Skip to content
Open ECH Transcript Studio

ECH TRANSCRIPT STUDIO · EARLY ACCESS

Privacy policy

How information is handled in the ECH Transcript Studio early-access pilot, operated by ECH Reporting LLC.

Effective September 22, 2026 · Pilot policy

1. What is processed and where

Transcript text and confirmed case terms
Opening a file loads it into your browser. Starting AI checking sends the text and confirmed terms through our server to OpenAI’s API for analysis. The app does not create a server-side transcript library. Processing through our server and provider is still a disclosure of that content outside your device.
Local drafts, decisions, and notes
Recovery drafts contain the transcript, filename, findings, edits, decisions, and personal notes. They are stored in this browser’s database on this device, not synchronized to another device. New drafts are listed only for the signed-in account that saved them. Older drafts without an account association are preserved but hidden, not automatically assigned to the next person who signs in. The app does not add its own encryption to drafts or downloaded review backups. Personal review notes are not included in AI review requests.
Audio-scoping drafts and recordings
Opening an audio-scoping ZIP, matching saved transcription and playing a recording happen locally. Choosing Create reviewed draft after confirming the disclosure sends transcript text and saved speech-recognition text through our server to OpenAI. This text review does not upload the recording or independently listen to it. Audio-scoping work is held in the open tab, not autosaved to My transcripts. Save progress downloads a ZIP containing the transcript, findings, edits, decisions and attached recording. The smaller JSON backup excludes the recording. These downloads are not encrypted by ECH Transcript Studio.
Account and activity information
Our hosting sign-in service supplies an account identifier and email for access checks. Our activity database records user identifiers, joined/last-seen dates, review identifiers, counts, progress, decisions totals, and status. It does not store transcript text, filenames, or recordings. The administrator dashboard displays aggregate usage.
Feedback and support
Submitted ratings and comments are stored with a user identifier, optional review identifier, and timestamp. Administrators can read feedback. Support emails contain the information you choose to send and are handled through our email service. Do not include confidential transcript content in feedback or support messages.

2. Why information is used

We process information to provide requested reviews, restore local progress, control access, record usage, investigate problems, respond to support, and improve the service from submitted feedback. Personal My notes are part of your review, not a feedback submission.

The application does not include advertising trackers or a data-sale feature. Hosting and sign-in services may use necessary cookies or similar storage and process connection, security, and diagnostic information under their own policies.

3. Providers and access

ECH Transcript Studio uses OpenAI’s API for AI analysis, Sites hosting and sign-in, and Cloudflare-backed application infrastructure and activity storage. Support correspondence uses our email provider. These services process information needed to operate their functions. Authorized operators may access server-side records for support and administration; the aggregate dashboard is not a guarantee that operators cannot access underlying records.

We may disclose information when required by applicable law or when reasonably necessary to address abuse or protect the service. This policy does not override a court order, your client’s instructions, or your professional duties.

4. AI storage and model training

Our API requests disable response storage. This is not a zero-retention guarantee. OpenAI documents default abuse-monitoring retention of up to 30 days, with exceptions, and other feature-specific storage. Its API training policy excludes customer data by default unless the account opts in to sharing.

Sharing for model improvement is disabled for the API project used by ECH Transcript Studio. We do not opt your transcript inputs or review outputs into OpenAI’s model-training program. This does not eliminate provider security retention or change how previously shared data was handled. See OpenAI’s data controls for its current policy.

5. Retention and removal

  • Browser drafts: retained until you remove them, clear site data, or the browser removes them. There is no automatic expiration. Use Remove in Recent drafts for drafts listed under your account. Clearing site data removes all local recovery, including older unassigned drafts and other accounts’ drafts in that browser profile; back up authorized work first. Signing out alone is not a way to delete browser drafts.
  • Downloads: remain wherever you save them, including synced or backed-up folders, until you remove those copies. We cannot delete files from your computer.
  • Activity, feedback, and support: the pilot has no automated expiration schedule or self-service server-record deletion. Contact us to request access, correction, or deletion. We may need to verify your identity and explain any records retained for legal, security, or operational reasons.
  • Provider records: subject to provider policies and settings. Deleting a draft does not delete provider logs or previously submitted records.

6. Your choices and security

You can decline AI processing and use the prepared sample instead. Use a private, protected device and browser profile. Account-filtered draft lists are not encryption: someone with access to that browser profile or your unlocked tab may still access local content. Close review tabs before signing out or changing accounts. Store exports and backups according to your professional obligations. No internet service or browser recovery copy is guaranteed secure or continuously available.

The live site uses HTTPS. Cloudflare documents encryption at rest for D1, which holds our activity and feedback records—not a transcript archive. These provider controls do not establish that ECH Transcript Studio has its own SOC 2 report. ECH Transcript Studio has not completed an independent security audit, and no claim of HIPAA readiness or US-only processing is made.

Depending on where you live, additional privacy rights may apply. Contact us with a request or concern; please do not send identity documents or sensitive transcripts in the initial message. This pilot is intended for adult professional users, not children.

7. Done For You

This policy describes the self-service pilot. Before any managed-service intake, contact us without attachments to agree on data suitability, human access, transfer method, and retention. The website is not permission to email confidential material or assume a separate confidentiality or healthcare agreement is in place.

8. Contact and updates

Contact ECH Reporting LLC at mike.crager@gmail.com for privacy questions or requests. We will post revisions here with a new effective date. Review the policy before submitting material if the service or your requirements change.