ClinoteSign in

Privacy Notice

Last updated 16 July 2026

Who controls your data

Marlo Solutions Ltd, trading as Clinote, is the controller of the personal data used to provide Clinote accounts, authentication, billing, support, security, and product operation. It is registered in England and Wales under Company No. 17309992. Its registered office is Suite RA01, 195-197 Wood Street, London, E17 3NU, United Kingdom.

Our contact is hello@clinote.co.

Clinote is for anonymised logs only

Clinote is an AI-assisted professional clinical logbook for anonymised training logs. You must not type or dictate patient names, NHS numbers, hospital numbers, dates of birth, contact details, addresses, or any other information that could identify a patient. Your typed text and the transcript produced from your dictation are processed as they appear in the review flow and are stored when you save. Responsibility for keeping entries anonymised rests with you.

Personal data we collect

  • Account and authentication data, including your user id, email address, login provider, session and security information, and authentication timestamps.
  • Profile data, including your display name, specialty, country, default hospital, department, professional role or training level, onboarding status, and welcome-email status.
  • The content and metadata of saved entries: typed note text; the transcript of a voice entry and any edited version of it; the entry date and how it was set; save timestamps; and structured fields including entry type, age, sex, hospital, supervisor, summary, indication, findings, plan, difficulty, and prompts about useful missing details.
  • Voice audio while it is uploaded and processed to create a transcript. Clinote does not store your audio after processing.
  • Draft content held on your device, including entered text and any transcript created during the current unsaved entry.
  • Billing data, including Stripe customer and subscription identifiers, subscription status, trial and billing-period dates, cancellation status, access status, and payment or invoice records. Stripe, not Clinote, receives and stores full card details.
  • Transactional email data, including your name, email address, the service message sent, and delivery information.
  • Support messages and operational data such as IP address, technical logs, timestamps, device or browser information, and security events.
  • Cookieless product analytics: a pseudonymous account identifier, pages viewed, coarse product actions, a coarse entry category such as entry type, device or browser information, and approximate location derived from your IP address. Analytics does not include note text, audio, transcripts, summaries, findings, plans, patient age or sex, hospital, or supervisor.

How your entries are processed

When you create an entry, the text you type or the audio you dictate is processed by our systems and by OpenAI to produce entry text and structured fields for your review. When you choose Save, your reviewed entry text, the transcript where you dictated, the entry date, and the structured fields are stored in our database. Clinote does not store your audio after processing.

Drafts and temporary recordings on your device

The web app keeps an unsaved draft in your browser's local storage. The mobile app keeps it in on-device application storage. A draft contains the text and transcript as shown to you. It is not sent to our systems until you choose Save.

The mobile app may hold a temporary copy of a recording on your device until it is cleared by the app or operating system. Secure your device, use its access controls, and avoid shared devices.

Why we use personal data

  • To create and manage your account, authenticate you, and secure the service.
  • To transcribe voice, prepare entry text, produce structured fields, and let you review, save, view, delete, analyse, and export entries.
  • To manage trials, subscriptions, payments, cancellations, and receipts.
  • To send service emails, answer support requests, diagnose faults, prevent abuse, and meet legal obligations.
  • To understand coarse product usage and improve reliability and design without sending note text or detailed clinical content to analytics.

Legal bases under UK data protection law

This notice uses the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 as its framework. We rely on performance of our contract for account and product functions; legitimate interests for service security, reliability, fault diagnosis, abuse prevention, and strictly limited cookieless analytics; and legal obligation for required accounting and lawful requests. We use consent where we send optional direct marketing, and you may withdraw that consent at any time.

People and services we work with

We use OpenAI for AI processing; Render for application hosting; Supabase for the database and authentication; Vercel for delivering the web app; PostHog for product analytics; Stripe for payments; Brevo for transactional email; and Cloudflare for DNS and security. We give each provider only the data needed for its role. We do not sell your data or share clinical content for advertising. See our Subprocessors page for the current provider register, purposes, data involved, and locations.

Analytics

We use PostHog EU Cloud in Frankfurt for privacy-friendly, cookieless analytics. It helps us understand matters such as sign-ups, feature use, and return visits so we can improve the service.

Autocapture and session recording are switched off, and on-screen text is masked in the app. Analytics events contain only non-clinical product information such as a pseudonymous account identifier, pages viewed, coarse actions, a coarse entry category such as entry type, device or browser information, and approximate location derived from your IP address. They do not contain note text, audio, transcripts, summaries, findings, plans, or patient details. We do not use analytics for advertising or profiling, and analytics does not store anything on your device.

Where data is processed

Your saved logbook is stored with Supabase in the EU (Ireland). Application processing takes place on our systems hosted by Render in Frankfurt, Germany (EU). PostHog analytics runs in Frankfurt, and Brevo transactional email is processed in France.

The web app is delivered through Vercel's global edge network. Vercel does not store clinical content at rest, although request logs may transit the United States. Cloudflare provides DNS and security services.

OpenAI processes submitted text and audio in the United States. Stripe processes payment data in the United States and other locations from which it provides its service. EEA processing is covered by UK adequacy regulations. For other international transfers, we use recognised UK safeguards, including the UK-US Data Bridge where the provider is certified and the UK International Data Transfer Agreement or Addendum where required.

AI training and provider retention

OpenAI model training on data submitted through Clinote's API account is disabled. Under OpenAI's published standard API data controls, some customer content may be included in abuse-monitoring logs for up to 30 days, unless a longer period is required by law or needed to protect the service or others. OpenAI publishes different application-state and abuse-monitoring periods for different API operations.

How long we keep data

  • Voice audio is processed to produce a transcript and is not stored by Clinote. A mobile temporary file may remain on the user's device as described above. OpenAI retention is described in the AI section above.
  • Saved entries, including original transcript text where voice was used, remain until you delete the entry or your account.
  • Device drafts remain until successful save, reset or cancellation, storage clearing, or app removal. There is currently no automatic expiry.
  • Account and profile data is kept while your account is active.
  • When you delete your account, entries, profile, authentication account, and Clinote billing record are deleted from the live system. Stripe and Marlo Solutions Ltd keep only payment and accounting records that must be retained by law for the required period.
  • Deleted information may remain for a limited period in protected backups or provider logs before it is overwritten or removed under the provider's retention schedule. It is not restored to the live service except where needed for disaster recovery, security, or legal reasons.

When we disclose data

We do not sell or rent personal data. Apart from the providers needed to operate Clinote, we disclose data only where the law requires it, where necessary to protect users or the service, or as part of a sale or reorganisation of the business. If ownership changes, this notice continues to apply until it is replaced.

Your rights and contact

Under UK data protection law, you may have rights to access, correct, delete, restrict, object to, and receive certain personal data. To ask a privacy question or exercise a right, contact our privacy contact at hello@clinote.co.

You may complain to the Information Commissioner's Office at ico.org.uk. Clinote is for users aged 18 or over. The date and version at the top identify the current notice, and we will highlight significant changes.

If a personal-data breach is likely to put your rights or freedoms at risk, we will notify the Information Commissioner's Office and affected people where UK data protection law requires us to do so.