Privacy, answered plainly.
Last updated: October 10, 2026
Presto was built by a physician who refused to put a microphone in his consulting room. The entire product is designed around a simple idea: the less information we hold, the less can ever go wrong with it. This page says what that means in practice, in plain language.
Patient information: we're built not to keep it
Presto does not record your consultations. There is no ambient listening, ever. You type or dictate your own clinical shorthand — a professional summary in your words — and Presto writes the letter from that.
You are instructed, in the product itself, to keep your shorthand de-identified: no patient names, health-card numbers, or other direct identifiers. The letter comes back with placeholders for anything identifying, which you complete inside your own EMR.
When you generate a letter, your shorthand travels from your browser to our server and on to our AI provider, the letter travels back, and that is the end of it: we do not store your shorthand or your letters on our servers after the request completes. There is no server-side archive of your clinical documents to breach, subpoena, or leak. Your letters live where they belong — in your EMR, under your custodianship.
Under Ontario's health-privacy law (PHIPA), you remain the health information custodian. Presto is a documentation tool acting on the de-identified instructions you give it; every document requires your review and signature before clinical use.
Dictation
In the Presto app, dictation happens on your own computer or phone. The first time you press Dictate, the app downloads its speech model (about 80 MB to 1.6 GB, depending on your device) from Presto's own site and keeps it in your browser. From then on your voice is turned into text on your device: the recording never leaves it, and the app holds back its own background traffic (sign-in renewals, usage counts, update checks) until you stop dictating. The words you dictate travel exactly as typed words do — only when you press Generate. If the model can't run on your device, dictation is simply unavailable; the app never switches to an online speech service.
In the Presto Chrome extension, dictation uses your browser's own speech service (in Chrome, Google's), under that provider's terms — which is one more reason the product asks you to dictate de-identified wording only. If you prefer that nothing leave your keyboard, type instead: dictation is always optional.
What we do collect — about you, not your patients
- Your account: your email address, your password (kept only as a one-way code, never the password itself), your subscription tier and status, and your sign-in sessions, including when you last used Presto.
- Your free trial: your email address, display name and timezone; the dates of your trial; which of our links or buttons brought you, and any plan you picked on our website; a count of letters written (never their content); which devices you have signed in on; and your Stripe customer reference, once one has been made (see Stripe, below).
- Usage counts: how many letters your account generated in a billing period — a number, not the letters — so allowances and the usage meter work.
- How the app is used: the Presto app counts its own use, on our own systems — when it is opened (and from which site), signed in to, or used to try the demo; each letter's type, how long it took to write and how many words it has (never the words themselves); when a letter is copied; whether the finished-letter check found blanks still to fill (how many, never what); how long dictation ran and which speech model was used; error messages from the app's own code; time spent in the app; and the country and region, device type, operating system, browser, language and rough window size. When you're signed in, each event carries a one-way code made from your account — not your email or name — so we can count use per account. None of it contains your shorthand or a letter. These counts are kept for 400 days and shared with no one. Browsers that send a Do-Not-Track or Global Privacy Control signal are not counted. The Chrome extension sends none of these.
- Billing: handled by Stripe. Your card number goes directly to Stripe and never touches our servers; we see the subscription status and receipts, not your card. Stripe's checkout also asks for your billing address — at least your country and postal code — so it can add the right sales tax (GST/HST) for your province; Stripe keeps it with your customer record so renewals are taxed the same way. We don't copy it into Presto's own records.
- Style samples, if you provide them: if you share example letters to teach Presto your writing style, they are processed to build your style profile. Share only de-identified examples.
- Support email: if you write to us, we keep the correspondence so we can help you.
- Settings on your device: most of your preferences, your signature block, and drafts are stored locally in your own browser, not on our servers. Your screen-lock choice, your writing-style profile and the shorthand defaults Presto learns from your answers (preferences and counts, never patient details) are kept with your account.
Who processes data for us
We keep the list short, and each provider only sees what its job requires:
- Anthropic — the AI that writes the letters. Your shorthand and the generated letter pass through their API to produce your document. Under the commercial terms we use, this data is not used to train their models.
- Cloudflare — hosts this website, the Presto app, and the server that relays generation requests.
- Stripe — payments and subscriptions. It receives your email address, your name and our reference for your account when you first open the plan picker in the app, or when we make a resident's checkout link for you; at checkout you give it your card details and billing address directly.
- Email providers — sign-in codes, account and billing messages, a short series of up to five emails during a free trial (each with a link to stop them), and our support mailbox.
This website
The marketing site you're reading sets no cookies of its own and uses no third-party analytics or ad trackers. We count visits ourselves, on our own systems: which page was viewed, roughly how long it was read and how far down, which buttons were used, the site or campaign link the visitor came from, and the visitor's country and region, device type, operating system, browser, language and rough window size. Visitors are counted by a code made from a daily-changing key, the network address and the browser type, which is discarded every day; the network address itself is never stored, the counting stores nothing on your device, and nothing is shared with anyone. Browsers that send a Do-Not-Track or Global Privacy Control signal are not counted at all. One exception, plainly stated: if you use the live demo on our challenge page (prestoscribe.com/15), that page sets a single cookie that counts your three attempts for the day — a day and a number, nothing about you — and it expires after a day. If you click "Start free trial," you go to the Presto app (app.prestoscribe.com). It receives the email address you type and your timezone (from your browser, or else estimated from your network), so it can send you a sign-in code and start your fourteen days. It also notes which button you used and any plan you picked on our pricing page. Like any website, it sees your network address: it keeps that address for about an hour to limit how many codes are sent, and a keyed one-way code made from it for three days to limit new trials from one network. No card is asked for. Choosing a paid plan inside the app opens Stripe's checkout, which operates under Stripe's own privacy policy.
Once you have used the Presto app, it sets one small cookie on prestoscribe.com holding only your trial's end date (or, if you chose a plan during the trial, the date of your first charge) or whether you are on a plan — never your name, email or any identifier. It expires a year after you last used the app and is removed when you sign out. This site reads it only to show, in place of the email field, a button back into your trial with its days left, "Open Presto" or "Pick a plan." The app also keeps two cookies of its own on app.prestoscribe.com, which this site cannot read: your sign-in session (30 days from your last use) and a code that lets it recognise this browser (400 days).
The Presto Chrome extension
If you use the Presto extension with OSCAR, it uses the same account as the app and sends your shorthand to our server in the same way. It only writes the finished letter into your EMR, where you ask it to: it never reads, copies or sends the contents of any web page, including your EMR. Its settings are kept in your own browser. Its dictation is described above.
How long we keep things
- Clinical content (shorthand, letters): not stored after your request completes — there is nothing to retain.
- Account and billing records: for as long as you have an account, and afterwards only as long as tax and business-record laws require.
- Ended free trials: if you never choose a plan, your account and its settings are deleted twelve months after your trial ends, or twelve months after you last signed in if that is later. The Stripe customer record made when you opened the plan picker is deleted with it, as long as it holds no subscription or invoice. The free-trial code below is kept.
- Free-trial code: the keyed one-way code made from your email address (never the address itself), with the date your trial began, is kept permanently — even if your account is deleted — so the same address never gets a second free trial.
- "Stop these emails" list: if you stop our trial or marketing emails, a keyed one-way code made from your email address (never the address itself) is kept permanently — even if your account is deleted — so we never send you those emails again.
- Support correspondence: kept while it's useful for helping you, then deleted in the ordinary course.
Security
Everything travels over encrypted connections (HTTPS). Secrets and keys are stored in managed, encrypted infrastructure. And the deepest protection is architectural: a system that doesn't hold patient records can't lose them.
Your choices and rights
You can ask us at any time what we hold about you, ask us to correct it, or ask us to delete your account and its records (billing records we're legally required to keep, and the free-trial code and the stop list above, excepted). Email [email protected] — it's read by the physician who built the product, and Canadian privacy law (PIPEDA) backs these rights.
Changes
If this policy changes in any meaningful way, we'll say so plainly — on this page and, for material changes, by email to account holders. The date at the top always tells you the current version.
Contact
Presto is operated by Barnufa Innovations Inc. of Mississauga, Ontario, Canada — founded and run by Dr. W. Ahmad Thiryayi. Questions about privacy — or anything — go to [email protected].