top of page

TymStep Privacy Policy

Effective Date: 5/29/26
 

1. Overview

TymStep (“we,” “our,” or “us”) provides a digital patient intake system designed for independent healthcare practices. This Privacy Policy explains how information is handled when using TymStep.

By using TymStep, you agree to the terms outlined in this policy.
 

2. Information We Do Not Collect or Store

TymStep is designed with a privacy-first architecture.

We do not collect, store, or retain patient intake data on our servers.

All information entered into the TymStep intake system is processed locally in the user’s browser and remains under the control of the patient.

Once completed, data is either:

  • downloaded as a PDF, or

  • printed directly by the patient

We do not have access to submitted patient intake information.
 

3. How the System Works

When a patient completes an intake form:

  • Data is processed in real time within the browser

  • No patient medical information is transmitted to or stored on TymStep servers

  • Completed forms are generated locally as downloadable PDFs

  • Patients submit their completed forms directly to the healthcare practice using the practice’s chosen process
     

4. Practice Setup Information (Request Setup Form)

When a healthcare practice submits a “Request Setup” form, we may collect basic business contact information such as:

  • Practice name

  • Contact name

  • Email address

  • Phone number

  • Practice type and intake requirements

This information is used solely for:

  • setting up the TymStep system

  • communication regarding onboarding and delivery

  • customer support

We do not sell or share this information with third parties for marketing purposes.
 

5. Cookies and Analytics

The TymStep website may use basic cookies and analytics tools to understand website performance and improve user experience.

These tools may collect non-identifiable information such as:

  • browser type

  • device type

  • general usage patterns

No patient intake data is tracked or stored through cookies or analytics.
 

6. Data Responsibility

TymStep is a digital intake tool, not a medical records system.

Healthcare practices using TymStep are responsible for:

  • receiving patient-submitted intake forms

  • storing and managing patient data after download or submission

  • maintaining compliance with applicable healthcare regulations
     

7. HIPAA Considerations

TymStep is designed to minimize exposure of sensitive patient data by ensuring no patient information is stored on our servers.

However, healthcare practices are responsible for determining their own compliance obligations, including HIPAA or other applicable regulations, based on how they use and store patient data after submission.
 

8. Data Security Approach

Because TymStep does not store patient intake data on servers, the primary security model is based on:

  • local browser processing

  • user-controlled data export (PDF download or print)

This reduces centralized data exposure risks.
 

9. Third-Party Services

TymStep may use third-party services for:

  • website hosting

  • basic analytics

  • form submission handling for setup requests

These services do not have access to patient intake data, as no such data is transmitted or stored by TymStep.
 

10. Changes to This Policy

We may update this Privacy Policy from time to time. Updates will be posted on this page with a revised effective date.
 

11. Contact

For questions about this Privacy Policy or TymStep, please contact:

Email: hello@tymflo.com

bottom of page