Privacy and recordings
Know what happens before you practise
BedsideLoop is a formative training tool. It is not a clinical system and its AI feedback is not a grade of record.
What an encounter stores
When you explicitly agree and begin, BedsideLoop stores the timestamped conversation transcript, conversation language and mode, generated feedback, and—when audio storage succeeds—the candidate and simulated-patient recording. If final saving is interrupted, this device may retain the pending transcript—but not raw audio or transport diagnostics—in a browser outbox that is eligible for recovery for 24 hours. Expired data is removed the next time BedsideLoop is opened. The outbox is bound to the same signed-in account and also removed after a successful retry or when another account uses the app.
Why it is stored
The data is used to produce your formative report, let you replay the encounter, support authorised faculty review, and diagnose failed sessions. It must not be used as an official pass/fail result.
Who can access it
You can access your own encounters. Authorised faculty, examiners, and administrators in your organisation may access sessions for feedback, quality review, and approved calibration work. Ordinary practice audio is sent through OpenRouter to Google Gemini models for transcription, patient replies and speech. Ordinary examiner scoring also uses OpenRouter; approved calibration uses its separately locked provider. Hosting and encrypted media storage run in the configured BedsideLoop environment.
Retention and deletion
This build does not silently promise or enforce an automatic deletion period. Your UiTM pilot administrator must explain the institution-approved retention schedule before participation. You can delete your own ordinary practice session from its replay page; this removes its transcript, report, events, and recording. Exam or approved study records follow the institution’s retention process, so request access or deletion through the programme administrator who issued your account. If that schedule has not been explained, do not begin a recorded encounter. An encrypted upload left unattached by a server crash is not used for replay and is removed by the default orphan-media sweep within 24 hours; the administrator must disclose any deployment-specific change to that window.
Limited analytics
BedsideLoop records a small set of product events, such as encounter start and report display, only when analytics is configured and explicitly enabled under the approved pilot policy and you opt in from Account for that browser session. Automatic click capture and session recording are disabled. The telemetry processor is PostHog; unless the pilot administrator configures another endpoint, events go to the US-hosted PostHog ingestion service. This is limited pseudonymous event-level telemetry, reported only in aggregate. BedsideLoop does not send your application user ID or create a persistent analytics person profile, and consent does not carry over to another account on the device.
Privacy or deletion questions should be directed to the UiTM programme administrator who invited you to the pilot.