. They are used solely for the patient-matching purpose described above and for no other purpose. We do not use screen recording data for advertising, analytics, profiling, or marketing.
Storage and retention. Screen recording data is never stored. Captured screen images and recognized text are discarded immediately after matching completes; nothing is written to disk, and nothing is transmitted to Nightingale's servers. Our retention period for screen recording data is zero.
Disclosure and sharing. Screen recording data is never shared with, sold to, disclosed to, or made accessible to any third party. It never leaves your device. Screen recording data is not subject to the sharing practices described elsewhere in this Policy (see Section 5).
Audit records. When you accept or dismiss a patient suggestion, the application records an audit event containing only the internal patient identifier from our own system, as required for healthcare audit and compliance purposes, including under HIPAA. Audit events never contain screen images, recognized text, or any other screen content. Audit events are retained in accordance with our legal and compliance obligations and our agreements with your healthcare organization.
Relationship to PHI and HIPAA. Content displayed on your screen may include Protected Health Information ("PHI"), such as patient names shown in your electronic health record system, and the patient identifier contained in an audit event may itself constitute PHI. Although this Policy generally does not cover PHI (see the note at the top of this Policy), we include this Section so that the operation of Patient Detection is transparent to all users of the Superchart desktop application. To the extent screen recording data or audit events constitute PHI, they are handled in accordance with HIPAA and our agreements with your healthcare organization, including any applicable business associate agreement. Nothing in this Section limits those obligations, and in the event of any conflict between this Section and those agreements or HIPAA, those agreements and HIPAA control.
Your control. You can disable Patient Detection at any time in the application's Settings. On macOS, Patient Detection cannot operate unless you grant the Screen Recording permission in System Settings, and revoking that permission disables the feature.
You can opt out of marketing communications by emailing us at privacy@nightingale.tech, or by following the instructions included in the email or text correspondence. We may still contact you with important transactional or administrative information.
The Platform is meant for adults and we will not knowingly collect Personal Information from any person under the age of 13 without permission from a parent or guardian. If you are a parent or legal guardian and think your child has given us Personal Information, please email privacy@nightingale.tech and mark your inquiry "COPPA Inquiry."
Pursuant to California's Shine the Light statute (Cal. Civ. Code Sec. 1798.83), you can control if we share Personal Information with third parties for their marketing purposes. To opt-out, please email privacy@nightingale.tech.
We have taken reasonable steps to protect the information users share with us. No transmission of information via the Internet can be entirely secure. We will retain your Personal Information in compliance with the uses described in this Policy, as well as to comply with our legal, financial reporting, or compliance obligations.
Screen recording data processed by the Patient Detection feature of the Superchart desktop application is not retained at all: it is processed on your device, in memory, and discarded immediately after matching completes. See Section 7 (Patient Detection — Screen Recording Data).
Our Platform may include third party content and links to third party websites. We do not control these third parties and this Policy does not apply to their privacy practices. Please read the third parties' privacy policies carefully.
If you have any questions about this Policy, please email us at privacy@nightingale.tech or write to us at:
Nightingale Technology
Attn: Privacy Officer
901 N Glebe Road, Suite 500
Arlington, VA 22203
This policy may be amended from time to time. Unless otherwise indicated, any changes will apply immediately upon posting to the Platform. You can see when this Policy was last updated by reviewing the "Last Updated" date at the top of this page.