How we protect patient data.

What we collect, what we discard, how the record is encrypted, and who can see it.

Audio never storedDe-identified by defaultEncrypted in transit and at rest
The recording

Session audio is not stored.

Most clinical AI records the session and keeps the file. We do not. Speech is transcribed in memory, the words carry forward into the record, and the recording is dropped where it was made.

VOICEtranscribeIN MEMORYTEXT · KEPTsleeping better, stillanxious about workRECORDAUDIO · DISCARDEDnever written to diskno session archive to hold or hand over

No recording archive

Audio is transcribed and then discarded. There is no library of session recordings on our systems.

Consent before the microphone

Capture is opt-in per patient. Turn it off and everything else still works.

The same rule in the journal app

Speech becomes text you can edit. The audio is not retained.

Identity

Records are held under a code, not a name.

Identifiers are removed on the way in, including inside free text, where they usually survive.

In the consulting roomthe clinician sees their patient
In our systemsthe record holds a code
NameAanya Rao
Namept_8f2a41c9
Date of birth12 March 1991
Date of birthage band 30 to 39
Contactaanya.r@mail.com · +91 98•••
Contactremoved
AddressIndiranagar, Bengaluru
Addressregion only
Session textthe merger at Acme has me up at 3am
Session textthe merger at [ORG] has me up at 3am

The filter runs before storage, not after. In our database a patient is a code, and the identity behind it stays encrypted.

Defence in depth

Four layers around one record.

Four controls, each assuming the one outside it has already failed.

1234ONE RECORD
  1. 1NetworkTLS in transit, private cloud isolation
  2. 2StorageEncrypted at rest, encrypted backups
  3. 3IdentityPatients held as encrypted identities
  4. 4AccessScoped roles, every read logged
We hold ourselves to
  • We do not keep the recording
  • Identifiers are stripped before storage
  • A patient is a code in our database
  • Model improvement uses de-identified data only
  • Patient data is never sold
  • No advertising trackers in the app
  • Nothing enters the record unreviewed
Clinical safety

Every clinical decision stays with the clinician.

Empaithy highlights patterns for review. It does not diagnose or predict a crisis, and nothing enters the chart without a person approving it.

Third parties

Sub-processors.

Third-party AI and infrastructure providers help run the service, and data may be processed outside your country. The list is current, and you are told before it changes.

Cloud hosting and storageEncrypted clinical recordsConfirmed per engagement
Transactional emailAccount email addresses onlyConfirmed per engagement
Error and uptime monitoringNo clinical contentConfirmed per engagement

Each vendor is named in the data processing agreement.

Governance

Compliance and agreements.

HIPAA-ready with a BAA, GDPR-aligned with a DPA, SOC 2 Type II in progress.

HIPAA · BAA availableSOC 2 Type II in progressGDPR · DPAAudit logs

Questions about security?

Write to us and the right person on our team will answer.