Privacy Policy
AI clinical documentation SaaS — pay per report.
Last updated: June 2026
Overview
Our architecture is intentionally designed around an uncompromising Zero-Knowledge Security Model to protect patient and clinical data privacy. This policy describes how we handle information across our services at
app.cleannote.org and api.cleannote.org.
1. The Zero-Knowledge Privacy Standard
To protect medical-legal integrity and eliminate casual data spill liabilities, Cleannote operates on a strict PHI isolation model:
- Encrypted at rest after processing: Finished clinical outputs and pipeline drafts are stored encrypted on disk. Ephemeral plaintext exists only during active processing (speech-to-text / styling), then is sealed or purged.
- Client-side dashboard decryption: Report ZIP downloads are delivered as ciphertext. Decryption happens locally in your browser after you unlock with your Cleannote pasword on that device.
- No admin report viewer: Cleannote administrators and support cannot open or read your clinical text or generated reports through the admin tools. Operational support uses account codes and session/file timestamp IDs only (for example
CODE-DDMMYXxHHMSS).
- Infrastructure keys vs human browsing: A server-held master key is used only by the processing service to seal data after a job finishes and to manage secure-delivery key wraps. It is not used to provide staff a report-reading console. Finished delivery packages prefer client file-key (CS1) sealing so downloads are not server-decrypted to plaintext.
- Strict device authentication: Accessing secure download from a new browser or device requires your password to instantiate local decryption.
2. Information We Process
- Account Credentials: App signup/invite code, email address, securely hashed system credentials, and billing region context. (Your raw account password is cryptographically masked and is entirely invisible to Cleannote administrators).
- Ephemeral Clinical Workflow Data: Temporary audio dictation and text-draft uploads, styling sample documents, letterhead templates, and generated reports submitted entirely for immediate pipeline processing.
- Operational Telemetry: Anonymized country-level IP geolocation (via Cloudflare edge routing), session security cookies, and basic operational server logs used exclusively for performance monitoring and active abuse prevention.
3. Core Information Utilization
- Executing localized AI speech-to-text transcription and applying your custom structural formatting profiles.
- Authenticating platform sessions and accurately maintaining prepaid digital wallet or trial usage billing ledgers.
- Transmitting critical administrative or operational system alerts (e.g., automated signup confirmations).
- Ensuring absolute infrastructure integrity and preventing localized runtime loop failures.
4. Robust Data Retention & Auto-Purge
We treat clinical data as temporary data payloads. To shield medical practitioners from systemic data retention liabilities:
- 6-Day Auto-Purge: Uploaded files and finished reports are permanently and automatically deleted from our servers after 6 days. Sample reports, letterhead, and feedback files are retained until you remove them.
- Zero Global AI Model Training: Your clinical workflows, audio strings, and data patterns are completely isolated. Your files are never submitted, tracked, or used to train public or foundational machine learning models.
- Delivery decryption is performed locally in your browser after unlock; processing uses ephemeral plaintext then encrypted storage.
5. Third-Party Sharing
Cleannote does not monetize, distribute, lease, or sell clinical data or user profile metrics. Highly specialized cloud enterprise AI subprocessors are utilized solely as passive pass-through infrastructure to handle core processing loops. Data disclosures are restricted exclusively to mandatory legal compliance or valid statutory judicial orders.
6. Regulatory Compliance & Global Rights
In compliance with rigorous international healthcare privacy data structures and localized statutory laws (including India’s Digital Personal Data Protection Act / DPDP Act), you maintain unconditional rights to request the immediate manual erasure or correction of your core profile details. Please coordinate data access or custom purging configurations via support@cleannote.org.
Contact & Support
For immediate technical security deep dives or administrative questions: Visit our Contact page or email us directly at support@cleannote.org.