LEGAL
Privacy Policy
This policy explains what information DocVoc handles, why, where it goes, how long it is kept and what you can do about it. It covers docvoc.com, accounts.docvoc.com, api.docvoc.com, inference.docvoc.com and the DocVoc apps.
The short version
- Patient information belongs to the clinician’s practice. We process it only to provide DocVoc to that practice.
- By default, visit audio, transcripts and Genie questions go through our own AI gateway to OpenAI, in the United States, so the transcript and draft note can be written. On a Mac you can process on the machine itself instead.
- Getting the patient’s consent to record is the clinician’s job, not ours. We do not contact patients.
- Records are encrypted before they are saved and are kept on Google Cloud servers in Mumbai. This is not end-to-end encryption.
- We do not sell data, show ads, or use customer data to train AI models.
- You can export or delete your records at any time. Deleted records can remain in our encrypted backups for up to about 40 days.
1. Who we are
DocVoc (“DocVoc”, “we”, “us”) is an AI tool that helps Indian doctors write visit notes. DocVoc is operated from India. Our legal entity name and registered address are available on request from psasatte@docvoc.com.
The clinician records a visit with the patient’s consent. DocVoc writes the transcript and drafts a note in the template the clinician chooses (Standard note, Progress note, Referral letter or First visit). The clinician reviews and signs the note. Genie, DocVoc’s assistant, answers the clinician’s questions about a visit using the relevant parts of the record.
DocVoc is used in a web browser at accounts.docvoc.com, on phone browsers, and in the Mac app for Apple Silicon. Android, iPhone and Windows apps are on the way; this policy will apply to them too.
2. Your role and ours
India’s Digital Personal Data Protection Act, 2023 (the “DPDP Act”) gives different duties to the person who decides why and how personal data is used (the Data Fiduciary) and to a person who processes it on their behalf (a Data Processor).
Patient information: the clinician decides, we process
For information about patients in DocVoc (patients, visits, recordings, transcripts, notes, documents and appointments), the clinician or practice using DocVoc decides why and how it is processed. The clinician or practice is the Data Fiduciary and DocVoc is its Data Processor. We process patient information only to provide DocVoc to that practice, following its instructions and our Terms of Service.
This means:
- The clinician is responsible for getting the patient’s consent to record the visit, and for telling patients how their information is used, including cloud processing in the United States. DocVoc does not obtain patient consent on the clinician’s behalf and never contacts patients. DocVoc offers a consent prompt before recording — in Settings → Privacy, set to never ask, ask once per patient, or ask before every visit — and keeps the time of consent with the visit. It is off unless the clinician turns it on, and turning it on does not move the responsibility to us.
- The medical record stays the clinician’s. DocVoc is a tool for writing notes, not the custodian of anyone’s medical records. How long a practitioner must keep records, and in what form, is set by the law and the medical council regulations that apply to them; those duties stay with the practitioner, and DocVoc does not discharge them.
- Patients who want to see, correct or erase their information should contact their clinician. If a patient contacts us, we will pass the request to the clinician and help them answer it. DocVoc staff cannot see visit content, so we cannot answer a patient directly.
Account information: we decide
For information about clinicians and practices who use DocVoc (email addresses, practice details, billing and usage), DocVoc is the Data Fiduciary. The rest of this policy explains how we handle it.
3. What we collect and why
| Information | What it includes | Why we use it |
|---|---|---|
| Account and practice | Your email address, password (stored only as a salted hash), practice name, billing email, your role in the practice and the people you invite. | To create and run your account, approve your practice, and let practice owners manage members. |
| Sign-in and security | One-time sign-in codes (stored only as a hash), sign-in sessions, the devices you use DocVoc on and when they were last seen, failed sign-in attempts with the network address they came from, and a log of account changes. | To sign you in, keep your account secure, stop password guessing, and investigate problems. |
| Billing | Your plan, billing period, number of seats, payment status, amounts, and the reference numbers Razorpay gives each subscription and payment. | To charge for DocVoc, show your plan and payments, and meet tax and accounting law. |
| Usage | Hours of DocVoc cloud audio each practice uses in a billing month, and counts of cloud requests. | To apply plan hours and fair-use limits and to keep the service stable. This does not include what was said. |
| Your profile | Details you add to your profile, such as your name, credentials, specialisation, registration number, practice, contact email and phone. | To put your details on notes and letters. They are saved with your encrypted records. |
| Clinical records (processed for your practice) | Patients (for example name, date of birth, sex, phone and record number), visits, transcripts, notes, addenda, documents you attach, appointments and your settings. | To provide DocVoc: transcribe, draft notes, answer Genie questions, keep your records and sync them between your devices. |
| Patient languages | The languages you record for a patient: one main language and any others, from DocVoc’s list, or typed in yourself. | To help DocVoc hear the visit correctly. Only the short language codes travel with a recording, never the patient’s name or anything you typed. See section 4. |
| Visit audio (processed for your practice) | The recording of a visit. | To write the transcript. With “Keep audio after transcription” on (the default), the audio is also kept for playback on the device where it was recorded. |
| Support requests | The subject and message you write in Contact support or by email, our replies, and a short technical report about the device (platform, app version, plan, access state and cloud hours used). | To answer you and fix problems. A support request never carries patient names, audio, transcripts or notes; DocVoc refuses obvious pastes of clinical content. |
| Website visits | Standard request details (such as network address and browser) that our hosting provider processes to serve docvoc.com. | To deliver the website. docvoc.com has no analytics, cookies or trackers. |
We do not sell personal data, use it for advertising, or use customer data to train AI models.
We rely on your consent and on the “legitimate uses” the DPDP Act allows, such as information you give us voluntarily to use DocVoc and information we must keep by law. Where we rely on consent, you can withdraw it at any time by writing to us; this does not affect processing that already happened, and we may not be able to keep providing DocVoc without it.
4. What happens to a visit
DocVoc cloud (the default, and the only option on phones and in browsers)
- The clinician records the visit. The audio is encrypted and saved on the device while it is sent for processing.
- The audio goes over an encrypted connection to DocVoc’s servers in Mumbai, then through Vrinda, our own AI gateway, to OpenAI in the United States, which returns the transcript.
- To draft the note, the transcript is sent the same way. When the clinician asks Genie a question, the question and at most eight short excerpts of the record — not the whole record — are sent the same way.
- If the clinician attaches a PDF or Word document to a visit, it is sent to DocVoc’s servers in Mumbai so its text can be read.
Before DocVoc cloud is used on a device, the clinician has to read and accept what it does, naming OpenAI and the Vrinda gateway. If we change that description, we ask again.
DocVoc does not save audio, transcripts, documents or Genie questions sent for processing to a database, and does not use them for training. OpenAI does not train its models on data sent through its API, and may keep it for up to 30 days to monitor for abuse. The results (transcript, draft note, Genie answer, document text) are saved in the clinician’s encrypted records.
Languages
The languages recorded for a patient are sent with the recording as a hint, as short codes only — never the patient’s name and never text you typed in yourself. If exactly one language is recorded and DocVoc’s speech model supports it, we ask for that language. Otherwise the model works the language out for itself, so code-mixed speech such as Hindi and English in one sentence is written as it was spoken. The transcript stays in the language spoken, each language in its own script; the note is always written in clinical English.
Offline processing in the Mac app
The Mac app can transcribe, draft notes and answer Genie questions on the Mac itself, after a one-time model download. The visit is then not sent to DocVoc cloud or to OpenAI: it stays on the computer. Records made in the Mac app are saved on the Mac, and copied to your DocVoc account only when you choose Sync. Processing on the Mac understands English only; for another language, use DocVoc cloud.
After processing
The clinician reads the transcript and the draft, corrects it and signs it. After signing there is an 8-second Undo; after that, changes are added as dated addenda and the signed note does not change.
5. Who processes data for us
We use these service providers. Each may only use the data to provide its service to us.
| Provider | What they do for DocVoc | Data involved | Where |
|---|---|---|---|
| Google Cloud | Runs DocVoc’s servers, databases, the Vrinda AI gateway and nightly backups; delivers Mac app downloads. | Account data, encrypted records, and visit data in transit to processing. | India (Mumbai, asia-south1) |
| OpenAI, through DocVoc’s Vrinda gateway | Cloud transcription, note drafting and Genie answers. | Visit audio, transcripts, Genie questions with relevant record excerpts. | United States |
| Google Workspace | Sends sign-in codes and account emails from docvoc.com, and hosts our support mailbox. | Email addresses and message content. | Google data centres, which may be outside India |
| Razorpay | Payments, subscriptions, UPI AutoPay and e-mandates. | Contact and payment details you give at checkout, plan and amount. DocVoc never sees or stores card numbers. | India |
| Google Firebase Hosting | Serves the docvoc.com website. | Standard request details, such as network address and browser. | Google’s global network |
| Cloudflare R2 | Stores and delivers offline model files the Mac app downloads, alongside Google Cloud Storage. | Network address and the download request. No patient or account content. | Cloudflare’s global network |
DocVoc uses no analytics service, no advertising network and no third-party error-tracking service anywhere: on the website, in the apps or on our servers. The Vrinda gateway named above is DocVoc’s own software, running on DocVoc’s own servers in Mumbai; it is not a third party.
We will update this list before we add or replace a provider that handles patient information, and tell practice owners by email first. If a practice objects to a new provider, it may cancel before the change takes effect.
6. Transfers outside India
DocVoc’s servers and backups are in India. DocVoc cloud processing is a transfer of personal data outside India: visit audio, transcripts, and Genie questions with relevant record excerpts are processed by OpenAI in the United States. Email and website delivery may also be handled outside India, but these do not include patient records.
The DPDP Act allows transfers outside India except to countries the Government of India restricts. We will stop or change a transfer if the law requires it.
If a visit must not leave India, record it in the Mac app with offline processing. Phones and web browsers always use DocVoc cloud.
7. How long we keep data
| Data | How long |
|---|---|
| Clinical records in your account | Until you delete them, or until your account is closed and the export period has passed (see Terms, section 13). |
| Transcripts of signed visits | Until you delete them, which is the default, or for the period you choose in Settings → Privacy (90 days or 1 year). The signed note stays. |
| Kept visit audio | “Keep audio after transcription” is on by default. Kept audio stays encrypted on the device where it was recorded until you delete it. With the setting off, audio is removed once the transcript is saved. |
| Data sent for cloud processing | Not saved by DocVoc after processing. OpenAI may keep it for up to 30 days for abuse monitoring. |
| Backups | Nightly encrypted backups are kept in Mumbai for 30 days, and daily disk snapshots for 14 days. A record you delete is gone from your account at once, but can remain in a backup for up to about 40 days before every copy has expired. |
| Account, billing and security records | While your account is open. After it closes, we keep billing and tax records for as long as Indian law requires, and delete the rest. |
| Service logs | Our services keep request logs without patient information. They are rotated automatically and kept only as long as needed for security and troubleshooting. |
These are the periods for which we hold data. They are not a medical-records retention policy: a clinician’s own duty to keep records is set by the law and the regulations that apply to them, as section 2 explains, and it is unaffected by anything here. Export your records before you delete them or close your account.
8. How we protect data
- Encrypted in transit. DocVoc’s sites and apps use HTTPS.
- Encrypted when saved. Records and kept audio are sealed with AES-256-GCM before they are saved, in the browser, on the phone and in the Mac app. Each account has its own record key.
- Not end-to-end. Records sync between your devices through DocVoc’s servers. The servers protect each account’s record key with a master key, so DocVoc’s systems can open synced records when you sign in. We restrict access to those keys, and we do not access the content of your records unless the law requires it or you ask us to in writing.
- Staff access. DocVoc staff can see accounts, plans, devices and usage, so they can approve practices and answer support requests. They cannot see visits, notes, transcripts or recordings — and not only because the screens omit them: the staff service does not hold the encrypted records or the key that unwraps them, and each release checks that it does not. A support request refuses text that looks like a transcript or a note.
- Locks when idle. DocVoc locks after 5, 15 or 30 minutes without activity (your choice) and hides patient information until you sign in again.
- Sign-in protection. Passwords are stored only as slow salted hashes (PBKDF2-HMAC-SHA256, 600,000 iterations) and one-time sign-in codes only as keyed hashes that expire in 10 minutes. Repeated failed sign-ins are blocked.
- Backups. Backups are encrypted to a key held only by DocVoc’s owner, not by our servers, and are stored in Google Cloud Storage in Mumbai.
No system is perfectly secure. If there is a personal data breach, we will tell the Data Protection Board of India and the people affected, in the way and within the time the DPDP Act and its Rules require. Where the breach touches patient information, the practice is the Data Fiduciary and the duty to report is the practice’s: we will tell the practice without undue delay, give it what it needs to report — what happened, when, which records, what we are doing about it — and help it answer the Board and its patients.
You also play a part: use a strong password, lock or sign out of shared computers, and keep your devices up to date.
10. Your rights
Under the DPDP Act you have the right to:
- Access: get a summary of your personal data we process, what we do with it, and who we share it with.
- Correction: have inaccurate or incomplete data corrected, completed or updated.
- Erasure: have data erased when it is no longer needed, unless the law requires us to keep it.
- Grievance redressal: complain to our Grievance Officer and get a response (see section 14).
- Nominate: name another person to exercise these rights for you if you die or become unable to.
Many of these you can do yourself in DocVoc: edit your profile in Settings; use Export all my data and Delete my data in Settings → Privacy; delete kept audio and choose how long transcripts are kept. Exports are a file on your device that is not encrypted, so store it safely. To close your account, correct account details, nominate someone or make any other request, email psasatte@docvoc.com. We may need to confirm your identity first.
Patients: the clinician or practice that recorded your visit decides how your information is used. Please contact them first. If you write to us, we will pass your request to them and help them respond.
If you are not satisfied with our answer, you can complain to the Data Protection Board of India.
11. Children
DocVoc is for clinicians and their practices. It is not for use by anyone under 18.
Clinicians may record visits with children. For a patient who is a child, the clinician, as Data Fiduciary, is responsible for getting consent from the parent or lawful guardian where the law requires it. DocVoc processes that information only for the clinician, and never uses it for tracking, behavioural monitoring or advertising.
13. Changes to this policy
We will post any change on this page with a new effective date. If a change materially affects how we handle your data, we will email practice owners at least 30 days before it takes effect.
14. Grievance Officer
As required by the DPDP Act and Rules and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, our Grievance Officer is:
- Name
- Prashant Sasatte
- Company
- DocVoc
- Address
- Available on request from psasatte@docvoc.com
- psasatte@docvoc.com (subject “Grievance”)
We acknowledge a grievance within 48 hours and resolve it within 30 days of receiving it. If we need more information, we will ask, and tell you when to expect an answer. You can also raise it from inside DocVoc, under Contact support.