Privacy Policy
Last updated: September 15, 2026
WrenScribe ("WrenScribe", "we", "us", "our") is a private, on-device transcription and medical-reference companion for clinician–patient consultations. This Privacy Policy explains what data WrenScribe uses, where it is stored, and, importantly, what it does not collect or send.
This policy describes the current macOS App Store build. It is provided for the user's reference and for App Store review. It is not legal advice.
The short version
- Your consultation audio and transcript never leave your device. All transcription is performed locally on the device using bundled/downloaded on-device models. There is no cloud transcription provider.
- We operate no accounts, servers, analytics, ad, or crash-reporting services that receive your data.
- Data is stored only on your device, encrypted at rest behind a PIN you set. We cannot access it, and it is not sent to us.
- Two optional, user-controlled features involve the network: a generic medical-term reference lookup (a de-identified term name to a public encyclopedia) and an optional, provider-configured read-only connection to a practice's own EHR. Both are described below.
Information we do not collect
WrenScribe does not collect, store, track, or sell Personally Identifiable Information (PII), health information, or usage analytics. The application has no user accounts, no sign-in, no telemetry, and no third-party tracking.
Information you enter (such as a patient name, typed for on-screen masking of the transcript) is held only in memory for the duration of the session and is never written to disk and never transmitted.
On-device data (what your device stores)
The following are created on your device, at rest, and never transmitted to us or any third party except as described in the "Network use" section:
- Transcripts: the verbatim (raw) audio text and a redacted display copy, plus derived text (a cleaned transcript, a short summary, action items, and a structured assessment/plan).
- Detected clinical terms and suggested codes (ICD-10-CM / CPT / HCPCS), which are aids to review, not diagnoses.
- A local performance timeline used by the in-app performance panel.
- A non-PHI audit log of app events (start/stop, lock/unlock, redaction, model loads, exports).
- A local reference cache of generic term blurbs (24-hour expiry).
- Your PIN, stored only as a cryptographic hash (PBKDF2/bcrypt); the raw PIN is never stored.
- Optional: if you enable "Save audio," the original 16-bit WAV recording for a session is stored on-device.
Encryption at rest: the transcripts and other clinical content are stored in a SQLCipher database encrypted with a key derived from a 6-digit PIN you choose at setup. Without your PIN, that content is not recoverable.
Network use (the only things that can go over the network)
WrenScribe does not phone home, send analytics, or transmit your audio or transcripts. The only network communication is:
-
One-time local-model download (on first use). The on-device speech and language models are downloaded from Model Hubs you choose to use (for example Hugging Face) the first time you select them, only with your explicit action. These are public model artifacts and contain no user data.
-
Generic medical-term reference lookup (optional, off by default). When you view references, WrenScribe may look up a detected term by sending the single, de-identified term name only (for example "hypertension") to the public Wikipedia REST API to display a one-paragraph blurb. It does not send the transcript, patient identifiers, names, dates, or any context beyond the term. This is equivalent to you searching a term in a browser. Results are cached locally for 24 hours.
-
Practice EHR connector (optional, you configure it yourself). If you enable the EHR connector, you enter the address and read-only credentials of your own practice's FHIR (MedPlum) server. WrenScribe then: - sends the credentials you entered and the FHIR patient identifier to that own EHR server, over HTTPS, and - reads that patient's record (active problems, current medications, recent labs, allergies, immunizations, procedures, family history, recent encounters) into the PIN-locked app, on-screen, for the current session.
This is a read-only, provider-configured integration with a system you own and operate. WrenScribe never creates, updates, or deletes EHR records and does not route that record to any third party. WrenScribe is not a data processor for the practice's own EHR records; your practice's applicable agreements (for example a BAA) govern its own deployment. Family history is shown by relationship and condition only; a relative's name is not displayed.
Health information
WrenScribe is a documentation and reference aid. It does not diagnose, treat, or direct care, and it makes no medical-device claims. The transcript and any clinical content you create remain under your control on your device. If you use the optional EHR connector, the patient record belongs to your practice and is governed by your practice's own data handling.
HIPAA
We build in an explicit statement on how WrenScribe fits a clinician's or practice's HIPAA posture, because it matters. The short answer: because the audio, transcript, and notes never leave the device, WrenScribe (the app and its developer) does not receive, create, maintain, or transmit protected health information (PHI) on anyone's behalf.
That has two practical consequences. First, under the HIPAA framework a vendor that handles PHI on the covered entity's behalf is a business associate and requires a Business Associate Agreement (BAA). Because WrenScribe's developer operates no servers, no accounts, no telemetry, and no transcription service, and nothing a session produces is transmitted to us, there is no business associate relationship to paper and no BAA is required between you and WrenScribe. The on-device, PIN-encrypted design is what removes that step that cloud scribes (and their vendor risk reviews) typically add.
Second, the local-only design reduces (but does not eliminate) your own HIPAA responsibilities. You remain the party accountable for your own compliance: keeping the device itself secure (a strong PIN, the OS up to date, stolen/lost-device protection), controlling who physically sees the screen, applying "minimum necessary" in your own workflows, and securely wiping the device at end of life. WrenScribe gives you the audit trail, redaction, and PIN-encryption controls to support that; it does not remove the obligations the law attaches to you as the holder of the record.
Two boundaries to note. WrenScribe is a reference aid, not a medical device, and we make no FDA/medical-device or certification claims. And the optional EHR connector is read-only, connects only to your practice's own FHIR server that you configure, and is not a processor we run, so your practice's own agreements with that EHR remain in effect.
This is an engineering and product statement, not legal advice. Confirm your own HIPAA handling with your compliance officer or counsel.
Data you can control
- Lock stops recording, drops models, and removes the encryption key from memory.
- Erase sessions (two-step confirm) deletes all stored clinical content from the device; the audit log is retained.
- Deleting the app (and, if you use it, the practice-EHR connection) removes all local data with it.
Cookies / third parties
The WrenScribe app does not use cookies, advertising networks, or tracking, and ships no analytics of any kind.
The companion website (wrenscribe.com) uses Amplitude, a third-party
analytics service, to understand how visitors use the site. It may set a
cookie or similar identifier and reports only standard, non-identifying
website events: which page you viewed (URL and title) and which call-to-action
buttons you clicked. It does not receive any health information,
transcripts, or app data, and nothing on the website connects a site visit to
the app or to any patient. You can opt out by disabling third-party cookies or
blocking cdn.amplitude.com / api.amplitude.com.
Children
WrenScribe is intended for use by licensed clinicians and is not directed to children.
Changes to this policy
We may update this policy as features change. A "Last updated" line will reflect material changes.
Contact
For privacy questions or a data-handling review, contact us at or via the contact page on wrenscribe.com.
WrenScribe is a reference aid only, not medical advice.