01Who we are
Stephens AI LLC is a Kansas limited liability company that builds internal software and AI systems for independent healthcare practices. In this policy, "Stephens AI," "we," "us," and "our" refer to Stephens AI LLC. "You" refers to any visitor to stephensai.co, anyone who contacts us, and any client we work with.
Stephens AI is the party responsible for the information described in this policy. Contact details are provided at the end of this page.
02Scope of this policy
This policy applies to our public website and to our own business records: messages sent to us, calls booked with us, and the contact information we keep for prospective and current clients.
It does not govern the data handled within a client engagement. When we build or operate a system for a practice, the practice remains the owner of and responsible party for its data. Our handling of that data is governed by the signed agreement between us, including any Business Associate Agreement. Where a signed agreement and this policy differ, the signed agreement controls.
03Information we collect
We collect only the information described below.
Contact form
The contact form asks for your name, your email address, and your message. These are delivered to our business email so that we can reply. No other information is captured by the form.
Scheduling
Our scheduling link is hosted by Calendly. When you book a call, Calendly collects the details you enter and shares them with us so the meeting can be created. Calendly processes that information under its own privacy policy.
Direct correspondence
When you email us, we retain the correspondence, including your name, email address, and any information you provide about your practice, as part of our ordinary business records.
Technical information
- The contact form counts recent submissions per network address in order to limit automated abuse. This count is held briefly in memory and is not written to a database.
- Our hosting provider records standard server logs, which may include an IP address, the page requested, and a timestamp. We use these logs only to operate and secure the site.
04Information we do not collect
The following do not apply to this website:
- Analytics and advertising trackers. The site does not use Google Analytics, advertising pixels, or third-party tracking scripts.
- Tracking cookies. The site does not place advertising or analytics cookies on your device.
- Sale of personal information. We do not sell or rent personal information, and we do not share it for cross-context behavioral advertising.
05Business contact information and outreach
Like most business-to-business firms, we use commercial business-contact databases to identify practices that may benefit from our services, and we may contact those practices by email. The information involved is limited to business contact information: a name, a role, a work email address, and the practice.
We do not build profiles of individuals, we do not combine that information with activity on this website, and we do not use consumer or personal data for outreach.
If you do not wish to receive further contact from us, reply to any message or email alec@stephensai.co, and we will remove your details.
06How we use information
We use the information we collect to:
- Respond to inquiries
- Schedule and conduct calls
- Prepare proposals and deliver contracted services
- Issue invoices and maintain accounting and tax records
- Operate and secure the website
- Comply with legal obligations
For readers in jurisdictions that require a legal basis for processing, we rely on your consent when you contact us, on the performance of a contract when we deliver services, and on our legitimate interest in operating and securing our business.
We do not send marketing newsletters from this website. Should that change, subscription will be opt-in and every message will include an unsubscribe option.
07Service providers
We use established third-party providers to operate our business. Each receives only the information necessary to perform its function.
| Provider | Function |
|---|---|
| Vercel | Website hosting and server logs |
| Resend | Delivery of contact form submissions |
| Google Workspace | Email, calendar, and document storage |
| Calendly | Scheduling |
| Anthropic, OpenAI, and Amazon Web Services | AI services, as described in the following section |
We may also disclose information where required by law, to protect our rights or the safety of any person, or to a successor in connection with a sale or reorganization of the business.
08Use of AI tools
Artificial intelligence tools are part of how we perform our work. We use services from providers including Anthropic, OpenAI, and Amazon Web Services to draft, analyze, write software, and operate the systems we build. Information you share with us, including business information about your practice, may be processed by these tools in the course of our work.
- We do not train or fine-tune AI models on your information, and we do not authorize any provider to do so on our behalf.
- We select providers, service tiers, and account settings intended to keep client information out of model training. Systems we build and operate for clients run on commercial or enterprise services whose terms prohibit the provider from training on the data we submit.
- Protected health information is processed by AI tools only under a Business Associate Agreement, and only within an environment covered by that agreement, as described in the following section.
- We treat AI output as a draft subject to our review. The systems we build are designed so that a person reviews actions with consequences before they take effect.
- We identify the AI providers used in any system we build for you, and we will notify you if those providers change.
By engaging Stephens AI, you consent to our use of these tools in delivering our services.
09Patient information
Do not send protected health information through this website, the contact form, or unencrypted email. These channels are not appropriate for patient information. If such information is sent to us this way, we will delete it and ask you to use a secure channel.
Our approach
Most of the systems we build are designed so that patient information is not involved. Front desk knowledge bases, staff training materials, scheduling rules, bookkeeping, and vendor invoice handling can be built without access to patient records, and that is our default approach.
Business Associate Agreements
We sign a Business Associate Agreement with every healthcare practice we work with, before work begins, whether or not we expect protected health information to be involved.
Where an engagement does involve protected health information, the following also apply:
- The system operates within the practice's own cloud account, under the agreement between the practice and that cloud provider, rather than on infrastructure we own. The account belongs to the practice, and any access granted to us may be revoked by the practice.
- The AI services involved are configured so that the provider does not retain the data after a request is processed and does not use it for model training.
There is no government or industry certification for HIPAA compliance, and we do not claim one. We describe our practices so that a practice and its advisors can evaluate them directly.
10Data retention
- Inquiries that do not become engagements: retained while commercially useful, generally no longer than two years, and deleted thereafter.
- Client records: retained for the duration of the engagement and afterward as required for warranty, tax, and legal purposes, generally seven years for financial records.
- Server logs: retained according to our hosting provider's standard schedule.
You may request earlier deletion of your information as described under Your rights and choices.
11Security
The website is served over an encrypted connection, and we use multi-factor authentication where available. Where a system we build operates within your own accounts, the access it uses is granted by you and may be modified or withdrawn by you at any time.
Access to client systems
Access to client systems is limited to the two founders of Stephens AI. We do not use subcontractors, offshore staff, or an outsourced support desk. Our founders are currently based in the United States and in Asia, and access occurs from both locations over encrypted connections. If this changes, we will notify affected clients.
No method of transmission or storage is completely secure. If a security incident affects your information, we will notify you and any required authority as required by applicable law.
12Your rights and choices
You may request access to, correction of, or deletion of the personal information we hold about you by emailing alec@stephensai.co. We will respond within 30 days.
California residents
You have the right to know what personal information we collect and how it is used, to request its deletion or correction, and not to be discriminated against for exercising these rights. We do not sell or share personal information as those terms are defined under California law.
Residents of the European Economic Area and the United Kingdom
You have the right to access, correct, erase, restrict, or object to the processing of your personal data, and the right to data portability. Where processing is based on consent, you may withdraw that consent at any time. You may also lodge a complaint with your supervisory authority.
13International data transfers
Stephens AI is a United States company, and our service providers are primarily located in the United States, where your information is stored and processed. Because our founders are based in the United States and in Asia, your information may also be accessed from Asia. If you contact us from outside the United States, the privacy laws of the jurisdictions where your information is handled may differ from those of your own. By contacting us, you acknowledge that this transfer is necessary for us to respond.
14Children
This website is intended for businesses. It is not directed to children, and we do not knowingly collect information from anyone under the age of 16. If you believe a child has provided information to us, contact us and we will delete it.
15Changes to this policy
We may update this policy from time to time. The date at the top of this page reflects the most recent revision. Where a change materially affects how we handle information for an existing client, we will notify that client directly.
16Contact
Questions or requests regarding this policy may be directed to either founder:
Stephens AI LLC
A Kansas limited liability company
Alec Stephens, Co-founder: alec@stephensai.co
Jusheen Kim, Co-founder: jusheen@stephensai.co