What happens, step by step
On your device
You speak or upload
Microphone audio and documents leave your device only when you use documentation features. Live transcription can stream audio from the browser to OpenAI after Asternoos mints a short-lived session. Saved recordings are also uploaded to Asternoos over TLS.
Asternoos
We process the consultation
Our backend orchestrates transcription, note drafting, and chart updates. Clinical results are stored in your account on AWS in the EU (Frankfurt region, as configured).
AI processing
OpenAI & Gemini
Audio/transcripts and limited chart fields go to OpenAI for notes. Images (and sometimes transcripts) go to Gemini for extraction. Raw uploaded images are not kept as files by Asternoos.
Clinical storage
Database & encrypted audio
Transcripts and notes live in PostgreSQL. Audio objects use S3 server-side encryption. Temporary audio is purged after about 7 days unless you keep it.
Separate telemetry path
Sanitized → Langfuse EU
Only operational signals (model, tokens, latency, cost, HMAC pseudonyms) after a multi-stage scrub. No transcripts, notes, names, diagnoses, audio, or images.
Controls you can verify
- TLS in transit; S3 audio encrypted at rest (AES-256).
- Temporary audio purge job + patient/account deletion removes S3 objects.
- Clinical app loads no Google Analytics or Meta Pixel.
- Paddle receives billing identity only — not clinical content.
- Langfuse path uses capture-off, metadata allowlisting, and a wire-level scrubber.
Every destination, in exact detail
This is the complete list. If a place isn't named here, your consultation data does not go there. Tap any row to see precisely what it receives, why, and how long it's kept.
Read the details
Privacy Policy · Security & Compliance · Subprocessors · Patient Notice