
Effective date: 2 April 2026
SSapp is a clinical tool used by audiologists to turn shorthand into structured notes (Magic Notes), generate referral letters (Referral Letters), and ask point‑of‑care clinical questions (Chat to Me). SSapp is designed to be ephemeral by default and to minimise personally identifiable information in processing. When SSapp is used by a clinic, the clinic remains the New Zealand “health agency” and data controller; SSapp and its infrastructure providers act as data processors under the clinic’s instructions.
Jump to: New Zealand — Australia
Clinics and clinicians are responsible for what they enter into SSapp and for meeting their obligations under New Zealand’s Health Information Privacy Code 2020 and Privacy Act 2020. SSapp provides privacy‑protective defaults and guidance, but the clinic must ensure that unnecessary personally identifying information is omitted from prompts and drafts, and that final outputs are reviewed and filed correctly in the PMS/EHR. SSapp cannot accept liability for any disclosure or misuse arising from identifiers or patient details supplied by a clinic or clinician, or for failures to follow clinic policy and best practice.
SSapp processes health information as defined in New Zealand’s Health Information Privacy Code 2020 (for example, clinical observations, assessment notes, referral details). Inputs originate from a clinician and relate to a specific patient encounter; SSapp does not collect information directly from patients. Magic Notes and Referral Letters operate solely on the clinician’s text; Chat to Me operates on clinician queries plus a small rolling context to improve immediate relevance.
We process health information only to provide the features the clinician invokes: creating structured notes, generating referral letters, and answering clinical questions. These purposes are directly related to documentation and care delivery, consistent with HIPC Rule 1 and Rule 10 and Privacy Act IPP 1 and IPP 10. We do not use health information for model training or marketing; OpenAI API data‑use for training is explicitly disabled on our keys.
Information is collected from the clinician user and relates to their patient (HIPC Rule 2 and Rule 3/3A; IPP 2 and IPP 3). Clinics remain responsible for informing patients that overseas processors may be used to deliver SSapp’s functions, and that patients have rights of access and correction. SSapp does not provide a privacy notice template; clinics must maintain their own notices and consent processes.
Clinicians must review and verify AI‑generated content before it is saved to the patient record or disclosed (HIPC Rule 8; IPP 8). SSapp presents draft outputs and requires human confirmation for clinical notes and referral letters. This helps ensure information is accurate, up‑to‑date, complete, relevant, and not misleading before use or disclosure.
SSapp applies encryption in transit and at rest, strict access controls, and environment isolation proportionate to health information sensitivity (HIPC Rule 5; IPP 5). We minimise operational logs and avoid logging payload bodies that could contain health information. SSapp does not record audio and does not include any audio capture features.
SSapp is not a system of record. Magic Notes and Referral Letters are ephemeral in‑app; drafts exist only during the session unless the clinician exports them to the clinic’s PMS/EHR, where standard clinical retention periods apply (HIPC Rule 9; IPP 9). Chat to Me maintains a short rolling working memory across recent conversations to make the tool more helpful in context; the memory is session‑scoped and is wiped on exit. Certain providers may retain operational anti‑abuse telemetry briefly (for example, OpenAI’s 30‑day retention) and then delete it.
SSapp uses reputable processors that provide safeguards comparable to New Zealand law through recognised frameworks and contractual terms (HIPC Rule 12; IPP 12). Cloudflare relies on Data Privacy Framework certifications and SCCs/CBPR for cross‑border transfers. Railway is certified under the Data Privacy Framework and uses SCCs where applicable. Supabase offers region selection and SCCs for EU/UK transfers. OpenAI offers GDPR‑aligned contractual safeguards with model‑training disabled. Chroma Cloud hosts a vector database for general audiology knowledge; it stores no patient content for embeddings and relies on SCCs for cross‑border transfers.
SSapp encourages clinicians to remove direct identifiers unless necessary for the task at hand. Embeddings used by Chat to Me are limited to New Zealand‑relevant audiology sources such as NZAS best practice guidelines, manufacturer product information, funding information, and general medical audiology and technical hearing aid/test information. Embeddings do not include patient notes or patient‑specific content.
SSapp discloses information only to deliver the services requested by the clinician or as required by law (HIPC Rule 11; IPP 11). Typical recipients are the clinic’s own systems (for example, PMS/EHR) and the nominated recipient of a referral letter under the clinic’s authority. We do not sell personal information or permit processors to use it for their own marketing.
SSapp does not assign unique identifiers to patients (HIPC Rule 13; IPP 13). If a clinic includes an NHI or other identifier in an input or template, it is used solely for the documentation or referral purpose and is not repurposed.
We do not use analytics or marketing cookies in the clinical app. SSapp uses a strictly necessary JWT access token (access_token) to authenticate the request; in SSR contexts (for example, SvelteKit using Supabase helpers) this JWT may be stored in secure, HTTP‑only, same‑site cookies so the server can call Supabase with the correct identity. No other cookies are set by SSapp.
Patients have the right to request access to and correction of their health information held by the clinic (HIPC Rule 6 and Rule 7; IPP 6 and IPP 7). Because SSapp is a processor, clinics should direct requests through their privacy officer, who can retrieve any transient SSapp artefacts if still available and applicable. SSapp assists clinics to respond promptly to valid requests.
If a privacy breach occurs that is likely to cause serious harm, the clinic (as controller) will notify the Office of the Privacy Commissioner and affected individuals as soon as practicable (Privacy Act 2020, Part 6). SSapp maintains an incident response plan, supports clinics in assessment and containment, and cooperates with breach notifications.
Our primary processors today are Cloudflare (edge/security/CDN), Railway (application hosting), Supabase (authentication, customer account and subscription data), OpenAI (inference with training disabled), Chroma Cloud (vector store of audiology knowledge only), and Stripe (payments processing; credit card data handled by Stripe, not by SSapp). All are engaged under contractual terms that include confidentiality, security obligations, and recognised cross‑border safeguards such as the Data Privacy Framework and/or Standard Contractual Clauses. Stripe’s privacy policy: https://stripe.com/privacy
SSapp is not a system of record. Clinicians export finalised notes and letters to the clinic’s PMS/EHR, where the clinic’s standard clinical retention periods apply. SSapp’s ephemeral design avoids unnecessary duplication and long‑term storage outside the clinic’s records.
SSapp is a professional tool for clinicians and is not directed to children. Clinics should avoid entering superfluous sensitive details not necessary for clinical documentation or referral.
We may update this subsection to reflect changes in law, processors, or technical safeguards. Material changes will be highlighted in‑app or on our website, and the effective date will be updated.
For questions or to exercise rights of access or correction, please contact your clinic’s privacy officer in the first instance. If you need to contact SSapp about privacy or security, email support@shockinglysimple.app and we will coordinate with your clinic to support your request.
We collect only what is necessary for clinical documentation and referral, from the clinician, for lawful and related purposes. We require clinician verification of accuracy before use or disclosure, minimise storage, and delete transient data according to short retention windows. We disclose overseas only to vetted processors with comparable safeguards and contractually limit processing to your instructions. We assist clinics with patient rights requests and notifiable breach obligations, and we maintain robust technical and organisational controls proportionate to the sensitivity of health information.
Effective date: 2 April 2026
SSapp provides Magic Notes, Referral Letters, and Chat to Me to support clinicians. SSapp is designed to minimise identifiable data and to process ephemerally. When used by a clinic, the clinic remains the data controller; SSapp and its infrastructure providers act as processors under the clinic’s instructions. To the extent SSapp carries on business in Australia, the Privacy Act 1988 (Cth) and the APPs apply.
The clinic is responsible for lawful collection, notices, and consents; for omitting unnecessary identifiers from prompts; and for verifying and filing outputs in the PMS/EHR. SSapp provides privacy‑protective defaults, purpose‑limited processing, and security aligned with APP 1 and clinic instructions.
SSapp processes clinician‑entered health information related to a patient encounter (for example, shorthand notes, referral details, clinical observations). SSapp does not collect information directly from patients. Magic Notes/Referral Letters operate on clinician text; Chat to Me operates on clinician queries plus short rolling session context.
Processing is limited to providing the requested features: structured notes, referral letters, and clinical Q&A. We do not use clinical inputs for model training or marketing; OpenAI training is disabled on our API keys. Disclosures occur only as needed to deliver the Service or as required by law.
Information is provided by the clinician and relates to their patient. The clinic remains responsible for informing patients of overseas processing and their rights. SSapp does not provide patient‑facing notices; clinics maintain their own privacy notices and consent processes.
Clinicians must review and verify AI‑generated content before use or disclosure. SSapp presents drafts for human confirmation to help ensure information is accurate, up‑to‑date, complete, relevant, and not misleading.
We apply encryption in transit and at rest, access controls, and environment isolation. Operational logs are minimised and avoid payload bodies. SSapp does not record audio and includes no audio capture features. We take reasonable steps to destroy or de‑identify information that is no longer needed for Service delivery, subject to legal obligations.
SSapp is not a system of record. Drafts are session‑scoped and ephemeral unless exported by the clinician to the PMS/EHR. Chat to Me uses a short rolling memory within the session and wipes on exit. Certain providers may retain brief operational anti‑abuse telemetry (for example, OpenAI’s 30‑day retention).
We use subprocessors with recognised cross‑border safeguards (for example, DPF/SCCs/CBPR). We take reasonable steps to help ensure overseas recipients protect personal information in a way substantially similar to the APPs. Where APP 8.1 applies, the clinic acknowledges overseas disclosures may occur to deliver SSapp.
Clinicians should remove direct identifiers unless necessary for the task. Embeddings are limited to audiology knowledge sources (for example, NZAS guidance, manufacturer and funding information, general medical audiology and technical materials) and exclude patient notes or patient‑specific content.
Disclosures are limited to Service delivery or legal requirements. Typical recipients are the clinic’s own systems (for example, PMS/EHR) and the nominated recipient of a referral letter under the clinic’s authority. We do not sell personal information or allow processors to market to you using it.
SSapp does not adopt government identifiers as our own. If a clinic includes an identifier such as an IHI/Medicare number in an input or template, it is used only for documentation or referral purposes and not repurposed.
SSapp does not use analytics or marketing cookies in the clinical app. A necessary JWT may be stored in secure, HTTP‑only, same‑site cookies in SSR contexts to authenticate server calls to Supabase. No other cookies are set by SSapp.
Patients can request access to and correction of their information via the clinic. SSapp, acting as a processor, assists clinics with valid requests and with timely responses.
We promptly assess suspected incidents and aim to complete assessments within 30 days. We notify the clinic without undue delay and cooperate on containment. Where SSapp is the APP entity primarily responsible, we prepare the required statement and notify OAIC and affected individuals; otherwise the clinic is the default notifier and SSapp assists.
Our primary processors include Cloudflare (edge/security/CDN), Railway (application hosting), Supabase (authentication, customer account and subscription data), OpenAI (inference with training disabled), Chroma Cloud (vector store of audiology knowledge only), and Stripe (payments processing). All are engaged under confidentiality and security obligations and rely on recognised cross‑border safeguards such as the Data Privacy Framework and/or Standard Contractual Clauses. Stripe’s privacy policy: https://stripe.com/privacy
SSapp is not a clinical record. Clinicians export final outputs to the PMS/EHR, where standard retention applies. Ephemeral processing avoids long‑term storage outside clinic systems.
SSapp is for professional clinical use and is not directed to children. Avoid entering superfluous sensitive details not necessary for documentation or referral.
We may update this subsection to reflect changes in law, processors, or safeguards. Material changes will be highlighted in‑app or on our website, and the effective date will be updated.
Questions or requests should be directed to the clinic’s privacy officer. To contact SSapp about privacy or security, email support@shockinglysimple.app; we will coordinate with the clinic to support your request. For Australia, guidance is also available from the Office of the Australian Information Commissioner (OAIC).
We limit collection and use to documentation and referral, rely on clinician inputs, and apply purpose limitation and security aligned with APPs. We minimise storage, de‑identify or destroy information when no longer needed, assist clinics with rights requests and NDB obligations, and implement cross‑border safeguards for overseas disclosures.