← Back to ClinEmpower

Privacy Policy

CLINEMPOWER PTY LTD trading as ClinEmpower

1. Who we are and what this covers

ClinEmpower is clinical documentation software for occupational therapists and allied health practitioners. This policy explains how we handle personal information, including the health information of your clients.

We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

In this policy:

  • "You" means the practitioner who holds a ClinEmpower account.
  • "Your clients" means the people you provide services to, whose sessions you record.

You are the entity responsible for your clients' health information. ClinEmpower processes it on your behalf, under your direction, to produce documentation for you.

2. The short version

  • Your clinical records are stored on your own device, in your browser, encrypted. They are not stored on our servers.
  • We cannot read your clinical records. They sync between your devices through our relay, encrypted with a key only you hold.
  • At the moment you ask for a transcript or a report, the material needed for that task is sent to specialist providers overseas, processed, and then deleted. That is the only time your clinical content leaves your device in a form anyone else could read. Section 5 sets out exactly what is sent, to whom, and where.
  • We do not sell your data, and we do not allow it to be used to train AI models.

3. What we collect

3.1 Account information

Email address and a password (stored only as a cryptographic hash — we never see your password). Held so you can sign in.

3.2 Subscription and billing information

Your plan, subscription status, and billing period. Card details are handled entirely by Stripe and never reach us.

3.3 Usage records

For each transcription or report generation: the date, the type of action, and the duration of audio processed. These records contain no clinical content and no client identifiers. We use them to apply plan limits.

3.4 Clinical records

Session recordings, transcripts, case notes, assessments and reports you create. These are stored on your device, not on our servers. See section 4.

3.5 Technical logs

Standard web server logs (IP address, browser type, timestamps) generated by our hosting provider.

4. Where your clinical records live

On your device. ClinEmpower stores your clinical records — patient records, transcripts, case notes and reports — in your browser's storage, encrypted at rest. Audio you record inside ClinEmpower is encrypted the same way.

One exception, stated plainly: if you upload an existing audio file, the working copy ClinEmpower keeps is not encrypted. That file already sits unencrypted on your own computer, so encrypting our copy would add ceremony without reducing real exposure — anyone who could read our copy could equally read your original. Recordings made inside ClinEmpower are different: that recording exists nowhere else, which is why it is encrypted.

Multi-device sync is always on. An encrypted copy is relayed between your devices through a server we operate in Sydney, Australia. The encryption key is derived from your password and generated on your device. We never receive that key and cannot decrypt what passes through the relay.

If you lose both your password and your recovery phrase, we cannot recover your synced data. This is a consequence of the design, not an oversight.

How long audio stays on your device

  • Once a recording has been transcribed successfully, ClinEmpower deletes the audio from your device immediately — the transcript replaces it.
  • Audio whose transcription never completed is kept for 30 days, then deleted automatically.

Thirty days is deliberate. A recording of an assessment can be the only record of a session that cannot be repeated, and a transcription can fail for reasons that have nothing to do with you — a dropped connection, a closed tab. The window gives you time to notice and try again. When ClinEmpower offers to resume an interrupted transcription, you can also discard that audio yourself at that point.

5. What leaves your device, and when

Clinical content leaves your device only when you ask ClinEmpower to perform a task that requires it.

5.1 Transcription

When you record or upload a session and request a transcript:

What is sentThe audio recording
Where it goesStaged briefly in our storage in Sydney, Australia, then sent to AssemblyAI, processed in the European Union
What happens afterThe transcript returns to your device. Once your device confirms it is saved, we instruct AssemblyAI to delete both the audio and the transcript. An automatic deletion after one day also applies as a backstop

AssemblyAI does not use your audio or transcripts to train its models. We have turned off model training on our account, and material processed on their European servers is excluded from model training by default.

5.2 Generating a case note or an FCA report

Two kinds of material are sent to an AI provider: details you have typed in, and the session content itself.

(a) The details you have typed in

Where you enter itWhat is sent
Profile → Patient DetailsParticipant name; treating therapist (OT). For FCA reports only, also: gender, medical history, current medications, and the participant's representative
Visit / Meeting Minutes / Telehealth → Visit DetailsDate; time; location; persons present
The rest come from fields you fill in yourself. If you leave a field blank, nothing is sent for it.

(b) The session content

When generating a case note:

  • The transcript and the observation notes for that session

When generating an FCA report:

  • The case notes, meeting minutes notes, telehealth notes, external reports and previous FCA content you have selected as source material
The material sent for generation will usually contain names, addresses and other personal details — people say them out loud during a session, you write what you observed, and documents you select as source material are sent as they are. We cannot strip these out without producing a report you could not file.

Where it goes: OpenAI and Anthropic, both processed in the United States.

We want to be direct about this. Producing a usable clinical document requires the client's name and the real content of the session. We do not de-identify this material before sending it. If that is not acceptable for a particular client, do not use ClinEmpower's generation features for that client.

What our providers say they do with it

Neither provider uses it to train their models.

  • OpenAI: "As of March 1, 2023, data sent to the OpenAI API is not used to train or improve OpenAI models" — unless the customer explicitly opts in.
  • Anthropic: "By default, we will not use your inputs or outputs from our commercial products (e.g. Claude for Work, Anthropic API) to train our models." Anthropic's policy explains what "by default" means: the exception is where a customer explicitly opts in, or submits feedback (for example, by using a thumbs-up/thumbs-down button inside a Claude product).

We have not opted in to model training with either provider, and ClinEmpower has no feedback button that sends your content to them.

Both delete it within 30 days.

  • OpenAI generates abuse-monitoring logs that can include the prompts and responses themselves, and retains them for up to 30 days.
  • Anthropic "automatically delete[s] inputs and outputs on our backend within 30 days of receipt or generation" (policy dated 1 July 2026), with four stated exceptions:
Anthropic's exceptionDoes it apply to us?
You use a service with longer retention under your control — e.g. their Files API, where uploaded files persist until you delete them❌ No. ClinEmpower does not use the Files API. Images and documents are sent inline with the request, not uploaded to storage
You and Anthropic have agreed otherwise — e.g. a zero-retention agreement❌ No such agreement is in place
They need to retain longer to enforce their Usage Policy — i.e. where they are investigating a suspected policy violation⚠️ Would apply only if a violation were suspected
Required by law⚠️ As for any provider
So the material is not immediately gone. For up to 30 days after you generate a document, a copy may exist in your provider's systems. We would rather tell you that than imply it disappears the moment the text appears on your screen.

These are our providers' own published commitments, not guarantees we can give on their behalf. We link to their current terms rather than restate them, because they can change.

5.3 What is never sent

  • Your password
  • Your encryption keys or recovery phrase
  • Records for clients whose sessions you have not asked us to process
  • The NDIS number, date of birth and address you enter in Patient Details
  • Speaker labels you assign with Identify Speaker — these are applied in your browser, for your reading, and are never transmitted

6. Overseas disclosure (APP 8)

Some of the providers above are located outside Australia. Under APP 8 we must tell you where, and we must take reasonable steps to ensure they handle your information appropriately.

We have kept every service in Australia that can be kept in Australia. The remaining providers are outside Australia because they do not offer Australian processing. We keep this under review, and will move any service to an Australian region as soon as one becomes available.

6.1 Where your information goes

PurposeProviderLocation
Accounts, subscriptions, encryption key storageSupabase🇦🇺 Sydney, Australia
Application hosting and audio stagingVercel🇦🇺 Sydney, Australia
Multi-device sync relay (encrypted only)Operated by us on Fly.io🇦🇺 Sydney, Australia
TranscriptionAssemblyAI🇪🇺 European Union
Report generationOpenAI🇺🇸 United States
Report generation, scale extraction, document readingAnthropic🇺🇸 United States
Payment processingStripeAustralian entity; global infrastructure

6.2 Steps we take

  • We have disabled the use of our data for AI model training with our transcription provider.
  • We have not opted in to model training with any AI provider. OpenAI's and Anthropic's published policies both state that API data is not used to train their models by default.
  • Our transcription provider's data processing terms incorporate the EU Standard Contractual Clauses.
  • Our providers engage their own subprocessors. Rather than reproduce a list that changes without notice, we link to the provider's own published list: AssemblyAI's published subprocessor list.

6.3 What we cannot promise

We delete your transcripts and audio from our transcription provider as soon as your device confirms the transcript is saved. Deletion of the content is confirmed through their API.

However:

  • Deletion is not instantaneous. Our provider's deletion runs through their cloud infrastructure and can take from minutes to, in some cases, a few days to complete.
  • Some technical and billing metadata is retained after deletion — an internal record identifier, the duration of the audio, the language, and processing settings. This metadata does not contain clinical content or client identifiers.
  • Our transcription provider has confirmed in writing that no copy of the audio or transcript content is held in their backups. What remains in their production systems is governed by the automatic deletion period we have set.
  • We have not yet been able to confirm what, if anything, remains in their operational logs. We have asked, and we will update this policy when we have an answer.

We would rather state this plainly than make a promise we cannot substantiate.

7. Retention and deletion

DataHow long
Clinical records (documents, transcripts, reports)You control these. They stay on your device until you delete them
Audio on your deviceDeleted immediately after a successful transcription. Audio whose transcription never completed is deleted automatically after 30 days — see section 4
Audio staged for transcriptionDeleted once transcription completes
Transcripts at our transcription providerDeleted once your device confirms the transcript is saved; automatic time-based deletion as backstop
Material sent for report generationDeleted by the provider within 30 days (OpenAI: abuse-monitoring logs retained up to 30 days; Anthropic: inputs and outputs auto-deleted within 30 days). Not used for training
Account and subscription recordsWhile your account is open, and afterwards as required by law (tax records: 5 years)
Usage recordsWhile your account is open

If you close your account, we delete your account and subscription records. Your clinical records are on your device; deleting the app's data or your browser profile removes them.

8. Security

  • Clinical records — including audio you record inside ClinEmpower — are encrypted at rest on your device. Audio files you upload yourself are kept as an unencrypted working copy; section 4 explains why.
  • One customer cannot reach another customer's data. Your records are held on your own device, where we cannot reach them. Data you sync between your own devices does pass through our servers, but end-to-end encrypted with a key derived from your password — we hold only ciphertext. A transcript passing through our servers can only be read by the account that created it.
  • All traffic uses TLS.
  • Access to our production systems is restricted and logged.
  • Our transcription provider holds SOC 2 Type II and ISO 27001:2022 certification.

No system is perfectly secure. If we become aware of a data breach that is likely to result in serious harm, we will notify you and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.

9. Your clients' consent

Recording a session requires your client's consent. Obtaining that consent, and complying with the recording and privacy laws of your state or territory, is your responsibility as the treating practitioner. ClinEmpower does not obtain consent on your behalf.

10. Your rights

You may:

  • Access the personal information we hold about you
  • Correct it if it is wrong
  • Close your account and have your account records deleted
  • Complain if you think we have mishandled your information

Contact us at support@clinempower.com. We will respond within 30 days.

If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner — oaic.gov.au — 1300 363 992.

11. Children

ClinEmpower is for registered practitioners. We do not knowingly collect information directly from children. Where you record a session with a child client, that information is handled as clinical content under this policy, and consent is obtained by you from the child's parent or guardian.

12. Changes to this policy

We will post any changes on this page and update the effective date. If a change materially affects how your clients' information is handled, we will notify account holders by email before it takes effect.

13. Contact

CLINEMPOWER PTY LTD

9 Manning Parade, Dundas Valley NSW 2117, Australia

support@clinempower.com