Last Updated: January 2026
Guroo AI, Inc. ("Guroo Health," "we," "us," or "our") respects your privacy and is committed to protecting personal data and health information entrusted to us. This Privacy Policy describes how we collect, use, disclose, and safeguard information when healthcare organizations and their authorized users (collectively, "Customers" or "Users") use the Guroo Health platform, including our AI-driven and voice-driven knowledge management tools, SOP manager, and configurable productivity and back-office applications (the "Platform").
This Privacy Policy is designed for use in healthcare environments, including medical practices, clinics, hospitals, and related healthcare organizations.
This Privacy Policy applies to:
This Privacy Policy does not apply to third-party websites, services, or applications that may integrate with or be linked from the Platform.
Where Guroo Health processes Protected Health Information (PHI) on behalf of a Customer, we act as a Business Associate (as defined under the U.S. Health Insurance Portability and Accountability Act of 1996, "HIPAA") or equivalent service provider under applicable data protection laws, and our handling of such data is governed by a separate Business Associate Agreement (BAA) or data processing agreement.
We may collect information that Customers or Users provide directly, including:
When enabled by the Customer, the Platform may collect:
Voice features are configurable and may be disabled or restricted by the Customer at any time.
Depending on Customer configuration and use, the Platform may process limited patient-related or clinical context information, including PHI, strictly as instructed by the Customer. Guroo Health does not require Customers to upload PHI unless necessary for a specific, authorized use case.
We may automatically collect certain technical information, including:
This information is used to operate, secure, and improve the Platform.
We use collected information to:
AI models used within the Platform:
We do not use Customer PHI to train generalized AI models without explicit contractual authorization.
We may share information only as follows:
Information is made available to the Customer organization and its authorized Users according to access controls and roles defined by the Customer.
We may share information with trusted third-party service providers who perform services on our behalf, such as cloud hosting, transcription, analytics, and security services. These providers are contractually obligated to protect data and use it only as instructed.
We may disclose information if required to do so by law, regulation, court order, or governmental request, or to protect the rights, safety, or security of Guroo Health, Customers, or others.
In the event of a merger, acquisition, restructuring, or sale of assets, information may be transferred as part of the transaction, subject to appropriate confidentiality protections.
Guroo Health implements administrative, technical, and physical safeguards designed to protect information, including:
No system can be guaranteed to be 100% secure; however, we take reasonable and appropriate measures consistent with healthcare industry standards.
We retain information only for as long as necessary to:
Retention periods for PHI are governed by the applicable BAA or data processing agreement. Upon termination of services, data will be returned or deleted in accordance with contractual terms.
Depending on applicable law, Users may have rights to:
Requests should be directed to the Customer organization, which controls data access and permissions. Guroo Health will assist Customers in responding to verified requests as required by law.
Guroo Health is headquartered in the United States. Our engineering, operations, and customer success teams, as well as certain service providers, may be located in other countries, including the Philippines.
When personal data or PHI is accessed or processed outside the United States, such processing is performed solely to support U.S.-based healthcare Customers and is subject to:
We implement appropriate technical and organizational measures to ensure that cross-border access does not compromise the confidentiality, integrity, or availability of data.
The Platform is not intended for use by individuals under the age of 18, and we do not knowingly collect personal information from children.
We may update this Privacy Policy from time to time. Material changes will be communicated through the Platform or other appropriate means. Continued use of the Platform after updates constitutes acceptance of the revised Privacy Policy.
If you have questions about this Privacy Policy or our privacy practices, please contact:
Guroo AI, Inc.
Email: privacy@guroo.health
Address: 600 Park Offices Drive, Suite 300, #4128 Durham, NC 27713
When providing services to healthcare organizations, Guroo Health acts as a Business Associate to Covered Entities, as defined under HIPAA. We process PHI solely on behalf of and in accordance with written instructions from our Customers and applicable Business Associate Agreements (BAAs).
Guroo Health may use or disclose PHI only to:
We maintain safeguards consistent with the HIPAA Security Rule, including administrative, physical, and technical protections designed to:
All subcontractors that may access PHI are required to enter into written agreements imposing HIPAA-compliant obligations consistent with Guroo Health's role as a Business Associate.
Guroo Health's AI-driven and voice-driven features are designed to support healthcare staff by:
These features are intended as decision-support tools and do not provide medical advice or replace professional judgment.
Depending on Customer configuration, AI and voice features may process:
Customers retain full control over:
AI outputs should be reviewed by Users prior to reliance or action.
Voice recordings and transcriptions are retained only as long as necessary to provide requested functionality and in accordance with Customer-defined retention settings and contractual obligations.
What Guroo Health Does
Guroo Health provides an AI-enabled platform that helps healthcare organizations manage SOPs, operational knowledge, and back-office workflows.
Who We Serve
Enterprise hospital systems, multi-site practices, and small clinics.
Our Role
We act as a Business Associate when handling PHI and process data only on Customer instructions.
AI & Voice
AI and voice features support staff efficiency and do not replace professional judgment. Customer PHI is not used to train generalized AI models.
Security
We apply healthcare-grade security controls aligned with HIPAA requirements.
Your Data
Customers control their data, configurations, and access permissions.
Questions
Contact us at privacy@guroo.health