Privacy here is not a feature but the foundation: isolation between clinics, encryption, auditing, daily backups and strict control over who processes medical information, and how.
Each clinic's data resides in an isolated dataset, accessible strictly by token. Every request is scoped to your clinic alone, and the isolation is verified continuously by automated checks.
Data in transit travels over TLS. Sensitive fields (names, contacts, clinical notes) are encrypted in the database. A clinic's integration credentials are stored encrypted.
The infrastructure runs in Microsoft's certified cloud. Data is hosted in the Israel region, on an enterprise-grade platform with its own data-center certifications.
Sign-in by personal staff PIN codes with role-based permissions. Key actions are written to a secured audit log with an integrity chain.
A daily encrypted backup. At any time, the clinic can export its entire database (Excel / ZIP) and request the permanent erasure of all data.
The voice assistant stores neither audio nor transcripts of conversations — the system keeps call metadata (number, time, duration) and whatever the assistant files at the patient's request, such as a message for the physician or a refill request.
The platform runs two voice assistants — an in-app one (for the physician) and a telephone one (for patients). Speech recognition and synthesis run on an enterprise-grade speech platform, and telephony on a licensed global carrier.
Under our agreements, voice and text data passes through transiently, is not stored by the provider and is never used to train models (zero-data-retention terms). Written confirmation is provided on request; the current provider list is on the Sub-processors page.
Speech · zero data retentionTelephony · licensed carrierNo training on your data
Medical information is not disclosed to third parties, other than to trusted infrastructure providers — each under its own Data Processing Agreement (DPA) or Business Associate Agreement (BAA):
Cloud hostingSpeech synthesis/recognitionTelephonyWhatsApp delivery
Every provider is listed by name on the Sub-processors page, and that list is kept current.
The platform is a productivity tool, not a medical device. It makes no diagnoses and takes no clinical decisions: the final decision always rests with the physician, and it is the physician's note that is the record of truth.
The architecture follows a "privacy first" principle and is aligned with the requirements of GDPR and with the HIPAA approach. The full legal documents — Privacy Policy, Terms of Service and EULA — are available on the website.
On written request we provide clinics and their IT departments with the BAA (HIPAA), the Data Processing Agreement DPA (GDPR) and the speech provider's confirmation of non-retention.
Request documents →