Trust & safety

Your health records belong to you

Sodam handles only what is needed and puts storage, sharing, and deletion in your hands.

Privacy notice
Illustration of safely controlled personal health records
01 · Control

Control by default

Choose what to capture

Recording and calendar access require permission; core notes remain usable without them.

Choose what to share

Records are private by default and shared only when the user chooses.

Request deletion

Users can request record or account deletion. Data subject to a legal retention duty may be excepted.

02 · Data

How data is handled

Private storage

Supabase authentication and row-level security (RLS) restrict access by account.

Encrypted transport

HTTPS/TLS protects data in transit between supported services.

Purpose-limited processors

Data needed for requested transcription or summaries may be sent to processors such as OpenAI and Twilio.

Minimum permissions

Calendar and microphone access is requested when needed and can be revoked in device settings.

Operational access

Team access is intended to be restricted by role and business need.

Korean-law aware

We are incorporating PIPA principles and conducting legal review. We do not claim formal certification or complete compliance.

Security is an ongoing practice, not a one-time promise. Before launch, we will review data flows, retention, processor agreements, and user notices.

Available now

Bring Sodam to your next visit

Capture the conversation, understand what matters, and remember what comes next.