Privacy
Your health, your data
Healthcare is deeply personal and so is any healthcare data about you. Therefore, Ditto has a privacy-by-design approach to how we handle your data. We can never read or access what you do and store in the Ditto app. Read our highlights below or have a look at our complete privacy policy.

Data storage
Everything you do in Ditto is stored only on your device
Ditto does not store your medical data on its servers. It's your data, so you can carry it whenever you go. This is how it works:
Everything stays on your device
Your health information never leaves your phone unless you choose to share it or get an AI-summary. After processing, we delete all data on our side, such that only the summary on your device remains. We don't store medical data on our servers. Period.
You control access
Your app is protected by biometric login or passcode. No one—not even us—can access what's inside.
Your backup, your choice
Ditto uses your device's built-in backup (iCloud or Google Drive). We recommend enabling encrypted backups so you can recover your information if you lose your phone.
AI
AI that respects privacy
Artificial Intelligence is powerful technology. We use artificial intelligence to help translate medical lingo into plain language.
We are strong advocates of responsible AI. Ditto does that by:
-
We never train on your data. In fact, we don't even store it.
-
EU-infrastructure only. Your audio is transcribed in the Netherlands by NEN-certified Juvoly, and AI summaries are generated on EU-based Azure servers.
-
Prioritize validation and governance. We work with patients and doctors to extensively test our AI before releasing new versions.
-
Be on the safe side. If our AI is uncertain about something, it will tell you by saying that it cannot reliably provide you with a summary.


Security & compliance
Industry-standards are the Ditto standard
Our team has built security systems for enterprises. Now we're applying that same rigor to protect your personal health information.
Ditto is GDPR and ANG compliant in its handling of personal data. Our Data Privacy Policy explains exactly how we handle your data needed to keep the app running.
The only information we store centrally is fully-anonymous technical logging and quality metrics (kept on encrypted Azure servers in Amsterdam) needed to ensure the app works properly and safely.
Questions about security or privacy?
Reach out to Yury, our CTO, who genuinely loves talking about keeping your data safe. Because clarity shouldn't come at the cost of privacy. If you have identified vulnerabilities in our technology, you can file a vulnerability disclosure report here.