Privacy Policy
Effective date: May 14, 2026
1. Who we are
COR Perfusion AI (“COR,” “we,” “our”) is an AI assistant designed for cardiovascular perfusionists. COR is operated by Clifton Marschel and is available at perfusion-bot.vercel.app and as an iOS application.
2. Information we collect
- Account information: the email address and password you use to sign in.
- Conversations: the messages you send to COR and the responses generated. By default conversations are retained for 7 days; conversations you pin are retained until you delete them.
- Logbook entries: protocols, case notes, equipment, and other knowledge you save. These are retained until you delete them.
- Schedule and inventory data: any case schedule, equipment inventory, or time-off requests you enter.
- Voice input:when you use voice input, your speech is processed by your device's operating system and transmitted as text. COR does not store audio recordings.
- Uploaded files: any images, documents, or other files you attach are processed to generate responses and may be retained as part of your conversation history.
3. How we use your information
We use your information to provide and operate COR, including: authenticating you, generating AI responses to your questions, retrieving relevant context from your saved knowledge, and improving the quality of the service.
4. Third-party services
COR is built on the following third-party services, each with their own privacy policies:
- Supabase— database and authentication. Your account, conversations, and logbook are stored on Supabase infrastructure.
- Anthropic— language model. Your messages are sent to Anthropic's Claude API to generate responses. Anthropic does not train on API data.
- OpenAI— embedding model. Your messages are converted into numeric embeddings via OpenAI's embedding API to retrieve relevant knowledge from your account. OpenAI does not train on API data.
- Vercel— hosting. The COR web application is hosted on Vercel.
5. Clinical use disclaimer
COR is an educational and reference tool. It is not a medical device, has not been reviewed by the FDA or any other regulatory body, and is not intended for clinical decision-making, diagnosis, or treatment. COR is not HIPAA-compliant. Do not enter patient-identifying information (names, MRNs, dates of birth, or any other PHI) into COR.
6. Data security
All data in transit is encrypted via HTTPS/TLS. Account passwords are hashed and never stored in plain text. We follow industry-standard practices to protect your data, but no system is perfectly secure.
7. Your rights
You can at any time:
- Delete individual conversations or logbook entries from within the app.
- Request deletion of your entire account by emailing the address below.
- Request a copy of the data we hold about you.
8. Children
COR is intended for licensed healthcare professionals and is not directed at children under 18.
9. Changes to this policy
We may update this policy from time to time. The effective date at the top of this page indicates when this version was published.
10. Contact
Questions or requests can be sent to: cliftonmarschel@gmail.com.