Data & Privacy
I will not tell you that your data never leaves your device, because for some recordings that is not true. This page is the inventory: what goes up while a summary is being made, what is held, and when it is deleted. The privacy policy and the terms of service say these things in binding language; this page says them plainly.
What the servers hold
When you record on a current iPhone in English, the words become text on the phone while you talk and the audio file stays with you. On the other paths (another language, an older phone, or a phone too warm to keep up) the audio itself is uploaded and transcribed by AssemblyAI. In every case the transcript text, and the contents of any document you upload, go to OpenAI (GPT-6 Luna) to be annotated and turned into your visit summary, with Google’s Gemini 3.1 Pro standing in when either call fails. Google’s Gemini API still does some of the other steps (reading the documents you upload, marking who is speaking in a transcript made by AssemblyAI, translating into Spanish, and summarizing a recording that turns out not to be a visit), so on those paths it sees that text too. It also draws the illustrations on your summary’s slides when there isn’t already a matching one to reuse from a shared pool of past images; that request carries only the name of your main condition, not the transcript.
The copies on my side are working copies, not a library. They exist to build the summary and get it onto your phone, they are deleted once your device confirms it saved that summary, and a scheduled sweep runs behind that to remove anything left over and redact the record it came from. Your durable library, the profiles and summaries and clinical details you keep, lives on your device and syncs through your own iCloud account, encrypted and managed by Apple. It was never on my server to delete.
What joining holds
Reading this site holds nothing at all: it is static files on a content network with nothing running behind it. Joining does hold something, so here is that inventory too: one row in one table, carrying your name, your email address, your two answers, and the version of the consent line you agreed to. A single function writes that table and nothing else can reach it. Its logs record reason codes and row identifiers by design, so your name, your address, and your answers are not in them.
Taking it back out
A note to privacy@patientscribe.app takes it back out. That is one row, deleted by hand. If an invite had already gone out, your name and email are also sitting with Apple as a TestFlight tester entry, and that entry is removed separately. Then I write back to tell you it is done.