Security

Where a recording actually goes.

When you record with consent in Scribe, the audio goes over an encrypted connection to our BAA-covered transcription processor and the AI pipeline that formats your note (Claude on Amazon Bedrock) — never through our website's general hosting (Vercel). While you're recording, encrypted recovery data stays on your device as encrypted chunks stream to the processor. That design can recover many interrupted sessions without pretending any browser is impossible to lose.

Once the note is written

Audio is temporary. The approved note is yours.

In normal operation, the recording is automatically purged after the note is created. What remains is the note you read and approved — the same record that would exist if you'd typed it yourself.

What remains after a session

  • You keepThe note you read and approved — the same thing that would exist if you'd typed it yourself.
  • You keepAny note-field fingerprint you've taught Scribe — stored in your own browser, never your note text.
  • Not keptThe session audio — deleted once your note is written.
How we handle your data

In transit, at rest, and under our vendor BAAs with Deepgram and AWS.

In transit & at rest

Encrypted at every step

Audio and note content travel over encrypted connections at every step described here — from your browser to the BAA-covered processor and the AI pipeline, and back.

Session audio

Deleted once the note exists

Session audio is deleted once the note is generated. The two in-session backups — on-device and streamed — are purged automatically once the note is written, or within a day if a recording is never finished. Notes persist only until you file or discard them.

Who touches it

A short, fixed list of processors.

The same ones named in our privacy policy, kept in sync with it on purpose.

  • Deepgram

    Transcribes session audio to text, under a signed Business Associate Agreement. Not retained after transcription.

  • Amazon Web Services (Bedrock)

    Formats the transcript into your note (Claude), under a signed Business Associate Agreement. Also transcribes session audio to text (Amazon Transcribe) for clinicians not on the Deepgram allowlist above, under the same AWS agreement. Audio and note text are processed transiently and kept only as long as needed to produce the draft.

  • Vercel

    Hosts the website. Deliberately kept out of the PHI path: session audio and note content never pass through it.

The free Note Check tool is a separate path entirely — it runs in your browser, sends nothing to us, and touches none of the above.

Teaching Scribe your EHR

What gets stored is a content-free fingerprint.

If you use Teach an EHRto point Scribe at a note field on an EHR we don't have a built-in adapter for, what gets saved is a content-free fingerprintof that field — its tag, an id pattern, its label, its position on the page — never your note text and never patient data. It's stored in your own browser. Sharing an anonymized version of that fingerprint to help us build an official adapter is optional and off by default.

Your practice. Your keys.

Nothing files itself.

You read every note, change anything, and approve it before it goes into a chart.

What you approve

Nothing files itself. You read every note, change anything, and approve it before it goes into a chart. What remains is the note you read and approved.

What NoteScreen never does

NoteScreen doesn't access your microphone without your action, doesn't train any model on your notes, and doesn't sell or share personal data with advertisers.

For security reviewers

The same information, in the shape a review wants.

If you're evaluating NoteScreen for a group practice, here's the same information in the shape a security review usually wants:

  • Subprocessors

    Deepgram (transcription), Amazon Web Services / Bedrock (note formatting), Vercel (marketing site + app hosting, no PHI), Supabase (non-PHI billing and settings state). Full list and scope in the privacy policy.

  • PHI boundary

    Session audio and note text flow directly from the browser to our AWS-hosted pipeline and never transit Vercel's serverless layer — a deliberate architectural choice, not a policy statement alone.

  • Encryption

    Audio and note content travel over encrypted connections at every step described above.

  • Retention

    Session audio is deleted once the note is generated; the two in-session backups (on-device and streamed) are purged automatically once the note is written, or within a day if a recording is never finished. Notes persist only until you file or discard them.

  • Compliance posture

    NoteScreen is built for HIPAA-sensitive workflows. We don't claim blanket HIPAA certification as a product; our vendor BAAs with Deepgram and AWS and the architecture above are what actually govern PHI handling.

Questions a standard questionnaire doesn't cover? Email hello@notescreen.ai.

NoteScreen is a documentation support tool — not billing or legal advice, and not a guarantee of payment.