Privacy policy
Akoua Pty Ltd, trading as Small Mercy ("Small Mercy", "we", "us") provides a clinical documentation service from Australia. We handle personal information in line with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth), and health information with the extra care it deserves.
Information about you
Your account. Your name, email address, and role, and your organisation if you belong to one; your chosen sign-in credentials, if you add them — a hashed password or a passkey (passkey biometrics such as Face ID or a fingerprint never leave your device and are never seen by us); an optional voice profile you can record so Small Mercy can tell your voice apart from others in the room — used only for speaker attribution, deletable any time in Settings; and your subscription status. Payment details are handled by Apple, Google, or Stripe — we never see full card numbers.
Security records. Sign-in events and the method used, short-lived sign-in link and code records, IP address, device and app version, and an append-only audit log of access to clinical records — kept so unusual activity can be detected and every access accounted for.
Website visitors. The updates form has been retired from current site pages. Its legacy endpoint still accepts requests from old cached pages or direct submissions. If you submit one, we collect your email address, any name and clinician type you provide, the date and time, the country derived from your connection by our hosting provider, and your browser's user-agent string. If you send us a message through the contact form, we also collect your name (if you give one), your email address, the topic you select and the message you write, along with the date and time, the country your request came from, and your browser's user-agent string.
No tracking cookies. We do not use tracking or advertising cookies — on this site or in the apps — and the apps contain no third-party analytics or advertising SDKs. The web app uses only the essential cookies and tokens needed to keep you signed in. Account sign-up progress is also measured: when someone begins creating an account — whether or not they finish — we record how far the attempt got: a random number the browser tab invents for that attempt, which step it reached, how long it had taken, and, if the visitor arrived from a link on this site, the single word that link carried. No name, email address, IP address or account is stored alongside it, and the table it lands in has no column that could hold one. That random number is kept in the tab's session storage so a reload continues one attempt instead of counting two, and it is gone when the tab closes. This site self-hosts its fonts (no third-party font or CDN requests) and uses Cloudflare Web Analytics — a cookieless, aggregate page-count measure that does not profile you. This website sets no cookies at all. This website stores an appearance preference locally when you choose one; otherwise appearance follows your system. It also keeps the region you’re viewing on your device, permanently only when you choose it from the region switch and otherwise for the visit. It identifies nobody, is never shared, and you can clear it any time by clearing site data.
Anonymous website action counts. We count which fictional Demo story is started, whether its review/export step is completed, and clicks from this site to account signup. Our first-party endpoint stores only the event type, one of four story names (or “site”), and the day. Each event is a separate record in Cloudflare Workers KV and expires after 90 days. It does not store a visitor or session identifier, account, name, email, IP address, user agent, ad click identifier, page URL, referrer or any clinical data; it sets no cookie or browser storage. These are action counts, not a way to follow a person from the Demo into an account, and they cannot tell us whether someone actually signed up. Add ?internal=1 to the page URL to exclude your own test actions.
Ad-click measurement. When you arrive at one of our pages from a search ad, the link may carry a click identifier — a gclid, gbraid or wbraid code Google adds to the address, or an msclkid code Microsoft adds to a Bing ad's link. When sign-up measurement is switched on, we send that identifier — and nothing else — to our own Australian server, hold it encrypted, and remove it from your address bar; no cookie, no third-party tag or advertising SDK is involved — the exchange is our own first-party page code — and nothing is stored in your browser. For a Google click: if you then create an account, and again when the first note is confirmed in your account, we report the conversion to Google using only that click identifier, the event time, and a random reference number — never your name, email address, IP address, device details, account identifiers or any clinical data, and we do not use Google's Enhanced Conversions, Customer Match, remarketing or audience features. For a Microsoft click: if you then create an account, and again when the first note is confirmed in your account, we report the conversion to Microsoft Advertising using only that click identifier, the event time, and which of those two events it was — never your name, email address, phone number, IP address, device details, account identifiers or any clinical data, and we do not use Microsoft's enhanced conversions (hashed email or phone), remarketing or audience features. The identifier is deleted within 24 hours if no account is created, and otherwise within 30 days or as soon as the conversion is reported, whichever comes first. Your choice: the measurement exists only through the ad's click identifier, so visiting smallmercy.app directly — or removing the code from the link before opening it — means there is nothing to measure, and either way your sign-up works identically.
Clinical information recorded with Small Mercy
Audio of a consultation, captured only after the in-product consent step — including audio relayed from a paired watch; transcripts of that audio, with speaker labels and confidence markers; notes, letters, and tasks drafted from the transcript and confirmed by the clinician; and the patient details the clinician enters to file the record. We process this information on the clinician's or their organisation's behalf — it is part of their clinical record. If you are a patient and want access to or correction of your record, your clinician is the right first contact; we support them in meeting those requests.
How we use information
We use personal information to provide, operate, and secure the service — and for nothing else. Your email address is also used to send verification and sign-in links or codes that you request. We do not sell personal information or profile you, and the only advertising-related processing we do is the click-ID sign-up measurement described above — it identifies an ad click, never a person. Patients' clinical data is never used to train models — not by Small Mercy, and not by our providers. We use de-identified operational metrics (counts, performance, reliability) to run and improve the service. Updates-list emails are used solely to send occasional news about Small Mercy, and contact-form details only to read your enquiry and reply to it — we rely on your consent, because you chose to submit the form.
Consent
Recording starts only after consent is confirmed in the product, and Small Mercy asks again when someone new can hear the conversation. On AU Sovereign, Small Mercy stores the clinical record in Sydney and runs transcription and note drafting on vetted Australian services over private links — disclosed on every note under your organisation’s processing consent. The optional Global note fallback is currently disabled; if enabled, after an in-cell note-drafting failure a clinician may accept a single-use offer to send only that consult’s transcript for its note and later redrafts, never audio or other outputs. Global processing may occur outside Australia; the organisation and session stay AU Sovereign, with no automatic switch. Consent to record is separate for each consultation. Speaker identity is matched only on Small Mercy’s infrastructure. A Small Mercy-managed route outside Australia needs separate, explicit acceptance for that session and purpose. Sending a confirmed note or letter to connected practice software is a separate clinician action into the vendor account; Nookal’s Australian API service alone does not establish where that account stores data. On Global, processing follows the organisation profile and consent selected at sign-up.
Where your data lives — Australian and New Zealand service
For the Australian and New Zealand service, your clinical record is always stored in Small Mercy's Australian cloud (Sydney), on Amazon Web Services. How audio and transcripts are processed depends on the sovereignty profile chosen at sign-up, one per organisation. On AU Sovereign, Small Mercy stores the clinical record in Sydney and runs transcription and note drafting on vetted Australian services over private links — disclosed on every note under your organisation’s processing consent. The optional Global note fallback is currently disabled; if enabled, after an in-cell note-drafting failure a clinician may accept a single-use offer to send only that consult’s transcript for its note and later redrafts, never audio or other outputs. Global processing may occur outside Australia; the organisation and session stay AU Sovereign, with no automatic switch. Consent to record is separate for each consultation. Speaker identity is matched only on Small Mercy’s infrastructure. A Small Mercy-managed route outside Australia needs separate, explicit acceptance for that session and purpose. Sending a confirmed note or letter to connected practice software is a separate clinician action into the vendor account; Nookal’s Australian API service alone does not establish where that account stores data. On Global, audio and transcripts are processed by vetted global providers under your organisation's consent. On either profile, neither Small Mercy nor its providers use your data to train models. United Kingdom organisations use a separate UK service and UK privacy notice. See how we make privacy verifiable.
The optional Global note fallback is currently disabled. If enabled after an in-cell note-drafting failure, a clinician may accept an offer to send that consult's transcript — not audio or any other output — to Amazon Bedrock through the Global route, which may process it in any AWS commercial Region, including outside Australia. The organisation and session stay AU Sovereign; there is no automatic switch, and acceptance covers only that consult's note and later redrafts.
Website records (updates list, contact form and anonymous action counts) are stored using Cloudflare Workers KV, a globally replicated store, so they may be held outside Australia; contact-form enquiries also retain the name, email, topic and message you submit, a timestamp, your approximate country and browser user agent. Email notification to our team uses Amazon SES when available and may be processed outside Australia in transit. These website records are entirely separate from service data. Billing is handled by Apple, Google, or Stripe on their own infrastructure. Each provider processes data on our behalf under its own terms and privacy commitments; beyond them, we disclose personal information only where the law requires it.
Retention and deletion
Audio is deleted by default — on Free, deleted when the first draft arrives, with no listen-back; on paid plans, kept encrypted while the clinician reviews and deleted the moment the note is confirmed; a practice can instead set immediate deletion after processing, or a short fixed retention window, and every mode sits under a hard 7-day ceiling. Confirmed records are kept while the account is active; clinicians remain responsible for their own record-keeping obligations — export what you must keep before deleting. You can delete your account in Settings → Delete account in any Small Mercy app, or on the web account-deletion page for your region: there is a 7-day window in which you can change your mind, after which your account and its data are permanently removed and we issue a deletion receipt you can keep. On the updates list, we keep your email until you unsubscribe or ask us to remove it; contact-form enquiries are kept only as long as needed to handle your request, then removed.
Security
Clinical data is encrypted with AES-256 at rest and TLS 1.2/1.3 in transit. Transcripts, notes, personal information and voiceprints also use AES-256-GCM application-level encryption at rest. Access to clinical data is limited, logged in an append-only audit log, and reviewed. We support passkeys and multi-factor authentication. No method of transmission or storage is perfectly secure, but protecting this information is the job we take most seriously.
Your choices and rights
You can access or correct the information we hold about you, export your data from the service, delete your account and data as described above, and unsubscribe from updates at any time (every email includes a way out). To exercise any of these, use in-app export for individual documents, or email privacy@smallmercy.app for a full account export or other rights request.
Children
Small Mercy accounts are for adults (18+). Children's information may appear in clinical records as part of their care; it is handled with the same protections as all clinical information, under the consent of a parent or guardian where required.
Changes
We may update this policy as the product evolves. The "last updated" date above will change when we do, and we'll flag material changes in the app or by email.
Contact
Akoua Pty Ltd · ACN 700 204 388 · ABN 31 700 204 388 · South Yarra, Victoria, Australia. Questions or requests about privacy: privacy@smallmercy.app or +61 3 8904 9084. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC).