Cursive Privacy Policy
Effective date: August 27, 2026
This Cursive Privacy Policy (this "Policy") describes the privacy practices of Tide Medical LLC, a Wyoming limited liability company doing business as Cursive Health ("Cursive," "we," "us," or "our"), for the Cursive wound-care documentation application and related services (collectively, the "Services"). Cursive is used by licensed healthcare professionals and their organizations. Because Cursive handles patient information on behalf of healthcare organizations, different rules apply to patient PHI and to information about clinical users.
1. Definitions and Scope
1.1 Customer and Authorized User
"Customer" means the healthcare organization that has entered into an agreement with Cursive for the Services. "Authorized User" means a licensed healthcare professional or authorized staff member whom Customer permits to use the Services.
1.2 Protected Health Information
"Protected Health Information" or "PHI" has the meaning given under HIPAA.
2. Patient Information (Protected Health Information)
2.1 PHI Processed for Customers
Clinicians use Cursive to document patient wound care. That patient information—including names, dates of birth, contact details, wound assessments, measurements, notes, and photographs—is Protected Health Information (PHI) under HIPAA.
We process PHI only as a business associate of the healthcare organization that treats the patient, under a signed Business Associate Agreement ("BAA"). This means, in plain terms: the healthcare organization controls the patient record; we use PHI only to provide the Cursive service to that organization; we do not sell PHI; we do not use PHI for advertising; and we disclose it only as the BAA and law permit.
2.2 Patient Requests
If you are a patient with questions about your records, or you wish to exercise your rights to access or amend them, contact the healthcare organization that treats you—they control your record, and we support them in fulfilling your request.
3. Account Information for Clinical Users
For clinicians and staff who use Cursive, we collect the information needed to run their accounts: name, professional credential, work email address, mobile phone number (if provided for verification), sign-in records, and security events. We use this information to operate the Services, secure accounts, and maintain the audit trail that healthcare record-keeping rules require.
4. Cookies and Similar Technologies
The Services store session and working data on the user's device to operate the Services, including for reliability when connectivity is poor. We do not use advertising or cross-site tracking cookies. This on-device data is governed by this Policy.
5. Text Messages (SMS)
If you provide your mobile number and opt in, we send text messages for account verification and sign-in security codes. Message frequency varies with your account activity. Message and data rates may apply. Reply STOP to cancel or HELP for help at any time. Mobile numbers and text-message opt-in and consent information are never shared with or sold to third parties or affiliates for marketing or promotional purposes.
6. De-identified Data
6.1 De-identification
Where our agreement with a healthcare organization permits, we may de-identify patient information using the methods HIPAA prescribes (45 CFR §164.514), so that it no longer identifies any patient and is no longer PHI.
6.2 Uses of De-identified Data
We use de-identified data to improve and develop the Cursive product—including training and improving features such as automated wound measurement, and building aggregate clinical insights and benchmarks across the organizations we serve. We do not attempt to re-identify de-identified data, and we require the same of our service providers.
6.3 Work Product and Patient Record
Models, aggregate statistics, and insights built from de-identified data are Cursive's work product; the treating organization always remains in control of the identifiable patient record itself.
7. Information We Do Not Collect or Use
We do not sell any personal information—patient or clinician. We do not use PHI to train advertising systems or share it with data brokers. We do not serve ads. We do not track users across other companies' websites or apps.
8. Security
We are built for healthcare data: encryption of data in transit and at rest; an append-only clinical record in which corrections create new versions rather than overwriting history; audit logging of activity on the record; access limited to authenticated, authorized users of the treating organization; and infrastructure hosted with providers under HIPAA business associate agreements. No system is perfectly secure, but security is a design requirement of every part of Cursive, not an add-on.
9. Service Providers
We use a small number of infrastructure providers (such as cloud hosting and message delivery) to run Cursive. Providers that touch PHI do so under HIPAA business associate agreements. All providers are limited to the minimum necessary to provide their service to us.
10. Data Retention
10.1 Clinical Records
Clinical records are retained according to the treating organization's obligations and instructions under our agreement with them—healthcare records carry legal retention requirements, and the append-only record is designed to satisfy them.
10.2 Clinical-User Account Information
Account information for clinical users is retained while the account is active and afterward as required for audit and legal purposes.
11. Legal Disclosures
We disclose information when required by law—for example, in response to a valid legal demand—and, for PHI, only in the ways HIPAA and our BAA permit. Where allowed, we notify the affected organization before disclosing.
12. Breach Notification
If a breach of unsecured PHI occurs, we notify the affected healthcare organization without unreasonable delay as HIPAA and our BAA require, so the organization can meet its notification duties to patients and regulators.
13. Children's Privacy
Cursive accounts are for licensed professionals and authorized staff aged 18 and over. Patient records may describe the care of minors; that information is PHI handled under Section 2 and is never used for any other purpose.
14. Changes to This Policy
If we make material changes, we will post the updated Policy at this page with a new effective date and give notice through the application or to affected organizations.
15. Contact
Questions about privacy at Cursive:
Tide Medical LLC (d/b/a Cursive Health)
3000 S. Hulen St., Ste. 124-173, Fort Worth, TX 76109
privacy@cursive.health