Privacy
Privacy and data protection policy
Last updated: July 2026.
This policy is published in French and in English. In the event of any discrepancy between the two versions, the French version prevails.
1. Local storage of your health data
At Somae, the privacy of your health data comes first.
Everything you enter in the app (symptoms, bleeding scores (PBAC), clinical questionnaires (MRS, Greene, SGUM), personal notes, and so on) is kept solely in your browser’s secure storage (IndexedDB).
This data is never held on our servers and can only be reached from your device, except in the specific cases described below, where a feature needs temporary processing.
2. Voice transcription
When you use voice input to record your symptoms, one of two modes applies.
On-device transcription (default)
Where your device allows it, transcription happens right on your phone or computer, using an artificial intelligence model that runs inside your browser (Whisper WASM). In that case, no audio file and no text ever reaches our servers.
Server relay (when needed)
On some older devices or browsers (Safari on iOS in particular), transcription may need to run on a server. When that happens:
- the audio file is sent over an encrypted connection (TLS 1.3);
- processing runs on infrastructure located in the European Union (Belgium), certified as a Health Data Host (HDS);
- the audio file is held in memory only, for as long as the transcription takes;
- it is never written to disk and is deleted the instant processing ends;
- no audio recording is ever kept.
3. AI-assisted structuring
If you choose to switch on automatic structuring of your notes, the text of your consultation is sent, encrypted, to the API of a European artificial intelligence provider, hosted within the European Union.
Under our provider’s commitments:
- your data is not used to train artificial intelligence models;
- it is not kept beyond the processing itself.
Anything generated is always shown to you for review before you approve it. You can edit, add to, or delete any item before a summary is produced.
4. Data minimisation
We collect only what the app strictly needs in order to work. On that basis, the only details we ask for are:
- your first name;
- the initial of your surname;
- your year of birth (no day, no month).
At any time, you can:
- withdraw your consent to any optional processing;
- erase all of your data with the “Erase everything” button in your profile.
This deletion is permanent and wipes every piece of data stored locally on your device.
5. Waitlist
If you join our waitlist, we use your email address only in order to:
- send you a welcome email, where you can confirm the sign-up was really you, or erase it on the spot if it wasn’t;
- let you know when early access opens;
- share Somae news with you;
- if you ticked the optional box for it, reach out for a short survey or user test.
What we collect
- your email address;
- the date and proof of your consent;
- where relevant, your agreement to be contacted (survey or user test), with its date and the version of the wording you saw;
- opaque technical tokens used for the confirmation, erase and unsubscribe links.
This information is kept entirely separate from your health data.
Legal basis: your consent (Article 6(1)(a) GDPR).
Hosting: this data is stored on infrastructure located in the European Union.
Instant erase: the “Erase this sign-up” link in the welcome email removes the record straight away, with no delay and without your having to write to anyone. It is there above all for people whose address was entered by someone else.
Unsubscribe: you can unsubscribe at any time, or withdraw only your agreement to be contacted (survey or user test), by writing to contact@somae.care. Your email address is never sold, rented, or passed on to third parties.
Delivery feedback: our email provider flags addresses that permanently bounce our messages or mark them as spam. Those addresses are removed from future sends.
6. Interest questionnaire (optional)
After joining the waitlist, you can fill in a short, optional questionnaire covering topics such as:
- your situation;
- your next medical appointment;
- your interest in particular features;
- your willingness to pay;
- an open comment.
What we store — we keep only:
- your answers;
- the date they were recorded.
No email address, user ID or cookie is attached to these answers. The server automatically rejects any response that contains an email address.
Data separation: answers are stored independently of the waitlist, with no identifier that could tie them back to your sign-up. This adds an extra layer of privacy, but it also means we cannot retrieve or delete your answers individually. That is precisely why the questionnaire stays entirely optional.
Purpose: answers are used only to better understand the needs of future users, through aggregated statistics. No individual decision is ever made from them, and they are never shared with third parties.
Legal basis: your consent (Article 6(1)(a) GDPR), given by the act of answering the questionnaire.
7. Analytics
We use Plausible Analytics, a European service hosted in Germany, to measure how our site is used.
Plausible runs without cookies and collects no personal data. No IP address is kept, no identifier is created, and there is no tracking across sites.
What it gathers is strictly aggregated statistics, such as:
- the number of visits;
- the pages viewed;
- the type of device used;
- where the traffic comes from;
- some simple interactions (a button click, for example).
As a result, our site needs no cookie-consent banner for this analytics.
8. How long we keep data
How long we keep data depends on the type of data involved.
Health data: your health data (symptoms, questionnaires, notes, scores, and so on) is kept on your device only. It stays there until you delete it or use the “Erase everything” function.
Waitlist: your email address is kept until:
- you unsubscribe;
- the waitlist closes;
- or, at the latest, three (3) years after your last interaction with us.
Interest questionnaire: answers are kept without any identifier, separately from the waitlist, and used for statistics only.
Analytics: the statistics produced by Plausible Analytics are retained in line with the service’s own retention policy, and only in aggregated form.
9. Your rights
Under Regulation (EU) 2016/679 on data protection (GDPR), you have, among others, the following rights:
- the right to access your personal data;
- the right to rectification;
- the right to erasure;
- the right to restrict processing;
- the right to object;
- the right to data portability, where it applies;
- the right to withdraw your consent at any time, for any processing based on it.
When your data is stored exclusively on your device, you can exercise your right to erasure directly in the app, using the “Erase everything” button.
You can also contact us with any question about how your personal data is handled.
If, after contacting us, you feel your rights are not being respected, you can lodge a complaint with the competent supervisory authority, in particular France’s data protection authority, the Commission nationale de l’informatique et des libertés (CNIL), or the authority in your country of residence.
10. Contact us
For any question about this privacy policy, or to exercise your rights, you can contact us at: contact@somae.care.