Last updated August 2, 2026

Privacy Policy

How gBell handles information: what we collect on our website, what we do with patient information on behalf of the practices we serve, and what we will never do with it.

01The short version

gBell sells software to healthcare practices. The practice is our customer. Patients are the practice's patients, not ours.

That distinction decides everything else in this policy. When we handle patient information, we do it on the practice's instructions, under a Business Associate Agreement, and that agreement controls. This policy governs our website and our relationship with the practices that buy gBell.

We do not sell personal information. We do not run advertising trackers. We do not use patient information to train AI models.

02The BAA controls patient information

Where gBell processes protected health information, we act as a Business Associate under HIPAA, and the Business Associate Agreement signed with the practice governs that processing.

If anything in this Privacy Policy conflicts with a signed BAA, the BAA wins. No part of this policy expands what we are permitted to do with PHI, and nothing here should be read as the practice's own Notice of Privacy Practices.

A vendor who tells you their standard privacy policy or terms of service "already covers HIPAA" is telling you something that is not true. The BAA is a separate, legally required agreement. We sign one before any patient information moves.

03What we collect, and from whom

Three groups of people touch gBell, and we treat their information differently.

Website visitors. We do not use third-party analytics, advertising pixels, or session recording tools on gbellai.com. Our hosting provider keeps standard server logs, including IP address and request metadata, for security and reliability. If you send us a message or request a demo, we keep what you wrote and how to reach you.

Practice staff. Account information for the people at a practice who use the console: name, work email, role, and authentication records. We also keep audit logs of significant actions, because HIPAA requires it and because a clinic should be able to see who did what.

Patients. Contact details, appointment information, intake responses, insurance and eligibility information, and call audio and transcripts. This is protected health information. We hold it on behalf of the practice, under the BAA, and the practice decides what happens to it.

04Calls, recordings, and transcripts

gBell answers, records, and transcribes calls on behalf of a practice. Recording law varies by state, and California, Florida, Illinois, Pennsylvania, Washington and others require the consent of every party to a confidential conversation. Which law applies usually follows where the caller is, not where the practice is.

Our agent states at the start of every call that the caller is speaking with an automated assistant and that the call is recorded. It says recorded, not "may be recorded," because hedged notice is not notice. A practice can adjust the wording and the voice, but it cannot remove the disclosure, move it later in the call, or strip either fact out of it.

If a caller asks not to be recorded, the agent will say it cannot continue on a recorded line and offer to take a message or transfer to staff. The practice remains responsible for its own compliance with the law where its patients are.

Recordings and transcripts are patient information. They are stored under the same terms as everything else covered by the BAA, and are available to the practice through the console.

05AI models and training

We do not use protected health information to train, fine-tune, or evaluate any AI model, ours or anyone else's, and our agreements with model providers prohibit them from doing so with data we send.

Zero retention and no-training are two different commitments, and it is worth separating them. Where a provider offers zero data retention we enable it. Where a provider retains data briefly for abuse monitoring, that retention is covered by a business associate agreement and the data is still not used for training. We will describe the current configuration of any provider in our chain on request.

Where we improve the product using real usage, we work from aggregate operational metrics, such as call volumes, latencies, and error rates, that do not identify a patient.

06How we use information

To run the service the practice hired us to run: answering calls, scheduling, sending intake links, verifying insurance eligibility, and the billing workflows behind a visit.

To keep the service secure and available, including monitoring, backups, abuse prevention, and audit logging.

To support the practice when its staff contact us.

To bill the practice and keep the business records the law requires us to keep.

We do not use patient information for marketing. We do not sell or rent personal information to anyone, and we do not share it for cross-context behavioral advertising.

07Who else touches the data

Running gBell means using infrastructure and model providers. Each one that may encounter protected health information is bound by a written agreement, including a BAA where HIPAA requires it, before it is used in production.

The current categories are cloud hosting and databases, telephony and voice orchestration, speech recognition and synthesis, language models, transactional email, and clearinghouse services for insurance eligibility. A practice can request the current, named subprocessor list at any time, and we will give it to them.

We will give practices with active agreements at least thirty days' notice before adding a subprocessor that will handle protected health information. If you object on reasonable privacy or security grounds we will work with you on an alternative, and if there is not one you may terminate the affected service without penalty.

We do not disclose patient information to anyone else unless the practice directs it, the law requires it, or it is necessary to protect someone from harm. If we are ever compelled to produce patient information, we will tell the practice unless we are legally prohibited from doing so.

08Security

Information is encrypted in transit and at rest. Access to production systems is limited to the people who need it, protected by multi-factor authentication, and logged.

Patient-identifying detail is not placed in email or SMS message bodies. Those messages carry a link, and the patient verifies with a one-time passcode before anything is shown. That is a deliberate design choice: a forwarded email or a phone on a kitchen counter should not expose someone's appointment.

No system is perfectly secure, and we will not pretend otherwise. If a breach of unsecured protected health information occurs, we notify the affected practice on the timeline set in the BAA, with the detail they need to meet their own obligations.

09How long we keep things

Patient information is kept for as long as the practice's agreement with us is in force, and then returned or destroyed as the BAA specifies. A practice can ask us to delete specific records sooner, subject to any retention the law imposes on them.

Practice account records are kept while the account is active. Business and billing records are kept for seven years afterward for tax and audit purposes. Demo and contact enquiries are kept for twenty-four months. Website server logs are kept for thirty days.

10Your rights

If you are a patient and want to see, correct, or delete your health information, contact the practice that treated you. They hold the relationship and the legal obligation under HIPAA, and we act on their instructions. If you reach us directly, we will point you to them rather than act on our own.

California residents have rights under the CCPA as amended by the CPRA, including the right to know what personal information is collected, to have it deleted, to correct it, and to opt out of sale or sharing. We do not sell or share personal information, so there is nothing to opt out of. Medical information governed by HIPAA and by California's Confidentiality of Medical Information Act is largely exempt from the CCPA, and is handled under those laws instead.

Where another state's privacy law applies to us, we honor the rights it gives you. Most health information we handle is regulated under HIPAA and California's Confidentiality of Medical Information Act and is exempt from those state laws, and requests about health information should go to the practice that treated you. To exercise anything that does apply, write to info.y@gbellai.com. We will not treat you differently for asking.

11Children

gBell is sold to healthcare practices, and our website is not directed at children. Practices do treat minors, and when they do, information about a minor patient is protected health information handled under the BAA and under the practice's own policies.

One risk worth naming plainly. In California and elsewhere, a minor can consent independently to certain care, and that information is confidential from their parent. The service does not independently determine whether a given minor consented to confidential care, so an appointment confirmation sent to the number on file could disclose it. Practices are responsible for configuring which patients and appointment types the agent may discuss, confirm, or message about.

12Changes and contact

If we change this policy in a way that materially affects how we handle information, we will update the date at the top and notify practices with active agreements before it takes effect.

Privacy questions, requests, and complaints: info.y@gbellai.com.

gBell is a product of HFM Advisory Services, a California corporation. Questions about this document go to info.y@gbellai.com.