How your health data is protected
Row-level security, restricted access, UK data residency, and the third-party processing behind transcription and summaries.
A recording of a consultation is one of the most revealing files you will ever own. Diagnoses, medications, family history, the thing you were too embarrassed to mention until minute twelve. This post is about the choices that protect it, and how they work.
Isolation at the database level
Recordings, transcripts, summaries, symptom logs and medication lists are each locked to one account by the database itself, using what’s called row-level security. The rule lives in the database rather than in the app’s own code, which is what makes it hard to get round: a bug in the app can’t talk the database into handing over somebody else’s records.
How access is treated
We work to a core principle of restricting and minimising access to health data, and we don’t read your recordings. Nothing about running the service depends on us doing so: when you report a summary that came out badly, we work from technical logs that carry no health content, and from whatever you decide to show us.
Processing and AI
Transcription and summarising are done by specialist AI providers rather than by us. The feature depends on it: your recording, or text taken from it, is sent to be processed and the result comes back to your account. Those providers receive what’s needed to produce your summary, nothing is kept from the working steps in between, and your data isn’t used to train AI models without your explicit consent.
They aren’t the only third parties behind Seenly. Hosting, sign-in, analytics and payments involve providers too, and some of that processing may happen outside the UK. Our privacy notice lists the categories and covers international transfers.
Your records are stored on UK servers and handled under UK GDPR. When Seenly goes on sale, billing will run through the App Store and Google Play, so your card details go to Apple or Google and never to us. The summaries themselves are generated automatically, can contain errors, and never replace advice from your clinician.
What you control
- Delete any recording, transcript or summary whenever you like
- Your data exports in standard formats
- Closing your account permanently removes what was stored with it
Architecture, not promises
A privacy policy is a statement of intent. A database rule is a different kind of thing: it sits underneath the application, so a mistake in our code can’t talk its way past it, and it doesn’t rely on every future developer remembering it’s there.
Our privacy notice sets out in full how your data is handled. If you want the detail on any of this, ask us for it.