Effective date: July 13, 2026 · Last updated: July 13, 2026 · Company: Mahlum Innovations LLC d/b/a Chronos
Read this first. Chronos is a business-to-business (B2B) service sold to law firms and legal teams in the United States. This Policy describes how we handle data about the firms and individual professionals who use our platform, and how we handle the case files — including Protected Health Information (PHI) — that customer firms upload for processing. If you are an individual whose medical records were reviewed using Chronos, we process your records only on behalf of the law firm that engaged us; please contact that firm directly.
When you create an account or set up your firm, we collect: name, work email address, firm name and address, phone number, job title, and role/permission settings. Authentication (including mandatory multi-factor authentication) is handled by our identity provider, Clerk; no PHI is stored in the authentication system.
Payments are processed by Stripe. Stripe collects and stores payment card details; we receive only a tokenized reference, billing contact details, and transaction history. We never store raw card numbers, and no PHI is shared with Stripe.
We automatically collect service-interaction data: pages and features used, actions taken (uploads, exports, logins), timestamps, session duration, device/browser type, and IP address. We use this to operate and improve the service, detect security issues, and maintain the append-only audit log we make available to firms for compliance review.
When your firm uploads medical records or other case files, we process the contents — which may include PHI as defined by HIPAA (patient names, dates of service, diagnoses, treatment notes, billing records) — solely as a service provider / HIPAA business associate acting on your firm's behalf and at its direction, under the Business Associate Agreement (BAA) included with every account. Your firm controls this data.
If you email us, request a demo, or open a support ticket, we retain those communications to respond and improve support. Do not include PHI in support emails; use in-app channels for case-specific issues.
We use the data above to: provide, operate, secure, and maintain the service (including generating AI-assisted chronologies with per-line source-page citations on your firm's behalf); authenticate users and enforce role-based access; process payments and manage credit balances; maintain audit logs; send transactional communications; detect and prevent fraud, abuse, and security incidents; and comply with legal obligations, including HIPAA breach-notification duties.
We may use aggregated, de-identified usage data (never case files or PHI) to improve the service.
Chronos uses large language models to extract and structure information from uploaded records and to generate draft chronologies with per-line citations to source pages. AI inference runs on a HIPAA-eligible gateway under a BAA, with zero data retention and no training on customer content. All output is an AI-generated draft: attorney review is required, and each entry should be verified against its cited source page. Chronos provides no legal or medical advice. We describe our compliance posture as "HIPAA-aligned with a signed BAA on every account" — no government body certifies HIPAA compliance.
Upon account termination we return or destroy PHI in accordance with your BAA. You may trigger an immediate hard purge at any time using the in-app purge control.
Chronos runs on HIPAA-eligible infrastructure (Aptible) with encryption at rest (AES-256) and in transit (TLS), mandatory MFA for all users, role-based access controls, append-only audit logging, and least-privilege internal access. We operate a SOC 2 readiness program — we do not represent that we hold SOC 2 certification unless and until a report is issued. Details: medchronosai.com/security. To report a vulnerability: security@medchronosai.com.
All customer data, including uploaded case files and PHI, is stored and processed in the United States. We do not transfer customer case data outside the US.
HIPAA exemption note: PHI we process as a business associate is exempt from most state consumer privacy laws (e.g., Cal. Civ. Code § 1798.145(c); Mont. Code Ann. § 30-14-2804). Rights requests concerning medical records should go to the law firm handling your matter. The rights below apply to personal data we hold as a controller — chiefly account, billing, and marketing-site data.
Chronos is a Montana company. Montana residents may: confirm whether we process their personal data and access it; correct inaccuracies; delete personal data provided by or obtained about them; obtain a portable copy; and opt out of any sale, targeted advertising, or profiling (we do not conduct any of these). To appeal a refusal, contact us at the address in Section 13. Respond within 45 days (extendable by 45 days with notice).
California residents have the right to: know/access the personal information we collect, use, and disclose; delete it (subject to exceptions); correct it; opt out of sale or sharing (we do not sell or share personal information); limit use of sensitive personal information (we use it only to provide the service); and non-discrimination for exercising rights. To exercise rights, contact legal@medchronosai.com. Response within 45 days.
Residents of other states with comprehensive privacy laws (including Colorado, Connecticut, Delaware, Iowa, Indiana, Kentucky, Maryland, Minnesota, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia) may have similar rights of access, correction, deletion, portability, and opt-out. We honor these rights for all US residents regardless of state. Contact legal@medchronosai.com.
Chronos is a professional tool for licensed legal professionals and their staff. It is not directed to, and may not be used by, anyone under 18, and we do not knowingly collect personal information from minors. (Medical records uploaded by firms may pertain to minors; that data is PHI processed on the firm's behalf under the BAA and the firm's own authority.)
We may update this Policy. For material changes we will notify account holders by email and post notice on our website at least 30 days before the changes take effect. The "Last updated" date above reflects the current version; prior versions are available on request.
For privacy-related questions, requests, or concerns — including HIPAA-related inquiries — contact us at:
Mahlum Innovations LLC d/b/a Chronos
850 Holt Drive, Bigfork, MT 59911, USA
Privacy/Legal: legal@medchronosai.com
Security: security@medchronosai.com
HIPAA matters: reference your signed BAA (available in-app under Settings → Security).
See also: Terms of Service · Acceptable Use Policy · SLA · Subprocessors · Security overview