Privacy and security are our number one priority, and we've built this into every part of the Lyrebird Health platform. Data is processed and stored within the same region it originates from - for example, UK data is stored in the UK, and Australian data is stored in Australia - and is never transferred outside that region. Our practices are designed to align with the applicable data protection law for each region we operate in, including the Australian Privacy Act 1988, UK GDPR, and HIPAA (US).
A brief overview of how we keep your information secure:
We perform all transcription in real time, on servers located in your region, so audio is turned into text during the consult and is never permanently stored. By the time you finish a consult, the audio has already been transcribed and discarded - it is never sent outside your region or made accessible to a third party.
Will my data be used to train AI models? No. In our Terms of Service (Clause 6.8), we guarantee that Lyrebird will never use your customer data to train or fine-tune any AI models. This commitment is absolute and extends contractually to all of our third-party service providers. Your data remains your own and is not used as a resource for training general-purpose AI.
How do I know which third parties have access to my data? A comprehensive, centralised list of every third-party service we engage - including what they do and where they're located - is maintained in the Sub-Processors section of our Trust Centre.
Saved documents are encrypted at rest (AES-256) and in transit (TLS 1.3), stored on regional AWS infrastructure. Documents are retained for 7 days by default, then permanently deleted - this can be reduced to 24 hours or extended up to 6 months.
For the full, current detail on our certifications, security posture, and sub-processors, see our Trust Centre - our source of truth for all privacy and security information.
Medicolegal Assurance
Lyrebird has been designed in collaboration with Medical Indemnity Organisations, and we worked with MDA National on their advice and support for using AI tools in consultations, which is another excellent resource for practitioners.
Clinicians must obtain patient consent before any use of Lyrebird during a consultation. To make this second nature, we prompt for consent before each consult and store the time it was obtained.
Every day, Lyrebird gets used in over a thousand real world consults. Over 99.5% of patients are consenting the first time. In addition to verbal consent, you can also obtain consent in written form through your practice registration form.
We have also made an A4 privacy printout for you to place in your practice that patients can scan to find out in depth information about how we keep their data secure on our data storage and privacy page.
Click here to create a custom A4 privacy printout for your clinic
Have any questions?
We're here to help if you have any questions at all. Don't hesitate to reach out to our privacy/security team here [email protected]
Alternatively, click the blue widget on the right for an instant response.
See these pages for more info:

