Sign In

Privacy Policy

Last updated: 30 July 2026

⚠️ Draft — not yet reviewed by a lawyer. Do not publish live or rely on this for a paying customer until an actual privacy/health-law solicitor has checked it (allied health client records are "sensitive information" under the Privacy Act, which carries a higher bar than most SaaS).

PearWise ("we", "us") operates PearScribe. This Privacy Policy explains how we collect, use, store, and protect personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Because PearScribe is used to process health information about your clients, APP obligations apply to us regardless of business size — there is no small-business exemption for health service-related data.

1. What We Collect — and What We Deliberately Don't

Account data (we store this): your name, email address, organisation name, and billing details.

Your client database (we do NOT store this): PearScribe is built so that your clients' records — names, session transcripts, generated reports — live in a single file (.ahadata) encrypted on your own device (or your own connected Google Drive), protected by a password and a recovery key that only you hold. Our servers never receive or retain a readable copy of this file. If our servers were compromised, an attacker would find no readable client records there.

This is a meaningful architectural choice, not a legal loophole: it does not remove PearScribe's obligations under the Privacy Act (see Section 4), but it dramatically reduces what could be exposed if our infrastructure were ever breached.

2. What Happens During a Recording Session

When you record a client session, the audio and resulting transcript are sent, for processing only, to:

Neither we, nor (per our agreements with these providers) they, retain a copy of this audio/text after processing it, and it is not used to train their models. You are shown an explicit consent notice before each recording naming these processors. This is a cross-border disclosure of personal information (APP 8) — both providers are US-based; we take reasonable steps to ensure they handle it consistently with the APPs.

3. Your Recovery Key — Your Responsibility

When you create your client database, PearScribe shows you a one-time recovery key. We do not store it. If you lose both your password and your recovery key, we have no way to recover your client data — we genuinely cannot access it. Please store your recovery key somewhere safe (a password manager, a printed copy in a locked drawer).

4. This Doesn't Remove Your Obligations, or Ours

Not storing your client database in readable form does not mean PearScribe has no responsibilities under the Privacy Act, and it does not remove your own record-keeping obligations as a registered practitioner (e.g. under AHPRA / NDIS Practice Standards, which typically require client records be retained for at least 7 years). PearScribe is a processing tool, not a substitute for your own compliant record-keeping system — you remain the custodian of your client file.

5. Third-Party Services (Subprocessors)

6. Data Retention

Account data is retained while your subscription is active, and for up to 90 days after cancellation. We retain no copy of your client database at any time — it never reaches our servers in readable form. If you use the optional Google Drive sync, the encrypted file is retained in YOUR Drive, governed by your own Google account, not by us.

7. Your Rights

Under the Australian Privacy Principles, you may access, correct, or request deletion of the account data we hold about you. Because we don't hold your client database, requests relating to specific client records should be directed to your own copy of the file — we have nothing to search or delete on our end.

Contact: hello@pearwise.au

8. Data Breach Notification

We follow the Notifiable Data Breaches scheme. Because your client database is never held by us in readable form, a breach of our infrastructure is very unlikely to expose readable client information — but we will still assess and notify as required by law for any incident involving account data.

9. Changes to This Policy

We may update this Privacy Policy periodically and will notify you by email before material changes take effect.

10. Contact and Complaints

Privacy enquiries: hello@pearwise.au
If unsatisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.