Privacy Policy
The short version. notavik has no server, no user account and no analytics. The visit recording, the transcript and the note are created on your iPhone, stored on your iPhone, and never sent to us or to anyone else. We do not receive them, cannot access them, and hold no copy of them. We collect no personal data about you at all.
Because the audio never reaches us, most of what a privacy policy normally has to explain simply does not apply here. The rest of this page explains exactly what does.
- Who this policy is from
- What we collect about you
- What the app creates on your device
- Patient data and your role
- What leaves the device
- Permissions the app asks for
- Retention and deletion
- Backup, export and sharing
- How your data is protected
- Your rights
- A note on HIPAA
- Children
- Changes to this policy
- Contact
1. Who this policy is from
notavik is an iPhone application published by Vast Flow ("we", "us"). This policy describes how the notavik app handles information. It applies to the app and to this website, and to nothing else.
You can reach us about anything in this policy at [email protected].
2. What we collect about you
Nothing. This is not a stylistic claim, it is a description of the architecture. notavik has:
- no user accounts, no sign-up and no login;
- no backend server that the app sends content to;
- no analytics or product-measurement SDK of any kind;
- no crash-reporting service;
- no advertising identifier, no tracking, and no advertising of any kind;
- no access to your contacts, photos, location, calendar or health data.
We do not know who you are, whether you have opened the app, how often you use it, or how many visits you have recorded. In Apple's App Privacy terms, the app's data practice is Data Not Collected, apart from the purchase information Apple and our payment provider necessarily process to run a subscription — described in section 5 — which is not linked to your identity by us.
3. What the app creates on your device
Using notavik produces three things, all of which live only on your iPhone:
| What | Where it is kept | Leaves the device? |
|---|---|---|
| Visit audio | An encrypted file in the app's private storage area, in AAC format | Never, unless you deliberately export or back it up yourself |
| Transcript | An encrypted database on the device | Never, unless you deliberately export or share it yourself |
| Note | An encrypted database on the device | Never, unless you deliberately copy, export or share it yourself |
| Your settings | On the device, including how you would like notes addressed, your specialty, visit language, retention preference and appearance | Never |
Speech recognition, speaker separation and note drafting all run on the iPhone itself, using models stored on the device. At no point is a recording, a transcript or a note sent to a remote service for processing — not to us, not to a transcription provider, and not to any cloud AI model. After the app has downloaded its speech models once, it works with no network connection at all, including in airplane mode.
4. Patient data and your role
A recorded consultation contains the patient's voice and information about their health. That is sensitive personal data, and this section matters more than any other on this page.
You are the controller of that data, not us. The patient is the data subject. You decide whether to record, on what legal basis, what you write in the note, how long you keep it and where you send it. Under the GDPR and comparable laws, that makes you — the clinician or your practice — the data controller.
We are not a processor of that data, because we never receive it. There is no server on our side that it could be processed on and no copy for us to hold. For the same reason there is no data processing agreement for you to sign with us in respect of your recordings: no processing by us takes place.
Obtaining consent is your responsibility. Recording a consultation requires a lawful basis, and in many places it requires the patient's agreement. Several US states require the consent of every party to a recorded conversation, and across the EU, UK and Switzerland the GDPR and national health-confidentiality rules apply. The requirements where you practise are yours to know and to meet.
To help you meet them in the room, notavik provides a one-tap consent script you can read to the patient, records whether consent was asked and given, and writes that marker into the note. If the patient withdraws consent during the visit, one tap stops the recording and permanently deletes the audio, the transcript and the note together. These features assist your documentation. They are not legal advice, and using them does not by itself make a recording lawful where you practise.
5. What leaves the device
The app makes network connections to exactly three destinations. This is the complete list, and none of them carries a recording, a transcript or a note.
| Destination | What is exchanged | Why |
|---|---|---|
| Apple (App Store, StoreKit) |
Your purchase, restore and subscription status, handled by Apple under Apple's own privacy policy | To sell and restore the subscription or lifetime purchase |
| RevenueCat | Whether a subscription is active, against an anonymous identifier generated by the app. We do not send your name, email address, Apple ID, device identifier for advertising, or any visit content | To check that a purchase entitles the device to unlimited visits |
| huggingface.co | An inbound one-time download of the speech models, roughly 1.5 GB, on first launch. Nothing about you is uploaded in order to fetch them | To put the speech engine on your device so it can run offline |
If you email us for support from inside the app, the message is composed in your own mail app and sent from your own address, so we see whatever you choose to write plus your email address. The app pre-fills a short technical block — app version, iOS version, device model, language, and your retention and appearance settings — which contains no visit content, no dates, no identifiers and nothing about your patients. Please do not include patient information in a support email.
This website uses Microsoft Clarity to understand how the page is used. That is web analytics on this site only; it has no connection to the app and no access to anything on your device.
6. Permissions the app asks for
- Microphone — required to record the visit. The audio is written to encrypted storage on the device and used only to produce your transcript and note.
- Face ID or Touch ID — optional. If you turn on the app lock, biometrics unlock the app. Apple performs the match on the device; we never receive biometric data.
- Notifications — optional, and used only to remind you before a free trial ends. Notifications are generated on your device; we send no push messages because we have no server to send them from.
The app does not request location, contacts, photos, calendar, camera or HealthKit access.
7. Retention and deletion
We retain nothing, because we receive nothing. What follows is about the copies on your own device, which you control entirely.
- Audio is deleted automatically after 30 days by default. You can change this to 7 days, 90 days, or never, in Settings. Automatic deletion removes the audio only — your transcripts and notes are kept.
- Transcripts and notes are kept until you delete them.
- Deleting a visit removes its audio, transcript and note together. The deletion is permanent and cannot be undone.
- Deleting the app removes all of it from the device.
Purchase records held by Apple and RevenueCat are governed by their retention policies, not ours.
8. Backup, export and sharing
Content leaves your device only when you deliberately move it, and only to where you send it. notavik never uploads anything on your behalf.
- Copy puts the note text on your clipboard so you can paste it into your EHR.
- Export PDF and Share hand the note to the standard iOS share sheet — AirDrop, Files, Mail, or any app you pick.
- Backup writes a single password-protected file, encrypted with AES-256 using a key derived from a password you choose. You save it yourself through the share sheet. We never hold it, and we cannot recover it or reset its password. If you lose the password, the backup cannot be opened.
Once you export, share or back up content, it is governed by wherever you put it — your mail provider, your cloud storage, your EHR — and by that provider's terms, not by this policy. Note that if you use iCloud Drive or a similar service to store a backup file containing patient information, you are sending that information to a third party and should confirm that doing so is permitted where you practise.
notavik does not automatically send a note to any electronic health record system. There is no EHR integration.
9. How your data is protected
- Recordings, transcripts and notes are stored using iOS file protection, which means they are encrypted and unreadable while the device is locked.
- You can require Face ID, Touch ID or your passcode to open the app. Starting a recording is deliberately never blocked by the lock, so an in-progress visit is never interrupted.
- Backups are encrypted with AES-256 under a password only you know.
- The strongest protection is structural: content that never leaves your device cannot be exposed by a breach of a server we do not operate.
Because the data lives on one device, the security of that device is decisive. Use a passcode, keep iOS current, and enable Find My. And be aware of the trade this architecture makes: if you lose the phone and have no backup, the notes are gone. We cannot restore them for you, because we never had them.
10. Your rights
Under the GDPR, the UK GDPR, the CCPA and similar laws you have rights of access, correction, deletion, restriction, objection and portability over personal data a company holds about you.
We hold no personal data about you, so with respect to us there is nothing to disclose, correct, delete or export. You exercise the equivalent control directly and immediately on your device: open a note to read or edit it, export it in full to take it with you, delete a visit to erase it, or delete the app to remove everything at once. No request to us is needed, and no waiting period applies.
For your patients' rights over the record of their consultation, you are the controller and those requests come to you. You can fulfil them entirely within the app — the note can be exported for an access request and a visit can be deleted permanently for an erasure request.
For purchase data, contact Apple or RevenueCat, who hold it. We sell no data to anyone, and there is nothing for us to sell.
11. A note on HIPAA
We deliberately do not describe notavik as "HIPAA compliant". Compliance under HIPAA is a property of a covered entity and its business associates — of your practice and the vendors who handle protected health information on its behalf — not of a piece of software sold in an app store. Any app claiming the badge by itself is overstating what such a badge can mean.
What we can tell you precisely is where notavik sits: because the app has no server and never receives, stores or transmits your recordings, we do not handle protected health information at all. We are therefore not a business associate, and there is no business associate agreement to be signed with us in respect of your visits. The information stays on a device that your own security policies already cover.
notavik is designed to support your HIPAA and GDPR obligations by keeping the recording under your control. Meeting those obligations — device security, consent, minimum necessary use, retention, and what you do with the note once you have exported it — remains yours.
12. Children
notavik is a professional tool intended for use by healthcare professionals in their practice. It is not directed to children and is not intended for anyone under 18. We knowingly collect no data from anyone, of any age.
Recording a consultation with a minor patient is subject to the consent rules where you practise, which usually involve a parent or guardian. Those rules are yours to apply.
13. Changes to this policy
If we change this policy we will update the effective date at the top of the page and publish the new version here. If a future version of the app ever introduced a feature that transmitted content off the device, that would be a material change: it would be described here plainly before release, and it would require your explicit, separate and informed consent inside the app. It would never be switched on silently or by default.
14. Contact
Questions about this policy, about how the app handles data, or about anything else go to one address, monitored by the people who build notavik:
Published by Vast Flow. Please do not include patient information in your message.