Privacy policy

Last updated 5 September 2026
This policy covers the akoua.ai website and the Akoua service — the web app at au.akoua.ai and the Akoua apps for iPhone, Apple Watch, Android, macOS and Windows. It explains what we collect about you (a visitor or account holder) and how we handle the clinical information clinicians record with Akoua on behalf of their patients. The providers that process data for the Australian service are published on the sub-processor list. United Kingdom organisations: the UK service is covered by its own UK privacy notice, Data Processing Schedule and sub-processor list.

Akoua Pty Ltd ("we", "us") provides a clinical documentation service from Australia. We handle personal information in line with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth), and health information with the extra care it deserves.

Information about you

Your account. Your name, email address, and role, and your organisation if you belong to one; your sign-in credentials — a hashed password, or a passkey (passkey biometrics such as Face ID or a fingerprint never leave your device and are never seen by us); an optional voice profile you can record so Akoua can tell your voice apart from others in the room — used only for speaker attribution, deletable any time in Settings; and your subscription status. Payment details are handled by Apple, Google, or Stripe — we never see full card numbers.

Security records. Sign-in events, IP address, device and app version, and an append-only audit log of access to clinical records — kept so unusual activity can be detected and every access accounted for.

Website visitors. If you submit the updates form we collect your email address, the date and time you signed up, and the country your request came from (derived from your connection by our hosting provider). If you send us a message through the contact form, we also collect your name (if you give one), your email address, the topic you select and the message you write, along with the date and time, the country your request came from, and your browser's user-agent string.

No tracking. We do not use tracking or advertising cookies — on this site or in the apps — and the apps contain no third-party analytics or advertising SDKs. The web app uses only the essential cookies and tokens needed to keep you signed in. One other thing is measured: when someone begins creating an account — whether or not they finish — we record how far the attempt got: a random number the browser tab invents for that attempt, which step it reached, how long it had taken, and, if the visitor arrived from a link on this site, the single word that link carried. No name, email address, IP address or account is stored alongside it, and the table it lands in has no column that could hold one. That random number is kept in the tab's session storage so a reload continues one attempt instead of counting two, and it is gone when the tab closes. This site self-hosts its fonts (no third-party font or CDN requests) and uses Cloudflare Web Analytics — a cookieless, aggregate page-count measure that does not profile you. This website sets no cookies at all. The only thing it keeps on your device is the region you're viewing — stored permanently only if you chose it yourself from the region switch, and otherwise just for the visit. It identifies nobody, is never shared, and you can clear it any time by clearing site data.

Ad-click measurement. When you arrive at one of our pages from a Google ad, the link may carry a click identifier — a gclid, gbraid or wbraid code Google adds to the address. When sign-up measurement is switched on, we send that identifier — and nothing else — to our own Australian server, hold it encrypted, and remove it from your address bar; no cookie, no third-party tag or advertising SDK is involved — the exchange is our own first-party page code — and nothing is stored in your browser. If you then create an account, and again if a subscription starts, we report the conversion to Google using only that click identifier, the event time, and a random reference number — never your name, email address, IP address, device details, account identifiers or any clinical data, and we do not use Google's Enhanced Conversions, Customer Match, remarketing or audience features. The identifier is deleted within 24 hours if no account is created, and otherwise within 30 days or as soon as the subscription conversion is reported, whichever comes first. Your choice: the measurement exists only through the ad's click identifier, so visiting akoua.ai directly — or removing the code from the link before opening it — means there is nothing to measure, and either way your sign-up works identically.

Clinical information recorded with Akoua

Audio of a consultation, captured only after the in-product consent step — including audio relayed from a paired watch; transcripts of that audio, with speaker labels and confidence markers; notes, letters, and tasks drafted from the transcript and confirmed by the clinician; and the patient details the clinician enters to file the record. We process this information on the clinician's or their organisation's behalf — it is part of their clinical record. If you are a patient and want access to or correction of your record, your clinician is the right first contact; we support them in meeting those requests.

How we use information

We use personal information to provide, operate, and secure the service — and for nothing else. We do not sell personal information or profile you, and the only advertising-related processing we do is the click-ID sign-up measurement described above — it identifies an ad click, never a person. Patients' clinical data is never used to train models — not by Akoua, and not by our providers. We use de-identified operational metrics (counts, performance, reliability) to run and improve the service. Updates-list emails are used solely to send occasional news about Akoua, and contact-form details only to read your enquiry and reply to it — we rely on your consent, because you chose to submit the form.

Consent

Recording starts only after consent is confirmed in the product, and Akoua asks again when someone new can hear the conversation. On AU Sovereign, everything stays in Australia: transcription and note drafting run on vetted Australian services over private links inside Akoua’s cloud — disclosed on every note, under the consent your organisation gives for that processing. Ordinary consent to record is a separate authority, given for each consultation. Who’s speaking is recognised only on Akoua’s own infrastructure, and nothing is processed outside Australia without a separate, explicit request for that specific session. On Global, processing follows the organisation profile and consent selected at sign-up.

Where your data lives — Australian and New Zealand service

For the Australian and New Zealand service, your clinical record is always stored in Akoua's Australian cloud (Sydney), on Amazon Web Services. How audio and transcripts are processed depends on the sovereignty profile chosen at sign-up, one per organisation. On AU Sovereign, everything stays in Australia: transcription and note drafting run on vetted Australian services over private links inside Akoua’s cloud — disclosed on every note, under the consent your organisation gives for that processing. Ordinary consent to record is a separate authority, given for each consultation. Who’s speaking is recognised only on Akoua’s own infrastructure, and nothing is processed outside Australia without a separate, explicit request for that specific session. On Global, audio and transcripts are processed by vetted global providers under your organisation's consent. On either profile, neither Akoua nor its providers use your data to train models. United Kingdom organisations use a separate UK service and UK privacy notice. See how we make privacy verifiable.

Website records (updates list and contact form) are stored using Cloudflare Workers KV, a globally replicated store, so they may be held outside Australia; contact-form enquiries are also delivered to our team inbox through Amazon SES and may be processed outside Australia in transit. These website records are entirely separate from service data. Billing is handled by Apple, Google, or Stripe on their own infrastructure. Each provider processes data on our behalf under its own terms and privacy commitments; beyond them, we disclose personal information only where the law requires it.

Retention and deletion

Audio is deleted by default — kept encrypted only while the clinician reviews and deleted the moment the note is confirmed; a practice can instead set immediate deletion after processing, or a short fixed retention window, and every mode sits under a hard 7-day ceiling. Confirmed records are kept while the account is active; clinicians remain responsible for their own record-keeping obligations — export what you must keep before deleting. You can delete your account in Settings → Delete account in any Akoua app, or on the web account-deletion page for your region: there is a 7-day window in which you can change your mind, after which your account and its data are permanently removed and we issue a deletion receipt you can keep. On the updates list, we keep your email until you unsubscribe or ask us to remove it; contact-form enquiries are kept only as long as needed to handle your request, then removed.

Security

Everything is encrypted in transit and at rest (AES-256). Access to clinical data is limited, logged in an append-only audit log, and reviewed. We support passkeys and multi-factor authentication. No method of transmission or storage is perfectly secure, but protecting this information is the job we take most seriously.

Your choices and rights

You can access or correct the information we hold about you, export your data from the service, delete your account and data as described above, and unsubscribe from updates at any time (every email includes a way out). To exercise any of these, use the in-app controls or email privacy@akoua.ai.

Children

Akoua accounts are for adults (18+). Children's information may appear in clinical records as part of their care; it is handled with the same protections as all clinical information, under the consent of a parent or guardian where required.

Changes

We may update this policy as the product evolves. The "last updated" date above will change when we do, and we'll flag material changes in the app or by email.

Contact

Akoua Pty Ltd · ACN 700 204 388 · ABN 31 700 204 388 · South Yarra, Victoria, Australia. Questions or requests about privacy: privacy@akoua.ai or +61 3 8904 9084. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC).