Privacy policy
Draft, not yet reviewed by counsel.
This policy explains what HealthPod Scribe does with your data, in plain words. It is written to satisfy the GDPR (we are a German company) and the LGPD (you are likely in Brazil) at the same time, so where the two differ we describe the stricter one.
1. Controller and contact
| Controller | [[LEGAL_ENTITY]], [[REGISTERED_ADDRESS]] |
| Data protection officer / encarregado | [[DPO_CONTACT]] |
| Privacy contact | [[PRIVACY_EMAIL]] |
| Support | scribe@dehaze.de |
| Representative in Brazil | [[BR_REPRESENTATIVE]] |
2. The short version
- We collect as little as we can: your email address is the only thing we require.
- Your recordings and everything derived from them are health data, and we only process them because you explicitly consented. You can withdraw that consent by deleting your data or your account, in the app, at any time.
- Every optional feature is off until you switch it on. Usage statistics, AI training, and visit location are three separate switches, each off by default and each revocable; visit location is described in section 3.7.
- We do not sell your data, we do not advertise, we do not track you across apps or websites, and we use no third-party analytics SDKs.
- Your audio and text are stored in Brazil (São Paulo). Speech-to-text runs in the EU, because the speech service is not available in Brazil — you are asked to consent to that specific transfer.
- Google Cloud's terms, which all our AI processing runs under, bar Google from training its models on your data.
This is what we do today. If it changes, this policy changes with it, and where the change affects what you agreed to, we ask you to agree again (section 9).
3. What we process, why, and on what legal basis
3.1 Account and sign-in
| Data | Why | Legal basis |
|---|---|---|
| Email address | Sign-in, security notices, deletion confirmations | GDPR Art. 6(1)(b) contract · LGPD Art. 7(V) |
| One-time sign-in codes (stored hashed, valid 10 minutes), with the app language you signed in from | Passwordless sign-in, and sending the code email in your language | GDPR Art. 6(1)(b) · LGPD Art. 7(V) |
| Session tokens (refresh tokens stored hashed, 90 days, rotating) | Keeping you signed in | GDPR Art. 6(1)(b) · LGPD Art. 7(V) |
| Content language, reading level | Showing generated text in your language, at the level you choose. The language the app itself is shown in stays on your device | GDPR Art. 6(1)(b) · LGPD Art. 7(V) |
| Service region, set when your account is created | Keeping your data in the storage region your account belongs to | GDPR Art. 6(1)(b) · LGPD Art. 7(V) |
| Consent history — for each consent: kind, granted or withdrawn, exact text version, a fingerprint of the exact wording shown, language, timestamp | Proving that consent was given or withdrawn, as the law requires | GDPR Art. 6(1)(c), Art. 7(1) · LGPD Art. 8 §2 |
3.2 Your visits — health data
This is the core of the app, and all of it is special-category health data (GDPR Art. 9, LGPD Art. 11). We process it only on your explicit consent (GDPR Art. 9(2)(a), LGPD Art. 11(I)), which you give during sign-up and can withdraw at any time.
| Data | Where it comes from |
|---|---|
| Audio recordings (AAC, mono, ~64 kbit/s) | Your microphone, only while a recording is running |
| The moment you confirmed your doctor agreed, plus the version of the consent text shown | The Consent Gate, once per recording |
| Pause markers within a recording | Your pause/resume actions |
| Transcripts, with time-aligned segments and — when the engine provides it — speaker labels | Automatic speech recognition on your audio |
| Your transcript corrections, with full revision history and who wrote each version (you or the engine) | Your edits |
| Summaries, extracted medical terms (medications, dosages, symptoms, conditions, procedures, dates, doctors, institutions, follow-ups), to-dos and their due dates, suggested questions | AI processing of the transcript |
| Your questions in Ask and the answers, with references to transcript passages | Your use of the Ask feature |
| Your visit notes: typed note blocks (thoughts, questions, to-dos, headings) with full revision history and who wrote each version — including notes the AI writes during a recording (live notes, if you switch them on) and afterwards, verdicts on whether your prepared questions were answered, and AI-proposed notes, whether you confirmed or dismissed them | You, and AI processing of your recording; every AI-written note is labelled with its author |
| Visit details: date and time, appointment type, institution, doctor's name, your prep notes | You, and — where the transcript makes them clear — automatic pre-filling that your own edits override |
| Documents you attach (photos, PDFs) | Your camera, photo library, or file picker |
| Visit location, only if you switch it on (off by default) | Your device, as a recording starts (the fix can take a few seconds to arrive), not in the background |
| Technical processing data: durations, file sizes, processing state, error codes, per-call AI usage units, the app version that made the recording | The processing pipeline |
Recording length is capped at 120 minutes, and processing at 120 audio-minutes per day. Over-cap recordings are kept and processed later, not discarded.
3.3 Other people in your recordings
A recording contains your doctor's voice, name, and what they said — and sometimes other people present. That is their personal data, and we process it as part of providing the service to you.
- We ask you to obtain your doctor's agreement before every recording, and the app cannot record without your confirmation that you did.
- We do not create profiles of doctors and do not link recordings across patients. We use what a recording contains about your doctor to produce your own transcript and your own summary.
- When speaker labels are shown, they are best-effort — names only when the conversation itself makes attribution clear, otherwise roles ("physician", "patient", "assistant"), not bare numbers.
- If you switch on AI training, doctor and clinic names are replaced with
[DOCTOR]and[CLINIC]before anything enters the training set. - [[COUNSEL: legal basis for third-party data — see 19_counsel_question_register.md Q-04]]
- If your doctor wants to know what we hold or wants it deleted, they can contact [[PRIVACY_EMAIL]]; in practice this means deleting the recording, which only you can do directly, so we contact you.
3.4 Usage statistics — only if you allow it
Off by default. If you switch it on, the app and our servers send events only: which screen and which feature you used, and when, not the content of your recordings. These are the events: sign-up, onboarding completed, consent gate confirmed, recording started/stopped, upload completed, processing ready/failed, transcript viewed, summary viewed, terms viewed, summary shared (only which class of app), question asked, recording deleted, account deleted, training opt-in changed, recording added to a visit, visit planned, location attached, which system shortcut was used, reminders sent and tapped, question suggestions adopted, medication thread viewed, note block created, notes-only visit created, visit recap shown, AI note proposal shown, AI note proposal approved, AI note proposal dismissed, follow-up suggestion accepted.
- Events carry a random identifier created when you opt in, not your email, not a device fingerprint. IP addresses are truncated at ingest and not retained.
- Each event also carries the language you use the app in, so we can see which language a feature was used in.
- Switching it off, or deleting your account, breaks the link between those events and you.
- This also covers the count of registrations — we deliberately have no consent-free exception, which means our own launch metrics undercount, and we accepted that.
- Legal basis: GDPR Art. 6(1)(a) consent · LGPD Art. 7(I).
- Retention: 24 months, then the events are deleted. If you switch analytics off or delete your account, the stored events of your random identifier are deleted within 30 days.
- Events are stored in Google BigQuery in the same region as the rest of your data (São Paulo).
We also record operational measurements that contain no personal content and no user identifier — processing durations, error codes, queue depths, cost per stage — to keep the service running.
3.5 AI training — only if you allow it
Off by default, revocable at any time in Settings. If you switch it on, then after a visit is ready, the transcript text and the text of your visit notes (including notes the AI wrote) go through de-identification and only the redacted result is added to a training dataset kept in a store of its own, segregated from your visit data (a fully separate project with its own access controls is planned) and used to improve dehaze's AI models.
- Removed or replaced: names, phone numbers, email addresses, addresses, identification numbers, locations; exact dates are shifted while keeping intervals intact; doctor and clinic names become
[DOCTOR]and[CLINIC]. - A second automated pass checks for identifiers that survived; anything flagged is set aside and not used.
- The training set is text only: the redacted transcript and note text described above. Your audio is not part of it, and neither are your email address, your documents or your identity.
- If you withdraw consent or delete your account, your contribution is removed from the training set within 30 days.
- Legal basis: GDPR Art. 6(1)(a) + Art. 9(2)(a) explicit consent · LGPD Art. 7(I) + Art. 11(I).
3.6 Notifications
If you allow notifications, we store a push token per device and send you a message when a visit finishes processing or fails, before a planned visit, and for to-dos that have a date. Message text is deliberately neutral ("You have an outstanding step from your visit") because lock screens are semi-public. Legal basis: GDPR Art. 6(1)(a) consent (the OS permission) · LGPD Art. 7(I).
3.7 Visit location — only if you allow it
Off unless you turn it on, in Settings → Features. While it is on, the app saves the coordinates of where you are as a recording starts (the fix can take a few seconds to arrive), attached to that visit, together with the time they were captured. Nothing between recordings: the app does not follow you around, and it never asks for background location.
We treat this as health data rather than ordinary metadata, because the address of a clinic can reveal what you are being treated for even when nothing else does: an oncology practice, a psychiatric clinic. So it gets the same treatment as your recordings — explicit consent, off by default, deletable.
Legal basis: your consent (GDPR Art. 9(2)(a); LGPD Art. 11, I). You can withdraw it at any time.
Showing it on a map. When a visit's map is drawn, those coordinates go to the map service your phone uses: Apple Maps on iPhone, Google Maps on Android. Opening a location in a separate maps app is your own action, and hands the coordinates to whichever app you choose.
Removing it. You can remove the location from any visit without deleting the visit. Turning the switch off stops new captures immediately; it does not delete locations already saved, because a saved location is yours to keep or delete. You remove those yourself, one visit at a time, or by deleting the visit they belong to.
3.8 Device permissions
Microphone (recording), notifications (see above), camera and photo library (attaching documents), and location (only if you enable visit location). Each is requested at the moment it is first needed, not at startup, and each can be reviewed and revoked in Settings → Notifications & permissions or in your device settings.
3.9 Crash reports
If the app crashes, a crash report is sent to us through Google's Firebase Crashlytics so we can find and fix the fault. A crash report contains technical information about the crash: the stack trace, your device model, operating system version and app version. It contains no recording, no transcript, no summary, no email address and no user identifier: we cannot look up who a crash report belongs to, and we do not combine crash reports with the usage statistics above. Crash reports are kept for 90 days and then deleted — the fixed retention period of Google's Crashlytics service, which stores them. Legal basis: GDPR Art. 6(1)(f) legitimate interest in running a reliable service · LGPD Art. 7(IX). Our servers report errors the same way, from logs that do not contain health content.
3.10 Protecting sign-in and the service
To stop abuse, such as someone guessing sign-in codes or flooding our servers with requests, we count recent requests in short-lived counters. Depending on the request, a counter is keyed by the email address entered, by your account, or by your device's IP address. The counters contain nothing else, and each one ages out within an hour. Legal basis: GDPR Art. 6(1)(f) legitimate interest in keeping the service secure · LGPD Art. 7(IX).
4. Where your data is, and who touches it
At rest, your health data is stored in Brazil — southamerica-east1 (São Paulo): the database, the audio and document storage, and the servers.
Three exceptions you should know about:
- Speech-to-text runs in the EU. Google's Speech-to-Text service is not available in the São Paulo region, so audio is sent to the EU multi-region for transcription and the result comes back. This is an international transfer of health data out of Brazil, and it is why the health-data consent explicitly names it (LGPD Art. 33(VIII) — specific and highlighted consent for the transfer). The EU has a strong data-protection regime, and Google's data-processing terms for the service (the Cloud Data Processing Addendum that governs our account) commit it to process the audio only to deliver the transcription, not to keep it for its own purposes.
- Notifications are delivered through Google (Firebase Cloud Messaging) and, on iPhones, Apple's push service. The delivered message contains no health content beyond the neutral wording above.
- Crash reports go from the app to Google's Crashlytics service, which stores them on Google's infrastructure rather than in the São Paulo region. They are content-free, as described in section 3.9.
Because we are a German controller storing data in Brazil, that storage is itself a transfer under the GDPR, covered by standard contractual clauses with our cloud provider. [[COUNSEL: confirm the transfer mechanism and transfer-impact assessment — Q-03]]
The full list of companies that process data on our behalf, what each does, and where, is in the subprocessor list. Summary: Google Cloud (hosting, storage, speech-to-text, AI, usage-event storage, crash reports, notifications) and Mailjet (the emails that carry your sign-in codes). The app stores are not our processors.
Two map services sit outside that arrangement, and only if you turn visit location on: when a visit's map is drawn, the coordinates go to Apple Maps on iPhone or Google Maps on Android under those companies' own terms for their platform services, the same way a notification passes through Apple's or Google's delivery service. They receive the coordinates being shown, nothing else.
Google Cloud's terms — the Cloud Data Processing Addendum and Service Specific Terms our account runs under — bar Google from using your data to train its models. Mailjet's data-processing terms restrict it to delivering our email.
5. How long we keep things
| Data | Kept |
|---|---|
| Recordings, transcripts, summaries, terms, to-dos, Ask history, documents, visit details | Until you delete them — we do not expire them for you |
| Account data and consent history | Until you delete your account (see below for what a deletion leaves behind) |
| Sign-in codes | 10 minutes, or until used |
| Session tokens | 90 days, rotating; revoked when you sign out or delete your account |
| Backups | Rolling 30 days — deleted data disappears from backups within 30 days |
| Server logs | 30 days; they do not contain recordings, transcripts, summaries or extracted terms |
| Usage events (if enabled) | 24 months, linked only to a random id |
| Activity log — a content-free record of what happened in your account and who did it, you or Scribe ("you deleted this visit", "Scribe finished processing this recording"), not the content it touched | Until you delete your account |
| Crash reports | 90 days |
| Training set contribution (if enabled) | Until you withdraw or delete — removed within 30 days |
| Support emails you send us | 24 months after your request is closed |
What an account deletion leaves behind. Deleting your account erases your data. Three content-free records remain: (1) proof that the deletion happened, so we can show we honoured your request; (2) your consent history (for each consent only its kind, whether it was granted or withdrawn, the language, the timestamp, and the text version with a fingerprint of the exact wording, which a grant always carries and a withdrawal carries only where a text was shown), kept so we can prove what was agreed if a legal claim is ever raised. It is stored under a cryptographic code derived from your email address with a secret key we hold; without that key it identifies nobody, and we can match it only against an email address its owner shows us; and (3) if you sent us a data request by email, the fact and dates of that request, kept the same way, so we can show we answered in time. None of the three contains any recording, transcript, name or email address. For up to an hour after a deletion, the short-lived security counters described in section 3.10 can also still exist before they age out; they then disappear on their own.
6. Your rights
Under the GDPR (Art. 15–21) and LGPD (Art. 18) you may:
- See what we hold and get a copy — we answer within 30 days. Today this runs through
scribe@dehaze.derather than a button in the app; the export is produced by the same mechanism that performs deletion, so it reaches the same data a deletion reaches. - Correct what is wrong. You can edit transcripts yourself, the original is kept and you can still view it, and the summary can be regenerated from your correction.
- Delete anything: a recording, a visit, or your entire account (Settings → Account → Delete account, confirmed with a fresh email code). Deletion is immediate on our live systems and cannot be undone; two things take longer to finish: backups age out within 30 days, and if you had usage statistics switched on, the stored analytics events of your random identifier are purged within 30 days (usually much sooner). What an account deletion leaves behind is exactly the three content-free records described in section 5; your activity log dies with the account.
- Withdraw consent at any time, without giving a reason. Withdrawing consent for health-data processing means the app can no longer function, so it takes the form of deleting your data or your account. Withdrawal does not make what happened before it unlawful.
- Object, restrict processing, and receive your data in a portable format.
- Complain to a supervisory authority — in Germany [[COMPETENT_SUPERVISORY_AUTHORITY]], in Brazil the ANPD (
gov.br/anpd). - Under the LGPD you may additionally ask about with whom we share data, about the consequences of refusing consent, and for anonymisation, blocking or elimination of unnecessary data.
We do not make automated decisions with legal or similarly significant effects about you. The AI in the app produces text for you to read; it decides nothing about you.
7. Security
TLS in transit, encryption at rest, customer-managed encryption keys on the audio and document storage, and encrypted storage on your device. Access to data is scoped per user at the query layer: a query that reads your data is bound to your account. Health content is excluded from logs by an allowlist that applies in every environment, so transcripts do not reach our log lines. Signed download links are short-lived (15 minutes). We do not use service-account keys in our delivery pipeline.
No system is perfectly secure. If a breach affects you, we notify you and the authorities as required (GDPR Art. 33/34, LGPD Art. 48).
8. Children
Scribe is for adults. We do not knowingly process data of anyone under 18. If you believe a minor uses Scribe, contact [[PRIVACY_EMAIL]] and we delete the account.
9. Changes to this policy
We update this policy when the app changes. Material changes are shown in the app before they take effect, and where the change affects what you consented to, we ask again. Every published version is available at https://scribe.dehaze.de/inapp/privacy, with the change history.