privacy_v1 · last revised 2026-07-26

Privacy Policy

This privacy policy explains what information we collect, how we use it, and how we protect your privacy.

Information We Collect

We collect information that you provide directly to us, as well as information generated through your use of our service.

  • Account information: email address, display name, and password.
  • Content you submit through the service.
  • Device and technical information: device identifiers, IP address, and timestamps.
  • Usage information: how you interact with the service and your activity history.

How We Use Your Information

We use the information we collect to provide, maintain, and improve our service, to communicate with you, and to comply with legal obligations. We process information only for the purposes described in this policy.

Information Sharing

We do not sell your personal information. We may share information with service providers who perform functions on our behalf, subject to appropriate confidentiality obligations. We may also disclose information when required by law or to protect our rights and safety.

Security

We implement reasonable security measures to protect your information. However, no security measure is perfect, and we cannot guarantee absolute security of your data.

Retention and deletion

This section describes what the system does today, not what it is intended to do eventually. Where the two differ, the difference is stated.

There is no automatic expiry on your recordings or measurements. They are kept for as long as your account exists.

You can ask us to erase your data. When that request is processed, the system: marks your encryption key as destroyed; deletes several derived analysis tables; and redacts identifying fields from security audit records. What it does not yet do is as important:

  • Marking the key destroyed is a record of intent, not a cryptographic erasure. Your per-patient key is derived deterministically from a master key we still hold, so it can be re-derived. Genuinely destroying it requires rotating that master key, which is a manual operation performed outside the automated process. We do not claim your data is cryptographically destroyed, because it is not.
  • Your audio files in object storage are not deleted by the automated process. The step that was designed to schedule them for expiry is not implemented, and the erasure job reports itself incomplete when it reaches that step. Removing recordings currently requires a manual operation, and until it is performed the audio remains in storage in encrypted form.
  • Your account record itself is retained, so that security audit records remain internally consistent. Identifying fields inside those audit records are replaced with a tombstone marker, and the append-only audit ledger keeps its original entries with a redaction layer applied on read, so that the tamper-evidence chain stays verifiable.
  • Object storage has no versioning, so a deletion that is performed is not recoverable.

Your Rights and Choices

Depending on your location, you may have certain rights regarding your personal information, including the right to access, correct, or delete your data. You may also have the right to withdraw consent or object to certain uses of your information.

To exercise any of these rights or to make inquiries about your data, please contact us using the information provided at the bottom of this policy.

Changes to This Policy

The current version is privacy_v1, last revised 2026-07-26. We may update this policy from time to time. Continued use of our service constitutes acceptance of any changes.