Two months free. Download LogBlues and let us prove it — no card, no contract. Start free →
LogBlues

Privacy

Your patients’ records never reach us.

Not encrypted on our servers. Not anonymised in a research set. Not pooled, brokered, or sold to anyone, at any price. They stay on the computers in your practice, and the only people who can read them are the people you gave logins to.

Where a chart actually sits.

When a clinician writes a note, it is written to a database on a machine the practice owns, encrypted at rest with AES-256-GCM. The key lives in the operating system’s own secure store — Windows DPAPI, the Android keystore — not in a file we invented.

There is no step in that sequence where the note travels to us. Not for processing, not for backup, not for “quality improvement”. That is not a setting you switch on. It is the shape of the software.

The assistant works the same way. Blues runs against a model on the same machine, so asking it about a patient does not put that patient in anybody’s API log. Unplug the clinic from the internet and it still answers.

What we will never do with patient information.

These are not intentions. They are things the architecture makes impossible.

The part most vendors leave vague.

Ask any practice-software company where your records live and who can read them. The answer is usually that they are “secure in the cloud”, which means they are on somebody else’s computer, readable by that company’s staff under some policy, and worth money to whoever eventually buys that company.

We are not more virtuous than those companies. We simply cannot do that, because we never have the data. When a business changes hands, what changes hands is the software, not your patients.

What we do hold, and it is small.

A clinic-owner email address, so you can sign in and we can send a receipt. Whatever you type into the contact form. That is the list. The email is never sold, rented or handed to an advertiser, and every message we send carries an unsubscribe link that works.

The full detail, in the language a lawyer will want, is in the Privacy Policy.

When a patient asks you a hard question.

“Who else can see my file?” is a fair question, and a clinician should be able to answer it without a call to support. The answer here is short: the people in this practice who have a login, and nobody else. Not the software company. Not a subprocessor. Not an analytics vendor.

A Business Associate Agreement is available on request, at no charge. Ask for it before you commit, not after — and ask every other vendor on your shortlist the same question, including us.

Try it free for two months How the security works →