Asternoos Asternoos

Your clinical data stays private

Asternoos · Last updated: August 23, 2026

When you speak with a patient, your voice and everything you type stay within a specific, named set of places — and this page lists every one of them. Audio and documents pass through Asternoos's AI infrastructure only to build your clinical documentation. That content never reaches our analytics or observability tooling: the telemetry we do send to monitor performance and cost is stripped of names, diagnoses, audio, and images before it ever leaves for the EU.

Encrypted in transit Audio encrypted at rest Clinical content ≠ Langfuse Images are never stored

This page explains technical controls. It is not a claim of being “HIPAA compliant”, “KVKK compliant”, or “GDPR compliant”. Full legal text lives on Privacy, Security, and Subprocessors.

YOUR CONSULTATION Audio / Document Live mic (WebRTC) → OpenAI directly, via a short-lived key from Asternoos ASTERNOOS Processing AI Processing OpenAI / Gemini Clinical Storage Asternoos DB + S3 Your account SEPARATE TELEMETRY — clinical content does not enter Langfuse EU · performance / cost only

The moving dots trace data's real route — not decorative.

What happens, step by step

On your device

You speak or upload

Microphone audio and documents leave your device only when you use documentation features. Live transcription can stream audio from the browser to OpenAI after Asternoos mints a short-lived session. Saved recordings are also uploaded to Asternoos over TLS.

Asternoos

We process the consultation

Our backend orchestrates transcription, note drafting, and chart updates. Clinical results are stored in your account on AWS in the EU (Frankfurt region, as configured).

AI processing

OpenAI & Gemini

Audio/transcripts and limited chart fields go to OpenAI for notes. Images (and sometimes transcripts) go to Gemini for extraction. Raw uploaded images are not kept as files by Asternoos.

Clinical storage

Database & encrypted audio

Transcripts and notes live in PostgreSQL. Audio objects use S3 server-side encryption. Temporary audio is purged after about 7 days unless you keep it.

PHI boundary — clinical content stops here

Separate telemetry path

Sanitized → Langfuse EU

Only operational signals (model, tokens, latency, cost, HMAC pseudonyms) after a multi-stage scrub. No transcripts, notes, names, diagnoses, audio, or images.

Controls you can verify

  • TLS in transit; S3 audio encrypted at rest (AES-256).
  • Temporary audio purge job + patient/account deletion removes S3 objects.
  • Clinical app loads no Google Analytics or Meta Pixel.
  • Paddle receives billing identity only — not clinical content.
  • Langfuse path uses capture-off, metadata allowlisting, and a wire-level scrubber.

Every destination, in exact detail

This is the complete list. If a place isn't named here, your consultation data does not go there. Tap any row to see precisely what it receives, why, and how long it's kept.

What it receivesConsultation audio (uploaded, or streamed live from your browser during a live session), the resulting transcript, and the chart fields needed to draft the note — name, age, gender, admission date, bed, main problem.
RegionOpenAI's own infrastructure.
RetentionGoverned by OpenAI's API terms — not independently verified by us. Not used to train their models under the business terms we operate on.
ProtectionTLS in transit. Live audio uses a short-lived session key minted by Asternoos — never a reusable credential.
What it receivesThe bytes of an uploaded lab report or photo, held only in memory — and, on some flows, the consultation transcript, to pull out new-patient details.
RegionGoogle's own infrastructure.
RetentionThe image itself is never written to Asternoos storage — processed once, then discarded. Only the extracted fields (name, complaint, notes) are saved to your chart.
ProtectionTLS in transit. Not used for model training under the paid API terms.
What it holdsThe finished transcript and clinical note, patient chart fields, and — if you choose to keep it — the audio recording itself.
RegionAWS, configured for the EU (Frankfurt).
RetentionChart data stays while your account is active. Temporary audio is purged ~7 days after upload unless you explicitly keep it. Deleting a patient or your account removes the audio file itself, not just the database row.
ProtectionTLS in transit; audio objects use AES-256 server-side encryption; access is authenticated and scoped to your account only.
What it receivesWhich AI model ran, how many tokens, how long it took, what it cost, and a one-way scrambled reference code standing in for your account or patient — never your real name or database ID.
RegionEU (Ireland).
RetentionGoverned by Langfuse's own policy — telemetry only, never clinical text.
ProtectionA four-stage filter strips clinical text before it's even packaged, checks again immediately before transmission, and discards anything it can't confirm is clean. There is no code path that lets a transcript, name, diagnosis, image, or audio file reach this destination.
What it receivesYour email address and a one-time verification code, or an account notice. Never a word of patient information.
RegionUS / EU.
ProtectionTLS in transit.
What it receivesYour name, email, country, tax status, and subscription state. Paddle is merchant of record — full card numbers never touch Asternoos at all.
RegionUK / EU.
ProtectionSigned, verified webhooks. No clinical field is ever part of a billing event.
What it receivesNothing from the clinical application. These trackers exist only on the public marketing website (asternoos.com), never on app.asternoos.com where documentation happens — and even on the marketing site, only after a visitor accepts cookies.
Why list it at allSo "we use analytics somewhere" is never mistaken for "somewhere" including the product itself.

Read the details

Privacy Policy · Security & Compliance · Subprocessors · Patient Notice