Privacy policy

What NotoVet processes, where it goes, and what you control.

This policy describes the current text-based documentation workflow. Audio-to-SOAP is not generally available.

Effective and last updated: August 14, 2026

NotoVet privacy policy

1. Information NotoVet processes

Generator input

Rough visit notes, optional patient descriptors, visit type, template choice, and the generated SOAP draft.

Account and workspace

Email, optional profile name, settings, saved notes, saved templates, usage events, and authentication identifiers.

Plans and billing

Paddle customer and subscription identifiers, plan status, price identifier, billing dates, and scheduled plan changes. NotoVet does not store full card numbers.

Waitlists and support

Email address, requested plan, form source, and the information you choose to include in support or privacy messages.

2. How information is used

  • Generate and display the SOAP draft you request.
  • Save notes and templates only when an authenticated user chooses to save them.
  • Authenticate users, enforce plan allowances, and provide billing access.
  • Operate Pro and Clinic waitlists and respond to support, privacy, and security requests.
  • Protect the service through input validation, abuse prevention, error monitoring, and security investigation.

NotoVet does not sell clinical input or use it for advertising to pet owners. NotoVet does not use submitted content to train its own public model.

3. Unsaved notes and AI processing

Unsaved generator input is processed for the request and is not written to NotoVet’s application database. The current production drafting provider is Cloudflare Workers AI. If NotoVet later enables its optional OpenAI provider, this policy will be updated before that provider receives production note text.

Generated drafts and source text are returned through private, no-store application responses. Infrastructure and security logs may still be retained under Cloudflare’s applicable service terms and controls.

4. Saved records and retention

  • Saved notes and templates remain in the authenticated workspace until you delete them or delete the account.
  • Account records remain while the account exists and are removed through the account-deletion workflow, subject to operational failure handling described below.
  • Waitlist entries remain until the requested launch communication is sent or you ask for removal.
  • Usage and subscription records are retained as needed to operate allowances, billing, fraud prevention, financial reconciliation, and legal obligations.
  • Backups and service-provider logs may persist for limited periods under the providers’ documented retention and recovery processes.

5. Service providers

Cloudflare

Hosts the application and D1 application data, supplies network-security and delivery infrastructure, and runs the current text-drafting model through Workers AI.

Supabase

Provides account authentication and identity management.

OpenAI

Optional inactive text and transcription provider. It does not receive production note text unless NotoVet explicitly configures and enables it.

Paddle

Acts as the checkout and merchant-of-record provider for paid subscriptions and billing support.

6. Security and access

NotoVet uses encrypted transport, server-verified sessions, prepared database statements, user-scoped ownership checks, private/no-store API responses, input limits, timeouts, usage allowances, and anonymized rate-limiting identifiers. No online service can guarantee absolute security.

Read security & data handling

7. Your choices and deletion

Generation requires a free or paid account. You can choose whether to save a generated draft, delete individual saved notes, and request removal from a waitlist. Account deletion removes saved NotoVet application data and the Supabase identity after active subscriptions are canceled.

If self-service deletion is unavailable or fails, contact privacy@vetsoapnotesai.com. Billing providers may retain transaction records required for financial, fraud-prevention, dispute, or legal purposes.

8. Veterinary records and consent

You are responsible for using authorized information, following your clinic’s record and retention policies, obtaining any notice or consent required in your location, and ensuring the final record is stored in the appropriate system. NotoVet does not claim compliance with a specific healthcare privacy framework unless a separate written agreement says so.

9. Contact and updates

Privacy and data requests: privacy@vetsoapnotesai.com. General product and billing support: support@vetsoapnotesai.com.

Material changes will be reflected by a revised date and, where appropriate, a notice in the service.