Patient PA

How your information is handled

Patient PA is available only to existing invited users. New accounts are closed and no payments are taken.

Privacy and retention

Patient PA and named AI provider(s) temporarily process appointment audio and transcript to create the transcript, structured summary, and title. Saved records are encrypted in your browser afterward, including appointment titles, transcripts, summaries, your own notes and their titles. Personal notes written here are encrypted without sending their text for AI title generation.

Appointment audio and readable processing files are temporary. They are removed before a saved appointment is completed. You can retry an unfinished recording for 24 hours after recording starts. Expired server copies are removed by the next successful daily cleanup; failures or outages can delay removal. A closed or offline browser removes its expired local copy when Patient PA is next opened.

Recovery phrases are generated in your browser. Patient PA may remind you to save one, but it never emails, logs, or stores the plaintext phrase.

Sign-in and your record key

Your email opens your account. Your browser key opens encrypted records. A recovery phrase protects a backup of that same key; Patient PA cannot reset a lost phrase to decrypt old records.

Your choices

You can withdraw AI processing without deleting saved records. Reading, exporting and deleting saved records never requires another purchase. Personal notes are free.

Manage your data after signing in

Health information is special category data under UK data protection law. Read the ICO’s guidance.

Interest requests and public page counts

Submitting your email with “Join the waitlist” requests a place on the waitlist and an email when you can join. We keep your email and a record of that request only to gauge interest and prepare that availability notification. It does not create an account, add you to the whitelist or permit other marketing. No automatic email is sent.

Requests expire after 90 days. Expired requests are excluded from review and export, then removed by the next successful daily cleanup; failures can delay physical removal. Use the removal link saved after your original request to delete it earlier. Repeated submissions do not replace that link. Keep it somewhere safe; there is no automated email verification or recovery for a lost link.

We count full loads of a fixed set of public pages and the referring website’s hostname. Daily totals contain no email, account or visitor identifier, IP address, full URL, query or patient information. We filter known bots and prefetches, exclude signed-in browsers, and do not measure private record pages. Repeat loads can count again; these are page loads, not unique people. Navigation without a full page load is not counted.

These aggregates are kept for 90 UTC days, then removed by the next successful daily cleanup. We use no analytics cookies, local storage, fingerprinting or replay. If you choose not to be counted below, an essential cookie containing only “off” remembers that choice for 90 days on this browser. It is not a visitor identifier. We also respect browser Do Not Track and Global Privacy Control signals.

Only the site operator can review or export interest emails and aggregate reports using secured infrastructure access. Our hosting and database providers may hold separate security logs or backups; these application controls do not erase every provider copy or a previously downloaded export.