Privacy Policy
Last updated: 03 March 2026
Overview
This Privacy Policy explains how Lumina AI Solutions Pty Ltd ("Lumina AI", "we", "us", "our") collects, uses,
discloses, and otherwise handles personal information when you download and use the Scriba application (the
"App").
We are committed to protecting the privacy of our users, including healthcare professionals and their patients,
and handling personal information in a manner that complies with the Australian Privacy Act 1988 (Cth) (the
"Privacy Act") and the Australian Privacy Principles (APPs).
This App and its services are intended for use by authorised healthcare professionals, practice staff, and their
patients in Australia. By accessing or using the App, you agree to the terms of this Privacy Policy.
1. Scope
This policy applies to all users of the App, including:
- Healthcare Professionals: such as Physiotherapists, Occupational Therapists, and other
allied health or medical practitioners.
- Authorised Practice Staff: administrative or support staff of a healthcare practice.
- Patients: individuals whose information may be processed through the App by a healthcare
professional.
We collect several types of information from and about users of our App. Information that identifies, relates to,
describes, or could reasonably be linked with a particular individual is considered "personal information".
Under Australian law, health information is a category of sensitive information and receives enhanced
protections.
2.1 User Information (Healthcare Professionals & Staff)
- Identity Information: Name, professional registration number and details, job title.
- Contact Information: Business email address, practice or organisation name, business
address, and phone number.
- Account Information: Username, password.
2.2 Audio Recordings
Audio recordings of clinical consultations, patient sessions, or dictated notes, created when the recording
feature is enabled by the user. These recordings may contain sensitive health information about patients.
2.3 Transcripts and Clinical Documentation
- Speech-to-Text Transcripts: Machine-generated transcripts of audio recordings.
- AI-Generated Notes: Draft clinical notes, SOAP notes, reports, treatment summaries, and
other documentation generated by our AI-assisted tools.
- User Input: Any clinical observations, notes, or data that you input, upload, or import
into the App.
2.4 Health Information (Sensitive Information)
Patient health information, including medical history, treatment notes, clinical observations, diagnosis
information, and other personal health information discussed during a consultation or entered into the App. This
is classified as sensitive information under the Privacy Act.
2.5 Technical and Usage Data
- Device Information: Device model, operating system version, unique device identifiers
(e.g., IDFA on Apple devices).
- Log Data: IP address, access times, app features accessed, crash logs, and performance
data.
- Diagnostic Data: Information we collect to troubleshoot and improve the App.
3. How We Collect Information
We collect information in the following ways:
- Directly from you: When you register for an account, set up your profile, use the App's
features (like recording), or contact our support team.
- Automatically: As you navigate through and interact with our App, we may automatically
collect Technical and Usage Data using technologies such as logs and cookies.
- From you about patients: Healthcare professionals input or generate patient health
information when using the App for its intended purpose.
4. Purpose of Collection and Use
We collect, hold, use, and disclose personal information for the following purposes:
- To Provide the Service: To create and manage your account; to transcribe audio recordings;
to generate AI-assisted clinical draft documentation; and to provide you with access to your data within the
App.
- To Operate and Improve the App: To maintain, troubleshoot, and enhance the functionality,
performance, and security of the App; to develop new features; and to conduct data analysis to improve our
AI models (using de-identified information where possible).
- To Comply with Legal Obligations: To meet our legal, regulatory, and professional
obligations, including those related to health records and privacy.
5. Consent and Lawful Recording
Healthcare professionals using the App are responsible for complying with all applicable laws and professional
standards regarding patient consultations, informed consent, and the recording of consultations.
- You, as the healthcare professional, confirm and agree that you will obtain informed, voluntary, and
explicit patient consent before using the App's recording feature.
- You are responsible for documenting that consent appropriately in the patient's record.
- You must ensure your use of the App complies with relevant state and territory surveillance legislation,
health records legislation, and the professional codes of conduct for your discipline.
6. AI Processing
The App uses artificial intelligence (AI) and machine learning tools to generate draft transcripts and clinical
documentation from audio recordings.
- Outputs are for Clinical Support Only: AI-generated outputs are draft versions only and are
intended to assist, not replace, professional clinical judgment. They must be reviewed, edited, and
clinically verified by a qualified healthcare professional before being finalised or used for any clinical
or administrative purpose.
- No Medical Advice: We do not provide medical advice. The AI-generated content does not
constitute a medical opinion or diagnosis. The final clinical decision-making responsibility rests solely
with the healthcare professional.
- Data Use for Model Improvement: We may use transcripts and user feedback to train and
improve our AI models.
7. Data Storage and Security
We take the security of your information, particularly sensitive health information, very seriously.
- Infrastructure: Your data is hosted on secure servers provided by Microsoft Azure, located
in Australia.
- Security Measures: We implement a range of industry-standard security measures to protect
your information from misuse, interference, loss, unauthorised access, modification, or disclosure. These
include:
- Encryption: Data is encrypted in transit using TLS/SSL protocols and encrypted at
rest.
- Access Controls: Strict role-based access controls limit access to personal
information to authorised personnel only.
- Monitoring: We employ security monitoring tools to detect and prevent unauthorised
access.
8. Overseas Disclosure
While your primary data is stored in Australia, some of our service providers (including Microsoft Azure and
providers of AI services) may store or process data outside of Australia. These disclosures are limited to what
is necessary to provide our service.
We take reasonable steps to ensure that any overseas recipient (including Microsoft Azure) complies with privacy
obligations that are at least substantially similar to the Australian Privacy Principles (APPs), such as through
contractual arrangements.
The countries where data may be processed include China, the United States and Singapore. By using the App, you
acknowledge that your information may be transferred to these countries for processing.
We may share your personal information in the following circumstances:
- With Your Consent: When we have your explicit consent to share the information.
- With Authorised Users: Information and content generated within a practice or clinic may be
accessible to other authorised users within that same practice, as determined by the account administrator.
- Service Providers: We may share information with third-party service providers who perform
services on our behalf, such as cloud hosting (Microsoft Azure), customer support, and AI processing
services. These providers are contractually bound to protect the information and use it only for the
services they perform for us.
- Legal Compliance: Where required by law, such as to comply with a court order, subpoena, or
other legal process, or to meet reporting obligations to government or regulatory authorities (e.g., AHPRA,
OAIC).
- We Do Not Sell Data: We do not and will not sell, rent, or trade your personal information
to any third party for their own marketing purposes.
To provide audio transcription and AI‑assisted clinical documentation functions, we may transmit your audio
recordings and related medical information to strictly vetted third‑party AI service providers for processing.
Such processing is solely for the purpose of delivering the core functionalities of this Application. These
third‑party service providers are prohibited from using the data for any other purpose. We ensure the security
of your data during transmission and processing through encryption, access controls, and data processing
agreements, and prohibit service providers from identifying, retaining, or misusing your personal information,
thereby effectively preventing privacy breaches.
10. Retention and Deletion
We retain your personal information for as long as your account is active or as needed to provide you with the
App's services.
- User-Controlled Deletion: You have the ability to delete individual audio recordings and
transcripts directly through the App's interface.
- Account Termination: If you wish to de-register your account and request deletion of your
personal information, please contact us using the details in Section 15. We will process your request in
accordance with our legal obligations.
- Legal Requirements: We may be required by law (such as health record retention laws) to
retain certain records for a specified period, even after account deletion. If such an obligation applies,
we will retain the data in a secure manner and restrict its use to those legal requirements.
11. Your Rights: Access and Correction
Under the Australian Privacy Principles, you have the right to:
- Access your personal information that we hold.
- Request Correction of your personal information if you believe it is inaccurate,
out-of-date, incomplete, irrelevant, or misleading.
To request access to or correction of your personal information, please contact our Privacy Officer using the
details below. We may need to verify your identity before processing your request. We will respond to your
request within a reasonable period, as required by law.
12. Children's Privacy
The App is not intended for direct use by individuals under the age of 16. Healthcare professionals may, however,
use the App to document consultations with their patients who are minors. In such cases, the healthcare
professional is responsible for obtaining the necessary consent from a parent or legal guardian, in accordance
with their professional and legal obligations.
13. Cookies and Similar Technologies
Our App may use cookies and similar tracking technologies to enhance user experience, analyse trends, and
administer the App. You can manage your cookie preferences through your device or browser settings. However,
disabling cookies may affect the functionality of certain parts of the App.
14. Updates to this Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the law, or the features
of our App. The updated policy will be posted within the App, and the "Last updated" date at the top of this
policy will be revised. We encourage you to review this policy periodically. In the case of material changes, we
may provide a more prominent notice (such as an in-app notification).
If you have any questions, concerns, or complaints regarding this Privacy Policy or our handling of your personal
information, please contact our Privacy Officer:
16. Third-Party AI Services
To enable audio transcription and AI‑assisted clinical documentation features, we use artificial intelligence
services provided by OpenAI (including the OpenAI API). When you use these features, the following data may be
transmitted to OpenAI for processing:
- Audio recordings of clinical consultations or dictations;
- Machine-generated transcriptions;
- Contextual information necessary to generate clinical documentation (e.g., patient encounter details entered
by healthcare professionals).
The AI service provider processes data in accordance with its own privacy and security commitments. You can review the provider’s privacy policy here:Privacy policy | OpenAI