About this notice. Notra Scribe is a product of Notra Labs, LLC. This page describes our current data-handling practices. It is not a substitute for your practice's Notice of Privacy Practices, which is the document your patients receive. Contact us at team@notralabs.com with any questions.
Our role under HIPAA
Notra Labs, LLC is a Business Associate as defined in 45 CFR 160.103. Your practice (or your employing covered entity) is the Covered Entity. We process Protected Health Information (PHI) on your behalf solely to provide Notra Scribe — recording, transcription, and clinical note generation.
A Business Associate Agreement (BAA) is available for you or your covered entity to sign. Contact us at team@notralabs.com to obtain one.
What we collect
- Account data: your name, email, password hash (bcrypt; we never see your password), specialty, default template, general documentation rules, and theme preference.
- Security data: encrypted authenticator-app (TOTP) secret and hashed backup codes when you enroll in MFA.
- Billing identifiers: Stripe customer and subscription IDs if you subscribe. Payment card details are collected by Stripe, not by us.
- Visit audio: the audio you record during a visit, plus an optional patient name or chart number you choose to attach.
- Generated content: the transcript, clinical note sections, and suggested ICD-10/CPT codes produced from each visit.
- Audit log: records of who accessed which note, when, from what IP. We never log PHI itself in audit entries.
How we protect it
- Encryption in transit: all connections use HTTPS with HSTS enforced.
- Encryption at rest: patient identifiers, transcripts, sections, codes, and audio blobs are encrypted with AES-256-GCM using a customer-managed AWS KMS key before being persisted.
- De-identification before note generation: text sent to the note-generation model is run through a redaction layer that replaces names, dates, phone numbers, email addresses, MRNs, addresses, and other likely identifiers with placeholder tokens. The original mapping never leaves the server. Visit audio sent to AssemblyAI for transcription is not de-identified; that processing is covered by our AssemblyAI BAA.
- Access control: web sessions sign out after 30 minutes without activity (an in-progress recording is never interrupted); mobile sessions stay signed in on the personal device and are not revoked by web idle timeout, with Face ID unlock at most once per day and never during a visit; authenticator-app MFA (TOTP) is required for paid and complimentary accounts after the trial (a personal browser may skip the MFA prompt for 14 days, and the iPhone app for 30 days, after a successful MFA login); each API call validates the session before touching any record. Sign-in, note and audio access, template changes, and account changes are audited.
Who we share it with (subprocessors)
We use a small number of subprocessors to provide the service. We have signed a Business Associate Agreement with Amazon Web Services covering AWS services, and a Business Associate Agreement with AssemblyAI:
- Amazon RDS (PostgreSQL): stores account data and the encrypted blobs described above.
- Amazon S3: stores encrypted audio recordings.
- AssemblyAI Medical Mode: converts visit audio to text. Audio is uploaded to AssemblyAI for transcription. Notra Scribe also keeps an encrypted copy of the recording for 60 days, then deletes it.
- Amazon Bedrock (Claude Sonnet): generates the structured note from the de-identified transcript. Covered by our AWS BAA.
- AWS KMS: holds our encryption key material.
- AWS App Runner / CloudWatch: hosts the service and stores operational logs (no PHI in logs).
- Amazon SES: sends account email (verification, password reset, deletion notices). Covered by our AWS BAA.
- Stripe: processes subscription payments. Stripe receives your account email and name and collects payment details on Stripe’s hosted checkout. Stripe does not receive visit recordings, transcripts, or notes.
We do not sell or rent PHI. We do not use PHI to train AI models.
How long we keep it
Visit recordings are deleted 60 days after the visit. Transcripts, notes, and codes stay for the lifetime of your account. You can delete any individual note at any time from the Notes screen. Deleted notes (and any remaining audio) are removed from primary storage immediately; backups roll off within 7 days. You can delete your account (and erase your clinical data from primary storage) from the Account page in the app or on the web. We keep a limited operational record of the deletion (your email, time, and item counts — not clinical content) for support and security. If you need help, contact team@notralabs.com.
Your rights as a user
- Access: view your data inside the app, or request a full export via team@notralabs.com.
- Correction: edit any note section directly in the app. Edit your name from the Account page.
- Deletion: delete individual notes via the note's menu, or delete your account from the Account page. For help, contact team@notralabs.com.
- Portability: notes can be copied or shared as plain text from the note detail screen.
Patient rights
Patients exercise their HIPAA rights — access, amendment, accounting of disclosures, complaints — through your covered entity, not through Notra Scribe. We will assist your practice in fulfilling those requests when required by our BAA.
Reporting a security incident
If you suspect a breach or unauthorized access, contact team@notralabs.com immediately. We commit to investigating and notifying affected covered entities within the timelines required by 45 CFR 164.410.
Changes to this notice
We may update this notice as our practices evolve. The current version is always on this page.
Effective: August 2026 · Contact: team@notralabs.com