How Carl protects your data
Privacy isn’t a feature. It’s the foundation Carl is built on.
When you use Carl, you’re entrusting us with some of the most sensitive information in your professional practice — we’re fully aware of that. Whether it’s your session notes, information about your patients, or how your practice is organized, this data deserves the highest level of protection.
That’s why security, privacy, and professional confidentiality were built into Carl from the ground up. They aren’t features bolted on afterward — they’re principles that guide every one of our decisions, from day one.
Your data belongs to you
Primary hosting in Europe
Data encrypted in transit and at rest
Automatic, encrypted backups
No audio kept after transcription
No data used to train AI
No AI diagnosis or interpretation
GDPR compliant
01
Our philosophy
Security, privacy, and professional confidentiality aren’t features added as an afterthought: they’re part of Carl’s design from the very first line of code.
Three principles guide every one of our technical decisions: collect only what’s necessary, never let sensitive information travel or be stored without protection, and leave the professional — you — in final control of your data and the clinical decisions that follow from it.
02
Your data belongs to you
The data stored in Carl remains your exclusive property. You keep control of your information at all times: you can view it, edit it, export it, or delete it whenever you need to.
Carl claims no rights over the content of your patient records. Our business model relies on your subscription — never on exploiting your data.
03
Primary hosting in Europe
Carl’s primary application data — including patient records, notes, and documents stored in the application — is hosted in the European Union by Supabase.
Some providers required to deliver the service may nevertheless process data outside the European Economic Area. Where necessary, these processing activities are covered by the safeguards required under the GDPR.
04
Data encryption
The security of your data starts with how it’s protected. All communication between your device and Carl’s servers is encrypted, and your data is also encrypted when it’s stored.
This encryption protects your information from unauthorized access, both while it’s being transmitted and while it’s kept on our infrastructure.
05
Audio recordings
Carl never records your sessions. When you use voice dictation to take notes, three steps happen in sequence: your recording is transmitted securely, a transcript is generated, and then the audio is deleted.
Audio is never kept after transcription. Only the text you choose to keep stays saved in your Carl workspace — never the sound of your voice.
06
Protecting your identity and your patients’ identity
Carl is designed around the principle of data minimization: we encourage using only the information that’s strictly necessary for your practice.
Where compatible with how you work, using a first name only or internal identifiers further limits the exposure of your patients’ personal data.
07
Access control
The confidentiality of your patient records is an absolute priority. Access to production systems is strictly limited to authorized personnel, following the principle of least privilege.
Carl’s teams do not have access to your patient records: our architecture is designed so that maintenance and operations can be carried out without accessing the clinical content you record. Every access to our systems is monitored, limited, and secured.
08
Backups and service continuity
Your data can represent several years of work. That’s why it’s protected by automatic backup mechanisms, performed regularly, encrypted, and stored in secure environments — with the same level of protection as your primary data.
In the event of a hardware or software incident, recovery procedures help preserve the integrity of your information and ensure service continuity. Our goal is simple: you should be able to find your data whenever you need it.
09
Protecting your account
Access to your Carl workspace is secured. We implement mechanisms designed to protect your account from unauthorized access, and we continuously evolve our security measures to keep up with industry best practices.
10
Responsible AI, never clinical
Carl’s artificial intelligence remains an assistant: it never replaces your expertise, never makes a diagnosis, never interprets a clinical situation, and never issues a therapeutic recommendation.
Its role is limited to:
Structuring your notes
Generating summaries
Quickly retrieving information
Preparing your upcoming sessions
Simplifying your organization
All clinical decisions remain entirely in your hands.
11
What Carl will never do
We believe certain rules should be simple and unambiguous.
Carl will never sell your data.
Carl will never use your patient records to train an AI model.
Carl will never share your information with third parties for commercial purposes.
Carl will never run advertising based on your data.
Carl will never replace your clinical judgment.
Carl will never make therapeutic decisions on your behalf.
12
GDPR compliance and your rights
Carl is developed in accordance with the requirements of the General Data Protection Regulation. In particular, we apply the following principles:
Data minimization
Purpose limitation
Transparency
Security of processing
Confidentiality
You have, at any time, the rights guaranteed by the GDPR over the data you process with Carl: the right of access, rectification, erasure, and data portability.
13
Our subprocessors and their DPAs
We select every subprocessor after reviewing its purpose, security measures, processing locations, international transfers, and its own subprocessors. Only providers that are necessary to operate Carl receive the data strictly required for the service they deliver.
In accordance with Article 28 of the GDPR, every relationship that qualifies as processing on our behalf is governed by a Data Processing Agreement, or DPA.
Our subprocessor list and the corresponding DPA documents are available on request. To obtain them, contact our DPO using the contact form.
14
Security as continuous improvement
Security is never a finished task. We continuously evolve our infrastructure, procedures, and tools to maintain a high level of protection against emerging threats.
In accordance with the GDPR, any data breach likely to pose a risk to your rights is reported to the competent supervisory authority within 72 hours, and you are informed if you are affected. Our ambition is to offer a solution that is ever more reliable, more transparent, and more respectful of the confidentiality of care and support professionals.
15
Frequently asked questions
Where is the data stored?
Carl’s primary application data — including patient records, notes, and documents stored in the application — is hosted in the European Union by Supabase. Some providers required to deliver the service may nevertheless process data outside the European Economic Area, subject to the safeguards required under the GDPR.
What happens in the event of an outage or technical incident?
Your data is protected by automatic, encrypted backups performed regularly. In the event of a hardware or software incident, recovery procedures help preserve the integrity of your information and ensure service continuity.
What security measures do you have in place?
Security is built into Carl from the design stage. Data is encrypted in transit and at rest, anonymized where possible, and protected by security mechanisms aligned with industry best practices. Access is secured to guarantee the confidentiality of your patients’ information.
Is my data used to train your AI?
No. The data you enter into Carl is never used to train AI models. It remains exclusively for your practice and is processed with respect for your confidentiality.
Do you share my data with third parties?
No. We never sell or share your patients’ data for commercial purposes. The only providers we work with support the secure operation of the service and are bound by strict confidentiality obligations.
Does Carl make diagnoses or interpret sessions?
No. Carl never replaces your clinical expertise. It organizes, structures, and summarizes the information you provide, but it never makes a diagnosis or offers a clinical interpretation.
Are audio recordings kept?
No. Audio recordings are used only to produce the transcript, then deleted. Only the content you choose to keep in the patient record stays saved.
Is Carl GDPR compliant?
Yes. Carl is designed to comply with the requirements of the General Data Protection Regulation (GDPR). In particular, we apply principles of data minimization, security, confidentiality, and transparency in processing.
Can I export my data if I leave Carl?
Yes. Your data belongs to you. You can export it to keep or import it into another tool if you ever decide to leave Carl.
We built Carl because we believe therapists should spend their energy on their patients, not on admin work.
Technology should stay discreet. It should save you time. Never cost you trust.
A question about security?
Our team is available to answer any questions you have about privacy, security, or data protection.
Last updated: August 29, 2026. This document evolves with the product and will be updated accordingly.