PostureAI

Privacy Policy

Last updated: April 1, 2026

1. Who we are

Arcstone Solutions LLC, doing business as PostureAI (“PostureAI”, “we”, “us”) provides software that chiropractic practices use to capture, analyze, and report on patient posture. This policy explains what data we collect, how we use it, who we share it with, and the rights you have over it.

2. Data we collect

  • Account data: name, email, practice name, role, and hashed password of people who create accounts.
  • Patient data: names, dates of birth, scan imagery, measured angles, and report files. This data is Protected Health Information (PHI) under HIPAA when uploaded by a covered-entity customer.
  • Usage data: aggregated product-usage events (e.g., “scan completed”) used to improve reliability and features. No PHI is sent to usage analytics.
  • Device data: browser user-agent, IP address, and device type, used for security monitoring and fraud prevention.

3. How we use data

We use collected data only to:

  • Provide and operate the PostureAI service.
  • Generate reports on behalf of our customer practices.
  • Communicate about your account, billing, or material changes to the service.
  • Improve product quality and security.
  • Comply with legal obligations, including HIPAA where applicable.

We do not sell personal information. We do not use PHI to train generalized models, and we do not share PHI with advertisers.

4. Role under HIPAA

For our customer practices that are Covered Entities, PostureAI acts as a Business Associate. We sign Business Associate Agreements (BAAs) with these customers and handle PHI according to the Privacy, Security, and Breach Notification Rules.

5. Data storage and security

Data is stored in AWS US regions; a BAA is available via AWS Artifact. Specific safeguards include:

  • AES-256 encryption at rest with AWS KMS-managed keys.
  • TLS 1.2+ for data in transit.
  • Role-based access control with least-privilege defaults.
  • 15-minute idle session timeouts.
  • Full audit logging retained for at least six years.

6. Sub-processors

We use a small number of vetted sub-processors (hosting, error monitoring, payments, email delivery). A current list, and the BAA status of each sub-processor that may encounter PHI, is available on request.

7. Your rights

Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal information. For patient records, the Covered Entity who uploaded the data is the primary point of contact — PostureAI assists on their direction.

To exercise a right, email privacy@posturegrade.com.

8. Retention

Active customer data is retained for the life of the account. On cancellation, an export is made available for 30 days. Because clinical records are subject to legal and regulatory retention requirements, primary data is retained in accordance with our retention policy rather than deleted immediately. Audit logs are retained for six years as required by HIPAA.

9. Changes to this policy

We will notify account owners by email at least 30 days before material changes take effect.

10. Contact

Privacy questions: privacy@posturegrade.com.