Common questions
Where do my patient names actually live?
Scrambled on the app’s servers, with a readable working copy on your phone. The servers can’t read the names. See Where your data lives.
Can the people running the app read my patient names?
No. Even with full access to the servers, the patient names are scrambled with a key derived from your backup password, which only your phone sees.
What can the people running the app see?
Procedure, date, hospital, side, complications, notes. Everything except the patient name, the MRN, and your earnings figures — those three are scrambled on your phone before they leave it. Plus your account email, display name, specialty, and — if you’ve set them — your gender and how you’d like to be addressed.
Can the developers see my patients or my earnings?
No. Your patients’ names, their MRNs, and your earnings figures are all scrambled on your phone — with a key built from your backup password — before they ever leave it. The servers only ever hold unreadable bytes; there is nothing in them for the people running the app to read. Only your own phone, once you’ve unlocked it, can turn those bytes back into a name, an MRN, or a money figure. The server has zero knowledge of any of it.
What if I forget my backup password?
If Face ID / fingerprint still works on one of your devices, nothing is lost: unlock with it, then use Settings → Security → Change backup password → Forgot your backup password? to set a new one — no old password needed. Failing that, any device where the vault is still unlocked lets you change the password from Settings → Security — your data stays readable. Only if you have neither will you have to reset your vault, which keeps your cases but loses the patient names on them. See Your backup password.
What’s a “Lost in reset” label?
A case where the scrambled patient name on the servers can’t be unlocked by your current key — usually because you reset your vault at some point. Tap the label to re-enter the name, or to delete the case. The app fixes most of these on its own when your phone still has a readable copy.
A device is showing blank or old patient names — what happened?
That device is holding an out-of-date key (common on an older phone or one you signed in on early). The names are safe; the device just needs the current key. The app usually offers a one-tap fix on the unlock screen — or go to Settings → Backup & recovery → Resync. There’s a single Resync button now; it works out what’s out of step and fixes it for you. See Using a new or lost phone.
Why did the auto-fill change “C-arm” to “fluoroscopy”?
The app normalises informal terms into standard procedure language so case statistics stay consistent across surgeons. If you don’t like the change, edit the case and put your preferred wording back — the auto-fill won’t overwrite anything you’ve set manually.
Why did the auto-fill miss medical terms in my dictation?
By default, transcription is done on your phone — the audio never leaves it — and the model that does it is smaller than the one that analyses the text, so some uncommon terms come out wrong. Read the transcript before tapping Capture and edit anything that needs fixing. If you regularly hit terms it mis-hears, you can turn on the optional higher-accuracy cloud mode (see below).
If I search, does it find all my cases?
Yes. Search looks across every case you’ve logged, not just the ones scrolled into view. Type a name, an MRN, a procedure, or a hospital, and any matching case will surface — even ones from years ago that you haven’t scrolled to.
Why can’t I change the MRN on a case?
The MRN is the thread that ties the case back to the hospital’s own records — it’s how your case lines up with the hospital EMR, your eLogbook export, and the settlement sheet when it arrives. If the MRN could drift, those links would break. So the MRN doesn’t get edited casually inline: you can always add or correct the patient’s name there. If an MRN went in wrong, use the guided Correct the MRN flow — it moves the case to the right number while keeping everything else intact. See Capturing cases.
Can I import old cases from a spreadsheet?
Yes. Use the Import a spreadsheet link on your case list to bring in a backlog — the app reads your hospital sheet, shows you a preview of what it found, and only writes the cases once you confirm. See Capturing cases.
Re-uploading the same sheet is safe — you won’t get duplicates. If you import a sheet you’ve already imported (or a newer version with extra rows), the app recognises the cases already on file and adds only the genuinely new ones. The matching uses a one-way code built from each case’s MRN — never the patient’s name, and nothing your phone has to decrypt — so it works even on a fresh device. Two genuine same-day operations on one patient still come through as two cases. (One thing it can’t catch: if the same patient appears under two different MRNs across sheets, that reads as two patients — there’s no reliable way to know they’re the same person from the numbers alone.)
Verification keeps working after the import. A case you imported before its hospital settlement sheet arrived stays unconfirmed for now, but the app re-checks your cases on every authoritative import — so older cases get confirmed automatically once their sheet lands. You can also tap Re-verify now under Settings → Backup & recovery to re-check everything on demand. This only ever upgrades a case to confirmed; it never undoes a confirmation. (No patient name or MRN ever leaves your device — the matching uses a one-way code the server can’t read back.)
How do I produce a logbook for credentialing or an interview?
Go to Settings → Backup & recovery. Two exports live there:
- Logbook summary — procedure counts, split into performed and assisted: the at-a-glance answer to “what is your operative experience?” for boards and interviews.
- Credentialing logbook — one row per case (date, MRN, age and sex, procedure, hospital, role, verification status) for a credentialing body to inspect. It contains no patient names — the MRN identifies the case, which keeps the document safe to hand over.
Pick the scope first — specialty (your own is preselected), hospital, and date range. Then either download a spreadsheet file (CSV), or open the printable report and use your browser’s print dialog to save it as a PDF. The printable report includes a signature line so a consultant or head of department can sign it off. Both documents are built entirely on your device — the servers play no part. See Where your data lives for what goes into each export.
What happens if I capture a case while offline?
The app queues your capture and sends it when the network comes back. The auto-fill (procedure, side, etc.) waits until you’re online.
How do I delete a case?
Open the case → tap the … menu → Delete. Type “DELETE” to confirm. The case stops showing up. If you delete by accident, email support — recovery is possible.
Why does the app ask for my gender?
It’s optional, and it’s used only to address you correctly — Mr or Ms in the UK. Everywhere else the title is Dr regardless, so you can leave it blank. If you’re a UK surgeon and haven’t set it, the app shows your name without a title rather than guess. Your gender is never shown to anyone else — not to colleagues you invite, not on any screen but your own profile.
Can I change what the app calls me?
Yes. The app addresses you the way colleagues in your country would — Dr Biswajit in India, Mr Dutta Baruah in the UK. If that default doesn’t sound like you, fill in “How should we address you?” on Settings → Profile: whatever you write there is used, word for word, everywhere the app addresses you. Formal documents are different — the credentialing logbook and case-summary exports always carry your full name.
How do I change my email?
Email [email protected] with your old and new addresses. There’s no self-service email change yet.
How do I close my account?
Email [email protected] and ask. Account closure includes a wipe of your case data.
Is anything sent to other companies’ AI services?
The text analysis (filling in procedure, side, role from your notes) goes to one AI provider. Voice transcription happens on your phone by default — no audio leaves it. The one exception is if you deliberately turn on the optional higher-accuracy cloud mode for a recording: then that recording’s audio (which can include a spoken patient name) goes to a contracted, healthcare-grade transcription service just for that dictation and is deleted straight after — nothing is kept. Magic-link emails go through one email-sending service. That’s all.
Should I turn on the higher-accuracy cloud transcription?
Only if the on-device transcription keeps mis-hearing your terms — heavy accent or dense sub-specialty vocabulary. It’s off by default, and the first time you switch it on you’re asked to agree to a plain-spoken consent. The tradeoff: your dictation is more accurate, but for a recording you mark as cloud, that one recording’s audio leaves your phone (see above) instead of staying on it. It goes to a healthcare-grade service under a signed data-protection agreement, is used only to produce the transcript, and is deleted immediately — nothing is stored. You can turn it back off at any time, and if a cloud transcription ever fails your recording falls straight back to on-device. When it’s off, nothing leaves your phone.
Where do I report a bug or request a feature?
Email [email protected]. Include a screenshot if you have one.
I’m locked out of the app — how do I get help?
Email [email protected]. The locked-vault screen also shows this as a link right next to the backup-password field. Because it’s a plain email, it works even from a fully locked or offline phone — nothing to install, no sign-in. Your message becomes a tracked report (logged and queued like in-app feedback), and you get a plain-language reply back at the address you wrote from once it’s resolved. It’s an ordinary email channel alongside the app — it never touches your backup password or your vault. See Using a new or lost phone.