Privacy Policy
Last updated: July 12, 2026
SkyScribe(“we”, “us”, “the service”) is an AI Clinical Operating System that helps qualified medical practitioners document consultations, admissions and discharges, prescribe, order investigations, and coordinate clinical workflow. This policy explains what information we process, how we protect it, and the choices you have. By using the service you agree to this policy.
The clinical information entered into SkyScribe — histories, examinations, investigations, diagnoses, prescriptions, and the notes generated from them — is sensitive personal data. We process it only to provide the service the clinician requested, and to maintain the patient record on the clinician’s behalf. We never sell health data and never use it for advertising.
Before any content is sent to an external AI model, it passes through our Privacy Gateway, which replaces direct patient identifiers (such as name, hospital/UHID number, phone, address, date of birth, and other identifying details) with tokens. The external model sees only clinical content; the real identifiers are re-inserted in your record after the response returns. Deterministic safety and calculation features (clinical scores, allergy/interaction/renal-dose checks, critical-value flags) run inside the platform and are not sent to any external model.
Every AI output is a draft that a clinician must review and approve; nothing is prescribed, ordered, or entered into the record automatically.
1. Information We Process
- Account information. Your name, email, professional role and specialty, the clinic(s) you belong to, and your sign-in credentials. Clinicians may add a letterhead and signature used on issued documents.
- Clinical information. The patient details and clinical content a clinician (or authorised staff) enters, dictates, or uploads — histories, examinations, vitals, investigations and results, diagnoses, prescriptions, procedures, and the documents SkyScribe drafts — held in the patient record maintained for the clinic.
- Workflow information.Orders routed to the clinic’s own staff workspaces (pharmacy, laboratory, radiology, nursing, wards), and the results and actions they record back.
- Usage information. A metered count of AI usage, shown to you in the app as a percentage of your allowance, used to operate billing and fair usage.
- Payment information. Payments are processed by Razorpay, our payment gateway. We receive payment status and reference identifiers only — we never store card numbers or other payment-instrument details.
- Operational logs. Basic technical logs (timestamps, errors, audit records of clinically significant actions) needed to run the service securely.
2. How We Use Your Information
We use your information solely to operate the service: to sign you in and scope your access to the correct clinic, to draft and maintain clinical documentation, to run deterministic safety checks and clinical scores, to route orders to the clinic’s staff workspaces, to meter usage and process your subscription, and to respond to support requests.
3. How SkyScribe Processes Your Information
SkyScribe processes clinical information using its own platform architecture, clinical workflows, deterministic rule-based systems, and AI-assisted technologies. Certain technical infrastructure and AI providers assist us in delivering specific processing functions (for example, generating a draft note or reading an uploaded report). Such providers operate subject to applicable contractual obligations relating to confidentiality, security, and data protection.
We apply data-minimization principles and, where technically feasible, limit the information shared with these providers to the minimum necessary. As described above, direct patient identifiers are de-identified by the Privacy Gateway before content is sent to an external AI model. An uploaded document (for example, a photographed report) may itself contain printed identifiers that are transmitted to the reading model as part of that image; we minimise this by preferring de-identified text where available.
SkyScribedoes not sell identifiable personal information or identifiable medical information, and does not use your information for advertising. Information you provide is not used to train our own or third parties’ artificial-intelligence models.
4. Storage, Residency and Security
Clinical data is stored in an encrypted database, in line with local data-residency expectations for India. We apply industry-standard safeguards including encrypted connections, encryption at rest, role-based access controls scoped per clinic, and audit logging. A clinic’s records are scoped to that clinic; switching between clinics re-scopes access accordingly.
5. Data Ownership, Retention and Deletion
- The clinical records created in SkyScribe are maintained on behalf of the treating clinician / clinic, who remain responsible for them as the record-keeper.
- Records are retained in your account’s cloud storage for as long as your account is active. Storage is billed to the account that holds the records.
- You can download your records at any time, and you can delete them — per patient, or for a chosen date range, or the whole record — from the app, so you retain a copy and are no longer billed for storage of the deleted data.
- If you close your account, we delete your account data and records, except where a record must be retained to meet a legal obligation (for example, payment records or a statutory medical-record retention requirement).
6. Your Rights
Subject to applicable law, you may request access to, correction of, or deletion of your personal data, and you may withdraw consent. Many of these actions are available directly in the app; for anything else, email us at skyscribe@skyscribeai.com. We respond to verified requests promptly.
7. Cookies and Analytics
We use a session cookie (and equivalent local storage) to keep you signed in and remember your theme preference. We do not use third-party advertising trackers, and we do not run third-party analytics on your clinical activity.
8. Children
The service is intended for use by qualified professionals aged 18 or older. It is not directed to children, and we do not knowingly create accounts for them. (Clinical records handled through the service may relate to paediatric patients; those are processed as clinical data under this policy.)
9. ABDM / ABHA and Health-Information Exchange
If your clinic enables ABDM / ABHA features, your clinic (the facility and treating clinician) is the Data Fiduciary for that health information, and SkyScribe acts only as a Data Processor. Health records are linked to a patient’s ABHA, and shared over the ABDM network, only with the patient’s explicit consent— captured through ABDM’s own Consent Manager — and only against a valid consent artefact. SkyScribe transmits data strictly on your instruction; it does not itself obtain consent or decide what is shared. Your clinic is responsible for obtaining and recording that consent and for complying with the ABDM Health Data Management Policy and the DPDP Act.
10. Grievances and Contact
For any privacy question, request, or grievance, contact our grievance point at skyscribe@skyscribeai.com. We acknowledge grievances promptly and aim to resolve them within the timelines required by applicable law.
11. Governing Law
This policy is governed by the laws of India. We acknowledge and work to meet our obligations under the Digital Personal Data Protection Act, 2023 (DPDP Act) and other applicable data-protection and medical-record requirements.
12. Changes to This Policy
We may update this policy from time to time. The “Last updated” date above reflects the latest revision; material changes are communicated within the app. See also our Disclaimer and Terms & Conditions.