WoundFlowWoundFlow

Privacy Policy

Last updated: June 2026

WoundFlow (“WoundFlow,” “we,” “us”) provides wound-care documentation software for healthcare providers, delivered through our web application and iOS/Android mobile applications (collectively, the “Services”). This Privacy Policy explains what information we collect, how we use it, and the choices available to you. It applies to clinicians and staff who use the Services and to visitors of our website.

1. Information we collect

Account information. When a provider creates or uses an account, we collect an email address and authentication credentials.

Patient health information (PHI). When clinicians use the Services to document care, they enter and upload information about their patients, which may include patient names, medical record numbers, dates of birth, contact details, wound assessments, measurements, clinical notes, and wound photographs, videos, and audio notes. This information is entered by the clinician at their discretion and is processed by WoundFlow on the provider’s behalf.

Device permissions. The mobile app may request access to the camera, microphone, and photo library to capture and attach wound media. These are used only when you choose to capture or attach media; access can be declined and the app continues to function.

Marketing inquiries. If you submit our “Request Access” form, we collect the contact and organization details you provide.

Usage and technical data. We may collect limited technical information (such as app version and error diagnostics) to operate and improve the Services.

To measure which marketing sources drive app installs, our Android app reads the Google Play install referrer (a first-party click token) on first launch and sends it to our own servers. We do not use third-party advertising/attribution SDKs, we do not collect your device advertising identifier for this, and we do not share this data with third parties for advertising. We do not sell personal information or PHI.

2. How we use information

We use information only for these purposes (App Functionality). We do not use PHI for advertising.

Install attribution

Install attribution is done first-party via the Google Play install referrer—a campaign click token, not an advertising identifier—which our Android app reads on first launch. The data stays on our own infrastructure; we do not use a third-party measurement partner, and we do not collect an advertising ID. This is used only to understand which marketing sources drive installs, never for selling data and never combined with patient health information.

3. HIPAA and protected health information

WoundFlow is intended for use by HIPAA-covered entities and their workforce. When we process PHI on behalf of a provider, we act as a Business Associate and will enter into a Business Associate Agreement (BAA) with the covered entity as required by HIPAA. Providers are responsible for obtaining any patient authorizations required by law and for using the Services in compliance with their own obligations.

4. How information is stored and protected

Information is stored on managed cloud infrastructure (Microsoft Azure) in the United States. We use encryption in transit (HTTPS/TLS), access controls, and authentication to protect data. No method of transmission or storage is 100% secure, but we work to protect information using industry-standard safeguards.

5. Sharing of information

We share information only with: (a) service providers that host and operate the Services under contract (e.g., cloud hosting); (b) the provider organization and its authorized users to whom the records belong; and (c) as required by law or to protect rights and safety. We do not sell personal information or PHI.

6. Data retention and deletion

We retain information for as long as needed to provide the Services and as required by the provider’s record-keeping and legal obligations. Providers may request export or deletion of records associated with their account by contacting us.

7. Your choices and rights

Depending on your role and jurisdiction, you may have rights to access, correct, or delete information. Because much of the data is PHI controlled by the provider organization, requests are generally directed through that organization. Contact us using the details below and we will assist or route your request appropriately.

8. Children

The Services are intended for use by healthcare professionals and are not directed to children. We do not knowingly collect information from children except as part of a patient’s record entered by a clinician for treatment purposes.

9. Changes to this policy

We may update this Privacy Policy from time to time. We will revise the “Last updated” date above and, where appropriate, provide additional notice.

10. Contact us

WoundFlow
2101 E St Elmo Rd, Bldg 1, Ste 100, Austin, TX 78744, United States
Toll-free: (833) 968-6353 (1-833-WOUND-53)
Web: https://woundflow.com