Privacy Policy
Last updated: September 2026. Applies to unitypulse.io, manage.unitypulse.io, TScribe, Ureport and the UnityPulse Dictation browser extension.
UnityPulse (“we”, “our”, “us”) is a healthtech company based in Nigeria. We operate TScribe, Ureport, the organisation dashboard at manage.unitypulse.io and the UnityPulse Dictation browser extension (together, “the services”). This policy explains what information we collect when you use the services, how we use it, and what rights you have. It reflects our obligations under the Nigeria Data Protection Regulation (NDPR) and related guidelines. TScribe and Ureport each publish a version of this policy adapted to that product; where they differ, the product’s own policy applies to that product.
1. What we collect
When you create an account or contact us, we collect:
- Your name and email address
- Your professional role or specialty, which decides whether your account opens TScribe or Ureport
- Your organisation, if you belong to one, and your role in it
- Your phone number and profile picture, if you choose to add them
- Messages you send to our support team
When you use the services we collect anonymous usage analytics (pages visited, feature interactions, session duration) to understand how the products are used. These analytics are not linked to any patient data. On this website we use Google Analytics; see the Cookie Policy.
For security we record sign-in events, the device and browser used, and approximate location derived from the network address, so that you and your organisation’s administrators can approve devices and see active sessions.
2. Patient data
We do not retain patient-identifiable information or final clinical reports on our servers. Audio submitted for transcription is processed in transit using encrypted connections and discarded after the report is returned to your device. Live captions shown on screen while you speak are display-only: they are never stored and never billed. We do not use patient content to train AI models. We do not store, index or review clinical reports.
The clinician using the services is responsible for ensuring that their use is consistent with their institution’s data governance policies and their patients’ consent.
3. Sending reports to your own systems
The services offer three ways to move a finished report: copying it to your clipboard, dictating directly into a field in your browser through the extension, and, for organisations that enable it, filing the report into your own records system over standard healthcare interfaces (HL7 FHIR, SMART on FHIR, or a local agent for on-premise systems).
In every case the report goes to you or to a system you control. We do not keep a copy. Where an organisation files into its own records system, we record only that a report was sent and when, so an administrator has an audit trail. That record never contains the clinical content.
4. How we use data
We use account information to operate and improve the services, communicate with you about them, and respond to support requests. We use anonymous analytics to identify usability issues and prioritise improvements. We do not sell your data to any third party.
5. Storage and retention
Account data is stored on servers located in jurisdictions with adequate data protection standards. We retain account information for as long as your account is active or as required to comply with legal obligations.
You can delete your account yourself, from your profile in the app. Doing so closes it immediately, signs you out on every device, and schedules the account for permanent removal after 30 days. Within that window you can restore it using the link in the email we send you. After it, your name, email address, phone number and profile picture are permanently erased.
Two things deliberately survive. Records we are required to keep, such as payment and transaction history, remain but are no longer linked to a named person. Security and administrative logs also remain, because a record of what happened on an account is what protects the people whose data it touched. Neither contains clinical content, because we never held any.
Once you delete your account we stop emailing you. We keep a one-way fingerprint of your address, not the address itself, for the sole purpose of ensuring nothing is ever sent to it again. See how to delete your account and data.
6. Help and feedback
When you report a problem from inside an app we receive what you wrote, your app version, your device or browser, and your account details, so we can reproduce it without asking you for them. Any file you attach is scanned before anyone can open it.
Please do not include patient-identifiable information in a support message or attachment. We do not need it, and unlike your reports, a support message is stored so a person can reply to it.
7. Third-party services
We use a limited set of third-party processors to run the services. Each is bound by its own privacy policy and is selected to minimise data exposure:
- AI transcription and language providers, which receive audio to transcribe and return the draft; audio is not retained after processing
- Payment processing, which handles card and bank payments and receives your name, email address and the amount, never your reports
- Email delivery, for receipts, account notices and two-factor codes
- Hosting and infrastructure providers
- Google Analytics on this website only, as described in the Cookie Policy
We do not embed advertising pixels or social media widgets in the applications.
8. Organisation accounts
Where your account belongs to a hospital, practice, group or department, an administrator there can see your name, email address and specialty, how much of the shared credit pool you have used, the devices you have signed in from, and, if the organisation files reports into its own records system, that a report was filed and when.
An administrator cannot see your reports, your recordings or your dictation. There is nothing to show them: we do not hold that content.
If you leave the organisation, your account becomes an individual one and stops being billed to them. Your templates stay with you.
9. The browser extension
The UnityPulse Dictation extension reads and writes only the field you dictate into, on the page you are on, when you ask it to. It does not read pages in the background and does not send page content to us. Your session, settings, templates and interrupted drafts are kept in your browser’s extension storage. The browser extension privacy notice describes this in full.
10. Your rights
Under the NDPR and applicable law, you have the right to access, correct or delete personal information we hold about you. You may also object to certain processing or request a restriction. To exercise any of these rights, contact us at the address below. You may also lodge a complaint with the Nigeria Data Protection Commission.
11. Security
All data in transit is encrypted using TLS 1.2 or higher. Access to our systems is restricted to authorised personnel. Two-factor authentication and device approval are available on every account. We conduct regular security reviews. See our Security and Data Handling page for more detail.
12. Children
The services are professional tools for healthcare practitioners and the institutions they work in. We do not knowingly collect information from individuals under 18. If you believe a minor has provided us with personal data, contact us and we will remove it promptly.
13. Changes to this policy
We may update this policy from time to time. We will notify registered users of material changes by email or through an in-app notice. The date at the top of this page reflects when this version was last revised.
14. Contact
For privacy-related enquiries, contact us at hello@unitypulse.io or through the contact page. Unitypulse, Nigeria.