Chrome Extension Privacy Policy

Updated: May 26, 2026

1. Scope

This policy describes how the EvidenceMD AI Scribe Chrome Extension (the "Extension") collects, uses, stores, and shares data. The Extension is a companion to the EvidenceMD web application at evidencemd.ai and is intended only for licensed healthcare clinicians who operate under a Business Associate Agreement ("BAA") with EvidenceMD Inc. For data handling on the EvidenceMD web application, see our main Privacy Policy.

2. Single purpose

The Extension has a single purpose: AI medical scribe — capture audio of patient encounters and assist clinicians with clinical documentation inside their EHR. The Extension does not perform unrelated functions, run advertising, or include third-party analytics SDKs.

3. Data the Extension handles

The Extension acts on the clinician's direction. Each data flow below is initiated only by an explicit clinician action in the Extension UI; no flow runs in the background or without the clinician's instruction.

DataWhen it is collectedWhere it goesStored at rest in the Extension?
Microphone audio of patient encountersOnly while the clinician is actively recording in the widgetEvidenceMD transcription service over TLSNo — held in memory only, cleared on stop
Transcription textWhen the clinician clicks Generate noteEvidenceMD note-generation service over TLSNo
Generated clinical notesShown to the clinician; pushed to an EHR field only when the clinician clicks Push to EHREvidenceMD services over TLS; EHR field via in-page DOM write that the clinician focusedNo
EvidenceMD authentication cookieRead once per backend call to authorize the clinicianSent only to EvidenceMD as an Authorization: Bearer headerNo — re-read per request from the EvidenceMD domain cookie jar
Text and form-field values from the active EHR or web page(current tab only, clinician-triggered)Only when the clinician clicks Run CDI/UR on this pageEvidenceMD CDI/UR review service over TLSNo
Audit metadata (event name, timestamp, extension version, session id)Per backend call, for HIPAA audit loggingEvidenceMD audit log; no PHI includedNo

The Extension does not read EHR page content automatically. The CDI/UR on-page review is a clinician-triggered action; it captures text and form-field values from the current tab, up to roughly 95,000 characters, and sends it to the same CDI/UR review endpoint the EvidenceMD web app uses.

Microphone access is gated by Chrome's native permission prompt. The Extension cannot capture audio until the clinician explicitly grants microphone access to the Extension, and recording only begins after the clinician clicks the Record button inside the widget.

4. How we use the data

Audio, transcripts, generated notes, and page text submitted to CDI/UR are processed solely to provide the AI medical scribe service to the authenticated clinician who initiated the action. EvidenceMD does not use this data to train AI models, to serve advertising, or for any purpose unrelated to producing or reviewing clinical documentation for the clinician who recorded or submitted it.

5. Data sharing

We share Protected Health Information (PHI) only with subprocessors that are strictly necessary to operate the medical-scribe service and that are bound by a Business Associate Agreement (BAA) with EvidenceMD. We do not sell, rent, or transfer PHI to advertising networks, data brokers, or any third party for unrelated purposes. We do not transfer, use, or sell user data for personalized advertising, to determine credit-worthiness, or for lending purposes. We do not allow humans to read user data except (a) with the clinician's explicit consent (for example, a support ticket they file), (b) when required by law, or (c) as necessary for security investigations.

A current list of subprocessors that may process PHI on our behalf is available on request from founders@evidencemd.ai.

6. Limited Use compliance statement

EvidenceMD's use of information received via Chrome extension APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. We use this information solely to provide the single, user-facing AI medical-scribe purpose described in section 2 above.

7. Data security in transit and at rest

All network traffic between the Extension and EvidenceMD services is TLS 1.2 or higher. The Extension stores no PHI at rest in the browser. The authentication token used for backend calls is never persisted inside the Extension; it is re-read from the EvidenceMD cookie jar for each call so that signing out of the EvidenceMD web app immediately revokes the Extension's access. Backend storage is encrypted at rest.

8. Permissions and why we request them

PermissionWhy the Extension needs it
cookiesRead the EvidenceMD authentication cookie from evidencemd.ai so the Extension can call the EvidenceMD backend on the clinician's behalf without re-prompting for a password. Filtered strictly to the EvidenceMD domain.
offscreenHost the browser's MediaRecorder to capture encounter audio. Manifest V3 service workers cannot host MediaRecorder.
tabsOpen the EvidenceMD sign-in tab when authentication is needed; read the current tab's URL to route the toolbar action between popup and in-page widget based on whether the page accepts content scripts; re-attach the Extension's bundled content script to already-open EHR tabs after install or update so the toolbar opens without a page reload.
alarmsPeriodically tear down the offscreen document while it is idle, to release the microphone and free memory.
scriptingRe-inject the Extension's own bundled content script into already-open EHR tabs after install or update. Never used to execute remote or generated code; the injected file is shipped inside the Extension package and reviewed by the Chrome Web Store.
host_permissions for EvidenceMD services and standard http(s) web pagesRead the EvidenceMD authentication cookie, call the EvidenceMD backend, and open the widget on any browser-based EHR, charting page, or demo page the clinician chooses. EvidenceMD requests broad https://*/* and http://*/* access because hospital-hosted EHR URLs are not predictable in advance; the content script is lightweight and writes to a page only after the clinician clicks Push to EHR.

9. Data retention and deletion

The Extension itself does not retain patient data — there is nothing stored inside the browser to delete. PHI captured by the Extension is sent to EvidenceMD services and retained per the BAA between EvidenceMD and the clinician's practice. To request deletion of server-side data, contact founders@evidencemd.ai.

10. Children's privacy

The Extension is intended for use by licensed healthcare clinicians only. It is not directed at children and we do not knowingly collect personal information from anyone under 18.

11. GDPR (EU users)

Where GDPR applies, the legal basis for processing is the clinician-as-data-controller's instruction to provide the medical scribe service. EU users may exercise access, rectification, and erasure rights by contacting founders@evidencemd.ai.

12. CCPA (California users)

We do not sell personal information.

13. Changes to this policy

Material changes will be announced via the EvidenceMD web application and reflected here with an updated date. The EvidenceMD main Privacy Policy governs the EvidenceMD web product; this page governs the Chrome Extension only.

14. Contact us

EvidenceMD Inc.
8 The Green #17911
Dover, DE 19901
Email: founders@evidencemd.ai

This Chrome Extension Privacy Policy is effective as of the date listed above and applies only to the EvidenceMD AI Scribe Chrome Extension.

Chrome Extension Privacy Policy | EvidenceMD