// Legal

Privacy Policy

Effective date: July 13, 2026  ·  Last updated: July 13, 2026  ·  Company: Mahlum Innovations LLC d/b/a Chronos

Read this first. Chronos is a business-to-business (B2B) service sold to law firms and legal teams in the United States. This Policy describes how we handle data about the firms and individual professionals who use our platform, and how we handle the case files — including Protected Health Information (PHI) — that customer firms upload for processing. If you are an individual whose medical records were reviewed using Chronos, we process your records only on behalf of the law firm that engaged us; please contact that firm directly.

Contents

  1. 1. Data we collect
  2. 2. How we use data
  3. 3. What we never do
  4. 4. AI processing disclosure
  5. 5. Subprocessors & sharing
  6. 6. Data retention & deletion
  7. 7. Security
  8. 8. Data residency
  9. 9. Cookies & analytics
  10. 10. Your state privacy rights
  11. 11. Children
  12. 12. Changes to this policy
  13. 13. Contact us

1. Data we collect

1a. Account and firm data

When you create an account or set up your firm, we collect: name, work email address, firm name and address, phone number, job title, and role/permission settings. Authentication (including mandatory multi-factor authentication) is handled by our identity provider, Clerk; no PHI is stored in the authentication system.

1b. Billing data

Payments are processed by Stripe. Stripe collects and stores payment card details; we receive only a tokenized reference, billing contact details, and transaction history. We never store raw card numbers, and no PHI is shared with Stripe.

1c. Usage and telemetry data

We automatically collect service-interaction data: pages and features used, actions taken (uploads, exports, logins), timestamps, session duration, device/browser type, and IP address. We use this to operate and improve the service, detect security issues, and maintain the append-only audit log we make available to firms for compliance review.

1d. Uploaded case files and PHI (processed on your firm's behalf)

When your firm uploads medical records or other case files, we process the contents — which may include PHI as defined by HIPAA (patient names, dates of service, diagnoses, treatment notes, billing records) — solely as a service provider / HIPAA business associate acting on your firm's behalf and at its direction, under the Business Associate Agreement (BAA) included with every account. Your firm controls this data.

1e. Support and communications

If you email us, request a demo, or open a support ticket, we retain those communications to respond and improve support. Do not include PHI in support emails; use in-app channels for case-specific issues.

2. How we use data

We use the data above to: provide, operate, secure, and maintain the service (including generating AI-assisted chronologies with per-line source-page citations on your firm's behalf); authenticate users and enforce role-based access; process payments and manage credit balances; maintain audit logs; send transactional communications; detect and prevent fraud, abuse, and security incidents; and comply with legal obligations, including HIPAA breach-notification duties.

We may use aggregated, de-identified usage data (never case files or PHI) to improve the service.

3. What we never do

  • We do not sell personal information, and we do not "share" personal information for cross-context behavioral advertising, as those terms are defined by the CCPA/CPRA. We have not done so in the preceding 12 months.
  • We do not use your case files, uploaded records, PHI, or AI outputs to train AI models — ours or anyone else's. Our AI inference provider operates under a BAA with zero data retention and contractual prohibitions on training.
  • We do not use advertising or behavioral-tracking cookies and do not track users across third-party websites.
  • We do not process personal data for targeted advertising or profiling in furtherance of decisions producing legal or similarly significant effects (as defined by the Montana Consumer Data Privacy Act and similar laws).

4. AI processing disclosure

Chronos uses large language models to extract and structure information from uploaded records and to generate draft chronologies with per-line citations to source pages. AI inference runs on a HIPAA-eligible gateway under a BAA, with zero data retention and no training on customer content. All output is an AI-generated draft: attorney review is required, and each entry should be verified against its cited source page. Chronos provides no legal or medical advice. We describe our compliance posture as "HIPAA-aligned with a signed BAA on every account" — no government body certifies HIPAA compliance.

5. Subprocessors and sharing

We share data only with the vetted subprocessors listed at medchronosai.com/subprocessors, each bound by a data processing agreement and, where PHI is involved, a BAA. Current categories:

  • Hosting and deployment: Aptible, Inc. — HIPAA-eligible infrastructure, BAA signed.
  • Object storage: Google Cloud Storage, US region — BAA signed.
  • AI inference: Aptible AI Gateway — BAA signed, zero data retention, no training on customer content. See the full subprocessors list for current details.
  • Authentication: Clerk, Inc. — no PHI stored in authentication system.
  • Payments: Stripe, Inc. — no PHI shared with Stripe.

We may also disclose data: (a) when required by law, court order, or valid legal process; (b) in a merger, acquisition, or sale of assets, with prior notice to affected customers before PHI is transferred or becomes subject to a materially different policy; or (c) with your consent.

6. Data retention and deletion

  • Case files and PHI: firm-controlled. Each firm sets its own retention period in workspace settings. When a case is deleted or the retention period expires, data is hard-purged — permanent, irreversible, and recorded in the audit log. Deleted data is removed immediately from live systems; encrypted backup copies (AES-256) age out automatically on our hosting provider's fixed backup schedule (daily backups retained 30 days; monthly backups retained 12 months; yearly backups retained 6 years) and are never restored except for disaster recovery.
  • Account and firm data: retained for the life of the account plus up to 3 years after closure for legal and billing purposes.
  • Audit logs: retained for 6 years, consistent with HIPAA documentation requirements (45 C.F.R. § 164.316(b)(2)(i)). Audit logs are append-only.
  • Payment records: retained for 7 years for tax and accounting obligations.
  • De-identified, aggregated usage data: may be retained indefinitely.

Upon account termination we return or destroy PHI in accordance with your BAA. You may trigger an immediate hard purge at any time using the in-app purge control.

7. Security

Chronos runs on HIPAA-eligible infrastructure (Aptible) with encryption at rest (AES-256) and in transit (TLS), mandatory MFA for all users, role-based access controls, append-only audit logging, and least-privilege internal access. We operate a SOC 2 readiness program — we do not represent that we hold SOC 2 certification unless and until a report is issued. Details: medchronosai.com/security. To report a vulnerability: security@medchronosai.com.

8. Data residency

All customer data, including uploaded case files and PHI, is stored and processed in the United States. We do not transfer customer case data outside the US.

9. Cookies and analytics

  • Strictly necessary cookies — authentication, session management, and security; cannot be disabled without breaking the service.
  • Functional cookies — remember preferences (UI settings).
  • Analytics — on public marketing pages only (never inside the authenticated application), we use Google Analytics 4 to measure traffic. Analytics data is anonymized; no PHI is ever sent to analytics services. Opt out via the Google Analytics opt-out browser add-on or browser controls.

We do not use advertising or behavioral-tracking cookies. We do not track users across third-party websites.

10. Your state privacy rights

HIPAA exemption note: PHI we process as a business associate is exempt from most state consumer privacy laws (e.g., Cal. Civ. Code § 1798.145(c); Mont. Code Ann. § 30-14-2804). Rights requests concerning medical records should go to the law firm handling your matter. The rights below apply to personal data we hold as a controller — chiefly account, billing, and marketing-site data.

Montana residents (Montana Consumer Data Privacy Act)

Chronos is a Montana company. Montana residents may: confirm whether we process their personal data and access it; correct inaccuracies; delete personal data provided by or obtained about them; obtain a portable copy; and opt out of any sale, targeted advertising, or profiling (we do not conduct any of these). To appeal a refusal, contact us at the address in Section 13. Respond within 45 days (extendable by 45 days with notice).

California residents (CCPA/CPRA)

California residents have the right to: know/access the personal information we collect, use, and disclose; delete it (subject to exceptions); correct it; opt out of sale or sharing (we do not sell or share personal information); limit use of sensitive personal information (we use it only to provide the service); and non-discrimination for exercising rights. To exercise rights, contact legal@medchronosai.com. Response within 45 days.

Other states

Residents of other states with comprehensive privacy laws (including Colorado, Connecticut, Delaware, Iowa, Indiana, Kentucky, Maryland, Minnesota, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia) may have similar rights of access, correction, deletion, portability, and opt-out. We honor these rights for all US residents regardless of state. Contact legal@medchronosai.com.

11. Children

Chronos is a professional tool for licensed legal professionals and their staff. It is not directed to, and may not be used by, anyone under 18, and we do not knowingly collect personal information from minors. (Medical records uploaded by firms may pertain to minors; that data is PHI processed on the firm's behalf under the BAA and the firm's own authority.)

12. Changes to this policy

We may update this Policy. For material changes we will notify account holders by email and post notice on our website at least 30 days before the changes take effect. The "Last updated" date above reflects the current version; prior versions are available on request.

13. Contact us

For privacy-related questions, requests, or concerns — including HIPAA-related inquiries — contact us at:

Mahlum Innovations LLC d/b/a Chronos

850 Holt Drive, Bigfork, MT 59911, USA

Privacy/Legal: legal@medchronosai.com

Security: security@medchronosai.com

HIPAA matters: reference your signed BAA (available in-app under Settings → Security).

See also: Terms of Service · Acceptable Use Policy · SLA · Subprocessors · Security overview