ChartGuard
Last updated: June 11, 2026
ChartGuard is an AI-powered EMS PCR narrative analysis service operated by Polsia. Our platform analyzes patient care report (PCR) narratives to help EMS agencies identify documentation gaps, billing deficiencies, and QA/QI issues before claims are denied.
Contact: privacy@polsia.app · chartguard.polsia.app
When you register, we collect your email address and (optionally) your name. Payment processing is handled entirely by Stripe; we do not store credit card numbers.
Critical design principle: ChartGuard does not store the content of your PCR narratives. When you submit a narrative for analysis, we compute a SHA-256 cryptographic hash of the narrative text and store only that hash alongside your user ID, timestamp, and document hash. The original narrative text never leaves your device and is never persisted to our servers.
We store: SHA-256 hashes (not content), timestamps, user IDs, document metadata hashes, and analysis scores (billing readiness, QA/QI). No patient names, DOBs, addresses, SSNs, diagnosis codes, or treatment details are ever stored.
We collect anonymized usage analytics via a first-party beacon (polsia.com/api/beacon). This tracks page views and session identifiers for product improvement only. It does not collect or associate any PHI.
We do not use your submitted narratives to train or fine-tune AI models. AWS Bedrock HIPAA-eligible infrastructure is used; no customer data is used for model training under any circumstances.
Narrative content is never retained. Only SHA-256 hashes and audit metadata are kept for regulatory compliance purposes. Audit logs are retained as long as your account is active, plus 7 years for HIPAA compliance.
When you delete your account, all data associated with your account is permanently removed within 30 days. This is your right to erasure under NY SHIELD Act.
We do not sell, rent, or share your data with third parties for marketing purposes. Data shared with third parties is limited to:
You have the right to:
To exercise your right to erasure, contact privacy@polsia.app or use the account deletion feature in the app. Deletion completes within 30 days.
We use session cookies (httpOnly, sameSite=strict, secure in production) to maintain your authenticated session. These are essential for authentication and cannot be disabled without logging you out.
Analytics cookies are first-party only and do not track PHI. They can be opted out by contacting privacy@polsia.app.
We implement:
ChartGuard is built on HIPAA-eligible AWS infrastructure. A Business Associate Agreement (BAA) is included with every paid plan. We do not access, use, or disclose Protected Health Information (PHI) beyond what is necessary to provide the analysis service. No model training occurs on any customer data.
ChartGuard complies with the New York SHIELD Act and NYDPA. We maintain reasonable administrative, technical, and physical safeguards for personal information. A data breach notification will be provided to affected users within 72 hours of discovery, as required by law.
We will notify users of material changes to this policy via email and a notice on the platform. Material changes take effect 30 days after notice.
For privacy concerns, data deletion requests, or BAA requests: privacy@polsia.app