OUI RADDICTATE

Privacy Policy

Last updated: 25 July 2026. This policy covers the OUI RadDictate Chrome extension, the OUI RadDictate mobile app, the RadScribe Cloud desktop app, and the web account pages ("the Service"), operated by OUI Technologies (SMC-Private) Limited ("we", "us"). It describes all user data the Service collects, how it is used, handled, stored, and shared, and every party it is shared with.

What the Service is for

OUI RadDictate lets a signed-in clinician dictate radiology reports and have them transcribed by our secure cloud service, then place the text into the web-based radiology/hospital information system (RIS/HIS) they are using. Because clinicians use many different web-based RIS/HIS, the extension can operate on the site the clinician is working in; it does not act on other sites on its own. To place the report where you are typing, the extension reads which text field is focused (including a field inside a frame of the same RIS/HIS page) and writes the dictated report into it. If you use the optional "Grab text & proofread" action, the text currently in that focused field is sent to our secure cloud to be proofread and formatted and then returned to you — it is processed only for that purpose. Apart from the field you are dictating into or proofreading, the extension does not read, collect, or transmit other content from the pages you visit, and it does not collect your browsing history.

Information we collect and process

How we use it

We use user data only for the purposes above. We do not sell user data, use it for advertising or personalized advertising, transfer it to data brokers or information resellers, or use or transfer it to determine creditworthiness or for lending purposes. We do not permit humans to read your report content: it is end-to-end encrypted and unreadable by us; other account data is accessed by our staff only for support you request, security and abuse investigation, or where required by law.

Automatic background checks (browser extension)

While you are signed in, the browser extension may run brief background timers to: (1) automatically retry saving an already-encrypted report to your history if the first attempt failed (for example, a brief connectivity loss), and (2) periodically recheck your account status while access is temporarily restricted (for example, during a short identity-service outage), so the extension can update on its own without you reloading the page. Both checks reuse the sign-in and save requests already described in this policy and do not collect any additional information.

Chrome Web Store Limited Use compliance

OUI RadDictate's use and transfer of information received from the Chrome browser adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. Data is used only to provide and improve the extension's single, user-facing purpose described above.

How we store your data

How and with whom we share data

We transfer user data only where necessary to provide, maintain, secure, and bill the Service. The complete list of recipients is:

We share user data with no other parties. We do not sell it, share it with advertisers or data brokers, or transfer it for purposes unrelated to the Service.

Patient information

The Service is intended for de-identified report content. Do not enter directly identifiable patient information (such as names or medical-record numbers) into the cloud path unless your institution's privacy and data-processing requirements permit it. Stored report content — including any report label you attach — is end-to-end encrypted on your device and is not readable by us. Dictated audio is always encrypted in transit (TLS); the transcription service must momentarily process the audio itself to convert speech to text — it is handled transiently for that purpose only and is not retained by us.

Data stored on your device

Some information is stored locally on the device you use. Part of it is also transmitted when needed to provide the Service; the rest never leaves the device unless you export it yourself.

Stored locally and also transmitted to us

Stored only on your device

Anyone with access to your signed-in device profile could open these local files — use your institution's device security (OS login, disk encryption) accordingly. Uninstalling the extension/app removes its local storage.

When a different account signs in on the same device, the app automatically attempts to delete the previous user's raw recordings, audio/transcript backups, and decrypted report caches. Cleanup is retried later if it cannot finish immediately and does not block the new sign-in. Application owner fences prevent the new account from seeing, adopting, or uploading leftovers. DEK-encrypted pending reports remain locked to the previous account's UID and are not deleted by ordinary sign-out. A browser/PC restart or app update provides another cleanup opportunity but does not itself guarantee deletion or forensic erasure from storage media. Encrypting raw recordings per account is a future structural mitigation for this residual shared-device risk.

Password reset (email or administrator) restores account access but does not replace or delete the wrapped encryption key by itself, and does not delete cloud reports. The new password cannot unlock existing encrypted history. Explicit Reset Encryption / Fresh Reset hides old encrypted cloud reports immediately and schedules them for permanent deletion after about seven days (Firestore TTL is eventual). There is no support undo tool for that grace period. OUI Cloud does not currently offer a recovery key.

How long we keep data

DataRetention
Cloud report history (encrypted)Auto-deleted after 14 days by default; you can set 1–60 days or turn auto-delete off (kept until you delete it). You can delete any report, or all, at any time.
Dictated / uploaded audioNot retained by us after transcription.
Phone-dictation sessionsDeleted within 24 hours.
Local backups & offline copies on your deviceUnder your control; until you delete them or uninstall.
Templates & settingsUntil you delete them or your account is closed.
Sign-in tokensIdentity token expires after ~1 hour; refresh token until sign-out or revocation.
Wrapped encryption keyUntil you complete an in-app password change (rewraps the same key), explicit Reset Encryption / Fresh Reset, or account closure. Email/admin password reset alone leaves the old wrapper in place but inaccessible behind revoked sessions.
Push subscription (optional)Until you turn notifications off or sign out.
Usage & billing recordsFor the life of the account, as needed for quotas, billing, and legally required bookkeeping.
Security logs (IP, request metadata)Retained by our logging system for ~30 days.
Account records & terms acceptancesUntil account deletion, plus any legally required period.

Security

All traffic is encrypted in transit (TLS); stored data is encrypted at rest; report content is additionally end-to-end encrypted as described above. Each user's data is isolated to their own account, access is controlled by verified sign-in, administrative actions are audit-logged, and our servers are configured not to write report content, audio, or AI responses into application logs.

Your choices

Contact

Questions or requests: info@ouitech.net.

We may update this policy; material changes will be reflected by the date above and, where required, disclosed in the product.