Privacy

What Anastomo does with data

Anastomo is software a health practice runs on its own computer. It helps the practice create and maintain its documents — reading what arrives, keeping the patient record, drafting notes and letters — on that computer. Anastomo stores no patient or client medical information. Everything the practice keeps is on the practice’s own machine, and storing it safely and protecting its privacy is the practice’s duty, as the custodian of its patients’ information. This page says what the app does with data, the little that reaches us, and what other services it talks to, and only when. It is written to be checked against the code, which is open.

Draft. This policy is being reviewed and is not yet in force.

  1. 01On the practice’s computer Patient records, notes, recordings, documents, the practice’s mail as the app reads it, and conversations with the agent are kept on the computer the app runs on. The chart and the conversations are encrypted with a key held in the computer’s own keychain. The models that read documents, transcribe visits and run the agent are downloaded once and run there. We receive none of it, and there is no analytics or telemetry for it to reach us through.
  2. 02The practice’s duty, and its means The practice decides who uses the computer, keeps its keychain, and keeps its records safe. The app gives it the means: an optional lock (Touch ID or the computer’s password), and encrypted backups to a place the practice chooses — a drive plugged in, a network drive, another computer of its own — that open only with a recovery key the practice makes and keeps. We are never told the recovery key and never receive a backup, so we cannot restore one and cannot read one.
  3. 03Signing in to mail with Google or Microsoft A practice can connect its mailbox by signing in with Google (Gmail or Google Workspace) or Microsoft (Outlook.com or Microsoft 365). The sign-in happens on Google’s or Microsoft’s own page, so the app never sees the password. The app asks for two things: access to the mailbox over IMAP and SMTP (Google’s https://mail.google.com/ scope; Microsoft’s IMAP.AccessAsUser.All and SMTP.Send), and the account’s email address.
  4. 04What that access is used for To show the practice its mail in the app, to file a message or an attachment to a patient’s record when someone at the practice asks it to, and to send what someone at the practice presses Send on — a reply, an appointment invitation, a record sealed to a patient’s key. Nothing else. Mail is read on the practice’s computer and kept there; the sign-in’s long-lived token is kept in that computer’s keychain.
  5. 05What we never do with it Mail and account data never reach Anastomo: no server of ours receives, stores or can read them, and no person at Anastomo reads them. They are not sold, not shared with anyone, not used for advertising, and not used to create, train or improve any artificial-intelligence or machine-learning model. The agent that works with them is a model running on the practice’s computer, unless the practice itself chooses a hosted model (see 08).
  6. 06Google’s and Microsoft’s policies Anastomo’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.
  7. 07Ending it Sign out in the app (Settings or setup, under Mail) and its token is deleted from the keychain. Access can also be taken away from the account’s side, at any time: for Google at myaccount.google.com/permissions, for a Microsoft personal account at account.live.com/consent/Manage, and for a work or school account by its administrator.
  8. 08Other services, when asked The app talks to other services only for something the practice does, and only with what that needs: its own mail provider, for its mail; Apple Maps (on a Mac) or Photon, an OpenStreetMap service run by komoot (elsewhere), for what is typed into the practice’s address box — never a patient’s; Hugging Face, which hosts the models setup downloads once, for every app; and a hosted AI model, only if the practice chooses one in Settings, in which case what is typed to the agent goes to that provider under the practice’s own agreement with it.
  9. 09What reaches us If a practice has automatic updates on, the app reads one file from anastomo.io once a day — the current version — and sends nothing. To verify a practice, the practice’s name, address, phone, email address and the public half of its signing key go to our verification service; that page says what it keeps. That registration — the practice’s email address, name, address and phone, and the public keys of the computers acting for it — is the only information about anyone that we keep, with its plan if it pays for one. Payment is taken by Stripe, on Stripe’s own page: we never see a card, and keep only Stripe’s reference to the practice’s subscription, its plan and until when it is paid. A plan changes how the practice’s computers work together; it never locks the practice out of its records. This website sets no cookies and runs no analytics; like any website, its hosting keeps a standard log of requests, which includes the address a request came from. Both run on Google Cloud in the United States (Virginia), so what they hold can be reached by the courts, law enforcement and national security authorities there.
  10. 10Patients A record a practice sends a patient goes by the practice’s own email, sealed so that only the patient’s key opens it; it never passes through us, and we could not read it if it did. The page a patient opens to connect their key runs in their own browser and keeps their key there; it asks our verification service only whether the practice is who it says it is. Patients do not have accounts with us, and we do not charge them.
  11. 11Who is responsible Anastomo, in British Columbia, for what reaches us: British Columbia’s Personal Information Protection Act and, for what crosses a provincial or national border, the federal Personal Information Protection and Electronic Documents Act (PIPEDA). A practice is responsible for its patients’ information under its own province’s law — in Ontario, the Personal Health Information Protection Act — and the app keeps that information on the practice’s computer, in the practice’s hands.
  12. 12Your rights, and ours to keep Anyone can ask us what we hold about them — for a practice, its certificate — and to correct it or have it removed. If a breach of what we hold creates a real risk of significant harm, we will report it to the Privacy Commissioner of Canada and tell the people affected. A complaint we have not resolved can go to the Office of the Privacy Commissioner of Canada or the Office of the Information and Privacy Commissioner for British Columbia. Questions and requests go to ted@anastomo.io, who is responsible for Anastomo’s development and for privacy at Anastomo. This page changes when the code does, and the change is in the repository’s history.

The browser extension has its own page: what the Companion does with your data.