Legal

ChiroPad Privacy Policy

Last updated

Effective September 24, 2026

This policy explains how the ChiroPad mobile application for iOS and Android handles information. It is published by Life Systems Software Inc. (“Life Systems Software”, “we”), 2603 Camino Ramon, Suite 200, San Ramon, CA 94583.

ChiroPad is professional software for licensed chiropractic practices. It is not a consumer health app, and it is not intended for use by patients. Accounts are created by the practice that licenses ChiroPad, not by individuals.

1. Our role, and who controls your health information

ChiroPad is a client application for a chiropractic practice’s own ChiroPad server. Patient records are created by, belong to, and remain under the control of the practice — the Covered Entity under the U.S. Health Insurance Portability and Accountability Act (HIPAA).

Life Systems Software acts as a Business Associate of that practice and processes protected health information (PHI) only to provide the service, under a Business Associate Agreement with the practice.

If you are a patient, this policy does not govern your records. Requests to see, correct, or delete your health information go to the practice that treats you — they hold the records and the legal obligation to respond. We cannot act on a patient request without instruction from the practice.

2. What the app accesses on your device

ChiroPad asks for these permissions. Each is requested only at the moment the matching feature is used, and each can be declined or later revoked in your device settings — declining disables that feature and nothing else.

PermissionWhy
CameraPhotograph documents and images into a patient’s chart, and scan QR codes
Photo library (read)Attach an existing photo to a patient’s chart
Photo library (add)Save a document from a chart back to your device
MicrophoneDictate SOAP notes, and record video for a chart
Network accessCommunicate with your practice’s ChiroPad server

3. What is stored on your device

ChiroPad keeps only a small amount of non-clinical data on the device:

  • Your display theme, your preferred opening screen, and the Front Desk refresh interval.
  • Transient cached copies of documents you open, so they render without re-downloading.

Authentication tokens are held in memory only and are never written to device storage. Closing the app ends the session.

Patient records are not stored on the device for offline use. Uninstalling the app removes everything ChiroPad has written locally.

4. What is sent to your practice’s server

When you sign in and use the app, information travels between your device and the ChiroPad server your practice uses — by default host.chiropad.com, or a server address your practice specifies. That traffic includes your sign-in credentials, your user account identifier, and the patient chart data you view or enter, including any photographs, video, or audio you capture.

All communication uses HTTPS/TLS.

Where that server is hosted, how long records are retained, and who may access them are determined by your practice’s agreement with us and its own policies.

5. Speech recognition for dictation

⚠ Read this section if you dictate clinical notes.

When you use dictation, the audio you speak is converted to text by Microsoft Azure AI Speech, using a speech token issued by your practice’s ChiroPad server. Your dictated audio is transmitted to Microsoft for processing.

Because dictated clinical audio is PHI, Azure AI Speech is used under Microsoft’s HIPAA Business Associate Agreement, and runs in the same Azure subscription that hosts the ChiroPad service.

ChiroPad does not use your device’s built-in speech recognition (Apple or Google) for clinical dictation, and does not send dictated audio to those services. If your practice’s server does not provide a speech token, dictation is unavailable and notes must be typed.

Dictated audio is not retained by ChiroPad after the resulting text is inserted into the note.

6. What we do not do

ChiroPad contains no advertising, no analytics, no crash-reporting, and no tracking software of any kind. Specifically:

  • We do not track you across other apps or websites, and the app declares no tracking domains.
  • We do not build advertising or marketing profiles.
  • We do not sell, rent, or share personal information or PHI with third parties for their own purposes.
  • We do not use patient data to train machine-learning models, and our speech-recognition provider does not use it to train theirs.

7. Security

Data in transit is protected with HTTPS/TLS. Access requires authentication against your practice’s server, and what each user can see is governed by the roles and permissions their practice assigns. Files that ChiroPad stores on the device are held in the app’s private storage area and are protected by the operating system’s device encryption.

No system is perfectly secure. If we become aware of a breach affecting PHI, we will notify the affected practice in accordance with HIPAA’s Breach Notification Rule and our Business Associate Agreement.

8. Accounts and deletion

ChiroPad accounts are issued and withdrawn by the practice that licenses the software, not by individual users. To have your user account deactivated, contact your practice administrator.

Requesting account and data deletion. If you cannot reach your practice administrator, or if you are a practice that wishes to terminate service and have its data deleted or returned, email privacy@lifesystemssoftware.com with the practice name and the user account concerned. We will confirm the request with the practice before acting on it, because the practice — not Life Systems Software — controls the records.

What is removed, and what we must keep to meet legal or contractual obligations, follows the terms of the practice’s Business Associate Agreement. Deactivating a user’s login does not delete the patient records that user created; those belong to the practice.

9. Children

ChiroPad is licensed to healthcare professionals and is not directed at children, who are not permitted to hold accounts. Charts maintained by a practice may contain records of minor patients; those records are controlled by the practice as described in Section 1.

10. Changes to this policy

We may update this policy as the software changes. The effective date above will change, and material changes affecting practices will be communicated to them directly.

11. Contact

Life Systems Software Inc.
2603 Camino Ramon, Suite 200
San Ramon, CA 94583, USA

Email: privacy@lifesystemssoftware.com