Skip to main content

Privacy and protected materials

NeuroTrace uses server-derived ownership throughout the web workflow. Every assignment, attempt, recording, job, transcript, result, and event remains tied to the patient and owning clinician.

Patient identity profile

  • Email is required for account delivery. First name, surname, and date of birth are optional shared identification details.
  • A patient can review and correct shared details during activation and later from their profile.
  • An optional internal reference belongs to the owning clinician relationship and is not shown to the patient.
  • Profile audit events record identifiers, action, revision, timestamp, and changed field names without copying the personal values.
  • These fields are not sent to speech recognition, model prompts, scoring, assessment results, result artifacts, notifications, or email.

Diagnosis, medication, medical history, address, unrestricted notes, and assessment-specific context do not belong in invitation profile fields.

Access boundaries

  • Patients can access only their own assigned tests.
  • Only the owning verified clinician can access processing state and automated results.
  • Patients never receive automated results.
  • Prompts, raw provider responses, audit events, credentials, and private object keys have no public API or documentation surface.
  • The CTP stimulus is served from a separate private source using authenticated, no-store streaming and no download action.

Communications

Email notifications are intentionally sanitized. They contain no patient name, date of birth, clinician reference, task type, due date, recording, score, diagnosis, or clinical result.

These technical controls are not a legal or regulatory compliance assessment. Follow applicable law, ethics requirements, institutional policy, and care-specific procedures.