Nemira is a clinic operations platform used by independent healthcare providers to manage bookings, patient communication, financing options, and billing. This notice describes what we collect, why we collect it, how we store and share it, and how you can revoke access.
Contact information (name, email, phone), inquiry and visit details (treatment interest, preferred date and time, chart notes authored by the clinic), financing inputs (treatment amount, term preference, self-reported credit range, employment status, state), and the data we receive from connected third-party services that a clinic chooses to link, such as QuickBooks Online.
To route booking requests to the clinic you select, compute sample financing payment options, maintain your account, deliver communications you have asked for, sync invoice and payment data into the clinic's accounting system when they have authorized it, and operate basic platform features. We do not sell personal information to advertisers.
If you give a clinic your mobile number when booking or joining a waitlist, you may receive appointment reminders, confirmations, waitlist offers, and, where you agreed, occasional recall or promotional texts from that clinic. Message frequency varies. Message and data rates may apply. Reply STOP to any message to opt out, or HELP for help.
We do not sell or share your mobile phone number, or your SMS opt-in consent, with third parties or affiliates for their own marketing purposes. Your number is shared only with our messaging carrier (Telnyx) for the sole purpose of delivering the messages you asked for.
The clinic assistant and voice-to-SOAP charting run on Amazon Bedrock (Anthropic's Claude models) and Amazon Transcribe, both covered by our AWS Business Associate Agreement. Protected health information processed by these features stays inside our AWS environment under the BAA. Your data is never used to train the AI models. We do not send patient data to any vendor without a BAA. Chart notes and transcripts are part of the patient record and are deletable on the same terms as the rest of that record.
Clinics can connect their QuickBooks Online company file to Nemira. The connection is established by the clinic owner using Intuit's standard OAuth 2.0 flow. We never see the clinic's Intuit password. The clinic can disconnect at any time from Settings, QuickBooks, Disconnect, and also from inside QuickBooks Online under Apps, Manage my apps.
With the clinic's authorization, Nemira requests the QuickBooks Online accounting scope. We use this access to read chart of accounts, customers, items, and invoices so the clinic can map Nemira's services to QuickBooks accounts, and to write invoices, payments, and credit memos that reflect activity recorded inside Nemira. We do not read or write payroll, time tracking, or 1099 contractor data.
We store the OAuth access token, refresh token, the realm identifier of the connected company, and the timestamps of when the connection was created and last synced. Access and refresh tokens are encrypted at rest using AES-256-GCM with a key held in our server-side configuration and never exposed to the browser. Tokens are decrypted in memory only for the duration of an outbound API request to Intuit. We retain these records while the connection is active. When a clinic disconnects, we revoke the refresh token with Intuit and delete the stored tokens within seven days. Aggregate sync history (timestamps and counts, no QuickBooks field values) is retained for thirteen months for audit and support, then deleted.
Clinics can request a copy or deletion of QuickBooks-derived data we hold about their company by emailing support@nemira.app. Patient-facing data that originates in QuickBooks (for example, an invoice line) is treated under the same rules as the rest of the patient's record.
When a clinic enables Stripe for payments, Telnyx for SMS, AWS SES for email, or other integrations, those providers receive the minimum data needed to perform their function (for example, a payer's card details flow directly to Stripe and are not stored on Nemira). Each provider operates under its own privacy notice, and the clinic remains the controller of the underlying patient data.
Nemira runs on Fly.io and stores data in Amazon Web Services, both in the United States. Aurora Postgres holds the database, S3 holds file uploads, Amazon SES sends email, and the AI features run on Amazon Bedrock and Amazon Transcribe. Protected health information stays inside AWS and Fly, each covered by a Business Associate Agreement. Error monitoring (Sentry) and rate limiting (Upstash) receive only scrubbed, non-clinical data.
Account and booking data are retained while the account is active and for a period afterwards consistent with the clinic's recordkeeping obligations. Encrypted backups roll off on a thirty-five day cycle. Audit logs are retained for thirteen months. Specific deletion requests are honored within thirty days, subject to legal holds.
When the platform connects to real lenders, additional disclosures will appear at the time of application, including credit pull authorization, FCRA permissible purpose, and an electronic-signature consent. Those disclosures do not apply yet because financing offers shown today are estimates and not offers of credit.
Questions, access requests, deletion requests, or anything else: support@nemira.app.
Last updated: 2026-07-16.