How to read an AI scribe privacy policy in ten minutes

Before you let an AI scribe near a single session, the document that actually decides whether your clients’ words are safe is the privacy policy — not the marketing page, not the sales call. The problem is that most AI scribe privacy policies are written to be skimmed and forgotten. You can do better in about ten minutes if you know which seven clauses to find and what a good answer to each one looks like. Reading an AI scribe privacy policy this way is a fast, repeatable checklist you can run on any vendor, whether you end up choosing CouchNotes or anyone else.

The trick is to stop reading top to bottom. Privacy policies bury the parts that matter in the middle. Instead, search the document (Cmd-F is your friend) for a handful of specific words and read only the paragraphs around them.

A privacy policy document with five clause callouts A stylized document on the left with five highlighted lines, each connected by a teal line to a question a clinician should ask: where data is processed, how long it is retained, who the subprocessors are, whether data trains models, and what deletion rights exist. Privacy Policy Where is data processed? How long is it retained? Who are the subprocessors? Used to train models? What are your deletion rights?
Five searches turn a long privacy policy into a ten-minute read.

The seven clauses to find in an AI scribe privacy policy

Run these in order. Each one tells you something the others can’t, and together they form a complete picture of where your clients’ words go.

1. Where is the data processed?

Search for “process,” “store,” “servers,” “cloud,” or “on-device.” This is the load-bearing clause. If audio and transcripts are sent to remote servers for transcription or note generation, every other protection is a promise about data that has already left your machine. If processing happens locally, the question changes shape entirely — there is no transmission to secure, no server-side copy to subpoena, no third party in the chain. This distinction matters more than any compliance badge, which is why HIPAA compliant is not enough to settle the question on its own.

2. How long is data retained?

Search for “retain,” “retention,” “delete,” and “storage period.” Look for an actual duration. “We retain data as long as necessary to provide the service” is not an answer — it’s an open-ended grant. You want a stated period, ideally one you control, and a clear statement that retention ends when you end it. Note whether audio and transcripts are treated separately; some vendors delete audio quickly but keep transcripts indefinitely.

3. Who are the subprocessors?

Search for “subprocessor,” “third party,” “service provider,” and “affiliate.” A subprocessor is any other company the vendor hands your data to — transcription engines, cloud hosts, analytics tools. A serious vendor lists them, often on a dedicated page, and commits to notifying you of changes. A vague “we may share data with trusted partners” with no list is a red flag. Every name on that list is another organization that touches protected health information and another agreement you should, in principle, be able to inspect.

4. Is your data used to train models?

Search for “train,” “training,” “improve our services,” “machine learning,” and “aggregate.” This is the clause most likely to surprise you. Many policies reserve the right to use your content to improve their models, sometimes framed as harmless because the data is “de-identified.” That framing deserves scrutiny — therapy transcripts are dense with identifying detail, and de-identification is harder than it sounds. We unpack exactly why in training on your data, “de-identified”. The answer you want is a flat no, with no carve-out for aggregated or anonymized use.

5. What does de-identification actually mean here?

Search for “de-identify,” “anonymize,” “aggregate,” and “pseudonymize.” If a policy leans on de-identification, find out which standard. There is a real difference between stripping a name and meeting a recognized de-identification standard with statistical assurance. A clause that says “we may use de-identified data for any purpose” is effectively a permission slip that depends entirely on a process you can’t see or verify.

6. What are your deletion rights?

Search for “delete,” “erase,” “your rights,” “access,” and “export.” You want three things: the ability to delete data on demand, confirmation that deletion propagates to backups and subprocessors within a stated window, and the ability to export your own notes if you leave. “Contact us to request deletion” with no timeline is weaker than a self-service delete you can trigger yourself.

7. What happens in a breach?

Search for “breach,” “incident,” “security,” “notify,” and “notification.” Look for a commitment to notify you within a specific timeframe, and whether the vendor positions itself as a business associate that will support your own breach-reporting obligations. Vague language here often signals that breach response is an afterthought.

A quick scoring sheet

ClauseReassuringWorth a follow-up
ProcessingOn-device / localRemote servers
RetentionStated period you control”As long as necessary”
SubprocessorsNamed list, change notice”Trusted partners”
Training useExplicit noReserved “to improve services”
DeletionSelf-service, with timelineEmail request, no timeline

The reason on-device processing keeps shortening this checklist is structural: when audio and transcripts never leave the Mac, several of these clauses simply have no surface to go wrong. CouchNotes is built that way — transcription and the SOAP, DAP, or BIRP draft are generated locally, with no cloud, no account, and no telemetry, and audio auto-deletes per your setting. The draft is always yours to review, edit, and sign.

None of this is legal advice, and the specifics vary by state board, payer contract, and your own business associate agreements — confirm the details with your board or attorney before you rely on them. But the ten-minute read is yours to run today, on any vendor, before a single session is recorded. A policy that survives these seven searches has earned a closer look. One that dodges them has told you what you need to know.

Dario Valles

Building CouchNotes — on-device AI session notes for therapists on macOS and Windows. Sessions never leave your computer; that's the whole point.

Get the free beta