Privacy Policy
Effective June 6, 2026 · Last updated June 8, 2026
1. Introduction
Sarer Health ("Sarer", "we", "us", or "our") operates the Sarer clinical documentation platform, available at app.sarerhealth.com and as a mobile application on the Apple App Store (collectively, the "Service").
We provide AI-assisted clinical documentation tools designed to help healthcare professionals generate structured clinical notes from voice recordings. Because our Service processes voice recordings made during or about patient encounters, we treat the privacy of both clinicians and patients with the highest standard of care.
This Privacy Policy explains what information we collect, how we use and protect it, who we share it with, and the rights you have over your data. By using the Service, you agree to the practices described in this policy.
If you do not agree, please discontinue use of the Service.
2. Scope and Who This Policy Applies To
This policy applies to:
- Clinicians and healthcare professionals who create an account and use the Service ("Users")
- Patients whose information may be referenced or discussed in voice recordings processed through the Service
- Visitors to our website and app
3. Information We Collect
3.1 Information You Provide Directly
| Category | Examples |
|---|---|
| Account Information | Email address, name, professional title or specialty |
| Authentication Data | One-time passcodes (OTP) sent to your email for login |
| Voice Recordings | Audio recordings you make of clinical encounters or dictation sessions |
| Clinical Content | Transcripts generated from your recordings; clinical notes you create, edit, or save |
| Template Data | Clinical note templates you create or customize |
| Communications | Messages you send to our support team |
3.2 Information We Collect Automatically
| Category | Examples |
|---|---|
| Usage Data | Features accessed, sessions created, templates used, note types generated |
| Device Information | Device type, operating system and version, browser type, screen resolution |
| Log Data | IP address, timestamps, page views, error logs |
| Performance Data | API response times, recording durations, processing latency |
| Token Usage | Number of AI tokens consumed per session (for service optimization and billing) |
3.3 Information We Do Not Collect
We do not collect:
- Identifiable patient names, dates of birth, contact details, or national identification numbers unless you voluntarily include them in a voice recording
- Payment card numbers (processed directly by our payment provider)
- Data from your device's contacts, camera, photos library, location, or health app
4. Microphone, Audio Recordings, and the Recording Lifecycle
4.1 Microphone Access (Apple App Store Disclosure)
The Service requires access to your device's microphone in order to record clinical dictation. This is the core function of the app.
- Microphone access is requested only at the moment you initiate a recording
- You may deny or revoke microphone permission at any time in your device Settings; doing so will prevent the recording feature from functioning
- Recordings are not used for advertising, profiling, or any purpose other than generating your clinical documentation
Apple Privacy Label Classification: Audio Data — App Functionality
4.2 What Happens to Your Audio — Step by Step
We want complete transparency about every stage an audio recording passes through:
| Stage | What Happens |
|---|---|
| 1. Recording | Audio is captured on your device via the browser or app microphone |
| 2. Secure upload | The audio file is transmitted to our servers over TLS 1.2+ encryption |
| 3. Deduplication check | A SHA-256 hash of the audio is compared against previously processed recordings. If you re-upload identical audio, we return the previously generated transcript without re-sending the audio to any third party. The dedup index stores only the audio hash and transcript text — never the raw audio — and an entry is removed once it is matched against a duplicate upload. Entries for audio that is never re-uploaded may persist indefinitely as part of this index |
| 4. Transcription | The audio file is sent to OpenAI's Whisper API for speech-to-text conversion |
| 5. Deletion of audio | The raw audio file is never written to our servers. It is processed in memory and discarded immediately after transcription completes. No audio file persists beyond the duration of the upload request. |
| 6. Note generation | The text transcript is sent to Anthropic's Claude API for clinical note generation |
| 7. Storage | Only the final transcript and structured note are stored, linked to your account |
4.3 No Human Listening Policy
Sarer Health employees, contractors, and support staff do not listen to, review, or access the content of your audio recordings.
Access to recordings is restricted to automated processing pipelines only. The only exceptions are:
- When you explicitly share a recording with us for the purpose of investigating a technical fault you have reported
- When required by a valid legal order
4.4 Third-Party Data Retention for Audio
When audio is sent to OpenAI (Whisper API):
- OpenAI does not use API inputs to train its models by default, per its API data usage policy
- OpenAI may retain API inputs for up to 30 days for abuse and safety monitoring, after which they are deleted
- OpenAI's Enterprise API terms apply; review them at openai.com/policies/privacy
When transcripts are sent to Anthropic (Claude API):
- Anthropic does not use API inputs to train its models by default, per its API usage policy
- Anthropic retains API inputs for a limited period for trust and safety review; review their policy at anthropic.com/privacy
- We do not send raw audio to Anthropic — only the text transcript
If your jurisdiction prohibits sending any patient-related data outside your country's borders, you must not use the Service until you have verified compliance with applicable data residency laws.
5. How We Use Your Information
| Purpose | Legal Basis |
|---|---|
| Provide and operate the Service (transcription, note generation) | Contract performance |
| Authenticate your identity via email OTP | Contract performance |
| Generate, display, and store your clinical notes | Contract performance |
| Improve transcription accuracy and note quality | Legitimate interests |
| Monitor service performance, uptime, and security | Legitimate interests |
| Respond to support requests | Legitimate interests / Contract |
| Comply with legal obligations | Legal obligation |
| Send service-related communications (e.g. maintenance notices) | Contract performance |
We do not use your clinical content or voice recordings to train AI models without your explicit, separate written consent.
6. Third-Party Service Providers
We share data with the following third parties solely to operate the Service. All providers are contractually bound to protect your data and are prohibited from using it for their own purposes.
| Provider | Purpose | Data Shared |
|---|---|---|
| OpenAI (Whisper API) | Speech-to-text transcription | Audio recordings |
| Anthropic | AI note generation (Claude); document/image extraction for templates and schedule imports | Transcripts, note content, and uploaded documents/screenshots (which may contain patient name or reference number) |
| Railway | Backend hosting and database | Encrypted application data |
| Vercel | Frontend hosting | Application content rendered to your browser |
| Resend | Transactional email — OTP login codes, clinical note delivery (when you choose to email a note), billing/subscription notices | Email address; clinical note content (only when you choose to email a note); billing status |
| Stripe | Payment and subscription processing | Email address, user ID, subscription plan and metadata (no card numbers) |
| Sentry | Error monitoring | Error messages and stack traces (no PII collected by default) |
Important: Audio recordings and transcripts may be transmitted to OpenAI and Anthropic for processing. These providers operate primarily in the United States. If you are located in the EU, GCC, or other jurisdictions with data residency requirements, please review their policies and contact us before using the Service.
We do not sell your data to any third party. We do not share your data with advertisers.
7. Clinical Data, Patient Information, and Our Role
7.1 Sarer's Role: Data Processor, Not Controller
Sarer is a clinician-facing tool. Any patient information that appears in recordings or notes was introduced by the clinician — we did not collect it independently.
In data protection law terms:
- You (the clinician or your practice) are the data controller for any patient personal data that enters the Service — you determine the purpose and means of processing
- Sarer Health acts as a data processor — we process patient data only on your documented instructions (i.e., the recordings you submit and the templates you select)
- This means your legal obligations as a data controller (obtaining patient consent, responding to patient rights requests, reporting breaches to authorities) remain with you
7.2 What Patient Data May Enter the Service
The Service is designed for clinical dictation, not structured patient intake. However, depending on how you use it, recordings may contain:
| Type | Examples |
|---|---|
| Identifiers | Patient first name, initials, date of birth, reference number |
| Clinical information | Presenting complaint, diagnoses, medications, examination findings |
| Sensitive special-category data | Mental health, sexual health, substance use, genetic or biometric information |
You are responsible for minimizing the identifiers you include. Best practice: use patient reference numbers or initials rather than full names wherever clinically appropriate.
7.3 Our Commitments Regarding Patient Data
- Clinical content is associated with your account only and is not visible to any other Sarer user
- We do not read, analyze, sell, or use the substantive content of patient recordings or notes for any purpose other than generating your documentation
- We do not build profiles of patients across clinicians or sessions
- We do not link patient information to any external database or marketing system
- Raw audio is never stored on our servers — it is processed in memory and discarded immediately after transcription completes (see Section 4.2)
7.4 Patient Rights Requests
Patients are not direct users of the Service and cannot log in or access data through the Service. If a patient exercises a right (access, erasure, rectification) that relates to data processed through the Service:
- The patient must direct their request to you (their clinician or practice) as the data controller
- You may then contact us at privacy@sarerhealth.com to assist with fulfilling the request
- We will cooperate with reasonable requests within 30 days
7.5 Data Breach Notification
If we discover a security incident that has compromised patient data processed through the Service:
- We will notify you without undue delay and in any case within 72 hours of becoming aware
- The notification will describe the nature of the incident, data types affected, likely consequences, and steps taken
- You remain responsible for notifying your patients and relevant supervisory authorities as required under HIPAA, GDPR, or applicable local law
8. HIPAA Notice (United States Users)
If you are a covered entity or business associate under the Health Insurance Portability and Accountability Act (HIPAA), please note:
- Sarer Health may qualify as a Business Associate when processing Protected Health Information (PHI) on your behalf
- We are in the process of establishing Business Associate Agreements with our AI processing subcontractors (OpenAI, Anthropic); until those are finalized, we are not yet able to offer a fully HIPAA-compliant processing chain
- If HIPAA compliance is required for your use case, please contact us at privacy@sarerhealth.com to discuss current status before submitting PHI through the Service
- In the meantime, we strongly recommend minimizing identifiable patient information in recordings (see Section 7.3)
9. GDPR and International Privacy Rights
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the following applies:
Your Rights
| Right | What It Means |
|---|---|
| Access | Request a copy of personal data we hold about you |
| Rectification | Correct inaccurate or incomplete data |
| Erasure | Request deletion of your data ("right to be forgotten") |
| Restriction | Ask us to limit processing of your data |
| Portability | Receive your data in a machine-readable format |
| Objection | Object to processing based on legitimate interests |
| Withdraw Consent | Where processing is consent-based, withdraw at any time |
You can exercise Access and Portability rights directly from Settings → Export Data, which provides your profile, encounter metadata, and clinical note content. This export does not currently include raw transcripts or audio recordings; contact privacy@sarerhealth.com if you need these included.
To exercise any other right, email privacy@sarerhealth.com. We will respond within 30 days.
Legal Basis for Processing
Our lawful bases for processing are: (a) performance of a contract (operating the Service), (b) legitimate interests (security, fraud prevention, service improvement), and (c) legal obligation.
International Transfers
Data may be transferred to and processed in the United States and other countries. Where required, we rely on Standard Contractual Clauses (SCCs) or other appropriate transfer mechanisms.
10. Data Retention
| Data Type | Retention Period |
|---|---|
| Account information | Duration of account + 90 days after deletion |
| Voice recordings | Never written to our servers. Audio is processed in memory and sent directly to OpenAI Whisper for transcription, then discarded. No audio file is stored. |
| Transcript deduplication cache | A SHA-256 hash of each audio file and its resulting transcript text is retained to avoid redundant API calls if the same audio is ever uploaded again. Contains only a hash and transcript text — never raw audio. An entry is deleted once it is matched against a duplicate upload; entries with no duplicate may persist indefinitely. |
| Transcripts and clinical notes | Retained while account is active; deleted on account deletion. Stored encrypted with AES-256-GCM. |
| Usage and log data | 12 months rolling |
| Support communications | 3 years |
| Billing records | 7 years (legal/tax obligation) |
You may delete individual encounters and notes at any time from within the Service. You may also permanently delete your entire account and all associated data at any time from Settings → Delete Account — this takes effect immediately. If you're unable to access the Service, you may instead contact privacy@sarerhealth.com to request deletion.
11. Data Security
We implement industry-standard technical and organizational safeguards including:
- Encryption in transit: All data is transmitted over TLS 1.2+
- Encryption at rest: Clinical notes, transcripts, and recording sessions are encrypted using AES-256-GCM at the application layer before being written to the database. The encryption key is stored separately from the data in Railway's environment configuration and never appears in source code
- Authentication: Passwordless email OTP; JWT session tokens with expiry
- Access controls: Role-based access; no employee has routine access to clinical content
- Secure infrastructure: Deployed on Railway with environment-level isolation
No method of transmission or storage is 100% secure. In the event of a data breach affecting your rights and freedoms, we will notify you and relevant authorities as required by applicable law.
12. Children's Privacy
The Service is intended for licensed healthcare professionals and is not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected such data, contact us immediately at privacy@sarerhealth.com.
13. Cookies and Tracking
The Service does not use cookies. Your session is maintained using a token stored in your browser's local storage, and local storage is also used to cache UI preferences, draft state, and your profile information for faster loading.
We do not use advertising cookies, cross-site tracking pixels, or third-party analytics that profile you individually.
14. Changes to This Policy
We may update this policy from time to time. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page
- Display an in-app notice on your next login
- Send an email notification for significant changes
Continued use of the Service after the effective date of a revised policy constitutes your acceptance of the changes.
15. Contact Us
For privacy questions, data requests, BAA inquiries, or complaints:
Sarer Health
Email: privacy@sarerhealth.com
Website: app.sarerhealth.com
If you are in the EEA and believe we have not adequately addressed your concern, you have the right to lodge a complaint with your local data protection authority.