Your information
Privacy policy.
This policy describes information handled by the Orbit Clinik website and clinic app. A clinic using the app is responsible for its patients’ records and recording permissions.
Last updated: 1 October 2026
1. Website visits and enquiries
The public website contains an illustrative walkthrough with fictional patients. It does not record your microphone or access clinic records. We do not add advertising trackers or analytics cookies to this website.
Cloudflare hosts the public website and may process connection information, such as your IP address and request details, to deliver and protect it. If you contact us by email, phone, or WhatsApp, we receive the information you choose to include and use it to respond and provide support.
Plan buttons open Stripe-hosted checkout. Stripe processes payment, billing, and receipt information under its own privacy policy. Card details are entered on Stripe, not on this website. WhatsApp and other services you open from the website handle information under their own policies.
2. Information in the clinic app
The app handles information entered or selected by clinic staff: clinic and staff account details, patient names and contact information, clinical history, notes, medicines, prescriptions, documents, recordings, transcripts, and suggested prescription details. It also uses account sessions and device identifiers to control access and record actions.
Information is used to find the correct patient, maintain clinic records, process selected recordings, prepare and review prescriptions, and support authorised sharing. Voice suggestions require clinician review; they are not an independent prescription.
3. Permissions and information on your device
- Microphone: records audio when you start recording or enable a voice preview.
- Camera: scans a clinic connection QR code when you choose to scan. Manual connection is also available.
- Files: imports the document or audio file you choose, including a voice message shared from another app.
- Face ID, Touch ID, or a supported device lock: optionally unlocks an app access key. The operating system performs the biometric check; the app does not receive your face or fingerprint template.
The app can keep clinic connection settings, session information, records needed for offline use, and unsent recordings or drafts on your device. Local copies and files you export need the same care as other clinic records. You can turn optional features off and revoke permissions in your device settings.
4. Voice processing and service providers
Recordings and transcripts are sent to the clinic service you connect to. Depending on its configuration, speech transcription and suggested clinical details can be processed locally or by managed speech and AI providers. Supported managed routes include Groq, Together AI, Deepgram, and OpenRouter and its selected upstream model providers, including Google. The provider used can differ by clinic, feature, or processing fallback.
External processing is controlled by the service’s vendor clearance register and provider settings, including applicable retention and model-training restrictions. Contact the clinic or Orbit Clinik for the providers enabled for your clinic before submitting identifiable patient information. This policy does not mean that every supported provider receives every recording.
Optional on-device voice preview uses the operating system’s speech recognition. Android also offers an explicitly labelled online Google preview for test dictation. The online test mode must not be used for patient audio. The iPhone preview requests on-device recognition.
If a clinician enrols their voice, the clinic service stores a voice profile to help identify that clinician’s speech. The clinician can withdraw that profile through the app. A clinician voice profile is separate from Face ID or fingerprint authentication.
5. Who can receive information
Clinic information is available to authorised clinic users according to their roles and to the service systems needed to operate the clinic. Hosting, storage, and processing providers handle information where their configured services are used. Support may need account or technical details to investigate a problem; send the minimum information necessary.
When you export or share a prescription, document, or audio file, it is sent to the app or recipient you choose. Check the recipient first. Orbit Clinik does not automatically read your WhatsApp inbox. Copies shared to another service are subject to that service’s privacy and retention rules.
We do not use the app’s patient records for advertising or sell them. Disclosure may also be necessary to meet a legal obligation. Providers and recipients may operate in countries different from your clinic; ask the clinic or support team about the location and arrangements for your deployment.
6. Retention and deletion
The clinic service’s default audio retention setting is 30 days. A clinic can have a different retention arrangement, including longer storage. Audio still awaiting processing can remain until that processing finishes. Audio removal does not remove the transcript, notes, prescription, or clinical history derived from it.
Clinical records, signed prescriptions, and audit history are retained separately. Signed records are preserved; a correction creates a replacement rather than erasing the historical prescription. Retention of clinical records and backups depends on the clinic’s obligations and deployment. The audio retention period is not a promise that all associated information or backup copies disappear at the same time.
Contact the clinic to request access, correction, deletion, or withdrawal of recording consent for patient information. Contact Orbit Clinik for staff account or support information. We may need to verify your identity and coordinate with the clinic. Some information may have to be retained for clinical or legal reasons; withdrawing permission for future recording does not automatically erase an existing clinical record.
7. Security and responsible use
The service uses account access controls and clinic separation. Public service connections should use HTTPS. A clinic can also configure a service on its own network; its operator is responsible for that deployment, device access, and appropriate connection security. No service or device can guarantee complete security.
Clinic staff should obtain the appropriate permission before recording or importing identifiable patient information. The app is intended for clinic professionals, not for children to create their own accounts. Where a clinic records information about a child, the clinic is responsible for the appropriate authorisation.
8. Contact and policy updates
For privacy questions or an account request: [email protected]. You can also call +92 328 4674612.
For patient records, contact the clinic that holds them. Avoid including identifiable patient information in an initial email or WhatsApp request.
We will update this page when the policy changes and show the updated date above. Visit our support page for app feedback and clinic assistance.