Privacy Policy

Privacy Policy

This policy explains what data PatientFill and Blaze collect, why we collect it, how we store and share it, and how you can access or delete it.

Last updated: September 9, 2026|Effective: September 9, 2026

At a glance

  • Who we are: PatientFill operates patientfill.com and the Blaze advertising product. We are the data controller for account data and a data processor for the business data you connect.
  • What we do: Blaze connects to your advertising and business accounts (Google Ads, Meta, Google Search Console, Gmail, Google Calendar) and uses AI agents to analyze performance and manage campaigns on your behalf.
  • We never sell your data, and we never use it for advertising to you or to anyone else.
  • Google user data is used only to provide the features you explicitly connect, in line with the Google API Services User Data Policy, including the Limited Use requirements. See Section 4.
  • You stay in control: you can disconnect any integration, export your data, or delete your account at any time. See Section 10.

1. Who We Are and What This Covers

PatientFill ("PatientFill", "we", "us") provides an AI-powered business operations platform at patientfill.com. Our primary product, Blaze, is an AI paid-advertising manager: it connects to a business's advertising accounts, audits them, and creates, monitors, and adjusts advertising campaigns under limits the business sets.

This Privacy Policy applies to the patientfill.com website, the PatientFill web application, the Blaze product, and any PatientFill application that authenticates with Google (collectively, the "Services"). It does not apply to third-party services you connect to PatientFill, which are governed by their own privacy policies.

Two kinds of people appear in this policy. Customers are the businesses and their staff who hold a PatientFill account. End customers are the individuals who interact with our customers' advertising, forms, and websites. For customer account data we act as a controller. For end-customer data that a customer brings into the platform, we act as a processor on that customer's instructions.

2. Information We Collect

We collect the following categories of information.

a. Information you give us

CategoryExamplesWhy we need it
Account identityName, email address, password hash or federated sign-in identifier, profile photo, job title, organization nameTo create and secure your account and identify you within your organization
Business profileCompany name, website, industry, locations, service menu, operating hours, target geography, brand voice and creative guidelinesTo let AI agents produce advertising and content that matches your business
Billing informationBilling contact, plan, subscription status, and a payment token held by StripeTo process subscription payments. We do not store full card numbers on our systems
Content you submitChat messages to AI agents, documents, images, knowledge-base items, notes, campaign briefs, approvals and rejectionsTo perform the tasks you ask for and to keep an audit trail of decisions
Support communicationsEmails and messages you send usTo answer your questions and improve the product

b. Information from services you connect

When you connect a third-party account, we collect data from that service using the permissions you grant. You choose which services to connect, and you can disconnect any of them at any time. Connected services may include Google Ads, Google Search Console, Gmail, Google Calendar, Meta (Facebook and Instagram) Ads, Slack, HubSpot, Stripe, QuickBooks, Twilio, SendGrid, and LinkedIn. Section 4 describes Google data specifically.

c. End-customer data our customers bring in

Businesses using Blaze receive advertising leads and manage client relationships in the platform. That can include an end customer's name, email address, phone number, the ad or form they responded to, appointment details, and message history. We process this data solely to provide the Services to the business that collected it. We do not use it for our own purposes, and we do not sell it.

d. Information collected automatically

  • Usage and product analytics: pages viewed, features used, actions taken, session timestamps, and referring page, tied to your account so we can operate and improve the Services.
  • Device and connection data: IP address, browser type and version, operating system, device type, and language.
  • Security and audit logs: sign-in events, permission changes, integration connections, and every read or write an AI agent performs against your data or your ad accounts.
  • Cookies and similar technologies: strictly necessary cookies for authentication and session integrity, and analytics cookies to understand product usage. We do not use third-party advertising or cross-site tracking cookies on patientfill.com.

3. How We Use Information

We use the information described above only for these purposes:

  • Provide the Services — authenticate you, render your workspace, and run the AI agents and automations you configure.
  • Manage advertising on your behalf — read campaign structure and performance from your ad accounts; generate audits, recommendations, budgets, keywords, audiences, and creative; and apply changes within the autonomy limits and spending caps you set.
  • Deliver leads and results — route leads generated by your campaigns into your workspace and, where you enable it, into your connected CRM, email, or calendar.
  • Measure and report — produce performance reporting, briefings, and insights for your organization.
  • Billing — process subscriptions, meter usage, and prevent billing abuse.
  • Security, safety, and integrity — detect and investigate fraud, abuse, and unauthorized access, and maintain audit trails for the automated actions taken on your accounts.
  • Support and service communications — respond to requests and send operational notices such as approval requests, spend alerts, and account changes.
  • Legal compliance — meet our legal obligations and enforce our Terms of Use.

We do not sell personal information, share it for cross-context behavioral advertising, use your business data or your end customers' data to advertise to them on our own behalf, or use Google user data for advertising purposes of any kind.

Legal bases (EEA/UK). We process data to perform our contract with you (providing the Services and billing), on the basis of our legitimate interests (security, abuse prevention, product improvement), with your consent where required (certain integrations and non-essential cookies), and to comply with legal obligations.

4. Google User Data

PatientFill uses Google APIs. This section explains exactly what Google user data we request, how we use it, how we store it, and who we share it with. We only ever request the scopes needed for the specific Google integration you choose to connect, and Google shows you those scopes on its consent screen before you approve them.

a. Scopes we request and how each is used

Google OAuth scopeIntegrationHow PatientFill uses the data
.../auth/userinfo.emailGoogle Sign-InRead your Google account email address to create your PatientFill account, identify you at sign-in, and link the connected integration to the right user.
.../auth/userinfo.profileGoogle Sign-InRead your basic profile (name and profile picture) to populate your PatientFill user profile.
.../auth/adwordsGoogle AdsRead your Google Ads account structure, settings, keywords, budgets, and performance metrics to audit and report on your account; and, when you grant that level of autonomy, create and modify campaigns, ad groups, keywords, ads, budgets, and bidding on your behalf.
.../auth/webmasters.readonlyGoogle Search ConsoleRead your verified site properties and search performance data (queries, impressions, clicks, position) to inform SEO and advertising recommendations.
.../auth/indexingGoogle Search ConsoleSubmit URLs from sites you own to the Google Indexing API when you publish or update a page through PatientFill.
.../auth/gmail.modifyGmailRead, compose, send, and organize messages in the connected mailbox strictly to perform the email tasks you configure — for example, identifying and replying to inbound lead enquiries, and applying labels. We do not read messages for any purpose other than executing the features you enable.
.../auth/calendar.readonlyGoogle CalendarRead your calendar events to determine availability for appointment booking and scheduling features.
.../auth/calendar.eventsGoogle CalendarCreate, update, and cancel calendar events on your behalf when you use PatientFill's booking and scheduling features.

b. How we store Google user data

  • OAuth access tokens and refresh tokens are encrypted at rest using AWS Key Management Service (KMS) and are never exposed to other customers or displayed in the interface.
  • Google data is stored in our databases in the United States on Amazon Web Services infrastructure, logically partitioned so that each organization's data is isolated from every other organization's.
  • All data is encrypted in transit with TLS and at rest with AES-256.
  • We retain only what the connected feature needs. Google Ads and Search Console performance metrics are cached to produce reporting and trend analysis. Gmail message content is processed transiently to execute the task you configured and is not retained in bulk; only the resulting record (for example, a lead record or an activity log entry) is stored.

c. How you can revoke access and delete Google data

You can disconnect a Google integration at any time from Command Center → Integrations in PatientFill, which deletes the stored tokens and stops all further access. You can also revoke PatientFill's access directly from your Google Account at myaccount.google.com/permissions. To have Google user data already stored in PatientFill deleted, disconnect the integration and email privacy@patientfill.com; we will delete it within 30 days.

Limited Use Disclosure

PatientFill's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, PatientFill:

  • Uses Google user data only to provide and improve the user-facing features that you have explicitly connected and authorized.
  • Does not transfer or sell Google user data to third parties, except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to affected users.
  • Does not use Google user data for serving advertisements of any kind, including retargeting, personalized advertising, or interest-based advertising.
  • Does not allow humans to read Google user data unless we have your affirmative agreement for specific messages, it is necessary for security purposes such as investigating abuse, to comply with applicable law, or the data is aggregated and anonymized for internal operations.
  • Does not use Google user data to develop, improve, or train generalized or non-personalized artificial intelligence or machine learning models.

5. AI Processing and Model Providers

PatientFill's AI agents are built on large language models operated by enterprise AI providers. To perform a task, the relevant portion of your data — for example a campaign's performance metrics, a business profile, or the text of a message you asked an agent to handle — is sent to the model provider over an encrypted connection and processed to produce a result.

  • No model training on your data. Our agreements with our model providers prohibit them from using data submitted through our API accounts to train their models. We also do not use your data to train our own models.
  • Google user data is never sent to a model for training purposes, consistent with the Limited Use Disclosure above.
  • Scoped retrieval. When an agent searches your knowledge base or records, the search is confined to your own organization's data. Agents cannot retrieve another organization's data.
  • Human oversight. Actions that spend money or change a live advertising account are subject to autonomy settings, spending caps, and approval requirements that you control, and every action is written to an audit log.

Our current model providers are Anthropic and OpenAI, both operating under commercial terms with zero data-retention-for-training commitments.

6. How We Share Information

We do not sell your personal information and we do not share it for cross-context behavioral advertising. We share data only in the following circumstances:

  • Within your organization. Data in your workspace is visible to other members of your organization according to the roles and permissions your administrators set.
  • With services you connect. When you direct us to, we send data to your connected platforms — for example, publishing a campaign to Google Ads or Meta, or writing a lead into your CRM.
  • With service providers (subprocessors) who process data on our behalf under contract, listed below.
  • For legal reasons. When required by law, subpoena, or other legal process, or where we believe disclosure is necessary to protect rights, safety, or property.
  • In a business transfer. In connection with a merger, acquisition, financing, or sale of assets, subject to this policy and with notice to affected users.

Our subprocessors

ProviderPurposeData processed
Amazon Web ServicesCloud hosting, database, storage, authenticationAll platform data (United States)
AnthropicAI model inferenceTask-relevant content sent to agents
OpenAIAI model inference and embeddingsTask-relevant content sent to agents
StripePayment processingBilling contact and payment details
Google LLCAds, Search Console, Gmail, Calendar APIsData within the scopes you authorize
Meta PlatformsMeta Ads and Messenger APIsAd account and lead data you authorize
Amazon SES (AWS)Transactional and notification email deliveryRecipient email address and message content

7. Data Retention

  • Account data is retained for as long as your account is active.
  • After account closure, we delete or anonymize your data within 90 days, except where we must retain it longer for legal, tax, or accounting obligations.
  • OAuth tokens are deleted immediately when you disconnect an integration or delete your account.
  • Google user data is deleted within 30 days of your request or of disconnecting the relevant integration.
  • Audit and security logs are retained for up to 24 months to support dispute resolution, financial reconciliation of advertising spend, and security investigations.
  • Blaze (Paid Ads) decision traces are retained indefinitely for platform security, spend reconciliation, and incident investigation. Access is limited to platform administrators with capability grants. Ordinary account data continues to follow the 90-day closure window above.
  • Backups are retained on a rolling basis and are cycled out within 35 days, after which deleted data no longer exists in any backup.

8. Security

  • Encryption. TLS 1.2+ in transit; AES-256 at rest. Third-party credentials and OAuth tokens are additionally encrypted with AWS KMS.
  • Tenant isolation. Every record is partitioned by organization, and authorization is enforced on every read and write.
  • Access control. Role-based access within your organization; least-privilege access for our staff, granted only when required for support or security investigation and logged when used.
  • Auditability. Every automated action taken on your connected accounts is recorded with its actor, inputs, and outcome.

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and any applicable regulator as required by law.

9. International Data Transfers

PatientFill is operated from the United States and your data is processed there. If you access the Services from outside the United States, you understand that your data will be transferred to and processed in the United States. Where we transfer personal data from the EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses, together with appropriate technical and organizational safeguards.

10. Your Rights and Choices

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Delete your data (the "right to be forgotten").
  • Export your records, contacts, and workspace configuration in a machine-readable format.
  • Object to or restrict certain processing, and withdraw consent at any time.
  • Opt out of the sale or sharing of personal information — noting that we do not sell or share personal information as those terms are defined under the CCPA/CPRA.
  • Non-discrimination for exercising any of these rights.

Some of these you can exercise directly in the product: you can edit your profile, and connect or disconnect any integration from Command Center → Integrations, which immediately deletes the stored credentials for that service. To request a copy of your data, correct it, or delete your account, email privacy@patientfill.com. We respond within 30 days and may need to verify your identity first.

If you are an end customer of a business that uses PatientFill, please direct your request to that business, which controls the data. If you contact us directly, we will forward your request to them and assist as their processor. EEA and UK users also have the right to lodge a complaint with their local supervisory authority.

11. Children's Privacy

The Services are business tools intended for use by adults. They are not directed to children, and we do not knowingly collect personal information from anyone under 16. If we learn that we have collected such information, we will delete it. If you believe a child has provided us with personal data, contact privacy@patientfill.com.

12. Changes to This Policy

We may update this policy as the Services evolve. When we do, we will revise the "Last updated" date at the top of this page. If the changes are material — for example, a new category of data or a new purpose of use — we will notify you by email or through an in-product notice before the change takes effect. Continued use of the Services after a change becomes effective means you accept the revised policy.

13. Contact Us

For privacy questions, data requests, or to exercise any of the rights described above:

Privacy enquiries: privacy@patientfill.com

Legal notices: legal@patientfill.com

Website: https://patientfill.com

We aim to respond to all privacy requests within 30 days.

See also our Terms of Use.