What iClerk Does
iClerk is a pre-deployment proof-of-concept experiment in the clinical application of AI, provided for evaluation. It works from a clinical team’s own guidelines, screens for the diagnoses that must not be missed, shows the source behind what it presents, transcribes consultations in real time and drafts structured notes. Your spoken words become text — iClerk does not record or store audio. It is not offered as a product for the care of real patients.
Status
Status: iClerk is a pre-deployment proof of concept provided for evaluation and demonstration — not a finished product and not a certified medical device — and does not currently hold formal data-protection or clinical-safety certifications (for example UK GDPR, DSPT, or MHRA classification). Your data may be processed by third-party AI services that can be located outside the UK. You may use iClerk at your own discretion with any form of data; if you choose to use it with real patient information, that choice — including compliance with the data-protection and clinical-governance rules that apply where you practise, and every clinical decision that follows — is entirely your own responsibility. Every AI-generated note must be reviewed by the responsible clinician.
What We Collect
- Consultation data — Transcripts and AI-generated notes from your clinical sessions
- Account details — Depending on how you sign in: your Google or Apple email and display name, or your mobile number if you sign in by text message. Your mobile number is stored encrypted and is used only to send you sign-in codes and to identify your account.
- Usage data — Login times, session activity, and IP address (for security)
We do not use tracking cookies, analytics, advertising, or third-party trackers. The only cookie is the session cookie required for login.
How We Use It
- Transcription and note generation — the core service
- Authentication and access control
- Security monitoring and audit logging
We never use your data for AI model training, marketing, profiling, or any purpose beyond providing the service.
Where Your Data Lives
Consultation data is encrypted in transit (TLS) and encrypted at rest at the application level (libsodium, 256-bit keys) on our servers in the UK and EU. It is not end-to-end encrypted: to transcribe and draft notes, content is decrypted on our servers and sent over encrypted connections to the services that process it. As set out in the Status section above, AI processing of your data may take place in other countries depending on the model in use.
Who Can See It
Only you (and your companion device, if enabled). We use the following services to operate iClerk:
- Our own UK/EU servers — Hosting and encrypted storage
- Speech-to-text and AI model providers (third-party services under their data-processing terms) — Transcription and note drafting; see the Status section regarding processing locations
- Google / Apple — Sign-in authentication only (no consultation data shared)
- Twilio — Delivers the text-message sign-in codes if you sign in with your mobile number. Twilio receives your mobile number and the code, nothing else, and keeps its own message delivery logs under its retention policy. Twilio is a US company; messages may be routed through its servers outside the UK/EU under its standard data-protection terms.
We do not sell, share, or trade your data with anyone else.
How Long We Keep It
Consultations are kept until you delete them. Account data is removed within 30 days of account closure. Access logs are retained for 90 days.
Mobile numbers. While your account is open your number is kept encrypted. When your account is closed the number itself is deleted; we keep only a one-way keyed fingerprint of it, the dates the account was opened and closed, and any security-block history, for 12 months, so we can answer audit questions and recognise repeat abuse. The fingerprint cannot be turned back into your number. Text sign-in security records (rate limits and blocks) are kept for 30 days, or 12 months if a block was applied.
Your Rights
You can request access to, correction of, or deletion of your data at any time. Contact us and we will respond within 30 days.
If you are unsatisfied with our response, you can complain to the Information Commissioner's Office.
Contact
The full regulatory privacy notice (iCLERK-PN-001) is available on request.