Back

Privacy Policy

Last updated: April 15, 2026

1. Data Collected

Samed collects the following data to provide the service: full name, email, medical license number (CRM), medical specialty, patient data (name, contact information, clinical history), medical histories, medical exams (PDFs and images), and payment data processed via Stripe.

2. Use of Data

Data is used exclusively for: patient and appointment management, AI-assisted clinical analysis (OpenAI GPT-4o), payment processing, and continuous improvement of the service.

3. Storage and Security

Data is stored on Supabase (US East region) with encryption in transit (TLS/HTTPS) and at rest. Access to data is isolated per physician via Row Level Security (RLS) in the PostgreSQL database.

4. Third-Party Services

We use the following services: Supabase (database and authentication), Stripe (payment processing), OpenAI (AI-powered clinical analysis), and Vercel (application hosting). Each service has its own privacy policy.

5. User Rights (LGPD)

In accordance with the LGPD (Lei Geral de Proteção de Dados) (Law 13.709/2018), you have the right to: access your personal data, request correction of incomplete or outdated data, request deletion of your data, revoke consent at any time, and request data portability.

6. Contact

To exercise your rights or clarify questions about this policy, contact us by email: privacidade@samed.com.br