1. Terms of Service
1.1 Acceptance
By creating an account or using Doctor Scribe AI, you agree to these Terms. If you do not agree, do not use the service.
1.2 Eligibility
You must be a licensed healthcare professional practising in Canada or the United States to use clinical features. You are responsible for the accuracy of your professional credentials.
1.3 Acceptable Use
- You may not use the service to record or transcribe consultations without informed patient consent where required by your jurisdiction.
- You may not attempt to reverse-engineer, scrape, or impersonate the service.
- You may not store the audio recordings yourself in a way that conflicts with our zero-retention guarantee.
1.4 SOAP Notes Are Drafts
The service produces an AI-generated draft. You are solely responsible for reviewing, editing, and signing every clinical note before it enters a patient record. The provider name on the chart is the human signer, not Doctor Scribe AI.
1.5 Termination
You may cancel anytime from Settings. We may suspend or terminate accounts that violate these Terms or applicable law. Upon termination, your data is exported on request and deleted within 30 days.
1.6 Limitation of Liability
To the maximum extent permitted by law, our total liability is limited to the amount you paid in the 12 months preceding the claim. The service is provided "as is" without warranty of fitness for any particular medical decision.
2. Privacy Policy
2.1 Data We Process
- Audio: processed in RAM in Toronto, never written to disk, erased after note generation.
- Patient PHI: name, vitals, SOAP notes, intake answers, messages — encrypted at rest with Fernet (AES-128 CBC + HMAC-SHA256).
- Account data: email, name, clinic, province, license number — encrypted in transit (TLS 1.3) and at rest.
- Metadata: consult duration, language, template used — kept for billing & analytics; no PHI.
2.2 Where Your Data Lives
All processing and storage happens on our Vultr Toronto datacentre (ca-central). Patient data does not cross the Canadian border. The model inference uses Google Gemini API in Canadian region.
2.3 Audit Trail (PHIPA Compliance)
Every access to a patient record (view, edit, export) is logged in an append-only audit_log table with user_id, action, resource, IP, and timestamp.
2.4 Your Rights (PIPEDA / Quebec Law 25 / GDPR)
- Access: export all your data from Settings → Export.
- Rectification: edit any patient record from the dossier view.
- Erasure: delete a patient record permanently from the dossier view (right to be forgotten).
- Portability: JSON export available on request.
2.5 Sub-processors
We use the following sub-processors. All are bound by Data Processing Agreements:
- Vultr (Toronto, Canada) — hosting infrastructure.
- Google Gemini API (Canadian region) — AI inference. Audio is sent ephemerally for transcription only and is not used to train models.
- Resend / Brevo (optional) — transactional email delivery (no PHI in email body, only links).
3. Refund Policy
3.1 14-Day Free Trial
All plans include a 14-day free trial with 30 consults included. No credit card is required during the trial. You will not be charged until the trial ends.
3.2 30-Day Money-Back Guarantee
If Doctor Scribe AI does not save you at least 1 hour of charting per day in your first paid month, contact support@doctorscribe.ca within 30 days of your first charge for a full refund. No questions asked.
3.3 Pro-rated Cancellation
You may cancel anytime. Subscriptions are charged monthly. There is no pro-rated refund for the current month after the 30-day window, but the service remains active until the end of the paid period.
3.4 Annual Plans
If you switch to an annual plan, the 30-day money-back guarantee still applies to the first 30 days. After that, annual plans are non-refundable but can be cancelled (the plan will not auto-renew).
4. Compliance & Security
4.1 PIPEDA (Canada)
We comply with the Personal Information Protection and Electronic Documents Act. We obtain consent, limit collection, secure storage, and respect subject access requests.
4.2 Quebec Law 25
For Quebec-based clinics, we comply with Loi modernisant des dispositions législatives en matière de protection des renseignements personnels (Law 25 / 2021): privacy officer appointed, breach notification within 72 hours, data residency in Canada, automated decision-making transparency.
4.3 PHIPA (Ontario)
For Ontario clinics handling Personal Health Information, we provide an append-only audit log, role-based access control, and encrypted backups.
4.4 Data Destruction Certificate
After every consult, you receive a signed Data Destruction Certificate showing: timestamp of audio destruction, bytes processed, encryption method, region, and a unique receipt ID. You can show this certificate to your professional college or auditor.
4.5 Breach Notification
In the unlikely event of a security breach affecting your data, we will notify you within 72 hours by email and provide details of the incident, scope, and remediation steps.
5. Contact
For privacy concerns, data subject requests, or any compliance questions, contact our Privacy Officer:
- Email: privacy@doctorscribe.ca
- Support: support@doctorscribe.ca
- Mailing address: Doctor Scribe AI · Toronto, ON · Canada
Doctor Scribe AI is a clinical decision-support tool. It does not provide medical advice. Always exercise professional judgment.