Skip to content

Legal

Privacy Policy

Last updated · September 10, 2026

Intake AI (“Intake AI,” “we,” “us,” or “our”) is committed to protecting the privacy and security of the information entrusted to us.

This Privacy Policy explains how we collect, use, process, store, disclose, and protect information when you visit our website, use the Intake AI platform, connect third-party systems, use our workflows, APIs, browser extension, or other products and services that reference this Privacy Policy (collectively, the “Services”).

Intake AI provides AI-powered software for clinical research operations. Our Services allow authorized users to connect and work across clinical research documents, systems, and data; ask questions across those sources; generate and manage study materials; and automate supported clinical research workflows.

A separate Chrome Extension Privacy Policy provides additional information about data collected and processed specifically through the Intake AI Chrome Extension.

01

Who This Privacy Policy Applies To

This Privacy Policy applies to:

  • visitors to our website (“Visitors”);
  • organizations that purchase, evaluate, or otherwise use Intake AI (“Customers”);
  • employees, contractors, investigators, coordinators, and other individuals authorized by a Customer to use Intake AI (“Authorized Users”); and
  • individuals whose information may be contained in documents, systems, records, or other data submitted to or accessed through the Services.

When Intake AI processes Customer Content on behalf of a Customer, the Customer generally determines why and how that information is used. Depending on the applicable law and contractual arrangement, Intake AI may act as a data processor, service provider, contractor, or business associate with respect to that information.

For information we collect for our own business purposes, such as account information, website analytics, security information, and business communications, Intake AI may act as the data controller or business responsible for that information.

02

Information We Collect

We may collect the following categories of information.

Contact and Account Information

When you request a demonstration, communicate with us, create an account, or use the Services, we may collect information such as your name, email address, organization, job title, telephone number, account identifier, role, and other information you choose to provide.

We may also process authentication information necessary to securely authenticate you and associate you with the appropriate organization and permissions.

Customer Content

Customers and Authorized Users may upload, submit, generate, connect, or otherwise make information available to Intake AI. Customer Content may include:

  • study protocols;
  • informed consent forms;
  • schedules of assessments;
  • case report forms and source-document templates;
  • standard operating procedures;
  • budgets and financial documents;
  • staffing records, training records, and site documentation;
  • clinical trial and study information;
  • communications and files from connected systems;
  • information contained in CTMS, EDC, eSource, document-management, email, and other clinical research systems;
  • prompts, questions, instructions, comments, corrections, and feedback submitted by users;
  • information generated by Intake AI in response to Customer Content; and
  • other documents, records, structured data, or unstructured data a Customer chooses to provide.

Depending on how a Customer uses the Services, Customer Content may contain personal information, sensitive personal information, clinical information, or protected health information (“PHI”).

Information From Connected Services

If you authorize Intake AI to connect to a third-party service, we may receive and process information from that service according to the permissions you grant.

Connected services may include email systems, document-storage platforms, clinical trial management systems, clinical research platforms, public databases, and other applications supported by Intake AI.

We may process authorization tokens, identifiers, metadata, files, messages, records, or other content necessary to provide the connected functionality.

Your use of a third-party service remains subject to that provider’s terms and privacy practices.

Browser Extension Data

If you use the Intake AI Chrome Extension, we may process information from supported browser-based clinical research systems, including relevant page content, form structure, field information, screenshots of an active supported page, workflow instructions, interaction results, user corrections, and technical information necessary to provide the Extension’s functionality.

For additional information, please review the Intake AI Chrome Extension Privacy Policy.

Usage and Technical Information

We may automatically collect technical and usage information such as:

  • IP address;
  • browser and device type;
  • operating system;
  • timestamps;
  • session identifiers;
  • pages or features used;
  • application events;
  • error and diagnostic information;
  • workflow status and completion information;
  • system performance and reliability information; and
  • security and audit events.

We use this information to operate, secure, troubleshoot, evaluate, and improve the Services.

Cookies and Similar Technologies

Our website and web applications may use cookies and similar technologies for authentication, security, preferences, analytics, performance measurement, and other operational purposes.

Where required by applicable law, we will provide appropriate choices regarding non-essential cookies.

03

How We Use Information

We may use information collected through the Services to:

  • provide, operate, maintain, and improve Intake AI;
  • authenticate users and enforce organization- and role-based permissions;
  • retrieve, organize, index, search, and analyze Customer Content;
  • generate AI-powered answers, summaries, mappings, documents, recommendations, and other outputs requested by users;
  • automate supported clinical research workflows;
  • connect and synchronize authorized third-party systems;
  • populate, configure, or otherwise interact with supported clinical research systems at the direction of authorized users;
  • provide source citations, provenance, audit trails, and workflow verification;
  • provide customer support;
  • detect, investigate, and prevent security incidents, abuse, fraud, or unauthorized access;
  • monitor reliability, performance, and product usage;
  • conduct research, testing, evaluation, quality assurance, and product development;
  • develop, train, fine-tune, evaluate, validate, and improve artificial intelligence and machine-learning systems as described below;
  • communicate with Customers and users about the Services;
  • comply with applicable laws, regulations, court orders, and legal obligations; and
  • establish, exercise, or defend legal rights.
04

Artificial Intelligence and Model Training

Intake AI uses artificial intelligence and machine-learning technologies to provide and improve the Services.

We may use information collected through the Services to develop, train, fine-tune, evaluate, test, validate, and improve our AI models, machine-learning systems, retrieval systems, automation systems, and related technology.

Depending on the applicable Customer agreement, permissions, and legal requirements, information used for these purposes may include Customer Content, prompts, outputs, document content, workflow interactions, browser-derived information, user corrections, feedback, model results, execution traces, and other information generated through use of the Services.

We may also create aggregated, de-identified, transformed, or derived datasets for product development, model evaluation, benchmarking, reliability testing, and similar purposes.

We do not use information for model training where doing so is prohibited by applicable law, a Business Associate Agreement, a Data Processing Agreement, another written customer agreement, or other binding restriction.

Where Customer Content constitutes PHI subject to HIPAA, our ability to use that information is governed by the applicable Business Associate Agreement and applicable law. We will not use PHI for model training or unrelated product-development purposes where such use is prohibited by those requirements.

Data may also be processed by third-party artificial intelligence providers when necessary to provide AI functionality. Their processing is governed by our applicable agreements with those providers.

Because machine-learning systems are developed from large datasets, deleting particular source data may not necessarily remove statistical effects from a model that was previously trained using that data, to the extent retention of those effects is permitted by applicable law and contract.

05

How We Share Information

We do not sell Customer Content or PHI to data brokers or advertisers, and we do not use Customer Content to serve third-party targeted advertisements.

We may disclose information in the following circumstances.

Service Providers and Subprocessors

We use third-party companies to provide infrastructure and functionality required to operate Intake AI. These may include providers of cloud computing and storage, databases, authentication, security, analytics, communications, support, and artificial intelligence services.

Depending on the product and deployment, providers may include companies such as Amazon Web Services, MongoDB, Clerk, OpenAI, and other vendors used to deliver the Services.

These providers receive information only as reasonably necessary to perform services for us and are subject to applicable contractual and confidentiality obligations.

Connected Services

When you instruct Intake AI to retrieve information from or transmit information to a connected system, we share information with that system as necessary to carry out your request.

Customer Organizations

If your account is associated with a Customer organization, administrators and other authorized members of that organization may have access to information associated with your account and use of the Services, according to the Customer’s permissions and policies.

Legal and Safety Reasons

We may disclose information where we reasonably believe disclosure is necessary to comply with applicable law, regulation, legal process, or governmental request; protect the security and integrity of the Services; investigate fraud or abuse; protect the rights or safety of Intake AI, our Customers, users, or others; or establish, exercise, or defend legal claims.

Corporate Transactions

Information may be transferred as part of a merger, financing, acquisition, reorganization, bankruptcy, sale of assets, or similar corporate transaction, subject to applicable legal requirements.

06

Sensitive Information, Clinical Research Data, and PHI

The Services are designed for use in clinical research environments and may process sensitive or regulated information.

Customers are responsible for ensuring that they have the necessary authority, permissions, notices, consents, and legal basis to provide information to Intake AI and instruct us to process it.

Where Intake AI processes PHI on behalf of a HIPAA covered entity or business associate pursuant to a Business Associate Agreement (“BAA”), the BAA governs our handling of that PHI. If there is a conflict between this Privacy Policy and an applicable BAA regarding PHI, the BAA controls.

Customers may also be subject to research protocols, informed-consent requirements, institutional policies, sponsor requirements, IRB requirements, GDPR, state privacy laws, FDA requirements, or other obligations independent of Intake AI. Customers remain responsible for determining whether their use of the Services satisfies those requirements.

07

Data Storage and Retention

We retain information for as long as reasonably necessary to provide the Services, fulfill the purposes described in this Privacy Policy, comply with contractual and legal obligations, maintain security and audit records, resolve disputes, and enforce our agreements.

Retention periods may differ depending on the type of information, Customer instructions, contractual requirements, regulatory requirements, and how the Services are configured.

Customer Content may be deleted or returned following termination of a Customer relationship in accordance with the applicable Customer agreement and our retention procedures.

Certain records may be retained longer where required for security, fraud prevention, auditability, legal compliance, dispute resolution, backup integrity, or other legitimate purposes.

Aggregated or de-identified information that can no longer reasonably be associated with an identifiable individual or Customer may be retained for longer periods.

08

Data Security

We use technical and organizational safeguards designed to protect information against unauthorized access, disclosure, alteration, destruction, and loss.

These safeguards include encryption of data in transit and at rest, authenticated access, role- and permission-based controls, logging and monitoring, access restrictions, security testing, and other measures appropriate to the nature of the information being processed.

Access to sensitive information is restricted to authorized personnel and systems with a legitimate need for access.

No method of transmitting or storing information is completely secure, and we cannot guarantee absolute security.

09

Your Privacy Rights and Choices

Depending on where you live and the nature of our relationship with you, you may have rights to request access to, correction of, deletion of, or a copy of your personal information; object to or restrict certain processing; withdraw consent where processing is based on consent; or exercise other rights available under applicable privacy law.

Where Intake AI processes personal information on behalf of a Customer, requests concerning that information may need to be directed to the Customer that controls the information. We will assist Customers with eligible requests as required by applicable law and contract.

California residents may have additional rights under the California Consumer Privacy Act and related laws, including rights to know, access, correct, or delete certain personal information and to receive equal service when exercising applicable privacy rights.

To submit a privacy request, contact us using the information in Section 14.

10

International Data Transfers

Intake AI and our service providers may process information in the United States and other jurisdictions.

Where required, we use appropriate legal mechanisms and contractual protections for international transfers of personal information.

11

Third-Party Websites and Services

The Services may contain links to, integrate with, or operate alongside third-party websites and services.

This Privacy Policy does not govern the independent privacy practices of those third parties. We encourage you to review their privacy policies before providing information to them.

12

Children’s Privacy

Intake AI is designed for businesses and clinical research professionals and is not intended for use by children.

We do not knowingly permit children under 13 to create Intake AI accounts or knowingly collect personal information directly from children through our website for consumer purposes.

Clinical research data processed on behalf of Customers may include information relating to minors where a Customer is legally authorized to process that information. In such circumstances, Intake AI processes the information on behalf of the Customer and subject to the applicable agreement and legal requirements.

13

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our Services, technology, business practices, or legal requirements.

When we make changes, we will update the “Last Updated” date above. Where required by law or where changes materially affect how we use personal information, we will provide additional notice.

14

Contact Us

For questions, concerns, or privacy requests relating to this Privacy Policy or Intake AI’s data practices, please contact us at:

If you are contacting us about information controlled by a Customer organization, please identify that organization so that we can appropriately route your request.

Questions

Security questionnaire, a BAA to review, or a privacy request? Write to us and we will route it to the right person.

hello@useintake.ai