Privacy you can verify, not just read.
Four promises from a private, Australian AI medical scribe, ratified word for word. Every one of them is a live compliance check the patient can watch — in the room, mid-consult — and this page shows exactly how each is kept.
Everything is processed in Australia — transcription and note drafting on vetted Australian services over private links inside Akoua’s cloud — and speaker identity never leaves Akoua’s own infrastructure.
If part of the pathway is unavailable, Akoua pauses and says so rather than silently rerouting — and anything beyond the Australian pathway runs only after clear disclosure and explicit acceptance for that session and purpose.
Not audio, not transcripts, not notes. Your consultations are not a dataset.
Audio exists only while you review. By default it's deleted on confirm; a practice can set a short fixed window instead, and 7 days is the hard ceiling either way.
Every access is written to an append-only audit log — entries can be added, never edited or removed.
From first word to deletion receipt.
Capture starts only in a consented session, and streams straight into Akoua's private Australian cloud in Sydney.
Audio is kept AES-256-encrypted only while you review the draft — so you can listen back to anything flagged.
By default the audio is deleted the moment you confirm the note; a practice can set a short fixed retention window instead. An automatic sweep enforces the 7-day hard ceiling in every mode.
A QR deletion receipt — login-free, PHI-free — flips to "Verified" only when the audio is actually gone. They can re-scan it any time.

The same lifecycle, seen from inside a confirmed note. The privacy rail names the encryption and the append-only audit log, offers to verify them, and reports that the audio has already gone — pointing back to its recorded lifecycle rather than asking you to take it on trust.
The patient watches the checks run.
During the consult, a privacy view runs live checks — encryption, residency, isolation, deletion, audit. Every line is a check against the running system, never a static claim. It's the difference between "trust our policy" and "watch it hold".
Every access to a record is written to an append-only audit log, enforced at the database level — entries can be added, never edited or removed.
Here's exactly what happens to this consult's recording. Each line is checked live, not just promised.
What you are promised, your clinician can verify. Processed in Australia · your data trains no one · audio deleted after confirmation.
The patient leaves with proof, not a pamphlet.
At the end of the consult the patient can scan a QR code and keep the receipt. It's login-free and carries no patient details — just a reference that flips to "Verified" when the audio is actually deleted. They can re-scan it next week and watch it still hold.
It's a small thing with a sharp edge: a deletion promise you can hand to someone is a deletion promise you have to keep.
The unglamorous parts, done properly.
TLS 1.2/1.3 in transit; application-level encryption of transcripts, notes, PII and voiceprints at rest.
WebAuthn by default, password + TOTP fallback, refresh-token rotation, and a WAF in front of everything.
All clinical data on Australian infrastructure, handled in line with the Australian Privacy Principles.
We don't yet hold formal certifications — they're on the roadmap, and we'd rather say that plainly than imply otherwise.
One profile per organisation, chosen at sign-up.
Every organisation runs on exactly one profile, chosen at sign-up and applied to everyone in it — it can't be switched in place. Your clinical record is stored in Australia on both. Change your region any time from the switch in the top bar.
On UK Sovereign, your clinical record is stored in the United Kingdom. Transcription and note drafting run on vetted services within the European Union, under the consent your organisation gives — disclosed on every note — and are never used to train models.
On AU Sovereign, everything stays in Australia: transcription and note drafting run on vetted Australian services over private links inside Akoua’s cloud — disclosed on every note, under the consent your organisation gives for that processing. Ordinary consent to record is a separate authority, given for each consultation. Who’s speaking is recognised only on Akoua’s own infrastructure, and nothing is processed outside Australia without a separate, explicit request for that specific session.
Global managed providers process audio and transcripts by default under your organisation's consent. Akoua stores your clinical record in Australia. No provider uses your data to train their models.
Akoua is a documentation aid, not a diagnostic device. It makes no clinical inferences, and every draft requires explicit clinician confirmation before it's saved. Anything unspoken is [not stated] — never a guess. Read the responsible-use statement.
Fair questions.
Only you, while the draft is open — that's what listen-back is for. Every access is written to the audit log, and once you confirm the note there is nothing left to listen to.
An automatic sweep deletes the audio within 7 days. It's a hard ceiling enforced by the system, not a setting someone can forget.
Never. Not audio, not transcripts, not notes. If that ever changed it would be opt-in, disclosed here first — and we have no plans to change it.
It's entirely separate from clinical data — an email address in a standard hosting store, disclosed plainly in the privacy notice for your region.
Show your patients, not just tell them.
Akoua is open. Individuals and two-seat practices get 14 days free — card required, cancel anytime; practices of three or more clinicians are charged from day one. Founders pricing — A$79/month + GST — is held for as long as your subscription stays active.