Privacy Policy
Effective date: 16.06.2026
1. Data controller
The Sentear service (app.sentear.com) is operated by:
KODEMAN OÜ Registry code: 16939400 J. Kuperjanovi tn 4-22, 51003 Tartu, Estonia Email: info@sentear.com
This privacy policy explains how we collect, use, store and protect your personal data in accordance with the European Union General Data Protection Regulation (GDPR, 2016/679) and the Estonian Personal Data Protection Act.
2. Description of the service
Sentear is a platform for healthcare professionals (psychologists, psychiatrists, therapists, nurses and other specialists) that allows you to:
- record and upload audio files of therapy and consultation sessions;
- transcribe audio files into text using Soniox artificial intelligence (including in Estonian);
- generate session summaries based on specialized templates.
Important: Sentear processes health data, which under GDPR Article 9 is a special category of personal data. As a user (healthcare professional), you are yourself the data controller with respect to your patients' data, and Sentear acts as the data processor on your behalf (see section 9).
3. What personal data do we collect?
3.1 Account and authentication data
- Email address (mandatory at registration)
- Password (encrypted, managed by Supabase Auth)
- When logging in via OAuth: name and email (Google)
- User's unique ID (UUID)
3.2 Payment and subscription data
- Credit balance and the history of all transactions
- Subscription status and validity period
- Stripe customer ID (for processing payments)
- Invoice and purchase history
3.3 Content and usage data (special category data)
Attention: The following data may contain health data and is handled in accordance with the requirements of GDPR Article 9.
- Uploaded audio files (session recordings)
- Transcriptions (the result of converting an audio file into text)
- Session summaries (generated by artificial intelligence)
- Metadata: recording duration, file size, session type
3.4 Technical data
- IP address and browser data (to ensure security)
- Login timestamps
- Service usage logs
4. Legal bases for processing
- Creating and managing an account — Art. 6(1)(b) – performance of a contract
- Providing the transcription and summarization service — Art. 6(1)(b) – performance of a contract; Art. 9(2)(a) – explicit consent for processing health data
- Processing payments — Art. 6(1)(b) – performance of a contract
- Transaction history and credit accounting — Art. 6(1)(c) – legal obligation (accounting)
- Ensuring the security of the service — Art. 6(1)(f) – legitimate interest
- Sending customer support and notifications — Art. 6(1)(b) – performance of a contract
For the processing of health data (audio files, transcriptions) we request separate consent at registration. You have the right to withdraw your consent at any time, but this affects your ability to use the service.
5. Third-party service providers
To provide the service we use the following third-party service providers. A data processing agreement (DPA) compliant with GDPR requirements has been concluded with each of them.
5.1 Soniox (European Union servers)
- Purpose: Transcribing audio files into text
- Data transferred: Audio files for transcription
- Data location: data is processed in Europe
- NB: Data sent via the API is not used to train models
- Privacy policy: soniox.com/privacy
5.2 Amazon Web Services / Bedrock (European Union servers)
- Purpose: Generating session summaries
- Data transferred: Transcriptions for generating summaries
- Data location: data is processed in Europe
- NB: Data sent via the API is not used to train models
5.3 Supabase (European Union servers)
- Purpose: Database, authentication and data storage
- Data transferred: User account data, credit history, job metadata, transcriptions and session summaries
- Data location: EU (AWS eu-central-1) – data is kept in Europe
- Privacy policy: supabase.com/privacy
5.4 Stripe (USA)
- Purpose: Processing payments and managing subscriptions
- Data transferred: Email address, payment and subscription data
- Data location: USA and EU (under SCCs)
- Privacy policy: stripe.com/privacy
5.5 Amazon Web Services / SES (European Union servers)
- Purpose: Sending transactional emails (invitations, notifications)
- Data transferred: Email address and message content
- Data location: data is processed in Europe
- Privacy policy: aws.amazon.com/privacy
5.6 Google (OAuth)
- Purpose: Optional login with a Google account
- Data transferred: Email address and public profile – only for authentication, we do not store additional data
- Use is optional – you can always register with an email address
6. Data retention
- Account data — until account deletion + 30 days
- Audio files — deleted automatically immediately after transcription; audio files are not stored long term
- Transcriptions and summaries — until account deletion (the user is responsible for downloading them)
- Credit transaction history — 7 years (accounting requirements, Accounting Act § 12)
- Payment data (in Stripe) — 7 years (requirements arising from tax laws)
7. Your rights (GDPR)
You have the following rights with respect to your personal data:
- Right of access (art. 15): you can request a copy of the data stored about you
- Right to rectification (art. 16): you can request correction of inaccurate data
- Right to erasure (art. 17): you can request deletion of data ("right to be forgotten")
- Right to restriction of processing (art. 18): in certain situations you can request suspension of processing
- Right to data portability (art. 20): you can obtain your data in a machine-readable format
- Right to object (art. 21): you can object to certain processing operations
- Right to withdraw consent (art. 7(3)): for special category data you can withdraw your consent at any time
To exercise your rights, contact: info@sentear.com. We respond within 30 days. To verify your identity we may ask for additional information.
You have the right to lodge a complaint with the Estonian Data Protection Inspectorate: aki.ee | info@aki.ee
8. Data security
We apply the following technical and organizational security measures:
- HTTPS encryption on all data connections
- One-way encryption of passwords (Supabase Auth)
- Row-Level Security in the database – a user sees only their own data
- JWT-based session management with server-side validation
- Signature verification of Stripe webhook calls
- Regular dependency updates and security audits
In the event of a security breach, we notify the data controller (if we are acting as the data processor) or the competent supervisory authority (if we are acting as the data controller) without undue delay in accordance with GDPR Articles 33–34 and, if the breach poses a high risk to your rights, also the affected data subjects.
9. Data processor role – for healthcare professionals
Because Sentear processes your patients' health data on your behalf, we are the data processor within the meaning of GDPR Article 28. You, as the healthcare professional, are the data controller.
This means:
- You are obliged to ensure your patients' consent for recording and processing the session
- You are responsible for which patient data is uploaded to the service
- We process data only according to your instructions and do not use it for any other purposes
- The data transferred to Soniox and AWS is only for processing the specific session – neither uses it to train models
10. Cookies
We use only functionally necessary cookies:
- Session cookies: for login and session management (Supabase Auth JWT tokens). Required for the service to work – without them logging into the service is not possible.
We do not use advertising, analytics or tracking cookies. Third-party tracking tools (Google Analytics etc.) are not used.
11. Minors
A Sentear user account can only be opened by an adult (18+) healthcare professional. We do not knowingly collect user accounts of minors.
Users of the service (healthcare professionals) may process the data of minor patients — this is common in medical practice. In such a case, the healthcare professional, as the data controller, is obliged to ensure that they have the consent of the patient's legal representative for processing the session.
12. Absence of a data protection officer
KODEMAN OÜ has not appointed a data protection officer (DPO). Please send all data-protection-related inquiries to info@sentear.com.
13. Automated decision-making
We do not make automated decisions (including profiling) that would have a legal effect on the user (GDPR art. 22). Artificial intelligence is used only to generate transcriptions and summaries – the final decision always remains with the user.
14. Changes to the privacy policy
We may update this privacy policy from time to time. In the event of significant changes, we will notify you by email at least 30 days in advance. Continued use of the service after the changes take effect means acceptance of the new policy.
15. Contact
For privacy-related questions, requests and complaints:
KODEMAN OÜ (16939400) Email: info@sentear.com J. Kuperjanovi tn 4-22, 51003 Tartu, Estonia
Data Protection Inspectorate (supervisory authority) www.aki.ee | info@aki.ee | tel: +372 627 4135