ChiroUnchained operates a suite of software tools for chiropractic practices, including RaveWall, Cortex, InnateScan, and related services available at chirounchained.ai and its subdomains. This Privacy Policy describes how we collect, use, and protect information when you use our platform.
We collect information you provide directly, including your name, email address, business name, and practice details when you register or connect third-party services. When you authorize our platform to connect with Facebook, Google Business Profile, or other platforms, we receive OAuth tokens and the permissions you explicitly grant.
We collect usage data including log files, IP addresses, and interaction data to operate and improve our services.
We use your information to provide and operate the ChiroUnchained platform, including posting content to connected social media and business profile pages on your behalf, generating practice marketing content, and displaying review data on your waiting room displays.
We do not sell your personal information to third parties. We do not use your data to train AI models without your explicit consent.
Our platform connects to third-party services including Facebook (Meta), Google Business Profile, and Google Photos on your behalf using OAuth authorization. Your use of these connections is subject to the respective platform's terms of service. We store only the access tokens necessary to perform the actions you have authorized.
We use Anthropic's Claude API and Amazon Web Services for AI processing and infrastructure. Protected health information is routed exclusively through HIPAA-compliant AWS infrastructure and is never transmitted to third-party AI providers without a signed Business Associate Agreement.
We retain your account data for as long as your account is active. OAuth tokens are stored securely and can be revoked at any time through your account settings or directly through the connected platform. Clinical and health-related data is retained for a minimum of seven years in accordance with HIPAA requirements.
We use AES-256-GCM encryption for sensitive credentials, HTTPS for all data in transit, and access controls to protect your data.
You may request access to, correction of, or deletion of your personal data by contacting us. You may revoke third-party platform connections at any time.
We use session cookies to maintain your authenticated state. We do not use tracking cookies or advertising cookies.
We may update this Privacy Policy periodically. We will notify registered users of material changes via email.