Security & trust

Security is the architecture,
not a setting.

VOSS is built to the standard patient data demands โ€” encrypted, redacted, and never retained on our servers after processing. Individual-mode sessions live only on the device; clinicians choose what, if anything, to back up to their account.

๐Ÿ”’

Encrypted in transit

All data is encrypted in transit over HTTPS/TLS, with secure transmission practices and access controls.

๐Ÿ—‘๏ธ

Immediate deletion

Audio files are deleted immediately after transcription โ€” on both the device and the server.

๐Ÿ“ต

On-device option

On-device transcription keeps all audio on the phone. If it's turned off, we warn you before anything is sent.

๐Ÿ›ก๏ธ

PHI redaction

Protected health information is redacted during backend processing. Our processing servers store none of it; the only session content in our infrastructure is what a clinician explicitly backs up to their account.

๐Ÿงน

Zero processing retention

Our processing servers retain no session or user content once the response is returned. Individual accounts cannot store session content in our cloud at all; what we keep for them is name, country, email and a content-free usage count.

๐Ÿšซ

No tracking or sale

No cross-app tracking, no advertising identifiers, and we never sell personal data.

How your data flows

From the room to the record โ€” and gone.

Data is used only to run the feature you asked for, then deleted.

01

Captured

The visit is recorded on your device, with explicit consent before anything is processed โ€” and, in the patient app, only after you confirm that everyone in the room has agreed to the recording.

02

Encrypted

If sent for processing, data travels encrypted over HTTPS/TLS โ€” never in the clear.

03

Processed

Our backend runs transcription, notes, and possible explanations under a zero-retention AI policy.

04

Deleted

Audio is deleted immediately; processing servers keep no session content. Individual sessions stay on the device; clinician sessions are stored only if backed up on purpose.

Our commitments

Trust, by design and by default.

The safeguards below aren't add-ons โ€” they're how VOSS is built.

๐Ÿฅ

HIPAA-ready

PHI redaction, non-identifying logging, and a BAA path for enterprise deployments.

๐Ÿค

Your data is not training data

Our AI providers do not use content submitted through their APIs to train models, and our backend keeps none of it after the response is returned.

๐Ÿ‘ค

Human in the loop

VOSS drafts and suggests; every note is reviewed and signed by a clinician.

โœ‹

Explicit consent

A clear consent screen discloses what's collected, who processes it, and how it's protected โ€” before use.

Read the details.

Our Privacy Policy covers data handling, retention, third-party AI services, and your rights in full.