Privacy Policy
Last updated August 31, 2026
1. Introduction and scope
This Privacy Policy describes how Skyflare Technologies, Inc. (“SFT,” “we,” “us”), the Delaware corporation behind Sammy, collects, uses, and shares personal information in connection with our websites and the publicly available Ask service. Services we provide to healthcare-organization customers under a signed agreement are governed by that agreement and, for protected health information, by a Business Associate Agreement — see Section 4.
2. Information we collect
We collect information directly from you and automatically as the Services are used:
- Account and professional information — such as name, professional role, email address or organizational identity, and the credentials used to access the Services.
- Content you submit — such as the questions you ask, the answers returned, and feedback you provide, retained so features like conversation history work.
- Usage and device information — such as log data, IP address, approximate location derived from IP, browser and device type, and how the Services are used, collected for security, operations, and service analytics.
3. Do not submit patient information to the public Ask
The public Ask answers questions from the medical literature and is not designed or offered for patient information. Do not enter patient information — names, dates, record numbers, or any other information that could identify a patient — into it.
Questions submitted to the public Ask are handled as ordinary service data under this policy, not as protected health information — which is exactly why no patient information belongs in them.
4. Health information in customer deployments
Where SFT creates, receives, maintains, or transmits protected health information on behalf of a healthcare-organization customer, it acts as a business associate under a signed Business Associate Agreement and uses that information only to provide the contracted services. Patients’ privacy rights in that information — access, amendment, and an accounting of disclosures — run through the healthcare organization, whose own notice of privacy practices governs, and we support the organization in honoring them as our agreements require.
5. How we use information
We use the information described above to provide, maintain, and secure the Services; operate features such as conversation history; respond to inquiries and support requests; measure and improve the quality of the Services; enforce our terms; and comply with legal obligations.
6. How we share information
We do not sell personal information, we do not share it for third-party or cross-context behavioral advertising, and we do not use it to train models for anyone else. We share personal information only:
- with service providers that process it on our behalf to operate the Services, under contracts that restrict their use of it — including, where the information is protected health information, a Business Associate Agreement;
- with your healthcare organization, where your access to the Services is provided through it;
- as required by law, legal process, or to protect the rights, safety, or security of the Services and their users; and
- in connection with a corporate transaction such as a merger or acquisition, subject to this policy’s commitments.
7. Cookies and similar technologies
The Services use cookies and similar technologies needed for the Services to function — such as keeping you signed in and remembering preferences — and to understand how the Services are used. We do not use them for third-party advertising. Like most services, the Services do not respond to browser “Do Not Track” signals.
8. Security
We maintain administrative, technical, and physical safeguards designed to protect personal information, appropriate to its sensitivity, including encryption in transit and at rest and role-based access controls. No method of transmission or storage is completely secure, and we will provide notice of incidents as our agreements and applicable law require.
9. Data retention
We retain personal information for as long as needed to provide the Services and for legitimate business or legal purposes, and then delete or de-identify it. You can delete conversations from your history, and closing an account starts removal of the information associated with it. Protected health information held for a customer is retained and returned or destroyed as the customer’s agreements direct.
10. Aggregated and de-identified data
We may create and use aggregated or de-identified data — data that no longer identifies you or any patient — to operate, measure, and improve the Services. We maintain it in de-identified form and do not attempt to re-identify it, except as permitted by law to test whether de-identification holds.
11. Your choices and rights
You may access and update account information, delete conversations, and close your account. Depending on where you live — including under U.S. state privacy laws such as California’s, and under the data-protection law of the European Economic Area or the United Kingdom where it applies — you may have statutory rights to access, correct, delete, or receive a copy of your personal information, and the right not to be discriminated against for exercising them. You may exercise these rights by contacting us; we will verify the request and respond as the law requires, and we will refer requests concerning protected health information held for a healthcare organization to that organization, as our agreements require.
12. International visitors
The Services are operated from the United States, and information we collect is processed and stored there, where the law may differ from the law of your jurisdiction. Where we transfer personal information from other jurisdictions, we do so using safeguards recognized by applicable law.
13. Children
The Services are for healthcare professionals and are not directed to anyone under 18. We do not knowingly collect personal information from children, and we delete any we learn we have collected.
14. Changes and contact
We may update this policy from time to time; material changes will be posted here with a new “last updated” date. Questions go to Skyflare Technologies, Inc., Palo Alto, California, via skyflare.tech.