Privacy Policy

Last updated: August 14, 2026

This Privacy Policy describes how Cobalt Speech and Language, Inc. ("Cobalt," "we," "us," or "our") collects, uses, and protects information when you use the SALT platform. We are committed to protecting the privacy and security of all data entrusted to us, including Protected Health Information (PHI) governed by HIPAA.

1. Information We Collect

Account Information

When you create an account, we collect your name, email address, professional credentials, and organizational affiliation. This information is used to verify your identity, manage your account, and communicate with you about the platform.

Clinical Data

You may enter clinical data into the platform, including client names, dates of birth, session notes, therapy goals, progress records, and other information related to your clinical practice. This data is considered Protected Health Information (PHI) and is handled in accordance with HIPAA.

Audio Recordings

The platform allows you to record or upload audio from clinical sessions. Audio files are processed for transcription and analysis. Recordings are encrypted in transit and at rest.

Usage Data

We automatically collect information about how you interact with the platform, including pages visited, features used, session duration, browser type, device information, and IP address. This data is used to improve the platform and is not linked to clinical records. Some of it is collected directly by our analytics provider through cookies set in your browser — see Cookies, below.

Cookies

We use essential cookies to maintain your session and preferences. We also use Google Analytics, which sets its own cookies to measure how the platform is used. Advertising features and cross-site identifiers are disabled, and we do not provide Google Analytics with any identifier that maps to you. The analytics events our application sends report only page templates and predefined categories — never names, email addresses, clinical content, or the identifiers of a client, session, or organization. We do not use advertising cookies.

2. How We Use Your Information

  • Providing the service: Processing clinical data, generating transcriptions, running analyses, and displaying results within the platform.
  • AI processing: Audio recordings and text are processed by AI models to provide transcription, language sample analysis, and articulation assessment. AI outputs are generated solely to support your clinical workflow and are not used for any other purpose.
  • Account management: Authenticating your identity, managing subscriptions, and processing payments.
  • Communication: Sending service-related notifications, security alerts, and subscription updates. We do not send marketing emails without your consent.
  • Platform improvement: Analyzing aggregated, de-identified usage patterns to improve features, performance, and reliability.
  • Legal compliance: Responding to lawful requests from regulatory authorities or as required by applicable law.

3. How We Protect Your Information

  • Encryption: All data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
  • Access controls: Access to PHI is restricted to authorized personnel on a need-to-know basis. Role-based access controls are enforced throughout the platform.
  • Audit logging: All access to clinical data is logged for compliance and security monitoring.
  • Infrastructure: The platform is hosted on SOC 2 Type II certified infrastructure with regular security assessments.
  • Incident response: We maintain an incident response plan and will notify affected users and relevant authorities of any data breach in accordance with HIPAA and applicable state laws.

4. HIPAA Compliance

We operate as a Business Associate under HIPAA when processing PHI on behalf of covered entities. We will execute a Business Associate Agreement (BAA) with your organization before PHI is processed through the platform. Our HIPAA compliance program includes:

  • Administrative, technical, and physical safeguards for PHI.
  • Regular risk assessments and security audits.
  • Workforce training on privacy and security requirements.
  • Documented policies and procedures for PHI handling.
  • Breach notification procedures compliant with the HITECH Act.

5. Data Sharing

We do not sell your data. We share information only in the following circumstances:

  • Service providers: We work with third-party providers for hosting, AI processing, authentication, analytics, and payment processing. All providers are bound by data processing agreements and, where applicable, Business Associate Agreements.
  • Analytics: Our analytics provider receives only usage measurements — no protected health information and no clinical data. It is therefore not a business associate and no Business Associate Agreement applies to it.
  • Legal requirements: We may disclose information when required by law, court order, or regulatory authority.
  • Business transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will notify you of any such change.

6. AI and Machine Learning

  • AI models are used to transcribe audio recordings and provide language and articulation analysis.
  • Your clinical data is not used to train general-purpose AI models. Data processing occurs solely to deliver results for your specific sessions.
  • AI-generated outputs are clinical decision support tools. They do not constitute medical diagnosis or treatment recommendations.

7. Data Retention

  • Clinical data is retained for the duration of your active account and for 90 days following account closure to allow for data export.
  • Audio recordings are retained according to your organization's configured retention policy. You may delete recordings at any time.
  • Usage data we hold is retained in aggregated, de-identified form for up to 24 months.
  • Analytics data held by our analytics provider is retained under that provider's own retention settings and is keyed to a pseudonymous cookie identifier rather than to your account. Because it is not linked to your account, we cannot retrieve or delete individual records from it; you can prevent its collection entirely by blocking analytics cookies in your browser.
  • After the retention period, all data held by us is permanently and irreversibly deleted.

8. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal information we hold about you.
  • Request correction of inaccurate information.
  • Request deletion of your account and associated data.
  • Export your clinical data in a standard format.
  • Restrict or object to certain processing activities.
  • Withdraw consent where processing is based on consent.

To exercise any of these rights, contact us at privacy@cobaltspeech.com.

9. Children's Privacy

The platform is designed for use by licensed clinical professionals, not by children. While clinical data entered into the platform may relate to minor clients, this data is managed entirely by the clinician and is governed by HIPAA and applicable state laws regarding minors' health information. The platform is not directed to children, accounts are held only by adults, and our analytics provider is not used to collect information from children. We do not knowingly collect personal information directly from children under 13.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or through the platform at least 30 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.

11. Contact

If you have questions about this Privacy Policy or our data practices, contact us at:

STAGINGNo real PHI / student data