HIPAA & GDPR Compliance

How Similia handles access, encryption, AI processing and deletion, and what practitioners need to verify for their own compliance obligations.

Our Commitment to Data Protection

At Similia, we understand the sensitive nature of healthcare data. We are committed to protecting patient information and continuously improving our security practices to meet healthcare data protection standards.

The platform uses encrypted storage, authenticated access and case-sharing permissions to control access to case notes and other private records.

Security & Compliance Features

Data Encryption

Case data is encrypted in transit and at rest. Authorized infrastructure and AI providers process data where needed to deliver the selected features.

Secure Infrastructure

Hosted on enterprise-grade cloud infrastructure with ongoing internal security reviews and monitoring.

Access Controls

Firebase authentication and server-side authorization control access to private records. Case-sharing permissions determine which invited users can access a shared case.

Data Storage & Processing

Case data is stored in encrypted databases. Firebase authentication, security rules and server-side authorization control access, including access granted through case sharing. Connections to the service use transport encryption.

Third-Party Services

Notes, case analysis, image analysis and transcription require AI processing consent. Semantic search sends the entered query to an embedding provider. Depending on the feature and request, content may be sent to OpenAI, Google, OpenRouter and a selected underlying model provider, or Deepgram for transcription. Retention and model-training controls vary by provider, account and request configuration. BAAs, zero-data-retention and no-training safeguards apply only where contractually applicable and enabled for the relevant service. Similia does not use User Content to train its own models. Consult the Privacy Policy and confirm the applicable agreements before submitting protected health information.

Data Retention & Deletion

When account or content deletion completes, affected data becomes inaccessible through the service and is removed from active storage. Deleted Cloud Storage objects can remain in a restricted soft-delete state for up to seven days. Residual backups, where applicable, follow separate retention schedules. De-identified shared proving records and other participants’ contributions may remain; the Privacy Policy explains these exceptions. Contact Similia for the retention details relevant to a compliance assessment. The linked billing analytics ledger is normally retained for 400 days and removed when account deletion completes. Minimal Stripe notification and retry records, without account or customer identifiers, contact details or patient content, are normally retained for 90 days. Bounded cleanup may lag during a backlog. Ledger deletion does not itself erase Stripe financial records or events already sent to analytics providers; the Privacy Policy explains these distinctions.

International Users (GDPR)

The Privacy Policy describes how Similia processes personal data and how individuals can exercise their rights under GDPR. See our Privacy Policy for details on your rights regarding personal data access, rectification, and erasure.

Questions about data protection?

Contact us for Data Processing Agreements or any compliance inquiries at info@similia.io

Contact Us