How Carl protects your data

Privacy isn’t a feature. It’s the foundation Carl is built on.

When you use Carl, you’re entrusting us with some of the most sensitive information in your professional practice — we’re fully aware of that. Whether it’s your session notes, information about your patients, or how your practice is organized, this data deserves the highest level of protection.

That’s why security, privacy, and professional confidentiality were built into Carl from the ground up. They aren’t features bolted on afterward — they’re principles that guide every one of our decisions, from day one.

Your data belongs to you

Primary hosting in Europe

Data encrypted in transit and at rest

Automatic, encrypted backups

No audio kept after transcription

No data used to train AI

No AI diagnosis or interpretation

GDPR compliant

01

Our philosophy

Security, privacy, and professional confidentiality aren’t features added as an afterthought: they’re part of Carl’s design from the very first line of code.

Three principles guide every one of our technical decisions: collect only what’s necessary, never let sensitive information travel or be stored without protection, and leave the professional — you — in final control of your data and the clinical decisions that follow from it.

02

Your data belongs to you

The data stored in Carl remains your exclusive property. You keep control of your information at all times: you can view it, edit it, export it, or delete it whenever you need to.

Carl claims no rights over the content of your patient records. Our business model relies on your subscription — never on exploiting your data.

03

Primary hosting in Europe

Carl’s primary application data — including patient records, notes, and documents stored in the application — is hosted in the European Union by Supabase.

Some providers required to deliver the service may nevertheless process data outside the European Economic Area. Where necessary, these processing activities are covered by the safeguards required under the GDPR.

04

Data encryption

The security of your data starts with how it’s protected. All communication between your device and Carl’s servers is encrypted, and your data is also encrypted when it’s stored.

This encryption protects your information from unauthorized access, both while it’s being transmitted and while it’s kept on our infrastructure.

05

Audio recordings

Carl never records your sessions. When you use voice dictation to take notes, three steps happen in sequence: your recording is transmitted securely, a transcript is generated, and then the audio is deleted.

Audio is never kept after transcription. Only the text you choose to keep stays saved in your Carl workspace — never the sound of your voice.

06

Protecting your identity and your patients’ identity

Carl is designed around the principle of data minimization: we encourage using only the information that’s strictly necessary for your practice.

Where compatible with how you work, using a first name only or internal identifiers further limits the exposure of your patients’ personal data.

07

Access control

The confidentiality of your patient records is an absolute priority. Access to production systems is strictly limited to authorized personnel, following the principle of least privilege.

Carl’s teams do not have access to your patient records: our architecture is designed so that maintenance and operations can be carried out without accessing the clinical content you record. Every access to our systems is monitored, limited, and secured.

08

Backups and service continuity

Your data can represent several years of work. That’s why it’s protected by automatic backup mechanisms, performed regularly, encrypted, and stored in secure environments — with the same level of protection as your primary data.

In the event of a hardware or software incident, recovery procedures help preserve the integrity of your information and ensure service continuity. Our goal is simple: you should be able to find your data whenever you need it.

09

Protecting your account

Access to your Carl workspace is secured. We implement mechanisms designed to protect your account from unauthorized access, and we continuously evolve our security measures to keep up with industry best practices.

10

Responsible AI, never clinical

Carl’s artificial intelligence remains an assistant: it never replaces your expertise, never makes a diagnosis, never interprets a clinical situation, and never issues a therapeutic recommendation.

Its role is limited to:

  • Structuring your notes

  • Generating summaries

  • Quickly retrieving information

  • Preparing your upcoming sessions

  • Simplifying your organization

All clinical decisions remain entirely in your hands.

11

What Carl will never do

We believe certain rules should be simple and unambiguous.

Carl will never sell your data.

Carl will never use your patient records to train an AI model.

Carl will never share your information with third parties for commercial purposes.

Carl will never run advertising based on your data.

Carl will never replace your clinical judgment.

Carl will never make therapeutic decisions on your behalf.

12

GDPR compliance and your rights

Carl is developed in accordance with the requirements of the General Data Protection Regulation. In particular, we apply the following principles:

  • Data minimization

  • Purpose limitation

  • Transparency

  • Security of processing

  • Confidentiality

You have, at any time, the rights guaranteed by the GDPR over the data you process with Carl: the right of access, rectification, erasure, and data portability.

13

Our subprocessors and their DPAs

We select every subprocessor after reviewing its purpose, security measures, processing locations, international transfers, and its own subprocessors. Only providers that are necessary to operate Carl receive the data strictly required for the service they deliver.

In accordance with Article 28 of the GDPR, every relationship that qualifies as processing on our behalf is governed by a Data Processing Agreement, or DPA.

Our subprocessor list and the corresponding DPA documents are available on request. To obtain them, contact our DPO using the contact form.

14

Security as continuous improvement

Security is never a finished task. We continuously evolve our infrastructure, procedures, and tools to maintain a high level of protection against emerging threats.

In accordance with the GDPR, any data breach likely to pose a risk to your rights is reported to the competent supervisory authority within 72 hours, and you are informed if you are affected. Our ambition is to offer a solution that is ever more reliable, more transparent, and more respectful of the confidentiality of care and support professionals.

15

Frequently asked questions

Where is the data stored?

Carl’s primary application data — including patient records, notes, and documents stored in the application — is hosted in the European Union by Supabase. Some providers required to deliver the service may nevertheless process data outside the European Economic Area, subject to the safeguards required under the GDPR.

What happens in the event of an outage or technical incident?

Your data is protected by automatic, encrypted backups performed regularly. In the event of a hardware or software incident, recovery procedures help preserve the integrity of your information and ensure service continuity.

What security measures do you have in place?

Security is built into Carl from the design stage. Data is encrypted in transit and at rest, anonymized where possible, and protected by security mechanisms aligned with industry best practices. Access is secured to guarantee the confidentiality of your patients’ information.

Is my data used to train your AI?

No. The data you enter into Carl is never used to train AI models. It remains exclusively for your practice and is processed with respect for your confidentiality.

Do you share my data with third parties?

No. We never sell or share your patients’ data for commercial purposes. The only providers we work with support the secure operation of the service and are bound by strict confidentiality obligations.

Does Carl make diagnoses or interpret sessions?

No. Carl never replaces your clinical expertise. It organizes, structures, and summarizes the information you provide, but it never makes a diagnosis or offers a clinical interpretation.

Are audio recordings kept?

No. Audio recordings are used only to produce the transcript, then deleted. Only the content you choose to keep in the patient record stays saved.

Is Carl GDPR compliant?

Yes. Carl is designed to comply with the requirements of the General Data Protection Regulation (GDPR). In particular, we apply principles of data minimization, security, confidentiality, and transparency in processing.

Can I export my data if I leave Carl?

Yes. Your data belongs to you. You can export it to keep or import it into another tool if you ever decide to leave Carl.

We built Carl because we believe therapists should spend their energy on their patients, not on admin work.

Technology should stay discreet. It should save you time. Never cost you trust.

A question about security?

Our team is available to answer any questions you have about privacy, security, or data protection.

Last updated: August 29, 2026. This document evolves with the product and will be updated accordingly.