Built for Healthcare. Trusted by Design.

HosTalky is designed for clinical environments. Your data stays in Canada, is encrypted end-to-end, and is never used to train AI models.

test

How HosTalky Handles Healthcare Data
A transparent, plain-English view of how information flows through HosTalky — so clinicians feel safe, and admins can approve with confidence. — Securely & in Canada.

STEP 1

Clinician 
Device

Audio is Captured only when recording is started by the cliniciian

  • No background recording

  • Purpose limited

STEP 2

Secure Processing

Information is processed in Canada with encryption and access controls.

  • Encrypted at rest

STEP 3

Review & Approval

Notes are reviewed and edited before they are finalized or exported.

  • Human-in-the-loop

  • Access controlled

STEP 4

Temporary Processing Only

Data is processed to generate clinical notes — not stored indefinitely.

  • Data minimization

  • Purpose-limited

STEP 5

Automatic
Secure Deletion

Audio is deleted by default. Draft transcripts are cleared. Retention is policy-controlled.

  • Deletion logged

  • Retention controlled

STEP 6

No AI Training on Patient Data

HosTalky does
not use patient 
data to train
AI models.

  • No resale

  • Retention controlled

For Clinicians
What clinicians
need to know
  • You stay in control: start/stop
recording anytime.

  • Review and edit before anything is 
saved or exported.

  • By default, audio and drafts are deleted after export.

For Admins
What Admins
need to know
  • Canada-based processing by default.

  • Role-based access (least privilege) 
and audit logs.

  • Defined breach response and transparency on subprocessors.

Deep dive
What the details?

Use the “For IT & Privacy Teams” section below for deeper technical and governance information.

Privacy isn’t a feature,
It’s a Boundary

We design HosTalky so clinicians and organizations 
can confidently use AI tools without creating new privacy risk.

What we do

  • Encrypt data in transit and at rest

  • Require clinician review before finalizing notes

  • Limit access using role-based permissions (RBAC)

  • Maintain audit logs for accountability

  • Delete data automatically after use (default)

What we don't

  • Train AI models using patient data

  • Sell or monetize healthcare data

  • Record audio in the background

  • Keep data longer than necessary

  • Access notes without authorization

For IT, Privacy & Compliance Teams

If you’re reviewing HosTalky for a pilot or organizational rollout, 
the items below answer the usual procurement and privacy questions.