
Most privacy policies ask you to read a page and believe it. In a consult room, that isn’t good enough. The person whose data is at stake is sitting right there, and “trust us, it’s handled” is not something a patient can check. So we built Small Mercy’s privacy to be watched, not just read.
Here is what that means in practice.
Small Mercy’s Australian processing
On AU Sovereign, Small Mercy stores the clinical record in Sydney and runs default transcription and note drafting on vetted Australian services over private links — disclosed on every note under your organisation’s processing consent. Consent to record is separate for each consultation. Speaker identity is matched only on Small Mercy’s infrastructure. A Small Mercy-managed offshore route needs separate acceptance for that session and purpose. An optional confirmed-note or letter send reaches the connected practice-software account; Nookal’s Australian API host does not establish that account’s storage region. Small Mercy and its processing providers do not use clinical data to train models.
Deleted by default
Small Mercy keeps as little as possible, for as short a time as possible.
- Audio is kept encrypted only while you review the note.
- The moment you confirm the note, the audio is deleted.
- If a draft is abandoned, it is swept and wiped within seven days, automatically.
Deletion is the default state, not a setting you have to go and find. The note you confirm is what remains; the recording that produced it does not linger.
Checks you can run in the room
This is the part we are proudest of. Small Mercy includes a patient-facing privacy view that runs live checks during the consult, rather than static claims copied out of a policy. It confirms, in the moment, that audio is encrypted, that it is being processed in Australia, that deletion is in force, and that access is being audited.
The patient can also keep a QR deletion receipt. They scan it, and later they can scan it again to confirm the audio has actually been deleted. It carries no login and no personal information. It is simply proof, in their hands, that what we said would happen did.
The security underneath
Beneath the visible checks, the fundamentals are in place:
- AES-256 encryption at rest and TLS 1.2/1.3 in transit.
- Passkey sign-in, so there is no reusable password to phish or leak.
- An append-only audit log, so every access is recorded and entries can be added but not quietly rewritten.
What we won’t claim yet
Here is the honest part, and we would rather say it plainly than let you infer more. Small Mercy does not hold formal certifications yet, and we won’t imply otherwise. Independent certification is on our roadmap; when we have earned it, we will say so, in the same plain language we use for everything else. We are also careful with words. We describe our audit log as append-only, which is precise, and we prefer precise to grand. Until the certifications are real, we would rather show you a live check than a badge we haven’t earned.
That posture is the whole point. A privacy promise you can watch happen, in the room, backed by Australian processing and default deletion, is worth more than a longer policy you have to take on trust. Small Mercy is a documentation aid, not a diagnostic device, and the people in the room deserve to see, not just be told, where their words go.