How we protect your data and your patients' information
Last Updated: September 15, 2026Questions? Email privacy@novascribe.us
NovaScribe is a medical documentation assistant for healthcare providers. You record patient encounters using our iPhone or Android app, and our AI generates clinical notes automatically.
The basics:
NovaScribe is designed to save you time on documentation while maintaining the accuracy and quality your patients deserve.
NovaScribe is designed and operated to comply with HIPAA requirements for protecting health information.
Important clarification: NovaScribe is a Business Associate, not a Covered Entity. We process Protected Health Information (PHI) on your behalf. Patient rights requests (access, amendment, accounting of disclosures) should be directed to you as the treating provider. We will assist you in responding to such requests.
| Data Type | Examples | Why We Need It |
|---|---|---|
| Account information | Email, password, name | To create and secure your account |
| Professional information | Medical specialty | To customize note formats |
| Audio recordings | Patient encounter dictations | To generate clinical notes |
| Payment information | Processed by Stripe | To manage your subscription |
| Data Type | Examples | Why We Need It |
|---|---|---|
| Clinical notes | AI-generated documentation | The service you're paying for |
| Medical codes | E/M levels, CPT codes | To assist with billing |
| Session metadata | Timestamps, duration | To organize your sessions |
| Data Type | Examples | Why We Need It |
|---|---|---|
| Device information | iPhone model + iOS version, or Android device model + Android version | To ensure compatibility and fix bugs |
| Push notification tokens | Apple-provided identifier (iOS) or Firebase Cloud Messaging token (Android) | To notify you when notes are ready |
| Crash reports | Error logs (no PHI) | To fix bugs and improve reliability |
The NovaScribe iOS app supports Face ID and Touch ID for convenient authentication. This biometric data never leaves your device - it's processed entirely by iOS and is not transmitted to or stored on NovaScribe servers. The NovaScribe Android app does not use biometric authentication; sign-in is via username and password.
When you use the NovaScribe iOS app, we request the following device permissions:
| Permission | Why We Need It | What Happens If You Decline |
|---|---|---|
| Microphone | To record patient encounter dictations | The app cannot record -- this is required for core functionality |
| Push Notifications | To notify you when your clinical note is ready | You can check note status manually in the app |
When you use the NovaScribe Android app, we request the following runtime permissions:
| Permission | Why We Need It | What Happens If You Decline |
|---|---|---|
Microphone (RECORD_AUDIO) |
To record patient encounter dictations | The app cannot record -- this is required for core functionality |
Notifications (POST_NOTIFICATIONS, Android 13+) |
To notify you when your clinical note is ready, and to show the ongoing recording notification mandated by Android 14+ for microphone access in the background | You can check note status manually in the app; recording itself remains available |
The Android app additionally declares the following install-time permissions (no runtime prompt): INTERNET and ACCESS_NETWORK_STATE (API calls to NovaScribe + network availability checks for the upload queue), FOREGROUND_SERVICE and FOREGROUND_SERVICE_MICROPHONE (required by Android 14+ to record while the app is backgrounded), and WAKE_LOCK (prevents the CPU from sleeping during an active recording).
Your audio is recorded locally on your device and transmitted to our servers only when you tap "Generate Note." We do not access your microphone at any other time.
Here's exactly what happens when you record a patient encounter:
Data location: Your data is stored on servers in the United States (Amazon Web Services, US-East-2 region). Some AI processing of text transcripts may run in other AWS regions worldwide, as described in Section 5; nothing is stored outside the United States.
We use secure, established AI cloud services to transcribe and generate your clinical notes. Here's how your data is processed:
| Processing Step | What Happens | Data Involved | Data Residency |
|---|---|---|---|
| Speech-to-text | Your audio is converted to a text transcript | Audio recordings (temporarily) | United States |
| Note generation | AI creates clinical documentation from the transcript | Text transcript | United States or another AWS region worldwide, selected automatically by the provider for speed and capacity; text transcript only, not retained |
| Clinical analysis | AI assists with E/M classification and billing codes | Text transcript | Primarily United States; some supplemental analysis may be processed internationally |
All AI service providers we use operate under agreements that:
android:allowBackup="false") and exclude all recording and queue data from device-to-device transfer and ADB extraction (via dataExtractionRules) so unfinished recordings cannot leave the device through Google's backup channels. Data on our servers is encrypted using industry-standard methods.| Data Type | How Long We Keep It | How It's Deleted |
|---|---|---|
| Audio recordings | Deleted within 6 hours of processing | Automatic, permanent deletion |
| Clinical notes | Until you delete them or close your account | You control this |
| Account information | While active + 30 days after closure | Upon account deletion request |
| Billing records | 7 years (legal/tax requirements) | Automatic after retention period |
| Audit logs | 90 days | Automatic rotation |
| In-app Help Chatbot conversations | 12 months (see below) | Automatic deletion after 12 months |
When you ask a question in the in-app Help Chatbot (the “Interactive Help” assistant), the question you typed and the assistant’s answer are saved so the NovaScribe team can review them for quality improvement — finding gaps in our help content, fixing answers that were confusing, and identifying topics that should be added.
To delete your account and all associated data:
Upon deletion request:
Note: We cannot delete data that we're legally required to retain (such as billing records for tax purposes).
We believe in being clear about what we don't do with your data:
You have control over your data:
Request a copy of the personal information we hold about you.
→ Email privacy@novascribe.us
Update inaccurate account information anytime in the app, or contact us for assistance.
→ Settings → Account in the app
Remove individual notes anytime, or delete your entire account.
→ Settings → Privacy → Delete My Account
Download your clinical notes in standard formats.
→ Contact privacy@novascribe.us
Unsubscribe from marketing emails (you'll still receive essential service communications).
→ Link in any marketing email
Control what notifications you receive.
→ Settings → Notifications in the app
If you're a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
In the past 12 months, we have collected:
We will verify your identity before processing requests. You may designate an authorized agent to make requests on your behalf.
NovaScribe is designed for licensed healthcare professionals. The service is not intended for use by individuals under 18 years of age.
We do not knowingly collect personal information from children under 13 (or other applicable age threshold). If we learn that we have collected personal information from a child, we will delete it promptly.
If you believe a child has provided us with personal information, please contact us at privacy@novascribe.us.
NovaScribe generates clinical documentation to assist healthcare providers. NovaScribe is NOT:
The clinical notes, billing codes, and other content generated by NovaScribe are suggestions only. As a healthcare provider, you are responsible for:
In accordance with Apple's App Privacy requirements, the following data may be linked to your identity for the iOS app:
In accordance with Google Play's Data Safety requirements, the NovaScribe Android app collects, processes, or stores the following categories of data; all are linked to your identity (your NovaScribe account):
| Data type | Collected | Shared | Purpose |
|---|---|---|---|
| Email address | Yes | No | Account creation, sign-in, password reset, email verification |
| User IDs | Yes | No | Identify your NovaScribe account on the server |
| Audio recordings | Yes | With our HIPAA-compliant speech-to-text subprocessors only | Generate transcripts; deleted within 6 hours of processing |
| Health information (clinical notes) | Yes | With our HIPAA-compliant AI subprocessors only | Generate and store your clinical notes |
| Device or other IDs (FCM push token) | Yes | No | Send "your note is ready" push notifications |
| App interactions | Yes | No | Diagnose bugs, identify reliability issues |
| Crash logs | Yes | No | Diagnose crashes (no PHI included) |
All transit is encrypted with TLS 1.2+ and certificate pinning to novascribe.us. Audio storage is local-only until you tap "Generate Note." None of the data above is sold or used for advertising.
AD_ID permissionNovaScribe subscriptions are managed through our website (novascribe.us) via Stripe. The iOS app supports both web-managed subscriptions and Apple In-App Purchases (StoreKit 2); the Android app opens the Stripe checkout and customer portal pages in a Chrome Custom Tab so management, billing, and cancellation happen on novascribe.us/settings. The Android app does not currently use Google Play Billing for in-app purchases of NovaScribe subscriptions.
We use Google Ads conversion tracking on our website (novascribe.us) to measure the effectiveness of our advertising. This tracking:
Google Ads conversion tracking is used on the website only, not within the iOS or Android apps. The mobile apps do not embed third-party analytics SDKs. The only third-party SDK integrated into the Android app is Firebase Cloud Messaging (FCM), which is used solely to receive push notifications when your clinical note is ready -- no analytics events are sent to Firebase.
To decide which features to invest in, improve, or retire, we record counts of which controls are used inside the NovaScribe application, with no name attached to them. This is separate from the website analytics described in Section 14, and it is used for product decisions only.
Your username is converted, using a secret key, into a scrambled code that is different for every feature and changes every month. That conversion happens in memory; your username is never stored alongside the counts. The code exists only so that one clinician using a feature a hundred times can be told apart from a hundred clinicians using it once — which are opposite findings.
The per-person codes are deleted when the month is summarized, and are erased from the live database no later than 41 days after the day they describe in normal operation. (The deletion job runs every hour and works in batches; an unusually large backlog would simply continue on the following hourly run.) Copies inside our encrypted database backups age out afterwards: routine automated backups roll forward on a 7-day cycle, and the occasional manual backup taken before a major maintenance change is deleted once that change has been stable for 14 days. What remains permanently is a plain total, for example "this feature was used 412 times by 3 people in August", carrying no name, code, or identifier of any kind. One caveat we would rather state than gloss: where a total covers only a single clinician, it is that clinician's own count, so it is not the same as being unidentifiable. We keep those figures rather than deleting them because with a practice this size the number of people using a feature is often the whole finding, and we treat them as confidential business data.
We never sell or rent this data, and no analytics company ever sees it. There is no analytics vendor, tracking pixel, or advertising tag involved. The only parties that handle it are NovaScribe and the sub-processors that run our infrastructure, the same ones that hold everything else we store: it lives in our own database, which runs on Amazon Web Services under a Business Associate Agreement. AWS holds that database on our behalf and does not use what is in it. Where your data is stored and who handles it is described in Section 4, "How Your Data Flows."
Our internal standard for this data, including its limitations, is the Product Telemetry Policy (NS-POL-024).
We may update this Privacy Policy from time to time. When we make material changes:
Your continued use of NovaScribe after changes take effect constitutes acceptance of the updated policy.
Previous versions: Contact privacy@novascribe.us to request previous versions of this policy.
We're here to answer your privacy questions.
Proctor Medical Consulting, LLC
5636 Lake Trace Drive
Hoover, AL 35244
Response Time: We aim to respond to all inquiries within a few business days.