Built so the recording cannot leave your computer
The recording of a conversation stays on your practice's computer, because the application has no path that sends an audio file out. There it is transcribed, matched to the speaking people, and stored encrypted; it is not uploaded. For the draft note, the application sends only the plain transcript text to the provider configured in the settings, unless you choose a local model. The access key to that provider sits encrypted in your operating system's protected store. The state of every session is saved at every step, so a crash costs at most one recording segment, never the whole conversation.
Reviewed editorially against product behaviour and the cited primary sources; not individual medical or legal advice.
Where the recording stays
The audio recording of a conversation is created and stays on the computer running KiPT Voice. There it is transcribed, the speaking people are matched, and the file is stored encrypted on the same disk. The recording is never uploaded.
- Recording, transcription, and speaker matching all run on the practice computer.
- The file is stored encrypted, not in plain text.
- There is no upload of the audio file, not even a cached one at a provider.
What leaves the practice computer and what does not
For the draft note, the application sends only the plain transcript text, not the audio file, to the provider you have configured in the settings. For anyone who instead works exclusively with a local model, the transcript text does not leave the practice computer either.
The relationship with that provider is a separate contract your practice holds, typically a data processing agreement under Art. 28 GDPR. KiPT Voice cannot technically enforce which region an external provider processes the data in; the application uses the provider you have configured exactly as you configured it.
- Leaves the computer: the transcript text, only to the chosen external provider.
- Does not leave the computer: the audio recording.
- With a locally run model, the transcript text does not leave the computer either.
- The choice of provider and its contractual terms rest with your practice.
Encryption and credentials
The stored recording sits encrypted on the practice computer. Should encryption ever fail, the recording is not deleted but kept, with the error reported visibly; a lost recording would be the worse failure.
The access key to the configured provider is never stored in plain text but secured through the operating system's protected store, on Windows via its own built-in protection mechanism, on macOS via the keychain. The key leaves the computer only to authenticate to the configured provider.
- Encrypted storage of the recording on the practice computer.
- Access keys sit in the operating system's protected store, not in plain text.
- The key is used only to sign in to the configured provider.
No silent losses
The state of a session is saved at every step, not only at the end. If the application crashes during a recording, at most the recording segment in progress is lost, never the whole conversation; on the next start the application resumes the session and continues processing the segments already saved. Recording only begins after consent has been explicitly confirmed with a timestamp; without that confirmation, no recording starts.
The application's log files never contain the content of the conversation, the transcript, or the note. Only technical details such as file paths, durations, exit codes, and error messages are logged.
- The session state is saved at every step, not on a schedule.
- Binding, timestamped consent before recording begins.
- Logs never contain conversation, transcript, or note content, only technical details.
What you control in the practice yourself
You choose the microphone and the provider in the settings, including the option of using a local model. You decide who has access to the stored recordings on the practice computer. Retention follows fixed rules: the audio recording is deleted as soon as you have confirmed the note; transcript and note text are removed from the application after an adjustable period, 90 days by default, leaving only the entry that an appointment took place.
- Choice of microphone in the settings.
- Choice of provider, including a local model.
- You control access to the practice computer and therefore to the recordings yourself.
- Audio is deleted once the note is confirmed; text after the set period.
Frequently asked questions
Is the recording uploaded to a cloud?
No. The audio recording is created and stays on the practice computer, where it is transcribed and stored encrypted. There is no upload of the audio file, not even to the provider that creates the note draft.
What happens on a crash?
The session state is saved at every step. A crash costs at most the recording segment currently in progress, never the whole conversation. On the next start the application resumes the session and continues processing the segments already saved.
Where is the access key to the provider kept?
Encrypted, in your operating system's protected store, never in plain text. It leaves the computer only to sign in to the configured provider.
Can I work entirely without an external provider?
Yes. If you configure a local model, the transcript text also stays on the practice computer. Without an external provider or a local model, no note draft is produced.
Can the manufacturer see my conversations?
No. J Medical GmbH has no access to recordings, transcripts, or notes. They never reach our servers at any point.