NeuroScribe
PricingSecurityGet started

Privacy policy

What we collect, who else touches it, how long we keep it, and what you can make us do with it.

Last updated September 20, 2026

Who is responsible for what

If you are a clinician or practice using NeuroScribe, you are the controller of your patients’ data. We process it on your behalf, under your instructions, and we acquire no rights to it by handling it. You decide what goes into the product, what comes out, and when it is deleted.

Neurocareva is the controller for your own account data: your name, email, practice details and billing information.

What we collect

Account informationYour name, email address, practice name, professional role and password. The password is hashed by our identity provider and never reaches us in readable form.
Clinical contentPatients you add, notes generated or imported, templates you create, appointments, and the documentation style profiles derived from your own writing.
Session audioCaptured in your browser and streamed to transcription. It is never written to our storage, and there is no file storage in the product at all.
Usage dataCounts of notes generated and assistant messages sent, used to apply your plan allowance. These are numbers, not content.
Technical logsRequest timing, error traces and identifiers. Logs never contain note text, patient names or any other identifier.
Billing dataHandled by Paddle as merchant of record. We receive a subscription status and a customer reference, never your card number.

Who processes your data

These are the only third parties that receive data from NeuroScribe. Each one is limited to the purpose listed, and none of them are permitted to use your data for their own purposes.

SupabaseDatabase and authentication

Stores your account, patients, notes, templates and appointments. Encrypted at rest.

VercelApplication hosting

Serves the application and runs the API routes. Does not retain request bodies.

AnthropicNote generation and clinical assistant

Receives the transcript, your template and your learned style. Commercial API terms exclude the content from model training.

AssemblyAISpeech to text

Receives session audio in a single streamed request and returns a transcript with speakers separated.

PaddlePayments

Handles subscriptions as merchant of record. Receives your billing details. Never receives clinical data.

GoogleCalendar integration, optional

Only if you connect it. Receives appointment times and titles, never note content.

Data is stored and processed in the United States. We do not sell data, we do not share it for advertising, and we do not run analytics that follow you across other websites.

HIPAA and our role as a business associate

When you use NeuroScribe to document patient care, you are a covered entity (or the business associate of one) and we are your business associate under 45 CFR Parts 160 and 164. We will execute a Business Associate Agreement with your practice before you put protected health information into the product. Ask and we will send one the same day.

Where this policy and a signed BAA differ, the BAA governs.

What we may and may not do with PHI

We use protected health information only to provide and support the service you are paying for: transcribing a session, generating a note, answering a question about a chart, and keeping those records available to you. We do not sell PHI, we do not use it for marketing, and we do not use it to train artificial intelligence models. Any use for our own purposes is limited to the proper management of the service and is carried out on de-identified data wherever it is possible to do so.

Minimum necessary

Each part of the system receives only what it needs. Transcription receives audio and returns text. The language model receives the transcript, your template and your learned style for a single request. Style learning receives text that has already had identifiers stripped. Our application logs carry identifiers and counts, never note content, patient names or any other identifier.

Safeguards

Administrative, physical and technical safeguards are in place as required by the Security Rule: encryption in transit and at rest, row-level access control keyed to the individual provider, two-factor authentication available on every account, column-level restrictions on privileged fields, an audit trail of security-relevant events, and access to production data restricted to the small number of people who operate the service. The technical detail is on the security page.

Subcontractors

HIPAA makes a business associate directly liable for its subcontractors. Every company that can touch PHI on our behalf is bound by a Business Associate Agreement carrying the same obligations we owe you. The current list is published on the security page, and we do not add one without an executed agreement first.

Breach notification

If we discover a breach of unsecured protected health information, we will notify you without unreasonable delay and in no case later than 60 calendar days after discovery, as required by 45 CFR 164.410. The notice will identify the individuals affected so far as we are able, what happened, what information was involved, what we have done about it, and what we recommend you do. You remain responsible for notifying affected individuals, HHS and, where applicable, the media, because that duty sits with the covered entity.

Helping you meet individual rights

If a patient exercises a right you must satisfy, we will give you what you need to satisfy it. That covers access to their designated record set under 45 CFR 164.524, amendment of it under 164.526, and an accounting of disclosures under 164.528. In practice most of this is already in your hands: every note is exportable to PDF or Word from inside the product at any time, without asking us.

Termination

When your agreement ends, we return or destroy the protected health information we hold, at your election, and we stop using it immediately. Where a backup makes destruction infeasible within the retention window described above, the information remains protected under these terms and is destroyed when that window expires.

HHS access

We will make our internal practices, books and records relating to our use of PHI available to the Secretary of Health and Human Services for the purpose of determining your compliance with the Privacy Rule.

How long we keep it

Session audioNot retained. It exists in memory for the length of one transcription request and is never written to disk.
Working transcriptsNot retained once the note has been generated.
Notes and chartsKept until you delete them or close your account. They are your records, so we do not expire them.
Style learning source notesParsed in your browser. Only extracted text is sent, identifiers are stripped before analysis, and the text is discarded once the style profile exists.
Account dataDeleted within 30 days of you asking us to close the account.
BackupsEncrypted database backups are retained on a rolling basis and age out within 30 days.

Your rights

You can export every note in your account to PDF or Word at any time, without asking us. You can delete patients, notes and style profiles from inside the product. You can ask us to delete your whole account and everything in it by writing to the address below, and we will confirm when it is done.

Depending on where you live you may also have rights to access, correct, restrict or object to processing, and to receive your data in a portable format. Ask and we will action it. We will not charge you and we will not ask why.

Cookies

NeuroScribe sets one category of cookie: the session cookie that keeps you signed in. It is required for the product to work, it is not shared with anyone, and it is not used to track you. We do not run advertising cookies, third-party trackers or cross-site pixels, which is why there is no cookie banner asking you to consent to any.

Security

Encryption in transit and at rest, provider-level isolation enforced in the database, and column-level restrictions on privileged fields. The detail, including what we have not finished, is on the security page.

Changes and contact

If we change this policy in a way that affects how your data is handled, we will tell account holders by email before it takes effect, not by quietly changing the date at the top.

Privacy questions and deletion requests: privacy@neurocareva.com
Security reports: security@neurocareva.com