Privacy policy
Effective date: 14 August 2026
Last updated: 14 August 2026
Samuel Suite (“we”, “us”) is an Australian business. We provide repertorisation and practice management software for qualified homeopaths and students.
We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. This policy explains what we collect, why, and what your rights are — in plain language, because you’re busy and we want this to be easy.
Contact for anything in this policy: hello@samuelsuite.com
The two kinds of information we hold
1. Information about you (the practitioner). You give this to us directly when you create an account and use the service.
2. Information about your clients. You enter this into your case records. Your clients are your clients — you hold the treating relationship and the consents that go with it. We store and process their information on your instructions so the service works, and we access it only where necessary to operate, secure, and support the service. We treat everything inside a case record as health information — the most protected category under Australian privacy law — regardless of what it contains.
What we collect
About you:
- Account details — email address and two-factor authentication settings. Your password is stored only as a cryptographic hash; we cannot see it.
- Rubric flags and feedback you submit about repertory content.
- Security logs — sign-in events and IP addresses, kept for security purposes.
- Calendar connection (optional). If you choose to connect your Google Calendar, we access it on a read-only basis to display your schedule inside the app. We read event details (times and titles) to show them to you, and we store a secure connection token, encrypted, so the connection persists. We never add, change, or delete anything in your calendar. You can disconnect at any time in settings, which revokes our access.
- Support correspondence if you contact us.
We do not currently take payments through the app. If we introduce subscriptions, we will update this policy first.
About your clients (entered by you):
- Case narratives — free-text intake notes, which may contain health information.
- Rubric selections, remedy results, case notes, and follow-up records.
- Appointment records you create — date, time, and the case they relate to.
We collect no information about your clients directly, and we have no relationship with them.
How we use information
- To provide and operate the service — storing your cases, running repertorisation, showing your results back to you.
- To generate AI-assisted suggestions (see the next section).
- To display your connected calendar and your clinic appointments together, if you connect a calendar.
- To send you appointment emails (with add-to-calendar attachments) when you create or change an appointment.
- To keep the service secure and investigate suspicious activity.
- To respond when you contact us for support.
- To meet our legal obligations.
We do not sell personal information. We do not use it for advertising. We do not currently use case data to train AI models — see Case contributions below for how that may change, and only ever with consent.
AI processing — what it is and what it isn’t
When you use repertorisation features, relevant case content is sent to our AI provider, Anthropic, to generate suggested rubrics and remedy rankings.
What the AI actually does: it matches your everyday case language to rubrics in our repertory — the classical book language. Its suggestions are drawn from that repertory content, not generated from the AI’s general knowledge, and it does not search the internet. Remedy rankings are calculated by our software from the repertory’s own gradings.
Three things to be clear about:
- AI output is repertorisation assistance only. It is information retrieval and suggestion — it is not a diagnosis, not clinical advice, and not a treatment recommendation. You remain fully responsible for all clinical decisions.
- Anthropic processes this content as our service provider, on our instructions, to return results to you.
- Under our agreement with Anthropic, content sent through the service is not used to train Anthropic’s models.
Case contributions (de-identified)
We are building a program where practitioners can contribute de-identified cases to improve repertorisation for every practitioner. How it works:
- Optional, per case. A tick box on each case — never pre-ticked, never required to save your case, never bundled with anything else.
- You confirm you have your client’s consent to contribute the case in de-identified form.
- You can untick it at any time before the case is contributed. Once a case has been contributed, the contribution is irrevocable — it has been de-identified and merged into an aggregate dataset and can no longer be separated or traced back to any individual.
- De-identification removes names, contact details, and identifying particulars before any use.
The contribution program has not yet commenced. Consent is collected now, at case intake; contributed data will only be used once the program begins, and this policy will be updated when it does.
Who we share information with
We share information only with the service providers that run the platform:
| Provider | What they do | Where |
|---|---|---|
| Supabase | Database and authentication | Sydney, Australia (ap-southeast-2) |
| Netlify | Web hosting and API delivery | United States (Ohio) |
| Anthropic | AI processing | United States |
| Resend | Account, invite and appointment emails | Japan (Tokyo) |
| Calendar display — only if you connect your Google Calendar | United States |
Each provider is bound by contract to handle information securely and only for the purpose of providing their service to us.
Beyond that, we disclose personal information only if required by law (for example, a court order), and we will tell you if we lawfully can.
We never sell personal information. We never share it for marketing.
Overseas disclosure
Your data’s primary home is Australia — our database and authentication run in Sydney. Some processing happens outside Australia: web hosting and AI processing occur in the United States, calendar display (if you connect Google Calendar) involves Google services in the United States, and account emails are dispatched via infrastructure in Japan. Emails we send never contain case content; appointment emails carry the date, time, and a case reference only. We take reasonable steps to ensure overseas providers handle personal information consistently with the Australian Privacy Principles, including contractual protections and security requirements.
How we keep it secure
- Two-factor authentication is mandatory for every account — no exceptions.
- Encryption in transit and at rest.
- Every practitioner’s data is scoped to their own account: all case data is tied to your authenticated, two-factor-verified login, and every server request is filtered to your account before any record is returned or changed.
- Sign-in and authentication activity is logged for security monitoring.
- Calendar connection tokens are stored encrypted, separately from case data.
- Daily backups, with restore procedures we have actually tested.
- Access to production systems on a least-privilege basis.
No system is perfectly secure, and we won’t pretend otherwise. We design so that no single failure — including a stolen password — is enough to expose your data.
Retention and deletion
- We keep your information while your account is active.
- Deletion: email hello@samuelsuite.com and we will delete your account and case records from live systems within 30 days. Before deletion, we will prompt you to export your records — you likely have professional record-keeping obligations to your clients that survive your use of our software, and those are yours to meet.
- Deleted data can persist in encrypted backups for up to 7 days before rolling off permanently.
- Disconnecting your calendar deletes the stored connection token.
- Contributed de-identified cases are not deleted — they are irrevocable, no longer identify anyone, and cannot be extracted from the aggregate dataset. Once contributed, a case has been stripped of identifiers and merged with others — there is nothing left that tells us which data came from which case or client, so there is nothing we can locate to delete.
Access and correction
- You can ask for a copy of the personal information we hold about you, or ask us to correct it: hello@samuelsuite.com. We respond within 30 days.
- If one of your clients wants access to or correction of their health information, they should contact you — you hold the treating relationship and the record. We will assist you in meeting that request.
Data breaches
We comply with the Notifiable Data Breaches scheme. If a breach occurs that is likely to result in serious harm, we will act promptly to contain it, assess it, and notify affected individuals and the Office of the Australian Information Commissioner as required.
Complaints
If you think we’ve mishandled your personal information, email hello@samuelsuite.com. We will acknowledge your complaint promptly and respond within 30 days.
If you’re not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).
Practitioners outside Australia
The service is operated from Australia and your data is primarily stored in Australia, under this policy and Australian privacy law. If you practise outside Australia, you are responsible for meeting any local obligations that apply to your clients’ information — including whether you may lawfully store client health records with an Australian provider. Contact us if you have questions.
Changes to this policy
We’ll update this policy as the service evolves, and note the date of the latest version above. Material changes will be notified in the app or by email before they take effect.
Contact
Samuel Suite
hello@samuelsuite.com