Last updated August 16, 2026
Tomo is built on one hard rule: we never collect, store, or process patient-identifying data. This policy explains the limited information we do handle to run your subscription and the app, and how the parts that touch your own content are designed so that content never lands on our servers.
Tomo is not a HIPAA Business Associate and is architected to stay that way. Our servers do not receive, store, or transmit Protected Health Information (PHI). Your case log lives in your own Notion workspace, and we handle only procedure-level content (technique, attending pearls, template structure) — never patient names, MRNs, dates of birth, or clinical history tied to a person. See our Security & PHI page for the technical detail.
We record privacy-preserving, count-only events (for example, that a brief was opened or a review was completed) to understand product usage. These events never contain your Notion content, patient data, or the text of anything you capture.
When the app reads from your Notion workspace, the request passes through a Tomo proxy that forwards the bytes from Notion back to your browser and never logs, caches, or stores the response. A small, allow-listed set of write operations create or refresh structural and procedure-level content in your own workspace (your case-log setup, a procedure template, your settings-derived configuration). We do not read your case content on the server for any other purpose.
A closed set of optional, procedure-level workflows can send de-identified text to our AI provider (Anthropic) to help draft templates and structure your own notes. Every such call runs through an automated redaction step first, is gated behind a feature flag, and writes only a metadata-only audit record (token counts and timing) — never the prompt or response content, and never patient data.
We rely on these vendors to operate Tomo:
We keep your account and subscription records for as long as your account is active. Your case content is retained in your Notion, under your control — not ours. When you close your account we cancel your subscription and delete or anonymize your Tomo records; your Notion workspace and its contents remain yours.
We use essential cookies for authentication and to remember your timezone, plus privacy-preserving analytics. We do not sell your data or use third-party advertising trackers.
We may update this policy as the product evolves. Material changes will be reflected by the “last updated” date above.
Questions about privacy or a data request? Email rserbin15@gmail.com.