Last Updated: October 1st 2026
At EE Dojo, Inc. (operating as ScribeMD.ai), we are committed to protecting the privacy of the healthcare professionals who use our service and of the patients whose information they entrust to it. ScribeMD.ai is an AI medical scribe: clinicians record or dictate patient consultations, and the service transcribes them and generates draft clinical notes, letters, billing codes and other documentation. This Privacy Policy explains how we collect, hold, use and disclose personal information in connection with the ScribeMD.ai service when it is used in Australia, and is our APP privacy policy for the purposes of Australian Privacy Principle (APP) 1.
ScribeMD.ai is provided by EE Dojo, Inc. (D/B/A ScribeMD.ai), a California-based corporation ("ScribeMD.ai", "we", "us" or "our").
EE Dojo, Inc. (D/B/A ScribeMD.ai)
10000 Washington Blvd, Suite 607
Culver City, CA 90232, USA
This policy is designed to comply with the Privacy Act 1988 (Cth) (the "Privacy Act") and the 13 Australian Privacy Principles, as amended from time to time, including by the Privacy and Other Legislation Amendment Act 2024 (Cth). Those amendments include, among other things, transparency obligations about automated decisions that use personal information and a statutory tort for serious invasions of privacy. Depending on where our customers practise, state and territory health records laws may also apply to health information, such as the Health Records Act 2001 (Vic), the Health Records and Information Privacy Act 2002 (NSW) and the Health Records (Privacy and Access) Act 1997 (ACT).
If you are a patient, your clinician's own privacy policy explains how they handle your health information, and your clinician is responsible for notifying you about, and where required obtaining your consent to, the use of ScribeMD.ai in your care.
We collect personal information directly from you when you create an account, subscribe, use the service or contact us; automatically through your use of the service and our website; and from our customers, who provide patient information to us through the service in the course of their clinical practice. We do not collect patient information directly from patients. We hold personal information electronically on infrastructure provided by Amazon Web Services.
You may browse our public website without identifying yourself and may make general enquiries using a pseudonym. Because the service is provided to identified healthcare professionals under a subscription, it is generally impracticable for account holders to deal with us anonymously or under a pseudonym.
We will only use or disclose personal information for a secondary purpose where permitted by APP 6, for example where you would reasonably expect it and the purpose is related (or, for sensitive information, directly related) to the primary purpose, where you consent, or where required or authorised by law. We may send account holders information about our service; you can opt out of marketing communications at any time using the unsubscribe link or by contacting us.
Health information is "sensitive information" under section 6 of the Privacy Act and attracts additional protection. Under APP 3, sensitive information may generally only be collected with the individual's consent or where another exception applies. Our customers are responsible for providing patients with any required notice and for obtaining any consent required by law before using ScribeMD.ai in a consultation. ScribeMD.ai handles health information solely to deliver the service to the relevant customer and in accordance with the customer's instructions. We do not sell patient information and we do not use identifiable patient information to train AI models. We may create aggregated and de-identified statistics from which no individual can reasonably be identified.
We do not sell personal information. We may disclose personal information to:
Personal information, including patient health information, is likely to be disclosed to and held by recipients located in the United States, unless a local hosting option has been agreed (see section 11). In line with APP 8, before disclosing personal information to an overseas recipient we take reasonable steps to ensure that the recipient does not breach the APPs in relation to that information, including by imposing contractual obligations on our service providers requiring them to protect it to a standard consistent with the APPs and to use it only to provide services to us.
By default, the service is hosted in the United States. We offer local data hosting options so that Customer Data, including patient health data, can be stored in the customer's own region. Where a local hosting option has been agreed in writing with a customer, that customer's data is stored in the agreed region. For any specific question about hosting, data location or this policy, please contact contact@scribemd.ai.
In line with APP 11, we take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. Data is encrypted in transit and at rest, and access is restricted to authorised personnel. No method of electronic transmission or storage is completely secure, but we work continuously to maintain appropriate safeguards.
Patient and clinical information is retained in accordance with the customer's configuration of the service and its instructions. On termination of a customer's subscription, we delete or return that information in accordance with our agreement with the customer, except where we are required by law to retain it. Account and billing information is retained for as long as needed to provide the service and to meet our legal, tax and accounting obligations, after which it is securely destroyed or de-identified.
Under APPs 12 and 13, you may request access to the personal information we hold about you and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. To make a request, contact contact@scribemd.ai. We will respond within a reasonable period, generally within 30 days, and will not charge you for making a request. If we refuse a request, we will give you our reasons in writing and explain how to complain.
If you are a patient, please contact your clinician first, as they are responsible for your health records. We will assist our customers to respond to patient requests for access or correction.
ScribeMD.ai uses AI to produce draft documentation. Clinicians review, edit and approve all AI output before relying on it, and the service does not make decisions about individuals that significantly affect their rights or interests without human involvement. The service is not intended to provide diagnosis or treatment decisions.
If we become aware of a data breach affecting patient or customer information, we will notify the affected customer promptly and assist it to carry out an assessment of whether the breach is an eligible data breach within 30 days, and to meet its obligations under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act. Where we are the responsible APP entity, we will assess the breach and notify affected individuals and the Office of the Australian Information Commissioner as required.
The service is intended for use by healthcare professionals and is not directed to children. Our customers may document consultations with patients of any age; any such information is handled on the customer's behalf as described in this policy.
We may update this Privacy Policy from time to time. We will post the updated policy on this page with a new "Last Updated" date and, where changes are material, notify account holders by email or in the service before they take effect.
If you have a complaint about how we have handled your personal information, please contact us first at contact@scribemd.ai. We will acknowledge your complaint, investigate it and respond within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC):
Office of the Australian Information Commissioner
GPO Box 5288
Sydney NSW 2001
Website: https://www.oaic.gov.au
For questions about this Privacy Policy, requests for access or correction, or questions about hosting and data location, please contact:
EE Dojo, Inc. (D/B/A ScribeMD.ai)
10000 Washington Blvd, Suite 607
Culver City, CA 90232, USA
Email: contact@scribemd.ai
Last Updated: October 1st 2026