Privacy Policy

How ChairScribe collects, uses, and protects your data and your patients' data.

Last updated: 9 July 2026

1. Who we are ChairScribe is a product of Tiny Logic Pty Ltd (ABN 86 799 163 724) ("Tiny Logic", "we", "our", "us"), an Australian company. ChairScribe is a web platform and mobile application that helps dental professionals record patient appointments and produce transcriptions and draft clinical notes. This Privacy Policy explains how we collect, use, store, share, and protect personal information when you visit our website or use ChairScribe. It covers your information as an account holder, the information of your patients that you process through ChairScribe, and the information of visitors to our website (including the waitlist). We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), including the additional protections that apply to health information. ChairScribe is designed and offered primarily for dental professionals practising in Australia. Questions or requests about this policy can be sent to support@chairscribe.com. 2. Information we collect 2.1 Account information - Name and email address - Practice details you choose to provide (for example your country and preferences) - Subscription and billing status. Payments are processed by Stripe; we do not store your full card details on our systems. 2.2 Audio recordings When you use the recording or dictation features, we collect audio captured by your device's microphone, along with recording metadata (start time, duration, and the associated appointment). Recording starts only when you explicitly start it, and a visible indicator is shown while recording is active. We never record in the background. 2.3 Transcriptions and clinical notes From your recordings we generate text transcriptions and draft clinical notes based on your templates. These are stored as part of your appointment records. 2.4 Appointment, patient, and practice data - Patient names and identifiers, as entered by you or extracted from documents you scan - Appointment details, titles, and dates - Clinical notes, templates, snippets, flags, and annotations - Photos you choose to scan, such as a photo of a paper day sheet (these images can contain patient names and appointment details) - Messages you send to the in-app assistant, together with the appointment or patient context you attach to them 2.5 Device and technical information - Device type, model, and operating system version - App version - Push notification tokens - De-identified crash and error diagnostics 2.6 Usage analytics We collect de-identified usage data to improve ChairScribe: which features are used, session frequency, and navigation patterns. Before any analytics event leaves the app we strip identifiers and free text, and we do not send your email, name, IP address, or any clinical content to our analytics provider. Analytics identifiers are random codes that do not directly identify you. 2.7 Website visitors and waitlist If you join the waitlist we collect your name, email address, and practice type. We also record your approximate location (city, region, and country, derived from your IP address) and your IP address, which we use to plan our rollout. This is stated on the waitlist form. Our website uses only the cookies and similar technologies described in section 11. 3. How we use your information We use the information we collect to: - Provide the recording, transcription, and clinical note drafting service - Process your audio, text, and scanned documents through AI models to produce transcripts, draft notes, and extracted appointment details - Answer the questions you ask the in-app assistant - Authenticate your account and maintain your session - Send push notifications about processing status - Process payments and manage subscriptions - Monitor service health, fix problems, and improve ChairScribe - Communicate with you about the service, and send occasional product updates you can opt out of - Comply with our legal obligations ChairScribe is a documentation aid. It does not diagnose, recommend treatment, or make clinical decisions, and every draft it produces is reviewed by you before it becomes part of a record. 4. Audio recording and AI processing 4.1 Recording and upload Audio is captured on your device and uploaded to our servers over an encrypted connection (TLS/HTTPS). 4.2 How long we keep audio On the web, your audio is not retained on our servers: it is processed to produce the transcript and then discarded, and only the transcript is kept. In the mobile app, uploaded audio is retained on our servers for up to 7 days so that a recording can be recovered or re-processed if something goes wrong (for example an interrupted upload or a failed transcription), after which it is automatically and permanently deleted. Transcriptions and clinical notes are retained as part of your appointment records until you delete them or your account. A local copy of a recording may also exist on your device until you delete it. 4.3 AI service providers ChairScribe uses specialised AI providers to process your data. All of them are engaged under commercial API terms: your data is used only to provide the service back to us, is never used to train their models, and is retained by them at most transiently (typically up to 30 days) for security and abuse monitoring before deletion. - Transcription: Deepgram (primary) and Google Gemini (fallback). We have opted out of Deepgram's model improvement program, so your audio cannot be used to train Deepgram's models. Some dictation features use OpenAI transcription models. - Clinical note drafting, document extraction (such as day sheet scanning), and the in-app assistant: Anthropic Claude. - Supporting features such as appointment titles, summaries, and template variable extraction: OpenAI. Provider terms: Anthropic (anthropic.com/legal/commercial-terms), OpenAI (openai.com/policies/business-terms), Google Gemini API (ai.google.dev/gemini-api/terms), Deepgram (deepgram.com/terms). 4.4 Mobile on-device processing The ChairScribe mobile app uses on-device speech recognition (the Apple Speech framework on iOS) to produce a preliminary transcript locally. That preliminary transcript is sent to our backend along with the uploaded audio for final processing. 4.5 Patient information in recordings Recordings of dental appointments can contain patient health information, including names, conditions, treatment plans, and clinical observations. As the treating practitioner, you are responsible for obtaining informed consent from your patients before recording, and for noting that consent in the patient record where your professional obligations require it. We process patient information solely on your behalf and on your instructions, as a service provider to your practice. 5. Where your data lives, and who we share it with 5.1 Data residency Your account data, appointment records, transcriptions, and notes are stored with Supabase in Australia. Where audio is briefly retained (the mobile app's 7-day recovery window), it is stored in the same Australian infrastructure. 5.2 Service providers We share data with a small set of providers, each bound by data processing terms: - Supabase (database, authentication, and file storage; hosted in Australia) - Vercel (application hosting) - Stripe (payments) - Anthropic, OpenAI, Google, and Deepgram (AI processing, as described in section 4.3; processed in the United States) - PostHog (de-identified product analytics and error diagnostics; hosted in the United States) - Expo (push notification delivery) 5.3 Overseas disclosures Apart from the AI, analytics, payment, and notification providers listed above (which process data in the United States), we do not disclose your information overseas. Where data leaves Australia, we take reasonable steps by contract to ensure it is handled consistently with the APPs. 5.4 We do not sell your data We do not sell, rent, or trade your personal information or your patients' information, and we do not use health information for advertising or marketing. 5.5 Legal requirements We may disclose information where required by law, regulation, legal process, or an enforceable governmental request. 6. Security - Encryption in transit (TLS/HTTPS) and at rest (AES-256) - Token-based authentication and session management - Row-level access controls so each account can only reach its own data - De-identification of all analytics before it leaves the app - Staff access to customer data is limited to support and troubleshooting, restricted to authorised personnel, and logged You are responsible for keeping your device and account credentials secure, and for complying with the health privacy rules and professional obligations that apply to your practice. 7. Data breaches We treat any suspected data breach as an emergency. If a breach occurs that is likely to result in serious harm, we will promptly assess it, notify affected account holders so that you can meet your own obligations to your patients, and notify the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme. 8. Data retention - Account information: until you delete your account - Audio: not retained on our servers for web recordings; in the mobile app, up to 7 days then automatically deleted (section 4.2) - Transcriptions and clinical notes: until you delete them or your account - Diagnostic error records that may include snippets of processed content: up to 30 days - De-identified usage analytics: up to 24 months - Waitlist details: until we invite you or you ask us to remove you - Billing records: as required for tax and accounting law When you delete your account we delete or de-identify your personal data within 30 days, except where the law requires us to keep it. Residual copies in encrypted backups are removed as those backups cycle out. Important: dental practitioners are legally required to retain clinical records for minimum periods (commonly at least 7 years, and longer for children). Deleting data from ChairScribe does not satisfy or replace those obligations. Export anything you are required to keep before deleting it; we can help at support@chairscribe.com. 9. Your rights You can ask us to: - Access the personal information we hold about you (APP 12) - Correct inaccurate information (APP 13) - Delete your personal information - Stop sending you marketing messages (every marketing email includes an unsubscribe link; service emails about your account continue) Write to support@chairscribe.com. We will verify your identity and respond within 30 days. If you are unhappy with our response, tell us and we will escalate it internally; you can also complain to the OAIC at oaic.gov.au. If you are a patient of a practice that uses ChairScribe, your records are controlled by your dental practice. Please direct requests about your health information to your practitioner; we will assist them in responding. If you use ChairScribe from outside Australia, you may have additional rights under your local law, and we will honour them to the extent they apply. 10. Health information and children ChairScribe processes health information as defined in the Privacy Act 1988 (Cth). We collect and handle it solely to provide the transcription and note drafting service, protect it with the safeguards described in this policy, and never use it for marketing or any unrelated purpose. ChairScribe accounts are for professionals aged 18 or over. Patient records processed on behalf of practitioners may include children's health information; we handle it with the same protections and only on the instructions of the treating practitioner. 11. Cookies and similar technologies Our website and web app use: - Essential cookies for sign-in and session security - Local storage for your interface preferences - De-identified product analytics (section 2.6) We do not use advertising cookies or cross-site tracking. 12. Automated decisions ChairScribe does not use your personal information to make automated decisions that have a legal or similarly significant effect on you or your patients. AI output is always a draft for your review. If this changes, we will update this policy and explain the decision-making involved before it takes effect. 13. Changes to this policy We may update this policy from time to time. For material changes we will update the date above and notify you by email or in the app before the change takes effect. 14. Contact us Tiny Logic Pty Ltd (ChairScribe) ABN 86 799 163 724 Email: support@chairscribe.com Website: https://chairscribe.com Complaints: contact us first at support@chairscribe.com. You can also contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.