Where your sessions live, who can see them, and what happens when you say delete.
These are the questions practitioners, insurers, and clients ask us before they trust a session to Parts Companion. The answers describe what we do today, with the vendor names and the number of days.
One region. One copy.
Everything a session produces, the recording, the transcript, the notes, the parts, is stored in a single database and file store on Supabase, in Amazon Web Services' North Virginia region. The app itself runs on Vercel in the United States.
That is true whether your practice is in Denver, London, Berlin, or Sydney. We say so plainly because the alternative, a vague "secure cloud," is the sentence that makes careful practitioners stop reading.
In transit with TLS, at rest with AES-256, including backups. What we control beyond that is who can read a session: you, the people you allow, four named people on our team, and the vendors below under contract.
Four vendors, in this order, for this long.
A recorded session passes through four hands besides ours. Each one is named here with what it does and how long it keeps a copy. All four are in the United States, and all four have signed a HIPAA Business Associate Agreement with us.
Recall.ai
AssemblyAI
Anthropic
Supabase
The full list, including vendors that never see session content, is published at partscompanion.org/legal/subprocessors. We give 30 days' notice before adding one.
Your sessions are not a product.
Parts Companion is a not-for-profit project. Paid plans cover the cost of running it. That changes what we have any reason to do with your data.
Never sold, never used for advertising
Not to partners, not to data brokers, not for targeting. There is no version of our business where that helps.
Session data is never used to train AI models
Not ours, not our vendors'. That restriction is in every vendor contract. De-identified data, with every identifier removed, may support research and product evaluation, and you can ask us to exclude your practice.
Never read by a person, unless you donated it
Four named people could technically reach session content: HIPAA-trained every year, multi-factor sign-in, attested encrypted devices, every access logged and reviewed. They almost never need to. When a session has a problem, an automated investigator reads the logs and content and reports what happened, so we fix it with no human eyes on your session.
Gone from live systems now. Gone from everywhere in 30 days.
Deleting a session removes the recording, transcript, notes, parts, and everything derived from them immediately. Deleting your account does that for every session in it. The rest is a matter of backups and vendor retention expiring on schedule.
Session notes, transcripts, and parts can be exported from your account at any time in machine-readable formats. Deleting is not the only way to leave.
If your practice is in the UK, the EU, or Australia.
For your clients' session data, you are the controller and Evolve Labs is your processor. Our Data Processing Addendum is now part of the terms of use for every account, so there is nothing extra to sign, though we will countersign a copy if your records need one.
Standard Contractual Clauses
Module Two, controller to processor, incorporated into the addendum. Irish law and courts for the clauses themselves. Explicit client consent, or care under professional confidentiality, is your lawful basis for health data.
UK International Data Transfer Addendum
The ICO's addendum to the EU clauses, version B1.0. Your rights, and your clients' rights, run to the Information Commissioner's Office.
APP 8, handled in writing
The addendum binds us to handle information consistently with the Australian Privacy Principles, which is the reasonable step APP 8.1 asks of you before disclosing to an overseas recipient.
Read the addendum at partscompanion.org/legal/dpa. It also records our 72-hour breach notice, 30-day sub-processor notice, and the deletion timeline above.
The long version.
Collected from due-diligence reviews by practitioners in the UK and Australia, and kept current in our help center. If your question isn't here, write to us and we'll add the answer.
Where your data lives
In the United States. The database and file storage run on Supabase (Amazon Web Services, North Virginia), and the app runs on Vercel in the US. This applies to every account, including practitioners and clients in the UK, EU, and Australia.
Yes. Everything is encrypted in transit with TLS and at rest with AES-256, including backups. Beyond encryption, what protects a session is who can read it: your account, your practitioner or client where you allow it, the four named people on our team described below, and the vendors above under contract.
Four named people on our team could technically reach session content. All four complete HIPAA training every year, are bound by confidentiality agreements, sign in to production with multi-factor authentication, work only on encrypted devices that pass a security attestation, and have every access logged and reviewed each quarter.
In practice they almost never need to look. When something goes wrong with a session, even a support request you have raised, an automated investigator reads the logs and the content, reports what happened in general terms, and we fix the problem from that report. No human eyes on the content. There is no routine review of session content, and nobody reads sessions to improve the product unless the session was donated.
Vendors
Yes. Each vendor's data processing terms, including the EU Standard Contractual Clauses where they apply, were accepted with that vendor's terms of service. The vendors that handle session content also hold a HIPAA Business Associate Agreement with us.
We email you at least 30 days before a new vendor begins handling session content, and update the sub-processor page. If you object on data-protection grounds and we can't resolve it, you can end your subscription without penalty.
Training, research, and product improvement
No. None of our vendors may use your data to train their models, and we do not use identifiable session content to train ours. This is written into our contracts with each vendor.
Not in identifiable form. Two things do happen.
Donated sessions: a practitioner or client can choose to donate a session to our research program. Only donated sessions are read by our team for research.
De-identified data: we may remove all identifiers, using the HIPAA safe-harbor standard, and use what remains for research, evaluation, and improving the product. We never try to re-identify it. Practitioners outside the US can ask us to exclude their practice.
Deleting
Deleting a session removes the recording, transcript, notes, parts, and everything derived from them from our live systems immediately. Deleting your account does the same for every session in it. Copies in database backups expire within 30 days. Vendors delete their transient copies on the schedules above, so the last trace is gone within about 30 days.
Yes. Session notes, transcripts, and parts can be exported from your account at any time in machine-readable formats.
Outside the United States
Transfers to the United States are made under the European Commission's Standard Contractual Clauses (Module Two, controller to processor) and the UK International Data Transfer Addendum. Both are incorporated into our Data Processing Addendum, which is now part of our terms of use.
For your clients' session data, you are the controller and Evolve Labs, Inc. (Golden, Colorado) is your processor. For your own account data, Evolve Labs is the controller. Our Data Processing Addendum covers GDPR, UK GDPR, and the Australian Privacy Principles, applies to every account through the terms of use, and can be countersigned on request.
You remain accountable for our handling of the information you disclose to us. Our Data Processing Addendum binds us to handle it in a manner consistent with the Australian Privacy Principles, which is the reasonable step APP 8.1 asks you to take before disclosing to an overseas recipient.
Clients need to know that sessions are recorded, that the recording is processed in the United States by the vendors above, and, in the UK and EU, to give explicit consent to the processing of their health data. A line in your intake paperwork covers all three. We can share wording if it helps.
Incidents, requests, and reviews
By email to your account address, and directly for anything involving session content, within 72 hours of confirming a breach. The notice says what happened, who is affected, what we have done, and who to contact. We will help with any notification you have to make to your regulator or your clients.
We tell you before disclosing anything, where the law allows it, so you can seek advice. We challenge requests we have reasonable grounds to consider unlawful, and disclose only the minimum required.
Yes. An independent assessor audits our HIPAA security and privacy program every year, and we can share the completion letter, data-flow map, security overview, and vendor register on request. We do not hold SOC 2 or ISO 27001. If your insurer needs evidence of a specific control, ask and we will tell you plainly whether we have it.
Need this in writing?
The Data Processing Addendum and the sub-processor list are public pages you can hand to a reviewer. For anything they don't cover, we answer directly.