How pilot data is handled
This page describes what happens today, during free pilot audits run directly with each design partner. It is not a description of a future hosted service.
Last updated 11 October 2026.
Please don't email patient conversations. Before any data is shared we agree in writing the scope of the audit, how transcripts are de-identified, and a secure way to transfer them.
1. Before anything is shared
- You de-identify transcripts before sending them: names, contact details, dates of birth, addresses, Medicare and other record numbers, and anything else that could identify a person.
- We agree the number of conversations, the time period they cover, the protocol they are checked against, and when the audit ends.
- We agree a transfer method. Email is not one of them.
2. The automatic de-identification pass and its limits
SafeRounds runs its own de-identification pass on every conversation before it is stored or sent for review. It replaces common identifier patterns such as phone numbers, email addresses, dates, and record numbers.
It is pattern-based and can miss things, in particular:
- names, nicknames, and family members mentioned in free text;
- unusual identifiers, misspellings, and numbers written out in words;
- details that identify someone only in combination, such as a rare condition plus a suburb plus an occupation.
It is a second safety net, not a replacement for your own de-identification.
3. What is sent to Anthropic
The review is done by Claude, a model made by Anthropic, through Anthropic's commercial API. For each conversation the following is sent:
- the de-identified conversation text;
- the relevant parts of your clinical protocol;
- any de-identified record text you supply for context.
Anthropic may process this data outside Australia. Under Anthropic's commercial terms, API inputs and outputs are not used to train its models. Anthropic keeps API data for a limited period for safety and abuse monitoring under its own retention policy; see Anthropic's commercial terms and privacy centre for current details.
4. What SafeRounds keeps, and for how long
- Kept: the de-identified conversations, the review results with their quoted evidence, reviewer decisions, and an audit record of who opened each conversation and when.
- Not kept: anything you have not sent for the agreed audit. Original, identified transcripts are never requested.
- How long: only for the agreed audit. Everything is deleted at the end of the audit, or earlier whenever you ask.
- Where: during pilots, data is held only on systems the founder controls, and the storage arrangement is agreed with you before the audit starts. Hosting in Sydney is planned before any ongoing service and is not in place yet.
5. Who can see it
- Only the founder, Justin Hiew, and the people you nominate from your own organisation.
- Each time a conversation is opened in the review queue, the access is recorded in an audit log, which you can ask to see.
- Nothing is shared with anyone else, used for marketing, or used to build public examples. The examples on this website are synthetic.
6. Deletion
Email [email protected] at any time to have your data deleted. Deletion covers the stored conversations, results, and reviewer notes, and is confirmed in writing. The audit log records the deletion itself. Copies held by Anthropic under its own retention policy expire on Anthropic's schedule.
7. What SafeRounds is not
SafeRounds is a retrospective review and quality-assurance tool. It does not see conversations as they happen, does not change or block replies, and is not medical advice or clinical decision support. Clinical responsibility stays with your service.
Questions
Email [email protected]. If something on this page is unclear or doesn't fit your organisation's requirements, raise it before the pilot starts and we'll work it out together.