Privacy Policy
Effective date: July 1, 2026
ABA Notes (“we”, “us”) is a Chrome extension that helps RBTs, BCBAs, and therapists review and improve Applied Behavior Analysis (ABA) session notes before they are submitted to an electronic health record (EHR). It provides suggestions only — it never submits notes on your behalf.
What we process
- Session note text you submit for review. This may include Protected Health Information (PHI). We use it only to generate the review and proofread suggestions you requested. We do not store it, log it, or use it to train any model. It exists only in memory for the duration of your request.
- Account information. Your email address and authentication credentials, handled by Firebase Authentication.
- Usage metadata. Non-identifying counts (e.g., number of reviews, AI token usage) and PHI-free feedback about which suggestions were useful. This contains no note content — suggestion references are stored as an irreversible hash.
- Device and abuse-prevention data. A random per-installation device id, and a one-way hash of your IP address used only to limit automated free-trial abuse. We do not store your raw IP.
- Billing. If you subscribe, payment is processed by Stripe; we receive a customer id and subscription status, not your card number. No PHI is sent to Stripe.
How your note is handled (PHI)
Your note is sent over an encrypted connection to our processing service and to our AI provider (Anthropic) to generate suggestions, then discarded. We operate under Business Associate Agreements with our AI and cloud providers, and our AI provider is configured for zero data retention — your note is not retained by them. We never sell your data or use PHI for advertising.
Service providers (subprocessors)
- Anthropic — AI review/proofread (under BAA with zero-data retention).
- Google Cloud / Firebase — authentication, compute, and database (under BAA).
- Stripe — billing only (no PHI).
Retention
We do not retain your session notes. Account, billing, usage counts, and PHI-free feedback are retained for the life of your account and deleted on request.
Security
Encryption in transit (TLS), server-side authentication and access control, per-account data isolation, single-device session binding, and no third-party analytics or crash reporting on paths that handle notes.
Your choices
You control what text you submit. You can request deletion of your account and associated data by contacting us. Because the extension makes suggestions only, nothing is ever sent to your EHR without your explicit action.
Changes
We will post changes here and update the effective date.