Privacy Policy

Effective 20 September 2026

PatientDesk is the data controller. This page says what we keep, where it is processed and for how long. You can reach us at patientdesk.ai.

What we collect

  • Account: your e-mail address, your name if you give it, and your password (hashed, held by our authentication provider).
  • API keys: only a SHA-256 hash of the key and its first 16 characters. We never hold the key itself; it is shown once when created.
  • Usage records: time, endpoint, audio duration in seconds, processing time and the key used. No audio, no text.
  • Technical logs: IP address, browser, request path and status code. Kept for up to 90 days.

Audio and transcripts

Audio you send is processed in memory, the transcript is returned to you and the audio is discarded right after the response. We do not store transcripts either.

Live streaming works the same way: audio chunks are processed, never stored. Only the number of seconds is recorded.

Where data is processed

The model is ours and currently runs on our own server hosted in the Netherlands (EU). Account and usage data are stored in Germany (EU). The website is served through a global content delivery network; its server-side functions run in Germany.

For enterprise customers the model is served from Turkey.

Model training

Audio sent on the free and standard plans is not used for model training today. If we ever want to change that, we will announce it here first and offer an opt-out. Enterprise agreements guarantee in writing that audio is never used for training.

Cookies

Session cookies for signing in, a language cookie and a theme preference kept in the browser. No advertising or third-party analytics cookies.

Service providers

  • A cloud infrastructure provider: model server (EU).
  • A managed database and authentication provider: account data and verification e-mails (EU).
  • A web hosting provider: the website.

Retention

Account and usage data are kept while the account exists and deleted within 30 days after it is closed. Technical logs are kept for up to 90 days.

Your rights

Under KVKK and GDPR you can access, correct, delete and object to the processing of your data. To close your account or make a request, reach us at patientdesk.ai.

Security

All traffic is encrypted with TLS. Keys are stored hashed. Access to the server is limited to authorised staff.

Changes

If we update this policy we publish it here with its date. For the terms of use see the Terms of Service.