Trust & safety

Sensitive records should stay under your control

Sodam aims to handle only what is needed and make storage, sharing, and deletion understandable choices.

Privacy notice
Illustration of safely controlled personal health records
01 · Control

Control by default

Choose what to capture

Recording and calendar access require permission; core notes remain usable without them.

Choose what to share

Records are private by default and shared only when the user chooses.

Request deletion

Users can request record or account deletion. Data subject to a legal retention duty may be excepted.

02 · Data

How data is handled

Private storage

Supabase authentication and row-level security (RLS) restrict access by account.

Encrypted transport

HTTPS/TLS protects data in transit between supported services.

Purpose-limited processors

Data needed for requested transcription or summaries may be sent to processors such as OpenAI and Twilio.

Minimum permissions

Calendar and microphone access is requested when needed and can be revoked in device settings.

Operational access

Team access is intended to be restricted by role and business need.

Korean-law aware

We are incorporating PIPA principles and conducting legal review. We do not claim formal certification or complete compliance.

Security is an ongoing practice, not a one-time promise. Before launch, we will review data flows, retention, processor agreements, and user notices.

Coming soon

Prepare for your next appointment.

Sodam brings everyday symptoms and visit details together, helping you remember the conversations that matter.

Get launch updates