Data we handle
BastCare handles the minimum information needed to provide an account, create a visit summary, deliver a share you request, and show whether those actions worked.
- Account: your Bast identity, sign-in state, and device/account identifiers.
- On your iPhone: temporary audio, the original transcript, your saved summary, sharing choices, and encryption keys.
- AI processing: a masked copy of transcript text sent over authenticated HTTPS to the selected AI provider when you create or regenerate a summary. The text may contain personal or health information from the conversation.
- Sharing: an encrypted copy of a summary only after you choose a CareTeam.
- Technical records: content-free times, status, app version, delivery, consent, security, token-count, and deletion results.
What Bast does not keep in server logs or storage
Audio stays on your iPhone until a summary is created successfully, then BastCare deletes it. The original transcript remains protected on the iPhone with the visit. Bast does not save or log transcript text on its servers.
Why we use data
We use information to provide features you request, secure accounts, create or regenerate summaries, deliver patient-directed shares, prevent abuse, diagnose content-free failures, and prove deletion. Bast does not sell health information or use visit content for advertising.
Retention and deletion
After a summary is saved successfully, BastCare deletes the visit audio. The original transcript and current summary stay protected on your iPhone until you delete the visit. Deleting a visit removes its transcript and summary; any exported copies remain outside BastCare’s control. Shared encrypted content remains available only while the share is active or until account deletion.
From Settings, you can remove BastCare data from one iPhone or delete your Bast account. Account deletion removes your Bast identity, active sessions, account-linked encrypted shares, CareTeam access, and the account’s local app data. Bast may retain only de-identified aggregate model token counts, a minimal content-free deletion event, and records required by law.
Security and service providers
BastCare uses authenticated HTTPS, account isolation, encrypted relay content, device-held keys, and least-privilege access. No internet service can promise perfect security.
Apple provides device speech and Sign in with Apple. Bast also uses named infrastructure, database, identity, deployment, and model-processing providers only for the purposes described here.
BastCare can use Anthropic or OpenAI. We select the model for the task and may change that selection as quality, reliability, speed, or resource needs change. Each request goes only to the provider selected for that request.
See the current BastCare service-provider and processor disclosure
Children, regional rights, changes, and contact
Depending on where you live, you may have rights to access, correct, export, restrict, object to, appeal, or delete personal information. Email us to make a privacy request. We may need to verify that the request concerns your account.
Material changes to vendors, purposes, retention, or visit-data flows require a new policy version and, where appropriate, a new choice in the app.
BastCare is not a medical device or medical advice. It does not diagnose, treat, monitor, predict, or recommend care. Do not use it for emergencies.
Contact: community@bast.ai
Bast, Inc.3700 Quebec St, Ste 195
Denver, CO 80207-1638
United States