Trust Center
Privacy you can verify.
Patient privacy is built into how CareNotes works. Audio never leaves the device, transcripts and notes are handled under HIPAA safeguards, and your data is never used to train AI models.
Our commitments
Six things that are always true.
Audio never stored
Speech-to-text runs on your device. No patient audio is recorded, uploaded, or retained, by us or anyone.
U.S. data storage
For U.S. customers, transcripts and notes are stored on U.S. infrastructure, encrypted in transit and at rest.
No training on your data
Your PHI is never used to train, fine-tune, or improve AI models. Providers are contractually prohibited from it.
BAA with every practice
We sign a Business Associate Agreement before PHI is processed. A separate BAA per legal entity.
Least-privilege access
No routine access to PHI. Rare support access is authorized, logged, and audited.
Zero Data Retention AI
AI providers process PHI under BAAs. Our primary provider (OpenAI) operates under an executed BAA with Zero Data Retention: data is not logged, stored, or saved to disk.
Data lifecycle
Where your data lives, and where it never goes.
On your device
Audio becomes text locally.
Speech-to-text and speaker diarization run on the phone with CareNotes’ own on-device technology. No temporary audio files are created. Only the resulting text is used to generate a note.
Never leaves the deviceIn transit
Encrypted on the way.
If you enable cloud sync, transcripts and notes travel to our Google Cloud backend over TLS. Every request carries app-integrity attestation.
TLS in transitAt rest
Encrypted where it sits.
On-device data is protected by iOS Data Protection and the device keychain. Cloud data is encrypted at rest by Google Cloud, on U.S. infrastructure for U.S. customers.
Encrypted at restAI processing
Under a BAA, with nothing kept.
AI providers that process PHI do so under HIPAA Business Associate Agreements. Our primary provider (OpenAI) runs with Zero Data Retention: not logged for human review, not stored persistently, not saved to disk.
Never used for trainingDeleting a note removes it from your device and, if synced, the cloud. Closing your account purges cloud copies (region-aware) and wipes local files. Encrypted disaster-recovery backups expire within 30 days and are never used for operations, analytics, or training.
Compliance
A HIPAA program, not a HIPAA paragraph.
What is in place
- HIPAA compliance program with administrative, physical, and technical safeguards, workforce training, and periodic reviews.
- A signed BAA before any PHI is processed, with a separate agreement for each subscribing legal entity.
- Least-privilege, role-based access. Multi-factor authentication is supported for accounts, and access to PHI is logged.
- Documented incident response. For a breach of unsecured PHI, affected practices are notified without unreasonable delay and no later than 60 days after discovery, consistent with HIPAA.
- You own the records. CareNotes acts as a Business Associate that processes data on your behalf. Export your notes at any time.
Patient audio files created, uploaded, or retained.
A separate Business Associate Agreement for every legal entity.
Breach notification window, consistent with HIPAA.
Encrypted disaster-recovery backups expire, never used for analytics or training.
How we handle patient information
Straight answers to the questions your compliance officer asks.
Is any patient audio recorded, uploaded, or stored?
Where are transcripts and notes stored?
Is my data encrypted?
Can CareNotes staff access my patients’ PHI?
Is my data used to train AI models?
Is AI processing covered by a BAA and Zero Data Retention?
Do you sell or share patient data?
Who owns the notes and data?
How is data deleted?
How do you secure account access?
Is CareNotes HIPAA compliant, and will you sign a BAA?
How do you handle a security incident or breach?
Documentation
Read it now, or request the full package.
Everything a security review needs. The BAA and policies are public; the compliance package is sent on request.
Talk to us
Questions about privacy, security, or a signed BAA?
Security contact
For privacy and security questions, subprocessor lists, or to get a BAA countersigned for your entity.
info@cnotes.aiResponsible disclosure
Found a potential vulnerability? Please report it privately to info@cnotes.ai and give us a reasonable window to remediate before public disclosure.