OUI RADDICTATE
Privacy Policy
Last updated: 25 July 2026. This policy covers the OUI RadDictate Chrome extension, the OUI RadDictate mobile app, the RadScribe Cloud desktop app, and the web account pages ("the Service"), operated by OUI Technologies (SMC-Private) Limited ("we", "us"). It describes all user data the Service collects, how it is used, handled, stored, and shared, and every party it is shared with.
What the Service is for
OUI RadDictate lets a signed-in clinician dictate radiology reports and have them transcribed by our secure cloud service, then place the text into the web-based radiology/hospital information system (RIS/HIS) they are using. Because clinicians use many different web-based RIS/HIS, the extension can operate on the site the clinician is working in; it does not act on other sites on its own. To place the report where you are typing, the extension reads which text field is focused (including a field inside a frame of the same RIS/HIS page) and writes the dictated report into it. If you use the optional "Grab text & proofread" action, the text currently in that focused field is sent to our secure cloud to be proofread and formatted and then returned to you — it is processed only for that purpose. Apart from the field you are dictating into or proofreading, the extension does not read, collect, or transmit other content from the pages you visit, and it does not collect your browsing history.
Information we collect and process
- Account details — the email address you sign in with and your organization/role settings.
- Sign-in credentials — your email and password are submitted to Google Identity Platform to authenticate you; we never store your password on our servers. On your device, the password is also used briefly at sign-in to unlock (or create) your report-history encryption key; the password itself is not retained for that purpose. After sign-in, your device stores an identity token, a refresh token, your email, and the token expiry; the identity token accompanies each request to our backend.
- Dictated or uploaded audio — microphone recordings and audio files you deliberately select for transcription. Audio is sent to the transcription provider to produce text and is not stored by us after transcription. Optional local backups may be kept on your own device — see "Data stored on your device" below.
- Report text — the transcribed report, stored end-to-end encrypted so your history syncs across your devices (see "How we store your data"). Text you submit for proofreading or template-filling is processed transiently to produce the result and is not stored by us in readable form.
- Optional report label — if you attach a label to a report, it is end-to-end encrypted the same way as report text.
- Templates & settings — report templates, trigger phrases, and preferences you save. Templates are synced to your account so they follow you across devices, and the template list is transmitted with each transcription request so a spoken template command can be recognized; a template's body and your spoken instructions are transmitted when you ask for a template to be filled or modified.
- A device identifier — a random per-install ID sent with requests to our backend, used only to enforce your subscription's device limits and detect account sharing.
- Phone-dictation sessions — when you use "Dictate on phone", a temporary session record links your computer and phone: a random session ID, session state and timestamps, the templates needed for the dictation, and the end-to-end-encrypted result. Session records are deleted within 24 hours.
- Push notifications (optional, mobile) — if you turn notifications on, we store your device's push subscription endpoint to deliver alerts such as phone-dictation requests. Notification payloads never contain report content.
- Usage, billing & security data — counts of requests and dictation minutes for your quota, records of payments applied to your account, records of your acceptance of our terms, and network metadata such as IP address and browser type used for security, rate limiting, and abuse prevention.
How we use it
- To authenticate you and provide transcription, proofreading, formatting, templates, and cross-device encrypted history.
- To enforce subscription limits (minutes, expiry, device count) and prevent credential sharing.
- To bill your account and keep required payment records.
- To secure the Service, prevent abuse, and investigate misuse.
- To notify you about your account (for example subscription-expiry reminders).
We use user data only for the purposes above. We do not sell user data, use it for advertising or personalized advertising, transfer it to data brokers or information resellers, or use or transfer it to determine creditworthiness or for lending purposes. We do not permit humans to read your report content: it is end-to-end encrypted and unreadable by us; other account data is accessed by our staff only for support you request, security and abuse investigation, or where required by law.
Automatic background checks (browser extension)
While you are signed in, the browser extension may run brief background timers to: (1) automatically retry saving an already-encrypted report to your history if the first attempt failed (for example, a brief connectivity loss), and (2) periodically recheck your account status while access is temporarily restricted (for example, during a short identity-service outage), so the extension can update on its own without you reloading the page. Both checks reuse the sign-in and save requests already described in this policy and do not collect any additional information.
Chrome Web Store Limited Use compliance
OUI RadDictate's use and transfer of information received from the Chrome browser adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements. Data is used only to provide and improve the extension's single, user-facing purpose described above.
How we store your data
- Where — account data, templates, settings, usage records, and encrypted report history are stored in Google Cloud, currently in Google's Singapore region, where our backend also runs. AI transcription and proofreading requests are processed by Google Vertex AI and may be processed in other Google Cloud locations; they are not stored by us.
- How it is protected — all traffic is encrypted in transit (TLS) and all stored data is encrypted at rest by Google Cloud. Each user's data is isolated to their own account and accessible only through verified sign-in.
- End-to-end encryption of report content — report text and labels are additionally encrypted on your device before upload with a random per-user data-encryption key (AES-256-GCM). That key is protected ("wrapped") by a key derived from your login password; our servers store only the encrypted report content and the wrapped key, neither of which we can read. The unlocked key stays on your device. Our server refuses unencrypted report writes; a report saved by an early pre-encryption version of the app is converted to encrypted form automatically the next time you use the app.
- How long — see the retention table below.
How and with whom we share data
We transfer user data only where necessary to provide, maintain, secure, and bill the Service. The complete list of recipients is:
- Google Cloud (our data processor), under Google's Cloud Data Processing Addendum: Identity Platform / Secure Token Service receive your email and password at sign-in and handle token refresh and password reset; Vertex AI receives dictated or uploaded audio, report text you submit for proofreading or formatting, templates, and related instructions to produce the requested output — Google does not use your prompts or responses to train its models, and may retain limited data transiently only as needed to run the service and for abuse and security monitoring under its Cloud terms; Firestore and Cloud Run store and serve the data described in this policy.
- Your organization's administrators — if your account is managed by a hospital or organization, its authorized administrators and ours can see your account status, subscription, device registrations, and usage totals (minutes, request counts, estimated cost). Administrators cannot read your report content or labels: the server holds only ciphertext.
- Legal and security disclosures — limited information may be disclosed if required by law or where reasonably necessary to investigate fraud, abuse, or threats to the Service.
We share user data with no other parties. We do not sell it, share it with advertisers or data brokers, or transfer it for purposes unrelated to the Service.
Patient information
The Service is intended for de-identified report content. Do not enter directly identifiable patient information (such as names or medical-record numbers) into the cloud path unless your institution's privacy and data-processing requirements permit it. Stored report content — including any report label you attach — is end-to-end encrypted on your device and is not readable by us. Dictated audio is always encrypted in transit (TLS); the transcription service must momentarily process the audio itself to convert speech to text — it is handled transiently for that purpose only and is not retained by us.
Data stored on your device
Some information is stored locally on the device you use. Part of it is also transmitted when needed to provide the Service; the rest never leaves the device unless you export it yourself.
Stored locally and also transmitted to us
- Sign-in session — identity and refresh tokens, your email, and the token expiry (the identity token accompanies backend requests).
- Device identifier — the random per-install ID described above.
- Templates & settings — kept locally for speed and synced to your account.
Stored only on your device
- Recording backups (Chrome extension) — when the Backup option is on (it is on by default), the extension keeps a local copy of each dictation on your computer: the raw recording, the pause-compacted recording that was transcribed (WAV files), and the transcript text. These are stored in the browser's private storage for the extension, never uploaded by us, and remain until you delete them. You can review, export (Archive), or delete them at any time from the extension's Recordings tab, and turn Backup off entirely.
- Audio backups (mobile app) — the mobile app can keep your recordings on the phone the same way; manage or delete them in the app's Audio backups section.
- Offline report copies (mobile app) — the mobile app keeps a local copy of your synced reports on the phone so history opens offline; copies are pruned to your history-retention setting and removed by "Clear" or clearing the app's data. The Chrome extension keeps no local copy of report text — its history is read from your encrypted cloud history.
- Encryption key — the unlocked key that decrypts your report history (held non-extractably by the browser on extension/mobile; protected by Windows account encryption in the desktop app).
Anyone with access to your signed-in device profile could open these local files — use your institution's device security (OS login, disk encryption) accordingly. Uninstalling the extension/app removes its local storage.
When a different account signs in on the same device, the app automatically attempts to delete the previous user's raw recordings, audio/transcript backups, and decrypted report caches. Cleanup is retried later if it cannot finish immediately and does not block the new sign-in. Application owner fences prevent the new account from seeing, adopting, or uploading leftovers. DEK-encrypted pending reports remain locked to the previous account's UID and are not deleted by ordinary sign-out. A browser/PC restart or app update provides another cleanup opportunity but does not itself guarantee deletion or forensic erasure from storage media. Encrypting raw recordings per account is a future structural mitigation for this residual shared-device risk.
Password reset (email or administrator) restores account access but does not replace or delete the wrapped encryption key by itself, and does not delete cloud reports. The new password cannot unlock existing encrypted history. Explicit Reset Encryption / Fresh Reset hides old encrypted cloud reports immediately and schedules them for permanent deletion after about seven days (Firestore TTL is eventual). There is no support undo tool for that grace period. OUI Cloud does not currently offer a recovery key.
How long we keep data
| Data | Retention |
| Cloud report history (encrypted) | Auto-deleted after 14 days by default; you can set 1–60 days or turn auto-delete off (kept until you delete it). You can delete any report, or all, at any time. |
| Dictated / uploaded audio | Not retained by us after transcription. |
| Phone-dictation sessions | Deleted within 24 hours. |
| Local backups & offline copies on your device | Under your control; until you delete them or uninstall. |
| Templates & settings | Until you delete them or your account is closed. |
| Sign-in tokens | Identity token expires after ~1 hour; refresh token until sign-out or revocation. |
| Wrapped encryption key | Until you complete an in-app password change (rewraps the same key), explicit Reset Encryption / Fresh Reset, or account closure. Email/admin password reset alone leaves the old wrapper in place but inaccessible behind revoked sessions. |
| Push subscription (optional) | Until you turn notifications off or sign out. |
| Usage & billing records | For the life of the account, as needed for quotas, billing, and legally required bookkeeping. |
| Security logs (IP, request metadata) | Retained by our logging system for ~30 days. |
| Account records & terms acceptances | Until account deletion, plus any legally required period. |
Security
All traffic is encrypted in transit (TLS); stored data is encrypted at rest; report content is additionally end-to-end encrypted as described above. Each user's data is isolated to their own account, access is controlled by verified sign-in, administrative actions are audit-logged, and our servers are configured not to write report content, audio, or AI responses into application logs.
Your choices
- Set the history auto-delete period (1–60 days, or off) in the app's settings; delete individual reports or your whole history at any time.
- Turn local recording backups off, and export or delete existing backups.
- Turn mobile push notifications on or off at any time.
- To access, export, correct, or delete your data — including full account deletion — contact your administrator or us at the address below.
Contact
Questions or requests: info@ouitech.net.
We may update this policy; material changes will be reflected by the date above and, where required, disclosed in the product.