Dr. Filler

Privacy policy

Last updated: 3 October 2026

This English text is a translation for convenience. If it differs from the Lithuanian version, the Lithuanian version applies. Lithuanian version

The key point: Our architecture follows the principle of data minimisation. The audio recordings you upload and the texts generated from them are not stored on our servers – the content is processed in real time and removed from working memory once processing is finished. The only exception is the text of a conversation recorded with the phone app: it waits on the server until you take it and is erased after 72 hours at the latest (see section 2.6). This exception applies only when you record with the phone. If you do not use the phone app, none of your content – neither audio nor text – is stored on our servers.

1. Introduction

Dr. Filler (“we”, “our” or “the Service”) is committed to protecting your privacy and to processing data in line with the principles of the General Data Protection Regulation (GDPR). This Privacy Policy explains what information we collect, how we use it and what rights you have when you use our browser extension and phone app.

The Service is provided by Abba group, MB (company code 307518144), Lithuania.

2. Information we collect

We collect only the minimum amount of data the Service needs to work.

2.1. Account information

Email and authentication: your email address and sign-in details are handled by Firebase Authentication.

Signing in with Google: if you sign in with a Google account, we receive from Google only your name and your email address (with confirmation that the address is yours). We do not see your Google password and have no access to other data in your Google account.

Credits and settings: our systems keep the number of consultations (credits) you have received, used and have left, and the Service settings you have chosen (for example, your specialty).

2.2. Content you submit for processing

To generate the text of medical forms, the extension sends, over an encrypted connection, what you provide: the description of the visit, the audio recording of your dictation or of the conversation with the patient and its text, and earlier extracts and other documents you add from the pages of the clinic’s information system (as text or PDF). Such content may include health information – symptoms, diagnoses, the course of an illness, test results. It is used only to carry out your request and is not stored on our servers (see section 2.5).

The extension uses the content of the clinic system’s pages only to perform the functions you choose (for example “Add to Dr. Filler”, the history summary, filling in a form). We do not collect your browsing history or the content of other websites.

2.3. Payment information

We never see or store your card number or other sensitive payment details.

All payments are processed directly by Stripe. We receive only the confirmation of a successful payment and the purchase details: the pack bought, the amount paid or refunded, the date of the payment and the kind of payment method (for example, card).

2.4. Technical usage records

For service quality, accounting and the prevention of abuse we record the technical parameters of requests: file size, recording length, amount of text, credits used, the model used and timestamps. These records contain none of the content itself – neither audio nor text.

2.5. Information we do not store

Audio recordings: processed in real time and not archived on our servers.

Generated texts: the final result is returned to you and is not stored in our databases.

Local storage on your device: so that work is not lost, each patient’s visit description, history and generated text are kept temporarily in your browser’s local storage (on your computer) for up to 72 hours, and the last dictation recording for up to 12 hours so that it can be sent again. After that they are deleted automatically, and all of them are removed when the extension is uninstalled. Local storage is not synchronised with our servers.

Phone app: the text of its recordings waits on the server for up to 72 hours – see section 2.6.

2.6. Phone app

With the Dr. Filler phone app a doctor can record the conversation with a patient away from the computer (for example, on a ward) and later put its text into the patient’s form with the extension. The app is optional: you can use the extension without it, and then none of your content is stored on the server. The rules below apply only to recordings made with the phone.

  • Recording: the app records only a conversation whose recording the doctor starts.
  • Audio recording: sent over an encrypted connection (HTTPS) to the Dr. Filler server, which turns it into text using the Soniox speech-recognition service (see section 4). The audio is not stored: the server holds it only in working memory until it is passed on for recognition, and the recognition service deletes it as soon as the text has been received.
  • Text: waits on the server until the doctor takes it in the extension, and is kept for no longer than 72 hours from when the recording was received – also after it has been put into a form, so that it can be put in again. After that the text is erased. For about 30 more days only a technical record without audio or text remains (code, time, length), so that the same recording, if sent again, is not billed a second time.
  • On the phone: the audio is deleted once the text is ready. The phone itself never receives or shows the text. A note the doctor types on the phone (for example, the patient’s name) is never sent anywhere and stays only on the phone.
  • Sent with the recording are its 4-digit code, its start time and its length – the doctor uses them to recognise the recording on the computer.
  • When a phone is linked, we store the phone model, the platform (iOS or Android) and the app version, as well as when the phone was linked and when it was last in contact – so that the doctor can see the list of their phones in the extension.
  • Analytics and advertising: the app contains no analytics or advertising tools. On Android phones the QR code is read by Google ML Kit on the phone itself: the camera image is not sent anywhere, but Google may receive technical data about how this tool works (device and app information, performance metrics). On iPhones the QR code is read by the phone’s own system.
  • Deletion: you can delete a recording in the app – its text on the server is then erased at once. A phone can be unlinked in two ways: in the extension (Nustatymai → Telefonas → “Atjungti”) – the phone’s data on the server is then deleted; in the app (Nustatymai → “Atjungti telefoną”) – the sign-in key is then deleted from the phone. When an account is deleted, all of its phone and recording data is deleted too.

3. How we use your information

We use the information we collect for these purposes and on these legal grounds:

  • To provide the Service (performance of a contract): to process the content you submit and return the result.
  • For payments (performance of a contract): to update your credit balance automatically after a payment.
  • For communication (legitimate interest): to contact you about important matters or to answer your requests.
  • For security (legitimate interest): to prevent fraud and abuse of the system.

4. Recipients and processors of data

To provide the Service we use a limited number of carefully selected service providers, who process data only on our instructions and only to carry out a specific request:

  • Providers of speech-recognition and text-processing technology: the content you submit is sent over an encrypted connection to international cloud technology providers (automatic speech recognition and artificial-intelligence text-processing services; headquartered in the USA) only to carry out your specific request. Under the terms of service that apply to us, content sent through the programming interface (API) is not used to train their models and may be stored only for a limited time and only for security and abuse-prevention purposes. Transfers of data outside the European Economic Area are based on the standard contractual clauses approved by the European Commission and/or the mechanisms of the EU–US Data Privacy Framework. We will provide the current list of the providers we use on request, at the email address given at the end of this policy.
  • Stripe: secure payment processing. Your financial data is kept in Stripe’s systems and does not reach us.
  • Firebase: secure user authentication (including signing in with a Google account), storage of account data and of the text of phone app recordings (for up to 72 hours, see section 2.6).

5. Data minimisation when using the Service

The Service is a documentation aid for professionals. Its functions do not need direct personal identifiers, so please follow the principle of data minimisation and avoid them in the content you submit:

  • Do not mention first names and surnames.
  • Do not mention personal identification numbers or exact dates of birth.
  • Avoid specific details that make a person identifiable (an exact place, an exact time, the names of other people).

Describe symptoms, diagnoses and the course of the illness, giving time relatively (for example “a week ago”) rather than absolutely. When you use the Service in your professional work, make sure that submitting the data complies with the internal rules of your institution and with the law that applies to you.

6. Roles under the GDPR

For your account data (email, credits and purchase information) we act as the data controller. When you use the Service in your professional work and submit content for processing, you or your institution decide what data is submitted, and we act as a data processor: we process the content only on your instructions, only to perform the functions of the Service, and we do not store it, except for the temporary storage of the text of phone recordings described in section 2.6. For institutions that need a separate data processing agreement, we will provide one on request.

7. Your rights

Under the GDPR you have the right:

  • To access the data we process about you and to receive a copy of it.
  • To ask for inaccurate data to be corrected.
  • To ask for your account and the data related to it to be deleted.
  • To restrict the processing of data or to object to it, as far as the law allows.
  • To receive the data you have provided in a structured, commonly used format.
  • To lodge a complaint with the State Data Protection Inspectorate of Lithuania (vdai.lrv.lt) if you believe your rights have been infringed.

8. How long data is kept

We do not store content (audio recordings and generated texts), so no retention periods apply to it. The exception is the text of phone app recordings: it is erased after 72 hours at the latest, and at once when the recording is deleted (see section 2.6). Account data is kept for as long as you have an active account; when the account is deleted, the data is removed, except for what we must keep by law (for example, payment accounting records). Technical usage records are kept for a limited time for statistics and security.

9. Security

All data is transferred over an encrypted TLS connection. We apply access control, data minimisation and other technical and organisational measures that match the nature of the data processed and the risks.

10. Children’s privacy

Our Service is intended only for professionals and for people aged 18 and over. We do not knowingly collect information about minors.

11. Changes to this policy

We may update this Privacy Policy. We will tell you about essential changes by updating the date at the top of this page or by sending a notice by email.

12. Contact us

If you have questions about privacy or data security, or wish to exercise your rights, contact us through the help section of the extension or by email: pagalba@drfiller.lt