Last updated August 2026
When you register we store your name, email address, and any professional details you provide (phone number, medical registration number, specialty, institution). Your password is stored only as a bcrypt hash.
When you use the product we store the clinical records you create: patients, encounters, transcripts and their translations, clinical notes, generated documents, dictations, uploaded files, and your conversations with the AI.
Your patients, encounters and dictations are visible only to your account. This is enforced on the server for every read and write, not merely hidden in the interface. Administrators of your deployment can access records for support and audit purposes.
Audio is captured only while you have explicitly started transcription, in short segments, and is sent to the configured AI provider to be transcribed. Segments containing no speech are discarded in your browser and never leave your device. We retain the resulting text with the encounter; we do not retain the audio.
Patient consent is your responsibility. Before recording any consultation you must obtain and document the patient's consent in the manner required by your institution and by Ethiopian law.
To perform a task you request, relevant content is sent to the AI provider you selected. Which provider handled each request is recorded and shown alongside the output. Provider credentials are held on the server and are never delivered to your browser. Provider retention and training practices are governed by that provider's own terms - review them before processing identifiable patient data.
Every action that changes a record is logged with the acting user, the route, the affected entity, the source IP and the outcome. Logs exist for security and clinical accountability.
You can edit or delete your records in the product, and export generated documents at any time. To request full deletion of your account and its data, contact us.