Data and security

Clear boundaries for practice business data.

A plain-language account of what AileronMD accepts, how access is limited, and where responsibility remains with the practice.

Data the product is designed for

AileronMD is designed for aggregate practice-level financial and operational metrics. Do not submit patient names, dates of birth, medical record numbers, diagnoses, notes, treatment information, or other patient-identifiable information.

Access controls

Practice accounts can access their own delivered briefings and submitted metrics. Broader administrative access is limited through role-based controls. Client briefing drafts are not released until an administrator completes review and marks them delivered.

AI-assisted analysis

AileronMD uses AI to help produce a structured draft from submitted business metrics. Paid client drafts receive human review before delivery. The instant public demonstration is automated and is labeled accordingly.

Retention and deletion

Submitted metrics and delivered briefings remain available while the account remains active. To request deletion of an account or its associated practice data, contact hello@aileronmd.com. Backup and legal retention requirements may affect timing.

Important limits

The no-PHI boundary is a product rule and user responsibility. AileronMD does not claim that the software can detect every accidental submission. AileronMD does not claim HIPAA certification, a BAA, SOC 2, HITRUST, or other security certifications on this page.

Questions about an intended data set or deletion request can be sent to hello@aileronmd.com. Product boundaries are described further on the legal page.