Privacy Policy
Last updated September 5, 2026
SpeakSOAP turns what a physical therapist says during a visit into the SOAP note, billing code suggestions, and a home exercise program, and gives patients a portal to follow that program between visits. Doing that means handling health information. This page says what we collect, why, where it goes, and how long it stays, in plain language.
1Two kinds of people use SpeakSOAP
Clinicians are physical therapists and practice staff who create an account, record visits, and manage patients. Patients are invited into the patient portal by their clinic to follow a home program, log exercises, answer check-ins, and send form-check videos.
When a clinic enters or generates information about a patient, SpeakSOAP processes it on the clinic’s behalf. The clinic decides what goes in, who on its team can see it, and when it is deleted. If you are a patient with a question about your records, your clinic is the right first call; we will help them help you.
2What we collect
Account information. Your name, email address, and password. Passwords are stored as a one-way hash, never as plain text. For clinicians, also your practice’s name and your role in it (admin or member).
Clinical content clinicians create. Transcripts of visit recordings, the SOAP notes drafted from them and the edits you make, home exercise programs, suggested billing codes, visit summaries, appointments, and a writing style guide that SpeakSOAP learns from how you edit its drafts.
Patient records the clinic enters. A nickname or alias, diagnosis, goals, tracked measures such as pain, and optionally an email address so the patient can use the portal. At signup every clinician agrees to refer to patients by nickname or alias, and not to enter real names, birthdates, or insurance IDs. SpeakSOAP is built around that rule; please keep it.
Portal activity from patients. Which exercises were done and when, answers to check-in questions, free-text notes, timezone (so a log lands on the right day), and form-check videos you choose to send.
Media. Exercise demonstration videos and photos uploaded by clinicians, and form-check videos uploaded by patients.
Voice recordings. Clips recorded during a visit are sent to our transcription provider and are not retained as clinical records on our servers. The Amazon Transcribe path temporarily places encrypted input and output in private Amazon storage, deletes both after the request, and has a one-day automatic expiration as a backstop. A retry copy may stay in the clinician’s browser until transcription succeeds and is then removed. Browser recovery records expire after twenty-four hours and are also removed when the note is signed, the session is discarded, the user signs out, or the user clears recovery data on that device.
Usage and technical data. Counts of AI notes, transcription seconds, model tokens, and storage used, which we meter to apply plan limits and understand our costs; ordinary server logs such as IP address, browser type, and timestamps; and anything you send through the in-app feedback widget, including optional screenshots and screen recordings. Patient information on screen is blurred before a capture is taken unless you turn that off.
3How we use it
To run the service: turn speech into notes, programs, and code suggestions; deliver programs and reminders to patients; keep the clinician’s writing style; show progress between visits.
To apply plan limits, keep accounts secure, respond to support requests, and fix problems.
To improve SpeakSOAP using aggregate usage patterns. We do not use patient content for advertising, and we do not sell personal information.
To notify our own team. A new signup, an upgrade request, a marketplace publication, or a piece of feedback posts a message to a private channel our team reads. A signup message includes the clinician’s name and email. A marketplace message includes the collection’s exercise names and video posters.
4AI processing
Transcription. Voice clips are transcribed by either OpenAI’s Whisper model or Amazon Transcribe, depending on the clinic’s controlled rollout setting. The audio and the resulting text are processed for that purpose.
Drafting. SOAP notes, exercise suggestions, code suggestions, and pre-visit summaries are drafted by either Anthropic’s Claude API or OpenAI’s GPT-5.6 Luna through Amazon Bedrock, depending on the clinic’s controlled rollout setting. The model receives the visit transcript, the patient’s alias, diagnosis, goals, and recent history, and the clinician’s style guide. Every draft waits for the clinician to review and sign; nothing is filed automatically.
Marketplace checks. When a clinician publishes an exercise collection, the selected drafting model reads the exercise names and descriptions to flag anything that does not look like a plausible therapeutic exercise.
We use these providers through their business APIs, whose terms state that customer data submitted through the API is not used to train their models.
5Where it is stored and who processes it
SpeakSOAP runs on Amazon Web Services in the United States. The database and media storage are encrypted at rest, and all traffic to and from SpeakSOAP is encrypted in transit.
Our service providers, and what each one handles:
- Amazon Web Services: hosting, database, video and photo storage, voice transcription, video transcoding, and email delivery (Amazon SES).
- Anthropic: note, program, code, and summary drafting on the rollback path.
- OpenAI: voice transcription on the rollback path and a drafting model delivered through Amazon Bedrock during controlled rollout.
- Resend: our earlier email provider, which may still deliver some mail during the transition to SES.
- Discord: the private channel where our team receives signup, feedback, upgrade, and marketplace notifications.
We do not use third-party analytics or advertising trackers on SpeakSOAP.
6Cookies and data kept in your browser
- speaksoap-session: keeps you signed in. HTTP-only, expires after seven days or when you sign out.
- tz: the patient portal records your timezone so exercise logs and check-ins land on the correct local day.
- Browser storage: your light or dark theme choice, your motion preference, and for clinicians, owner-scoped session recovery data kept for no more than twenty-four hours. Signing, discarding, signing out, or using the device-clear action removes it sooner.
There are no advertising cookies and no cross-site tracking.
7Who can see what
Within a practice. Every member of a practice can see all of that practice’s patients. Admins can additionally invite and remove therapists.
Patients. A patient sees their own program, reminders, and what they have logged. They do not see the clinician’s notes.
The exercise marketplace. If a clinician publishes an exercise collection, its exercise names, descriptions, and demonstration videos or photos become viewable by other SpeakSOAP practices that adopt it. Publishing is a deliberate action with its own confirmation. Patient videos are never part of the marketplace.
Service providers listed above, only to do the job described. Legal requirements, if we are required by law to disclose information, in which case we will tell the affected clinic where we are permitted to.
8How long we keep it
Account and clinical records may be retained as required by applicable law, clinic policy, contracts, legal holds, and legitimate security or operational obligations. Each clinic owns its retention schedule. Discharging a patient closes the chart but does not erase the clinical record. Verified export or deletion requests are handled with the clinic through a controlled process, and some records may need to be retained despite a request.
Patient form-check videos are kept for the number of days set by the clinic’s plan (ninety days on the free plan) unless the clinician pins one to keep it. Unpinned videos past that date are deleted automatically.
Clinician demonstration videos and photos stay until the clinician deletes them. If other practices adopted a published video, their copies keep working after the original is deleted.
Voice audio is not retained as a clinical record on our servers. Amazon Transcribe working objects are deleted after each request and have a one-day expiration backstop. Browser retry copies expire within twenty-four hours and are normally removed sooner after successful transcription.
Backups of the database are kept for a limited window and then overwritten. Deleted data can persist in a backup during that window.
9Your choices
Clinicians can edit records and discharge patients from within SpeakSOAP, remove eligible media, and ask us at hello@speaksoap.com for a verified export or deletion review. A deletion request does not override a legal, contractual, security, backup, or clinic-record retention obligation.
Patients can stop reminder emails with the one-click link at the bottom of every reminder, or from settings in the portal. To correct or delete your records, or to close your portal access, contact your clinic. If you cannot reach them, write to us and we will help.
10Security
Encryption in transit and at rest, hashed passwords, and access scoped to each practice. Invitation links for both clinicians and patients expire after seventy-two hours. Feedback captures blur patient information by default. No system is perfectly secure; if you believe you have found a vulnerability or an exposure, email hello@speaksoap.com and we will respond quickly.
11Health information and HIPAA
Clinicians are responsible for using SpeakSOAP in a way that meets their own obligations, including any consent needed to record a visit and have it transcribed and drafted by AI, and the alias commitment made at signup. If your practice needs a Business Associate Agreement with SpeakSOAP, contact hello@speaksoap.com before entering protected health information.
12Children
Patient portal accounts are created by clinics, not by patients themselves. A minor’s portal account is set up and used under the supervision of a parent or guardian, at the clinic’s discretion. We do not knowingly collect information directly from children.
13Changes and contact
When this policy changes in a way that matters, we will update the date at the top and, for material changes, tell clinicians by email before the change takes effect.
SpeakSOAP is operated by its founders in Austin, Texas. Write to hello@speaksoap.com for anything in this policy.
See also the Terms of Service. Questions: hello@speaksoap.com.