Last updated: September 7, 2026

Privacy Policy

How Nexus Wispr handles account information, recordings, transcripts, notes, attachments, and related service data.

Overview and Our Role

Nexus Wispr is a mobile and desktop service for recording, reviewing, synchronizing, and generating clinical notes and related workflow content. Nexus Wispr is operated by ZΞNCOM. This Privacy Policy explains what information we process, why we process it, where it is stored, and the choices available to users.

For direct individual accounts, we determine how account, security, support, billing, and service-operation information is processed. A clinician or healthcare organization normally determines why patient-related content is entered into Nexus Wispr. Where we process that content for an organization under a written agreement, the organization is the controller and we act as its processor or service provider.

Information We Process

We process account information such as your name, email address, authentication identifiers, language and role preferences, device and session information, and support communications.

When you use the product, we process content you provide or generate, including audio recordings, transcripts, encounter details, uploaded attachments, notes, templates, referral drafts, edits, code-search requests, usage and credit records, and synchronization records. This content may contain health information or other sensitive personal data.

We also process limited operational telemetry from signed-in use, such as application platform and version, operating-system version, a random installation identifier, event timestamps, selected reliability events, and an approximate country and continent derived from a network request.

How and Why We Use Information

We use information to provide and secure the service, authenticate users, synchronize signed-in devices, process audio and text, generate and edit notes, administer accounts and credits, troubleshoot issues, respond to support requests, and improve reliability and product quality.

For users in the European Economic Area or United Kingdom, our processing of account and service data is generally necessary to provide the service you request, comply with law, or pursue legitimate interests such as security, fraud prevention, support, and service reliability. Where consent is the appropriate basis, you may withdraw it. The clinician or organization using Nexus Wispr is responsible for establishing the lawful basis and any notices, permissions, or consents required for patient-related content.

We do not sell personal information, use patient-related content for advertising, or use it to track users across other companies' apps or websites.

Operational Telemetry and Approximate Location

Nexus Wispr records a limited set of events such as opening the app, signing in, creating or editing an encounter, processing an encounter, and whether synchronization succeeded or failed. These records do not include recordings, transcripts, clinical notes, attachment contents, patient names, encounter titles, search text, or other clinical content.

Product-activity records may include country and continent codes observed from the network request by our hosting infrastructure. This is approximate network information, not a verified physical location. A virtual private network, privacy relay, mobile carrier, or corporate gateway may cause a different country to appear. We do not store a raw IP address, GPS coordinates, city, or postal address in the product-activity record.

Public Website Analytics

We use Vercel Web Analytics on our public promotional homepage to understand visitor numbers, referring websites, approximate location, device and browser types, and interactions such as playing the promotional video, opening the features list, and clicking download or login links. These reports help us understand interest in Nexus Wispr and improve the website.

This analytics service does not use cookies. Vercel processes information from the network request to produce aggregate statistics using a temporary visitor identifier that resets daily. Approximate location can be affected by VPNs, privacy relays, and network providers. The website also stores your chosen light or dark appearance locally in your browser.

Our promotional analytics integration is limited to the homepage. It removes query strings and fragments from the page URLs it reports and sends only predefined interaction labels. We do not send account identifiers, form entries, recordings, notes, or other clinical content through this integration. The signed-in product uses the separate operational telemetry described above. See Vercel's analytics privacy information for more about its data handling.

Service Providers

We use service providers for functions such as authentication, cloud hosting and storage, web delivery, transcription and AI-assisted note generation, email delivery, and payment processing when billing is enabled. These currently include Supabase, Vercel, OpenAI, Resend, Apple and Google authentication services, and Paddle for the separately controlled billing workflow.

Providers process information only for the services they supply to Nexus Wispr, subject to their applicable agreements and our configuration. AI requests made through the Nexus Wispr backend are configured not to be stored by the OpenAI Responses API. We review provider terms and data-handling settings before activating a provider for regulated enterprise use.

Storage Region and International Transfers

The current Nexus Wispr production backend is hosted in the United States in AWS region us-east-1. Individual accounts are assigned to this U.S. region; Nexus Wispr does not currently select a database from your IP address, device locale, or physical location.

Our providers may also process information in other countries. Where European data-protection law requires safeguards for an international transfer, we use an applicable contractual or legal transfer mechanism. Additional dedicated regions may be activated later for eligible enterprise customers under their written agreement, but they are not active for the current consumer service.

Retention and Account Deletion

Account information and user content are generally retained while the account is active, unless you delete content earlier or a shorter period is agreed. Product-activity telemetry is automatically deleted after 400 days. Support and security records are retained only for as long as reasonably needed for the request, service protection, dispute handling, or a legal obligation.

You can request account deletion from the signed-in app settings or through the public account-deletion page. A request starts a 30-day recovery period and immediately locks normal product access. Unless you recover the account during that period, Nexus Wispr permanently removes the Auth account, owned database records, stored recordings and attachments, feedback, and telemetry. A narrowly limited non-identifying completion receipt may remain so that we can prove the deletion completed safely.

We may retain a limited record for longer when law requires it or when reasonably necessary for fraud prevention, security, accounting, or legal claims. Any such exception is limited to the information and period required for that purpose.

Your Privacy Rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to processing of, or receive a portable copy of your personal data. You may also withdraw consent where processing depends on consent. These rights may be subject to identity verification and lawful exceptions.

Send a request to support@zencom.net. We will acknowledge and handle requests within the period required by applicable law. Users in the European Economic Area may also lodge a complaint with the data-protection authority in the country where they live or work, or where they believe an infringement occurred.

Clinical Content and HIPAA

Nexus Wispr may process sensitive clinical or patient-related content. You must have the authority and lawful basis required to record, upload, process, and share that content, including any recording consent required in your jurisdiction.

The current direct-to-consumer service is not offered under a Business Associate Agreement and is not represented as HIPAA-compliant. Do not use the current service to create, receive, maintain, or transmit protected health information where HIPAA requires a Business Associate Agreement. HIPAA-regulated enterprise use requires a separate written agreement, provider review, risk analysis, and activation by Nexus Wispr.

Security

We use administrative, technical, and organizational measures designed to protect information, including encrypted network transport, private storage, account-scoped authorization controls, restricted administrative access, protected local storage, and monitored account deletion. No internet or cloud service can guarantee absolute security, so users should also protect their devices, accounts, and credentials.

Children

Nexus Wispr is a professional service and is not directed to children. Patients mentioned in clinical content are not Nexus Wispr account users; the clinician or organization remains responsible for the lawful handling of that content.

Changes

We may update this Privacy Policy as the product, providers, or legal requirements change. The updated version will be posted on this page with a new effective date. We will provide additional notice when a material change requires it.

Contact

The controller for direct individual account and service data is ZΞNCOM, 8 The Green STE A, Dover, DE 19901, USA.

For privacy questions or requests, contact us at support@zencom.net.