Last Updated: 10.7.2025
This Privacy Policy explains how AI Regent Inc. (dba “Doc Talk,” “we,” “us,” “our”) collects, uses, discloses, and protects information when you:
We primarily serve U.S. users. If you are a patient using our Services at the direction of your Provider, your Provider’s HIPAA Notice of Privacy Practices governs how your Protected Health Information (PHI) is used and disclosed by the Provider. Our handling of PHI as a Business Associate is governed by our Business Associate Agreement (BAA) with the Provider. This Privacy Policy supplements (but does not replace) the BAA for PHI processing. If there is a conflict:
We do not use automated decision-making to make medical diagnoses or treatment decisions. AI outputs are assistive and require human review.
We disclose information consistent with HIPAA, our BAA, and applicable law:
We do not “sell” PHI. We do not sell or share PHI for targeted advertising. For non-PHI personal information, see State Privacy Disclosures.
We use cookies, pixels, and SDKs to:
You can manage cookies via your browser/app settings. Some features may not work if you disable essential cookies. We honor Global Privacy Control (GPC) signals where legally required (e.g., California).
We employ industry-standard safeguards, including encryption in transit and at rest, strict access controls, role-based permissions, audit logging, vulnerability management, and incident response. No system is 100% secure; please safeguard your credentials and notify us promptly of suspected unauthorized access.
The Services are not directed to children under 13 and we do not knowingly collect their personal information without verifiable parental consent or Provider authorization consistent with law. If you believe a child provided information to us, contact ollie@doctok.co.
Email, SMS, Calls
Access, Correction, Deletion (Non-PHI) Depending on your state, you may request:
Submit requests via:
We will verify your identity and respond within statutory timeframes. Agents must provide authorization and we may require user verification.
PHI Requests
For medical records, corrections, or restrictions relating to PHI, please contact your Provider directly. We process PHI as a Business Associate and cannot fulfill PHI requests without Provider direction.
California (CPRA/“CCPA”)
We provide the following CPRA categories disclosure for the past 12 months (non-PHI context):
| Category | Examples | Collected | Disclosed for Business Purposes | Sold/Shared |
|---|---|---|---|---|
| Identifiers | Name, email, IP | Yes | Vendors; security; analytics | No sale, possible share for ads (opt-out available) |
| Customer Records | Account details | Yes | Hosting/support | No |
| Internet/Network | Device IDs, usage | Yes | Analytics/security | Possible share (opt-out) |
| Geolocation (coarse) | Approximate | Limited | Security/fraud | No |
| Professional/Employment | Role, org | Yes | Verification | No |
| Inferences | Product preferences | Limited | Product improvement | No |
| Sensitive PI | Login, auth | Yes | Security/auth | No "sale/share" |
Colorado, Connecticut, Virginia, Utah
You may have rights to access, correct, delete, obtain copies, and opt out of targeted advertising, sale, or profiling for significant decisions. Use the request methods above. If we deny your request, you may appeal by emailing ollie@doctok.co with subject “Privacy Appeal.”
Nevada
We do not sell covered information; Nevada residents may still email ollie@doctok.co to record an opt-out preference.
Our Services and data systems are primarily located in the United States. If you access the Services from outside the U.S., you understand your information may be transferred to, stored, and processed in the U.S., where laws may differ from those in your jurisdiction. If we later intentionally market to the EEA/UK/Switzerland, we will appoint an EU/UK representative (as applicable) and implement appropriate transfer mechanisms (e.g., SCCs).
Third-party services linked or integrated with the Services (e.g., EHRs, cloud telephony, payments, analytics) are governed by their own privacy policies and terms. We are not responsible for their practices.
We may update this Privacy Policy from time to time. We will post the updated version with a new Effective Date and, where required, provide additional notice. Your continued use of the Services after changes are posted constitutes acceptance.
For PHI handled on behalf of your Provider, please contact your Provider for their HIPAA Notice and to exercise HIPAA rights. You may also submit a complaint to the U.S. Department of Health & Human Services, Office for Civil Rights without fear of retaliation.
Frequently asked questions
Everything you need to know about our medical billing solution
We maintain full compliance with HIPAA and other security regulations, ensuring that all patient data is handled and stored securely. Our platform employs state-of-the-art encryption and robust access controls to protect sensitive information. Additionally, we conduct regular security audits and updates to safeguard against potential threats.
In contrast to traditional telehealth platforms that center around one-time urgent care visits, our service offers physician-led, message-based support, allowing for continuous, asynchronous communication to address any clinical questions.
We take security and compliance seriously. DocTalk is fully HIPAA compliant with end-to-end encryption, secure user authentication, comprehensive audit logs, and regular security assessments. We sign Business Associate Agreements (BAAs) with all our clients.
We offer full customer support via phone, email, and chat. All clients receive access to our comprehensive knowledge base, video tutorials, and regular webinars.