← Back to Home
Privacy Policy for ICD-10 Scribe
Effective Date: September 30, 2025
Last Updated: September 30, 2025
Introduction
ICD-10 Scribe ("we," "our," or "the App") is committed to protecting your privacy and ensuring the security of your medical documentation data. This Privacy Policy explains how we collect, use, store, and protect your information.
Data Collection and Storage
Local Storage Only
- All data stays on your device: ICD-10 Scribe stores all patient visit data, transcriptions, and ICD-10 codes locally on your iPhone using encrypted storage.
- No cloud backup: We do not transmit, store, or backup your data to any external servers or cloud services.
- No account required: The app does not require you to create an account or provide personal information to use the core features.
Information We Collect
Locally Stored Data:
- Voice transcriptions of patient visits
- ICD-10 codes selected for visits
- Visit notes and timestamps
- Patient identifiers (if you choose to include them)
Authentication Data (Optional):
- If you choose to sign in with Apple or Google, we store only your authentication token locally
- Email address (if provided through sign-in)
- Name (if provided through sign-in)
Subscription Data:
- Subscription status is managed through Apple's App Store and RevenueCat
- We do not store payment information
Permissions Required
Microphone Access:
- Required for voice-to-text transcription
- Audio is processed locally on your device
- Audio is not recorded, stored, or transmitted
Speech Recognition:
- Uses Apple's on-device speech recognition
- Transcriptions are processed locally
- No audio data leaves your device
HIPAA Compliance
While ICD-10 Scribe is designed with HIPAA-compliant practices in mind:
- All data is encrypted and stored locally on your device
- No patient data is transmitted to external servers
- You maintain complete control over your data
Important: You are responsible for:
- Ensuring your device is password-protected
- Not sharing your device with unauthorized individuals
- Following your organization's HIPAA policies
- Properly disposing of data when no longer needed
Data Security
- Encryption: All visit data is encrypted using iOS secure storage (Keychain)
- Biometric Lock: Optional Face ID/Touch ID protection
- No Third-Party Access: No third parties have access to your patient data
- Local Processing: All transcription and code matching occurs on-device
Data Sharing
We do NOT:
- Sell your data
- Share your data with third parties
- Use your data for marketing purposes
- Transmit your data to external servers
You CAN:
- Export visit summaries via sharing options
- Delete your data at any time by deleting visits or uninstalling the app
Third-Party Services
The app uses the following services:
RevenueCat:
Apple Sign In / Google Sign In (Optional):
- Purpose: Optional authentication
- Data collected: Email, name (stored locally only)
- Privacy Policies:
Children's Privacy
ICD-10 Scribe is not intended for use by individuals under 18 years of age. We do not knowingly collect data from children.
Data Retention and Deletion
- Retention: Data is retained locally on your device until you delete it
- Deletion: You can delete individual visits by swiping left in the History tab
- Complete Removal: Uninstalling the app permanently deletes all local data
Your Rights
You have the right to:
- Access all your data (visible in the History tab)
- Export your data (via sharing options)
- Delete your data at any time
- Use the app anonymously (without patient names)
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by:
- Updating the "Last Updated" date
- Posting the new Privacy Policy in the app
- Providing in-app notifications for material changes
Contact Us
If you have questions about this Privacy Policy or our privacy practices:
Consent
By using ICD-10 Scribe, you consent to this Privacy Policy and agree to its terms.
Note: This Privacy Policy applies only to ICD-10 Scribe. We are not responsible for the privacy practices of third-party services you may access through the app.