This session may be recorded to improve the service.Learn more
Skip to main content

Privacy Policy

Policy version 2026-07-22

This policy explains what personal data we process, why, and the rights you have over it. It applies to patients and the caregivers they invite.

1. Who is responsible

The data controller is the healthcare organisation operating this service. They decide why and how your personal data is processed and are your point of contact for any privacy request.

2. What we collect

Account details (name, phone and/or email), the password you set, and security metadata (trusted devices, sign-in times). Health data you create or receive: consultation recordings and their transcripts and summaries, documents you upload, care-path appointments, messages, and survey responses. Where you invite a caregiver, their name and contact details.

3. Why we use it

To provide the service: record and summarise consultations, keep your medical record, let you communicate with your care team, and — only if you choose — share parts of your record with a caregiver. Health data is processed only to deliver these features to you.

4. Legal basis

We rely on your explicit consent to process your health data (GDPR Art. 9(2)(a)), captured when you create your account, where accepting our terms and consenting to health-data processing are two separate choices. Three further purposes are optional and each is consented to separately: sharing your record with a caregiver, sending your voice recordings to our AI provider for transcription, and sending your text, transcripts and documents to our AI provider for analysis. The AI consents are requested the first time a feature would use them, never in advance, and each can be withdrawn on its own in Settings without affecting the rest of the service. You can withdraw consent to health-data processing by deleting your account.

5. Who we share it with

Your care team (your clinician and any caregiver you explicitly authorise). We use a small number of technical sub-processors to operate the service; we do not sell your data or use it for advertising.

The sub-processors that may receive your data are:

  • Hosting provider

    What they do:
    Runs the servers and storage the service operates on.
    What they receive:
    All application data, with health data encrypted at rest.
    Where:
    The region chosen by the data controller.
  • Google (Gemini AI)

    What they do:
    Transcribes and summarises consultation recordings, reads uploaded documents, answers your questions in the assistant, and drafts care-path steps for a clinician to review.
    What they receive:
    Consultation transcripts and summaries, the text of documents you upload, and what you write to the assistant. The consultation audio itself is sent only where the operator has enabled cloud speech-to-text; by default it is transcribed on our own servers and never leaves them.
    Where:
    United States and other regions of Google's infrastructure.
  • OpenReplay (session analytics)

    What they do:
    Records how the app is used so problems can be found and fixed. Active only where the operator has switched it on.
    What they receive:
    Interaction and screen data, with what you type hidden and email addresses and numbers obscured, linked to a pseudonymous identifier rather than your name.
    Where:
    OpenReplay's cloud service (United States), unless the operator hosts it themselves.
  • Resend (email delivery)

    What they do:
    Delivers sign-in codes, reminders and notifications by email. Active only where the operator has configured email delivery.
    What they receive:
    Your email address and the notification text, which never contains medical detail.
    Where:
    United States and the European Union.

Where a sub-processor operates outside the European Economic Area, the data controller must put a data-processing agreement (GDPR Art. 28) and a transfer safeguard (Art. 46) in place before that processing begins. You can request the current documentation from the contact below.

6. How long we keep it

Your medical records are kept for as long as your account exists; deleting your account erases them. Operational data is cleaned up automatically: expired sign-in sessions and audit logs beyond the retention window are purged on a schedule, and orphaned files are removed.

7. How we protect it

Health data is encrypted at rest with per-record keys, access is authenticated and rate-limited, and sensitive actions are logged. Caregiver access is limited to exactly what you grant.

8. If your data is ever breached

If a security incident affects your personal data, we notify the CNIL — the French data protection authority — within 72 hours of becoming aware of it, as the law requires. Where the incident is likely to put you at high risk, we also contact you directly, in plain language, telling you what happened, what data was involved, and what you can do. We keep an internal record of every incident, including those that do not need to be reported.

9. Your rights

You can access and export all of your data (a downloadable archive from the app), correct your profile, withdraw any optional consent individually — caregiver sharing and each AI purpose — and erase your account and all associated data at any time from Settings. You can also restrict processing (GDPR Art. 18): pausing puts your account into a read-only state where nothing new is added, no AI runs and no clinician or caregiver has access, while your data stays stored and exportable, and you can resume whenever you choose. You also have the right to lodge a complaint with your data-protection authority.

10. Cookies

We use strictly necessary cookies to keep you signed in and to protect requests. Any optional analytics are governed by the cookie banner and your choices there. We also use a session-analytics tool (OpenReplay) that may record how the app is used to help us improve it and support you; what you type and sensitive medical content shown on screen are masked, and sessions are keyed to an anonymous identifier rather than your name or email. Where recording requires your consent, it only starts after you accept in the cookie banner.

11. Contact

For any privacy request or question, contact the data controller using the details below.

TODO (operator): add the controller's contact and, where applicable, the Data Protection Officer's contact.

Read our Terms of Use