Privacy policy

Version privacy-policy-v1-2026-08, effective [[EFFECTIVE_DATE]]

Draft, not yet reviewed by counsel.

This policy explains what HealthPod Scribe does with your data, in plain words. It is written to satisfy the GDPR (we are a German company) and the LGPD (you are likely in Brazil) at the same time, so where the two differ we describe the stricter one.

1. Controller and contact

Controller[[LEGAL_ENTITY]], [[REGISTERED_ADDRESS]]
Data protection officer / encarregado[[DPO_CONTACT]]
Privacy contact[[PRIVACY_EMAIL]]
Supportscribe@dehaze.de
Representative in Brazil[[BR_REPRESENTATIVE]]

2. The short version

This is what we do today. If it changes, this policy changes with it, and where the change affects what you agreed to, we ask you to agree again (section 9).

3. What we process, why, and on what legal basis

3.1 Account and sign-in

DataWhyLegal basis
Email addressSign-in, security notices, deletion confirmationsGDPR Art. 6(1)(b) contract · LGPD Art. 7(V)
One-time sign-in codes (stored hashed, valid 10 minutes), with the app language you signed in fromPasswordless sign-in, and sending the code email in your languageGDPR Art. 6(1)(b) · LGPD Art. 7(V)
Session tokens (refresh tokens stored hashed, 90 days, rotating)Keeping you signed inGDPR Art. 6(1)(b) · LGPD Art. 7(V)
Content language, reading levelShowing generated text in your language, at the level you choose. The language the app itself is shown in stays on your deviceGDPR Art. 6(1)(b) · LGPD Art. 7(V)
Service region, set when your account is createdKeeping your data in the storage region your account belongs toGDPR Art. 6(1)(b) · LGPD Art. 7(V)
Consent history — for each consent: kind, granted or withdrawn, exact text version, a fingerprint of the exact wording shown, language, timestampProving that consent was given or withdrawn, as the law requiresGDPR Art. 6(1)(c), Art. 7(1) · LGPD Art. 8 §2

3.2 Your visits — health data

This is the core of the app, and all of it is special-category health data (GDPR Art. 9, LGPD Art. 11). We process it only on your explicit consent (GDPR Art. 9(2)(a), LGPD Art. 11(I)), which you give during sign-up and can withdraw at any time.

DataWhere it comes from
Audio recordings (AAC, mono, ~64 kbit/s)Your microphone, only while a recording is running
The moment you confirmed your doctor agreed, plus the version of the consent text shownThe Consent Gate, once per recording
Pause markers within a recordingYour pause/resume actions
Transcripts, with time-aligned segments and — when the engine provides it — speaker labelsAutomatic speech recognition on your audio
Your transcript corrections, with full revision history and who wrote each version (you or the engine)Your edits
Summaries, extracted medical terms (medications, dosages, symptoms, conditions, procedures, dates, doctors, institutions, follow-ups), to-dos and their due dates, suggested questionsAI processing of the transcript
Your questions in Ask and the answers, with references to transcript passagesYour use of the Ask feature
Your visit notes: typed note blocks (thoughts, questions, to-dos, headings) with full revision history and who wrote each version — including notes the AI writes during a recording (live notes, if you switch them on) and afterwards, verdicts on whether your prepared questions were answered, and AI-proposed notes, whether you confirmed or dismissed themYou, and AI processing of your recording; every AI-written note is labelled with its author
Visit details: date and time, appointment type, institution, doctor's name, your prep notesYou, and — where the transcript makes them clear — automatic pre-filling that your own edits override
Documents you attach (photos, PDFs)Your camera, photo library, or file picker
Visit location, only if you switch it on (off by default)Your device, as a recording starts (the fix can take a few seconds to arrive), not in the background
Technical processing data: durations, file sizes, processing state, error codes, per-call AI usage units, the app version that made the recordingThe processing pipeline

Recording length is capped at 120 minutes, and processing at 120 audio-minutes per day. Over-cap recordings are kept and processed later, not discarded.

3.3 Other people in your recordings

A recording contains your doctor's voice, name, and what they said — and sometimes other people present. That is their personal data, and we process it as part of providing the service to you.

3.4 Usage statistics — only if you allow it

Off by default. If you switch it on, the app and our servers send events only: which screen and which feature you used, and when, not the content of your recordings. These are the events: sign-up, onboarding completed, consent gate confirmed, recording started/stopped, upload completed, processing ready/failed, transcript viewed, summary viewed, terms viewed, summary shared (only which class of app), question asked, recording deleted, account deleted, training opt-in changed, recording added to a visit, visit planned, location attached, which system shortcut was used, reminders sent and tapped, question suggestions adopted, medication thread viewed, note block created, notes-only visit created, visit recap shown, AI note proposal shown, AI note proposal approved, AI note proposal dismissed, follow-up suggestion accepted.

We also record operational measurements that contain no personal content and no user identifier — processing durations, error codes, queue depths, cost per stage — to keep the service running.

3.5 AI training — only if you allow it

Off by default, revocable at any time in Settings. If you switch it on, then after a visit is ready, the transcript text and the text of your visit notes (including notes the AI wrote) go through de-identification and only the redacted result is added to a training dataset kept in a store of its own, segregated from your visit data (a fully separate project with its own access controls is planned) and used to improve dehaze's AI models.

3.6 Notifications

If you allow notifications, we store a push token per device and send you a message when a visit finishes processing or fails, before a planned visit, and for to-dos that have a date. Message text is deliberately neutral ("You have an outstanding step from your visit") because lock screens are semi-public. Legal basis: GDPR Art. 6(1)(a) consent (the OS permission) · LGPD Art. 7(I).

3.7 Visit location — only if you allow it

Off unless you turn it on, in Settings → Features. While it is on, the app saves the coordinates of where you are as a recording starts (the fix can take a few seconds to arrive), attached to that visit, together with the time they were captured. Nothing between recordings: the app does not follow you around, and it never asks for background location.

We treat this as health data rather than ordinary metadata, because the address of a clinic can reveal what you are being treated for even when nothing else does: an oncology practice, a psychiatric clinic. So it gets the same treatment as your recordings — explicit consent, off by default, deletable.

Legal basis: your consent (GDPR Art. 9(2)(a); LGPD Art. 11, I). You can withdraw it at any time.

Showing it on a map. When a visit's map is drawn, those coordinates go to the map service your phone uses: Apple Maps on iPhone, Google Maps on Android. Opening a location in a separate maps app is your own action, and hands the coordinates to whichever app you choose.

Removing it. You can remove the location from any visit without deleting the visit. Turning the switch off stops new captures immediately; it does not delete locations already saved, because a saved location is yours to keep or delete. You remove those yourself, one visit at a time, or by deleting the visit they belong to.

3.8 Device permissions

Microphone (recording), notifications (see above), camera and photo library (attaching documents), and location (only if you enable visit location). Each is requested at the moment it is first needed, not at startup, and each can be reviewed and revoked in Settings → Notifications & permissions or in your device settings.

3.9 Crash reports

If the app crashes, a crash report is sent to us through Google's Firebase Crashlytics so we can find and fix the fault. A crash report contains technical information about the crash: the stack trace, your device model, operating system version and app version. It contains no recording, no transcript, no summary, no email address and no user identifier: we cannot look up who a crash report belongs to, and we do not combine crash reports with the usage statistics above. Crash reports are kept for 90 days and then deleted — the fixed retention period of Google's Crashlytics service, which stores them. Legal basis: GDPR Art. 6(1)(f) legitimate interest in running a reliable service · LGPD Art. 7(IX). Our servers report errors the same way, from logs that do not contain health content.

3.10 Protecting sign-in and the service

To stop abuse, such as someone guessing sign-in codes or flooding our servers with requests, we count recent requests in short-lived counters. Depending on the request, a counter is keyed by the email address entered, by your account, or by your device's IP address. The counters contain nothing else, and each one ages out within an hour. Legal basis: GDPR Art. 6(1)(f) legitimate interest in keeping the service secure · LGPD Art. 7(IX).

4. Where your data is, and who touches it

At rest, your health data is stored in Brazil — southamerica-east1 (São Paulo): the database, the audio and document storage, and the servers.

Three exceptions you should know about:

  1. Speech-to-text runs in the EU. Google's Speech-to-Text service is not available in the São Paulo region, so audio is sent to the EU multi-region for transcription and the result comes back. This is an international transfer of health data out of Brazil, and it is why the health-data consent explicitly names it (LGPD Art. 33(VIII) — specific and highlighted consent for the transfer). The EU has a strong data-protection regime, and Google's data-processing terms for the service (the Cloud Data Processing Addendum that governs our account) commit it to process the audio only to deliver the transcription, not to keep it for its own purposes.
  2. Notifications are delivered through Google (Firebase Cloud Messaging) and, on iPhones, Apple's push service. The delivered message contains no health content beyond the neutral wording above.
  3. Crash reports go from the app to Google's Crashlytics service, which stores them on Google's infrastructure rather than in the São Paulo region. They are content-free, as described in section 3.9.

Because we are a German controller storing data in Brazil, that storage is itself a transfer under the GDPR, covered by standard contractual clauses with our cloud provider. [[COUNSEL: confirm the transfer mechanism and transfer-impact assessment — Q-03]]

The full list of companies that process data on our behalf, what each does, and where, is in the subprocessor list. Summary: Google Cloud (hosting, storage, speech-to-text, AI, usage-event storage, crash reports, notifications) and Mailjet (the emails that carry your sign-in codes). The app stores are not our processors.

Two map services sit outside that arrangement, and only if you turn visit location on: when a visit's map is drawn, the coordinates go to Apple Maps on iPhone or Google Maps on Android under those companies' own terms for their platform services, the same way a notification passes through Apple's or Google's delivery service. They receive the coordinates being shown, nothing else.

Google Cloud's terms — the Cloud Data Processing Addendum and Service Specific Terms our account runs under — bar Google from using your data to train its models. Mailjet's data-processing terms restrict it to delivering our email.

5. How long we keep things

DataKept
Recordings, transcripts, summaries, terms, to-dos, Ask history, documents, visit detailsUntil you delete them — we do not expire them for you
Account data and consent historyUntil you delete your account (see below for what a deletion leaves behind)
Sign-in codes10 minutes, or until used
Session tokens90 days, rotating; revoked when you sign out or delete your account
BackupsRolling 30 days — deleted data disappears from backups within 30 days
Server logs30 days; they do not contain recordings, transcripts, summaries or extracted terms
Usage events (if enabled)24 months, linked only to a random id
Activity log — a content-free record of what happened in your account and who did it, you or Scribe ("you deleted this visit", "Scribe finished processing this recording"), not the content it touchedUntil you delete your account
Crash reports90 days
Training set contribution (if enabled)Until you withdraw or delete — removed within 30 days
Support emails you send us24 months after your request is closed

What an account deletion leaves behind. Deleting your account erases your data. Three content-free records remain: (1) proof that the deletion happened, so we can show we honoured your request; (2) your consent history (for each consent only its kind, whether it was granted or withdrawn, the language, the timestamp, and the text version with a fingerprint of the exact wording, which a grant always carries and a withdrawal carries only where a text was shown), kept so we can prove what was agreed if a legal claim is ever raised. It is stored under a cryptographic code derived from your email address with a secret key we hold; without that key it identifies nobody, and we can match it only against an email address its owner shows us; and (3) if you sent us a data request by email, the fact and dates of that request, kept the same way, so we can show we answered in time. None of the three contains any recording, transcript, name or email address. For up to an hour after a deletion, the short-lived security counters described in section 3.10 can also still exist before they age out; they then disappear on their own.

6. Your rights

Under the GDPR (Art. 15–21) and LGPD (Art. 18) you may:

We do not make automated decisions with legal or similarly significant effects about you. The AI in the app produces text for you to read; it decides nothing about you.

7. Security

TLS in transit, encryption at rest, customer-managed encryption keys on the audio and document storage, and encrypted storage on your device. Access to data is scoped per user at the query layer: a query that reads your data is bound to your account. Health content is excluded from logs by an allowlist that applies in every environment, so transcripts do not reach our log lines. Signed download links are short-lived (15 minutes). We do not use service-account keys in our delivery pipeline.

No system is perfectly secure. If a breach affects you, we notify you and the authorities as required (GDPR Art. 33/34, LGPD Art. 48).

8. Children

Scribe is for adults. We do not knowingly process data of anyone under 18. If you believe a minor uses Scribe, contact [[PRIVACY_EMAIL]] and we delete the account.

9. Changes to this policy

We update this policy when the app changes. Material changes are shown in the app before they take effect, and where the change affects what you consented to, we ask again. Every published version is available at https://scribe.dehaze.de/inapp/privacy, with the change history.