Heidi Health
Heidi · Meeting notes · AU · www.heidihealth.com
services/heidi-health.yamlVendor data-handling terms
“No patient data is used to train, develop, or improve any of our AI models. / Queries may be reviewed and used in de-identified form to improve the platform, but PHI will not be used for model training.”
“Any sensitive health information is only retained for the duration requested by the Practitioner.”
Heidi publishes region-specific policies; the UK, EU and Australian versions each name local storage.
“Your personal information is stored in the UK / We do not transfer personal data outside of these jurisdictions.”
Domains and endpoints
observed means seen in Unseen deployments; vendor-documented means listed by the vendor. Vendors do not publish complete lists.
| Host | Role | Source |
|---|---|---|
| heidihealth.com | app | observed |
Assessment
Reasoning: An AI medical scribe for clinicians. Regional policies state local storage, no training on patient data, and retention set by the practitioner. The content is patient health data, so the low rating assumes it is used in a clinical setting under the organisation's agreement, not by staff outside healthcare.
Flags: Processes patient health data; needs an organisational agreement · Assessed 2026-09-16. The assessment is Unseen's; the terms above are the vendor's.
Changelog
- 2026-09-16Documented. Training, retention and storage terms verified against the Heidi Health UK privacy policy.
- 2026-09-15Listed from the Unseen catalogue with observed domains.
Corrections
Pull request on GitHub, or the form below. Changes are reviewed and recorded in the changelog.