นโยบายความเป็นส่วนตัว WellNote
อ่านตรงนี้ก่อน — สรุปสั้น ๆ
- WellNote คือสมุดสุขภาพส่วนตัว เก็บบันทึกการพบแพทย์ ยา การแพ้ยา และรูปเอกสารของคุณไว้ในบัญชีของคุณเอง
- ถ้าคุณกดให้ AI ช่วยสรุป ถามผู้ช่วย ถ่ายรูปยาให้อ่าน หรือให้ระบบจัดหมวดหมู่ข้อมูลที่คุณเพิ่มเข้ามา (รวมไฟล์ PDF) ข้อความ รูป หรือไฟล์นั้นจะถูกส่งออกไปนอกเซิร์ฟเวอร์ของเรา ไปยัง Google (Gemini) และถ้า Gemini ตอบไม่ได้ ระบบจะส่งข้อมูลชุดเดียวกันต่อไปยัง OpenAI โดยอัตโนมัติและไม่แจ้งบนหน้าจอ — อ่านรายละเอียดในข้อ 4 ก่อนใช้
- คุณไม่จำเป็นต้องใช้ AI เลยก็ได้ บันทึก แก้ไข ย้อนดูบันทึกเก่า เตือนกินยา และแบ่งปันให้ลูกหลาน ทำงานได้ครบโดยไม่ต้องส่งอะไรออกไปเลย (ช่องค้นหาบันทึกมีเฉพาะในเว็บแอป แอป Android ยังไม่มี)
- เรื่องเสียงพูดเปลี่ยนไปแล้วในเวอร์ชันนี้ และไม่เหมือนกันในสองแอป — เว็บแอป: เมื่อคุณกดไมค์ เสียงที่อัดได้จะถูกส่งผ่านเซิร์ฟเวอร์ของเราไปให้ Google (Gemini) ถอดเป็นข้อความ โดยเสียงอยู่ในหน่วยความจำระหว่างคำขอนั้นครั้งเดียว ไม่ถูกเขียนลงดิสก์ ไม่ถูกเก็บลงฐานข้อมูล และไม่ถูกเขียนลง log · แอป Android ที่ลงจาก Google Play: เสียงของคุณไม่เคยมาถึงเราเลย แต่ไปที่บริการถอดเสียงของเครื่องคุณเอง (ข้อ 3 และ 5 — และถ้าไม่ต้องการทั้งสองทาง ให้พิมพ์แทนการพูด)
- ลิงก์ QR ที่คุณสร้างให้ลูกหลาน จะเห็นเกือบทั้งหมดของบันทึกคุณ เลือกแบ่งเฉพาะบางเรื่องไม่ได้ (ข้อ 6)
- คุณลบบัญชีและข้อมูลทั้งหมดได้เองในแอป ลบแล้วกู้คืนไม่ได้ (ข้อ 11)
- ข้อจำกัดที่เราบอกตรง ๆ: ฐานข้อมูลไม่ได้เข้ารหัสขณะจัดเก็บ · ยังไม่มีปุ่มดาวน์โหลดข้อมูลของคุณ · ระบบไม่ลบบันทึกสุขภาพให้เองตามเวลา (ข้อ 7 และ 8)
1. เราคือใคร
WellNote พัฒนาและให้บริการโดย Cosyntec (“เรา”) เราเป็นผู้ควบคุมข้อมูลส่วนบุคคลตามพระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 (PDPA) สำหรับข้อมูลที่คุณบันทึกไว้ใน WellNote
ถ้ามีคำถาม ขอใช้สิทธิ หรือต้องการร้องเรียนเรื่องข้อมูลส่วนบุคคล ติดต่อเราได้ที่ contact@cosyntec.com
WellNote เป็นเครื่องมือช่วยจดบันทึก ไม่ใช่เครื่องมือวินิจฉัยหรือสั่งการรักษา อย่าเริ่มยา หยุดยา หรือปรับขนาดยาจากสิ่งที่แอปหรือ AI บอก ให้ปรึกษาแพทย์หรือเภสัชกรเสมอ
2. ข้อมูลที่เราเก็บ
ทั้งหมดนี้คือสิ่งที่คุณกรอกหรืออัปโหลดเข้ามาเอง และสิ่งที่ระบบสร้างขึ้นเพื่อให้แอปทำงานได้
ก. บัญชีและการเข้าสู่ระบบ
- อีเมล (เก็บเป็นตัวพิมพ์เล็กทั้งหมด ใช้เป็นชื่อผู้ใช้) และชื่อที่คุณกรอก
- รหัสผ่าน — เก็บเป็นค่าที่คำนวณทางเดียวด้วยวิธี scrypt ไม่ใช่ตัวรหัสผ่านจริง เราจึงอ่านหรือกู้คืนรหัสผ่านให้คุณไม่ได้
- ถ้าเข้าสู่ระบบด้วย Google: รหัสผู้ใช้ Google ของคุณ และลิงก์รูปโปรไฟล์จาก Google
- วันเวลาที่ยืนยันอีเมลสำเร็จ และวันเวลาที่เปลี่ยนรหัสผ่านครั้งล่าสุด
- สิทธิ์การใช้งานของบัญชี (ผู้ใช้ทั่วไป หรือผู้ดูแลระบบ) และสถานะว่าบัญชีถูกระงับหรือไม่
- โหมดการแสดงผลที่คุณเลือกไว้ ซึ่งมีสองแบบเท่านั้น คือ “พื้นฐาน” (ตัวใหญ่ ใช้ง่าย) และ “ขั้นสูง” (ข้อมูลแน่น)
- วันเวลาที่คุณกดยินยอมให้ส่งข้อมูลออกไปให้ AI และข้อความรุ่นของคำยินยอมที่คุณกดยอมรับ ซึ่งมีรายชื่อผู้ให้บริการที่ถูกแจ้งไว้ตอนนั้นอยู่ด้วย (เช่น “gemini+openai”) เก็บไว้เพื่อให้ระบบรู้ว่าคุณยินยอมกับข้อความรุ่นไหน ถ้าเราเพิ่มผู้รับรายใหม่ ค่านี้จะไม่ตรงอีกต่อไป และระบบจะถามคุณใหม่พร้อมบอกชื่อผู้รับรายใหม่ (ดูข้อ 4)
ข. โปรไฟล์สุขภาพ
- วันเกิด (หรือปีเกิด), เพศ, ส่วนสูง, น้ำหนัก, กรุ๊ปเลือด
- เบอร์โทรศัพท์, ที่อยู่ที่รถพยาบาลไปรับได้, สิทธิการรักษา (เช่น บัตรทอง ประกันสังคม ข้าราชการ)
- รายชื่อโรคประจำตัวและรายการแพ้ยาแบบย่อ ซึ่งระบบคัดลอกมาจากบัตรสุขภาพเพื่อให้หน้าแรกแสดงได้เร็ว
ค. บัตรสุขภาพ
- โรคประจำตัว: ชื่อโรค วันที่วินิจฉัย โรงพยาบาล ชื่อแพทย์ บันทึกเพิ่มเติม และสถานะว่ายังเป็นอยู่หรือหายแล้ว
- การแพ้: ชื่อยาหรือสารที่แพ้ อาการที่เคยเกิด ระดับความรุนแรง และบันทึกเพิ่มเติม
- การผ่าตัด: ชื่อการผ่าตัด วันที่ โรงพยาบาล ชื่อแพทย์ บันทึกเพิ่มเติม
- วัคซีน: ชื่อวัคซีน เข็มที่เท่าไร วันที่ฉีด โรงพยาบาล บันทึกเพิ่มเติม และวันนัดเข็มถัดไป
- ผู้ติดต่อฉุกเฉิน: ชื่อ ความเกี่ยวข้อง และเบอร์โทรศัพท์ของบุคคลอื่น ที่คุณกรอกไว้ให้เราติดต่อแทนคุณได้
- ระบบบันทึกด้วยว่ารายการไหน AI เป็นคนเสนอมาจากบันทึกไหน และคุณกดยืนยันเมื่อไร
ง. บันทึกการพบแพทย์และบันทึกการรับยา
- วันที่ โรงพยาบาล แผนก ชื่อแพทย์
- ข้อความถอดเสียงฉบับเต็ม ตามที่พูดหรือพิมพ์เข้ามา รวมทุกครั้งที่คุณกดเพิ่มข้อความเข้าไปในบันทึกเดิม พร้อมเวลาที่เพิ่ม
- วิธีที่บันทึก (พูด หรือ พิมพ์), การติ๊กว่า “แพทย์รับทราบ” พร้อมวันเวลาที่ติ๊ก
- อาการสำคัญ สรุปการพบแพทย์ คำแนะนำ บันทึกสุขภาพ และสถานะว่าเป็นร่างหรือเสร็จแล้ว
- ถ้าคนอื่นเป็นผู้บันทึกให้คุณผ่านลิงก์แบ่งปัน ระบบจะเก็บชื่อของคนคนนั้นไว้ในบันทึกด้วย (ถ้าเขาไม่พิมพ์ชื่อ จะใช้ป้ายชื่อที่คุณตั้งไว้ให้ลิงก์นั้น เช่น “ลูกสาว”) — นี่คือข้อมูลส่วนบุคคลของบุคคลที่สาม กรุณาบอกเขาก่อนส่งลิงก์ให้
- การวินิจฉัย: ชื่อโรค รหัส ICD-10 (ถ้ามี) และหมายเหตุ
- ยา: ชื่อ ขนาด รูปแบบ วิธีรับประทาน เวลาที่ต้องกิน วันเริ่ม–วันหยุด และตั้งเตือนไว้หรือไม่
- บันทึกการกินยารายมื้อ: วันที่ เวลา และคุณกดว่า “กินแล้ว” หรือ “ข้าม”
- การนัดหมาย: เรื่องที่นัด วันเวลา โรงพยาบาล แผนก หมายเหตุ และสถานะ
จ. ไฟล์ที่คุณอัปโหลด
- ไฟล์รูปหรือเอกสาร (JPEG, PNG, WebP, HEIC หรือ PDF ไม่เกิน 15 MB ต่อไฟล์) เช่น ใบผลแล็บ ฟิล์มเอกซเรย์ ใบสรุปการรักษา ซองยา
- ชื่อไฟล์เดิมจากเครื่องของคุณ ซึ่งบางครั้งมีข้อมูลทางการแพทย์อยู่ในชื่อไฟล์เอง (เช่น “ผลเลือด-เบาหวาน.pdf”) ชื่อนี้ถูกแสดงในแอปและถูกส่งให้ผู้ที่เปิดลิงก์แบ่งปันของคุณด้วย
- ชนิดไฟล์และขนาดไฟล์ และที่อยู่ของไฟล์บนเครื่องแม่ข่าย
- ป้ายประเภทของไฟล์ ซึ่งแอปเป็นผู้กำหนดให้เอง ไม่ใช่สิ่งที่คุณเลือก — ในแอปทั้งสองตัวไม่มีที่ไหนให้คุณเลือกประเภทไฟล์เลย ไฟล์ที่แนบจากหน้าบันทึกการพบแพทย์ถูกเก็บเป็น
documentส่วนรูปที่ถ่ายในหน้า “บันทึกการรับยา” ของเว็บแอปถูกเก็บเป็นphoto(แอป Android ส่งdocumentเสมอ) ค่านี้ไม่เคยถูกแสดงบนหน้าจอ และเครื่องแม่ข่ายรับค่านี้เป็นข้อความอิสระโดยไม่ได้ตรวจว่าเป็นค่าใด - ระบบมีช่องสำหรับทำเครื่องหมายว่าไฟล์ถูกเบลอหน้าแล้วหรือยัง แต่ยังไม่มีการเบลอหน้าจริงในระบบ ช่องนี้จึงเป็น "ไม่ได้เบลอ" เสมอ ไม่มีโค้ดส่วนไหนเขียนค่านี้เลย เราบอกไว้เพื่อไม่ให้เข้าใจว่ามีการเบลอให้
- ไฟล์ต้องผูกกับบันทึกการพบแพทย์ของคุณเสมอ ระบบจะตรวจว่าเป็นบันทึกของคุณจริงก่อนเขียนไฟล์ลงเครื่องแม่ข่าย
ฉ. ลิงก์แบ่งปัน (QR)
- ป้ายชื่อที่คุณตั้ง (เช่น “ลูกสาว” “หลานชาย”), สิทธิ์ว่าดูอย่างเดียวหรือช่วยเพิ่มบันทึกได้
- วันหมดอายุที่คุณตั้ง (ถ้าตั้ง), วันที่คุณกดยกเลิก, จำนวนครั้งที่ถูกเปิด และเปิดครั้งล่าสุดเมื่อไร
- ตัวลิงก์ (โทเค็น) ถูกเก็บไว้ในระบบตามที่เป็น ไม่ได้เก็บเป็นค่าแฮช ต่างจากลิงก์ยืนยันอีเมล/ตั้งรหัสผ่านใหม่ในข้อ ช. เพราะลิงก์แบ่งปันเป็นสิ่งที่คุณตั้งใจแจกให้คนอื่น และหน้าแบ่งปันต้องแสดง QR เดิมซ้ำได้ — ผู้ที่เข้าถึงฐานข้อมูลได้จึงอ่านลิงก์แบ่งปันของคุณได้ กดยกเลิกลิงก์ที่ไม่ใช้แล้วเสมอ
ช. ข้อมูลที่ระบบสร้างขึ้นเอง
- คิวอีเมลขาออก: ที่อยู่ผู้รับ หัวเรื่อง ชนิดข้อความ สถานะ จำนวนครั้งที่พยายามส่ง เวลาที่จะลองส่งครั้งถัดไป เวลาที่ส่งสำเร็จ และข้อความผิดพลาดจากผู้ให้บริการอีเมล (ตัดเหลือ 300 ตัวอักษร) — เนื้อความอีเมลทั้งแบบข้อความล้วนและแบบ HTML ถูกเข้ารหัสตั้งแต่วินาทีที่เข้าคิว และถูกลบทิ้งทั้งสองแบบทันทีที่ส่งสำเร็จหรือเลิกส่ง ลิงก์ยืนยัน/ตั้งรหัสผ่านใหม่จึงไม่ค้างอยู่ในระบบ
- โทเค็นยืนยันอีเมลและตั้งรหัสผ่านใหม่: เก็บเป็นค่าแฮชเท่านั้น ไม่ใช่ตัวลิงก์ พร้อมชนิดของโทเค็น วันหมดอายุ เวลาที่ถูกใช้ไปแล้ว และอีเมลที่ส่งไป
- วันเวลาที่สร้างและแก้ไขล่าสุดของทุกรายการที่กล่าวมา (เช่น บันทึก ยา นัดหมาย ไฟล์แนบ ลิงก์แบ่งปัน) เพื่อเรียงลำดับและตรวจสอบย้อนหลัง
- ค่าตั้งค่าของระบบที่ผู้ดูแลกำหนด (เช่น กุญแจของผู้ให้บริการ AI) เก็บอยู่ในตารางแยกต่างหาก ไม่มีข้อมูลของผู้ใช้อยู่ในนั้น ระบุไว้เพื่อให้รายการนี้ครบทุกตารางในฐานข้อมูล
- บันทึกความผิดพลาดของ AI: ชื่อผู้ให้บริการ ประเภทงาน ประเภทปัญหา รหัสผู้ใช้ที่พบปัญหา และข้อความผิดพลาดที่ผู้ให้บริการตอบกลับมา (ตัดเหลือ 300 ตัวอักษร) ซึ่งบางครั้งผู้ให้บริการสะท้อนข้อความที่เราส่งไปกลับมาด้วย จึงอาจมีเศษข้อความจากบันทึกของคุณติดมา ผู้ดูแลระบบเปิดดูรายการนี้ได้
- คิวรายงานเนื้อหา: เกิดขึ้นเฉพาะเมื่อคุณ (หรือผู้ถือลิงก์แบ่งปันของคุณ) กดปุ่ม “รายงาน” เก็บรหัสผู้ใช้ของคุณ ชนิดของรายงาน (คำตอบจาก AI หรือบันทึกที่มาจากลิงก์แบ่งปัน) หน้าจอที่กดรายงาน ข้อความที่ AI ตอบ ตัดไม่เกิน 2,000 ตัวอักษร รหัสบันทึกที่ถูกรายงาน ชื่อของผู้ที่เพิ่มบันทึกนั้น เหตุผลที่พิมพ์เอง (ไม่เกิน 500 ตัวอักษร) ว่าผู้กดรายงานเป็นเจ้าของบัญชีหรือเป็นผู้ถือลิงก์แบ่งปัน และถ้าเป็นผู้ถือลิงก์ ระบบจะเก็บรหัสของลิงก์แบ่งปันนั้น และป้ายชื่อที่คุณตั้งให้ลิงก์ (เช่น “ลูกสาว”) ไว้ด้วย พร้อมสถานะการตรวจสอบและเวลาที่ตรวจ ผู้ดูแลระบบอ่านได้ทั้งแถว แต่ต้องกดเปิดรายงานนั้นเป็นรายรายการ และการกดเปิดถูกบันทึกไว้ใน log (ดูข้อ 8) และรายการถูกลบเมื่อคุณลบบัญชี
- บันทึกการทำงานของเซิร์ฟเวอร์ (log) ตามปกติ — สำหรับหน้าค้นหาโรงพยาบาลใกล้เคียง เราปิด log ระดับปกติไว้เพราะ URL ของหน้านั้นมีพิกัดของคุณอยู่
ซ. ข้อมูลที่เก็บบนเครื่องของคุณ
- เว็บแอป: เก็บกุญแจเข้าใช้งาน (อายุ 30 วัน), โหมดการแสดงผล และวันเวลาที่คุณกดปิดแถบเตือน “ยืนยันอีเมล” ไว้ใน localStorage ของเบราว์เซอร์ ถ้าคุณใช้บัญชีทดลองที่ยังไม่ได้ใส่อีเมล กุญแจนี้คือทางเข้าบัญชีเพียงทางเดียวที่มี — ล้างข้อมูลเบราว์เซอร์ ออกจากระบบ หรือเปลี่ยนเครื่อง แล้วจะกลับเข้าบัญชีนั้นไม่ได้อีก (ดูข้อ 7)
- แอป Android: เก็บกุญแจเข้าใช้งาน และโหมดการแสดงผลไว้ในเครื่อง และปิด Auto Backup ไว้ เพื่อไม่ให้ข้อมูลเหล่านี้ถูกคัดลอกขึ้น Google Drive ของคุณ (เฉพาะรุ่นที่แจกเองนอก Google Play จะเก็บเวลาที่ตรวจหาอัปเดตครั้งล่าสุดเพิ่มอีกหนึ่งค่า)
- แอป Android รุ่นที่ลงจาก Google Play ขอสิทธิ์ 8 อย่าง ได้แก่ อินเทอร์เน็ต, ไมโครโฟน, กล้อง, การแจ้งเตือน, ตั้งเวลาปลุกเตือนกินยา, สั่นเตือน, เริ่มทำงานหลังเปิดเครื่อง (เพื่อตั้งเตือนใหม่) และตำแหน่งแบบคร่าว ๆ (COARSE ไม่ใช่ตำแหน่งละเอียด) รุ่นที่ลงจาก Google Play ไม่ได้ขอสิทธิ์ติดตั้งแอป (REQUEST_INSTALL_PACKAGES) และอัปเดตตัวเองไม่ได้ — การอัปเดตมาจาก Google Play เท่านั้น สิทธิ์ติดตั้งแอปมีเฉพาะในรุ่นที่เราแจกไฟล์ติดตั้งให้เองนอก Google Play
3. ข้อมูลที่เราไม่ได้เก็บ
- ไฟล์เสียง — เราไม่เก็บ แต่ข้อความเดิมของนโยบายนี้ไม่ถูกต้องอีกต่อไป และเราขอแก้ให้ตรง เวอร์ชันก่อนหน้าเขียนไว้ว่า “WellNote ไม่เคยได้รับ ไม่เขียนลงดิสก์ และไม่เก็บเสียงพูดของคุณ” ประโยคนั้นไม่จริงสำหรับเว็บแอปอีกต่อไป ตั้งแต่เวอร์ชัน 1.4 สิ่งที่จริงคือ:
- เว็บแอป — เสียงที่อัดได้หนึ่งช่วงถูกส่งมาที่เครื่องแม่ข่ายของเรา แล้วส่งต่อไปให้ Google (Gemini) ถอดเป็นข้อความในคำขอเดียวกัน สิ่งที่โค้ดบังคับไว้และเป็นสิ่งเดียวที่เรากล้ารับปาก คือ เสียงอยู่ในหน่วยความจำของเครื่องแม่ข่ายเฉพาะช่วงคำขอนั้น ไม่ถูกเขียนเป็นไฟล์ลงดิสก์ ไม่ถูกเก็บลงฐานข้อมูล และไม่ถูกเขียนลง log (log บันทึกเพียงขนาดไฟล์ ชนิดไฟล์ และจำนวนตัวอักษรที่ถอดได้ — ไม่มีตัวเสียงและไม่มีข้อความที่ถอดได้) เมื่อคำขอนั้นจบ เสียงก็หมดไป สิ่งที่ถูกเก็บไว้ในบันทึกของคุณคือข้อความที่ถอดได้เท่านั้น เราไม่ได้บอกว่าเสียงถูกเข้ารหัสเก็บไว้ หรือถูกลบภายในกี่วัน เพราะไม่มีการเก็บให้ต้องลบตั้งแต่แรก
- แอป Android (com.comed.wellnote) ที่ลงจาก Google Play — ไม่ได้ใช้เส้นทางนี้เลย ในแอปนั้นเสียงของคุณไม่เคยมาถึงเรา ไม่ว่ากรณีใด
- แต่ตัวถอดเสียงของเครื่องก็ยังเป็นผู้รับอีกรายหนึ่ง — ในแอป Android การถอดเสียงทำโดยบริการของระบบปฏิบัติการเสมอ ส่วนในเว็บแอป จะถูกใช้เมื่อเส้นทางข้างต้นใช้ไม่ได้ (เช่น Gemini ตอบไม่ได้ ใช้เกินโควตา หรือคุณไม่กดยินยอม) ระบบจะสลับไปใช้ตัวถอดเสียงของเบราว์เซอร์แทน เราไม่ได้บังคับให้ถอดแบบออฟไลน์ บนเครื่องทั่วไปเสียงของคุณจึงถูกส่งไปประมวลผลที่เซิร์ฟเวอร์ของผู้ให้บริการรายนั้น (โดยมากคือ Google) — คนละรายกับข้างต้น และเราตรวจสอบแทนเขาไม่ได้ ถ้าไม่ต้องการให้เสียงออกจากเครื่องเลย ให้พิมพ์แทนการพูด (รายละเอียดในข้อ 5)
- ตำแหน่งที่ตั้งของคุณ — พิกัดถูกใช้ครั้งเดียวเพื่อค้นหาสถานพยาบาลใกล้เคียง ไม่ถูกบันทึกลงฐานข้อมูล และไม่ถูกเขียนลง log ในหน่วยความจำของเซิร์ฟเวอร์มีเพียงกุญแจแคชที่ปัดพิกัดเหลือทศนิยม 2 ตำแหน่ง (ประมาณ 1 กิโลเมตร) เก็บไว้ 6 ชั่วโมงเพื่อลดภาระของ OpenStreetMap (ข้อนี้พูดถึงการ “เก็บ” เท่านั้น — เรื่องที่พิกัดถูกส่งไปที่ไหนบ้าง อ่านข้อ 5)
- ตัวติดตามโฆษณาและเครื่องมือวิเคราะห์พฤติกรรม — ไม่มีในแอปและเว็บ เราไม่ขายและไม่แลกเปลี่ยนข้อมูลของคุณกับใครเพื่อการตลาด
- ข้อมูลบัตรเครดิตหรือการชำระเงิน — WellNote ไม่มีการเก็บเงินในแอป
4. AI — สิ่งสำคัญที่สุดที่คุณควรอ่าน
WellNote มีความสามารถที่ใช้ AI อยู่ 6 อย่าง ซึ่งไม่ได้มีครบทั้งสองแอป — เว็บแอปมีครบทั้ง 6 ส่วนแอป Android มีเฉพาะข้อ 2, 3 และ 4 แอป Android ไม่มีข้อ 1 (ถอดเสียงที่เซิร์ฟเวอร์ของเรา) — เสียงจากแอป Android ไม่เคยถูกส่งมาที่เราเลยไม่ว่ากรณีใด และไม่มีข้อ 5 กับข้อ 6 ด้วย
ห้าอย่างแรกทำงานเมื่อคุณสั่งเท่านั้น (กดปุ่ม กดไมค์ หรือเลือกไฟล์) แต่ขอบอกตรง ๆ ว่ามีหนึ่งอย่างที่ไม่ใช่ คือการ์ดสรุปสุขภาพบนหน้าแรกของหน้าจอชุดใหม่ในเว็บแอป (ข้อ 6 ในรายการข้างล่าง) ซึ่งจะขอให้ AI เขียนใหม่เองโดยอัตโนมัติตอนเปิดหน้าแรก ถ้าบันทึกของคุณเปลี่ยนไปตั้งแต่ครั้งก่อน — เกิดขึ้นได้เฉพาะเมื่อคุณกดยินยอมไว้แล้วเท่านั้น ถ้ายังไม่ได้กดยินยอม จะไม่มีอะไรถูกส่งออกไปเลย
ก่อนส่งข้อมูลออกไปครั้งแรก แอปจะถามความยินยอมจากคุณก่อนเสมอ
หน้าจอนั้นจะบอกว่าจะส่งอะไรไป ส่งให้ใคร และข้อมูลจะออกนอกประเทศไทย
ถ้าคุณยังไม่กดยินยอม เครื่องแม่ข่ายของเราจะปฏิเสธคำขอนั้นเอง ไม่ใช่แค่ซ่อนปุ่มไว้ — ทุกเส้นทางที่จะส่งเนื้อหาของคุณออกไปให้โมเดล (การถอดเสียงในเว็บแอป สรุปการพบแพทย์ ผู้ช่วยตอบคำถาม การอ่านรูปยา และการจัดหมวดหมู่ข้อมูลที่คุณเพิ่มเข้ามา) จะตอบกลับเป็น 403 ai_consent_required
มีสามอย่างที่เราเปิดไว้โดยตั้งใจ คือการอ่านและการกดยินยอม/ถอนความยินยอมเอง การกดปุ่ม “รายงาน” คำตอบของ AI ซึ่งใช้ได้เสมอ แม้บัญชีนั้นไม่เคยกดยินยอมอะไรเลย เพราะคุณไม่ควรต้องยอมรับอะไรก่อน จึงจะร้องเรียนเรื่องเนื้อหาได้ และการ์ดสรุปสุขภาพบนหน้าแรกของหน้าจอชุดใหม่ในเว็บแอป ซึ่งไม่ตอบ 403 แต่จะเขียนการ์ดนั้นจากข้อมูลของคุณเองบนเครื่องแม่ข่าย และไม่ส่งอะไรออกไปให้ใครเลย เพราะหน้าแรกที่คุณมีสิทธิ์ดูไม่ควรกลายเป็นข้อความผิดพลาดเพียงเพราะคุณไม่ยอมให้ส่งข้อมูลออก
และคุณถอนความยินยอมเมื่อไรก็ได้ที่หน้า “ข้อมูลของฉัน” — ชื่อหัวข้อบนหน้านั้นไม่เหมือนกันในสองแอป คือในแอป Android อยู่ใต้หัวข้อ “ให้ AI ช่วยอ่านข้อมูล” ส่วนในเว็บแอปอยู่ใต้หัวข้อ “ตัวช่วย AI และความเป็นส่วนตัว” แล้วกดปุ่ม “ยกเลิกความยินยอม”
เมื่อถอนแล้ว ระบบจะหยุดส่งข้อมูลใหม่ออกไปทันที (แต่สิ่งที่ส่งไปก่อนหน้านั้นเรียกคืนไม่ได้)
- 1. ถอดเสียงพูดเป็นข้อความ — เฉพาะเว็บแอป (ใหม่ในเวอร์ชัน 1.4) — เมื่อคุณกดไมค์ในหน้าบันทึก เสียงที่อัดได้ช่วงนั้นจะถูกส่งผ่านเครื่องแม่ข่ายของเราไปให้ Google (Gemini) ถอดเป็นข้อความ พร้อมกับข้อความที่ถอดไว้ก่อนหน้าไม่เกิน 2,000 ตัวอักษร เพื่อให้สะกดชื่อยาและชื่อเฉพาะตรงกันระหว่างช่วง เสียงถูกส่งให้ Gemini เท่านั้น ไม่มีกรณีใดที่เสียงถูกส่งต่อไปให้ OpenAI ต่างจากความสามารถข้ออื่น ๆ ในรายการนี้ ถ้า Gemini ตอบไม่ได้ (เครดิตหมด เกินโควตา ระบบขัดข้อง หรือผู้ดูแลปิดไว้) เครื่องแม่ข่ายจะบอกให้แอปไปใช้ตัวถอดเสียงของเบราว์เซอร์แทน และจะไม่แต่งข้อความขึ้นมาเอง — ตัวถอดเสียงของเบราว์เซอร์คือผู้รับคนละราย อ่านข้อ 5 · ขีดจำกัด: หนึ่งช่วงยาวได้ไม่เกิน 5 นาที และไม่เกิน 4 MiB, ไม่เกิน 40 ช่วงต่อ 15 นาทีต่อบัญชี แอป Android ไม่มีความสามารถนี้ และไม่เคยส่งเสียงมาที่เรา
- 2. สรุปการพบแพทย์ — เมื่อคุณกดปุ่ม “ให้ WellNote ช่วย” หรือกดให้สรุปใหม่ ระบบจะส่งข้อความถอดเสียงทั้งหมดของบันทึกนั้นไปให้ผู้ให้บริการ AI (มีทั้งสองแอป)
- 3. ผู้ช่วยตอบคำถาม — เมื่อคุณพิมพ์คำถาม ระบบจะส่งคำถามของคุณ พร้อมบริบทจากบันทึกของคุณเอง ได้แก่ รายการแพ้ยาไม่เกิน 50 รายการ, โรคประจำตัวที่ยังเป็นอยู่ไม่เกิน 50 รายการ, การพบแพทย์ 30 ครั้งล่าสุด (วันที่ โรงพยาบาล การวินิจฉัย คำแนะนำ และคำสรุป — ถ้าบันทึกนั้นยังไม่มีคำสรุป ซึ่งเป็นกรณีของบันทึกที่ยังเป็นร่างและบันทึกการรับยาทุกใบ ระบบจะส่ง “อาการสำคัญ” ของคุณไปแทนคำสรุป), ยาที่ใช้อยู่ไม่เกิน 50 รายการ และการนัดหมายที่จะถึงไม่เกิน 20 รายการ — นับเฉพาะนัดที่ยังมีสถานะว่ายังไม่ผ่านและวันเวลานัดยังมาไม่ถึง นัดที่เลยวันไปแล้วแต่ไม่มีใครกดปิดไม่ถูกส่งออกไป พร้อมข้อความ 6 บรรทัดล่าสุดของบทสนทนาก่อนหน้าในหน้านั้น (นับเป็น 6 ข้อความ ไม่ใช่ 6 คำถาม–คำตอบ) — ขีดจำกัด 6 ข้อความนี้บังคับที่เครื่องแม่ข่ายของเราแล้ว ไม่ได้อาศัยแอปในเครื่องคุณอย่างเดียวอีกต่อไป ถ้ามีการส่งบทสนทนามามากกว่านั้น เครื่องแม่ข่ายจะเก็บไว้เพียง 6 ข้อความล่าสุด และตัดแต่ละข้อความให้ยาวไม่เกิน 2,000 ตัวอักษร ก่อนส่งต่อให้ผู้ให้บริการ AI
- 4. อ่านรูปยา/ฉลากยา — เมื่อคุณถ่ายรูปในหน้า “บันทึกการรับยา” รูปนั้นจะถูกส่งไปให้ AI อ่านทันทีที่ถ่ายเสร็จ พร้อมกับรายการแพ้ยาและโรคประจำตัวของคุณ เพื่อให้เตือนได้ว่ายาในซองอาจเป็นตัวที่คุณแพ้ (มีทั้งสองแอป)
- 5. จัดหมวดหมู่และสรุปข้อมูลที่คุณเพิ่มเข้ามา — เฉพาะหน้าจอชุดใหม่ในเว็บแอป (ใหม่ในเวอร์ชัน 1.4) เมื่อคุณเพิ่มข้อมูลสุขภาพหนึ่งรายการ ระบบจะส่งข้อความที่คุณพูดหรือพิมพ์ (ไม่เกิน 20,000 ตัวอักษร) และ/หรือรูปที่คุณถ่าย และ/หรือไฟล์เอกสาร PDF ที่คุณเลือก ไปให้ AI อ่าน พร้อมกับรายการแพ้ยาและโรคประจำตัวของคุณ เพื่อจัดว่าเป็นข้อมูลชนิดใดและร่างสรุปให้คุณตรวจ ไฟล์ PDF เป็นของใหม่ในเวอร์ชันนี้ — ก่อนหน้านี้ไม่เคยมีไฟล์เอกสารของคุณถูกส่งออกไปให้ผู้ให้บริการ AI เลย มีแต่ข้อความและรูป รูปส่งได้ไม่เกินประมาณ 6 MB และ PDF ไม่เกินประมาณ 7.5 MB ต่อครั้ง, ไม่เกิน 30 ครั้งต่อ 15 นาทีต่อบัญชี ขั้นตอนนี้ยังไม่บันทึกอะไรลงฐานข้อมูล จนกว่าคุณจะอ่านร่างแล้วกดบันทึกเอง
- 6. การ์ดสรุปสุขภาพบนหน้าแรก — เฉพาะหน้าจอชุดใหม่ในเว็บแอป (ใหม่ในเวอร์ชัน 1.4) ส่งบันทึกล่าสุดไม่เกิน 30 รายการ ยาที่ใช้อยู่ไม่เกิน 50 รายการ นัดหมายที่จะถึงไม่เกิน 20 รายการ รายการแพ้ยาไม่เกิน 50 รายการ โรคประจำตัวที่ยังเป็นอยู่ไม่เกิน 50 รายการ และอายุโดยประมาณกับเพศ ไปให้ AI เขียนเป็นสรุปสั้น ๆ (ไม่ส่งชื่อ เบอร์โทร ที่อยู่ และสิทธิการรักษา) นี่คืออย่างเดียวที่ทำงานเองโดยคุณไม่ได้กดปุ่ม — เกิดขึ้นตอนเปิดหน้าแรกเมื่อบันทึกของคุณเปลี่ยนไปจากครั้งก่อน และเฉพาะเมื่อคุณกดยินยอมไว้แล้วเท่านั้น ถ้ายังไม่ยินยอม การ์ดนี้จะถูกเขียนจากข้อมูลของคุณบนเครื่องแม่ข่ายเอง โดยไม่ส่งอะไรออกไป
ข้อควรทราบเรื่องผู้ให้บริการ AI ที่ WellNote ใช้อยู่ในขณะนี้
ขณะนี้ WellNote ใช้บริการ Google Gemini แบบเสียค่าบริการ (paid tier) ตามเงื่อนไขการใช้งานของ Google สำหรับบริการแบบเสียค่าบริการ Google ระบุว่าจะไม่นำข้อความ รูปภาพ เสียง ไฟล์เอกสาร หรือคำถามที่ส่งไป ไปใช้ฝึกหรือปรับปรุงโมเดลและผลิตภัณฑ์ของ Google และระบุว่าประมวลผลข้อมูลภายใต้ข้อตกลงการประมวลผลข้อมูล (Data Processing Addendum) คือ Google ทำหน้าที่เป็นผู้ประมวลผลข้อมูลตามคำสั่งของเรา ทั้งหมดนี้เป็นสิ่งที่ Google ประกาศไว้เอง เราตรวจสอบการทำงานภายในของ Google แทนคุณไม่ได้
แต่สิ่งที่ไม่ได้เปลี่ยน และเราขอบอกตรง ๆ คือ: ข้อความ รูป เสียงที่อัดในเว็บแอป และไฟล์ PDF ที่คุณเลือกของคุณยังถูกส่งออกไปนอกเซิร์ฟเวอร์ของเรา ไปประมวลผลที่เครื่องของ Google ซึ่งอยู่นอกประเทศไทย และ Google ยังเก็บบันทึกการใช้งานไว้ระยะเวลาหนึ่ง เพื่อตรวจสอบการใช้งานที่ผิดเงื่อนไขและการละเมิดนโยบาย ข้อมูลที่ส่งไปแล้วเราเรียกคืนหรือสั่งลบแทนคุณไม่ได้
ก่อนวันที่ 2 สิงหาคม 2569 WellNote ใช้ Gemini แบบไม่เสียค่าบริการ ซึ่งตามเงื่อนไขในตอนนั้น Google อาจนำเนื้อหาที่ส่งไปไปใช้พัฒนาและปรับปรุงผลิตภัณฑ์ของ Google ได้ และเจ้าหน้าที่ของ Google อาจอ่านได้ การเปลี่ยนมาใช้แบบเสียค่าบริการไม่ย้อนหลัง — สิ่งที่ส่งไปก่อนวันนั้นเราเรียกคืนหรือแก้ไขให้ไม่ได้
ดังนั้น ถ้าคุณไม่ต้องการให้ข้อความ รูป เสียง หรือไฟล์ของคุณออกจากเซิร์ฟเวอร์ของเราเลย กรุณาอย่ากดปุ่มที่ให้ AI ช่วย อย่าใช้หน้าผู้ช่วยตอบคำถาม อย่าถ่ายรูปยาให้ AI อ่าน อย่าแนบไฟล์ PDF เข้าไปในหน้าเพิ่มข้อมูลสุขภาพ และในเว็บแอป ให้พิมพ์แทนการกดไมค์ WellNote ยังใช้บันทึก แก้ไข ย้อนดูบันทึกเก่า เตือนกินยา และแบ่งปันให้ลูกหลานได้ครบทุกอย่างโดยไม่ต้องใช้ AI เลย (ช่องค้นหาบันทึกมีเฉพาะในเว็บแอป)
ข้อความข้างต้นเป็นเงื่อนไขของ Google Gemini แบบเสียค่าบริการ เท่านั้น ไม่ครอบคลุมผู้ให้บริการสำรอง (ดูหัวข้อถัดไป) เราตรวจสอบสถานะบัญชีแบบเสียค่าบริการครั้งล่าสุดเมื่อวันที่ 2 สิงหาคม 2569 หากวันหนึ่งเราต้องกลับไปใช้แบบไม่เสียค่าบริการ ซึ่งผู้ให้บริการอาจนำข้อมูลไปใช้พัฒนาผลิตภัณฑ์ของเขา เราจะแก้ข้อความในหน้านี้และแจ้งให้ทราบก่อน
เรื่องอื่นเกี่ยวกับ AI ที่คุณควรรู้
- ผู้ให้บริการสำรอง — ถ้า Google Gemini ตอบไม่ได้ (เช่น เครดิตหมด ใช้เกินโควตา หรือเครือข่ายมีปัญหา) ระบบจะส่งคำขอเดิมไปยัง OpenAI โดยอัตโนมัติถ้าผู้ดูแลระบบตั้งค่ากุญแจ OpenAI ไว้ ข้อมูลชุดเดียวกันจะถูกส่งไป และหน้าจอจะไม่แจ้งให้คุณทราบว่ามีการเปลี่ยนผู้ให้บริการ เงื่อนไขแบบเสียค่าบริการที่กล่าวถึงข้างต้นเป็นของ Google เท่านั้น ถ้าระบบสลับไปใช้ OpenAI จะเป็นไปตามเงื่อนไขของ OpenAI เอง ข้อยกเว้นเดียวคือเสียงพูด — การถอดเสียงในเว็บแอปเรียก Gemini โดยตรง ไม่ได้เดินผ่านลำดับผู้ให้บริการสำรองนี้ จึงไม่มีทางที่ไฟล์เสียงของคุณจะถูกส่งไปให้ OpenAI เมื่อ Gemini ตอบไม่ได้ ระบบจะเปลี่ยนไปใช้ตัวถอดเสียงของเบราว์เซอร์แทน (ดูข้อ 5)
- ถ้าไม่มี AI ตัวไหนตอบได้เลย ระบบจะไม่เดาแทนคุณ — ตัวสำรองที่ทำงานอยู่บนเครื่องแม่ข่ายของเราไม่จัดข้อมูลให้อีกต่อไป (เมื่อก่อนมันพยายามดึงชื่อยา ขนาดยา และวันนัดออกจากข้อความด้วยการจับคำ ซึ่งอ่านชื่อยาที่ไม่รู้จักผิดจนอันตราย เราจึงเอาออก) สิ่งที่เกิดขึ้นแทนคือ ข้อความของคุณถูกเก็บไว้ครบทุกคำตามที่พูดหรือพิมพ์ โดยไม่ตีความ หน้าจอจะบอกตรง ๆ ว่ายังไม่ได้ให้ AI สรุปข้อมูลนี้ และขอให้คุณกรอกรายการยา (ชื่อยา ขนาด วิธีใช้) เองก่อนบันทึก รายการยาที่ว่างจึงไม่ได้แปลว่าไม่มียา แต่แปลว่ายังไม่มีใครอ่านให้ ในทางความเป็นส่วนตัวข้อนี้เป็นผลดี คือระบบไม่เดาข้อมูลเพิ่มเติมเกี่ยวกับคุณ — และคุณยังบันทึกและแก้ไขข้อมูลได้ตามปกติ การบันทึกไม่เคยถูกขัดขวางเพราะ AI
- AI อ่านผิดได้ สิ่งที่ AI เสนอเข้าบัตรสุขภาพจะยังไม่นับเป็นข้อมูลจริงจนกว่าคุณจะกดยืนยัน และคำสรุปทุกครั้งขอให้คุณตรวจทานก่อนบันทึก
- ข้อความ เสียง รูป และไฟล์ที่ส่งให้ AI ไม่ได้ผ่านการลบชื่อหรือปิดบังข้อมูล ถ้าคุณเอ่ยชื่อ เลขบัตร หรือเรื่องของคนอื่นในบันทึก สิ่งนั้นจะถูกส่งไปด้วย และเสียงพูดยังพาสิ่งที่ข้อความไม่มีไปด้วย เช่น น้ำเสียงของคุณ และเสียงของคนอื่นที่พูดอยู่ในห้องตอนนั้น รวมทั้งเสียงของแพทย์ ถ้าไม่ต้องการให้สิ่งเหล่านี้ออกไป ให้พิมพ์แทนการพูด
- ผู้ให้บริการ AI ประมวลผลข้อมูลบนเครื่องของเขา ซึ่งอยู่นอกประเทศไทย
5. บุคคลภายนอกที่ได้รับข้อมูล และได้รับอะไรบ้าง
นี่คือรายชื่อทั้งหมดที่ข้อมูลของคุณอาจไปถึง
Google — Gemini API (generativelanguage.googleapis.com)
เมื่อไร: เมื่อคุณกดให้ AI สรุป ถามผู้ช่วย ถ่ายรูปยาให้อ่าน เพิ่มข้อมูลสุขภาพให้ระบบจัดหมวดหมู่ (เว็บแอป) เปิดหน้าแรกของหน้าจอชุดใหม่ทั้งที่ยินยอมไว้แล้ว (เว็บแอป) และ — เฉพาะเว็บแอป — ทุกครั้งที่คุณกดไมค์เพื่ออัดเสียง
สิ่งที่ส่งไป: ข้อความถอดเสียงฉบับเต็ม / คำถามของคุณพร้อมสรุปประวัติ ยา นัดหมาย และรายการแพ้ยา / รูปภาพที่ถ่าย พร้อมรายการแพ้ยาและโรคประจำตัว / ไฟล์เอกสาร PDF ที่คุณเลือกแนบในหน้าเพิ่มข้อมูลสุขภาพ / และ — เฉพาะเว็บแอป — ไฟล์เสียงที่อัดได้หนึ่งช่วง พร้อมข้อความที่ถอดไว้ก่อนหน้าไม่เกิน 2,000 ตัวอักษร
เสียงถูกส่งให้ Gemini ในคำขอเดียว ไม่ถูกเขียนลงดิสก์ ไม่ถูกเก็บลงฐานข้อมูล และไม่ถูกเขียนลง log ที่เรา — แต่สิ่งที่เกิดขึ้นหลังจากถึง Google อยู่นอกการควบคุมของเรา · ขณะนี้ใช้แบบเสียค่าบริการ (paid tier) — Google ระบุว่าจะไม่นำข้อมูลไปฝึกโมเดล และประมวลผลในฐานะผู้ประมวลผลข้อมูลแทนเรา แต่ยังเก็บบันทึกการใช้งานไว้ระยะเวลาหนึ่งเพื่อตรวจสอบการใช้ผิดเงื่อนไข — ดูกรอบสีแดงในข้อ 4
OpenAI (api.openai.com)
เมื่อไร: เฉพาะเมื่อผู้ดูแลระบบตั้งค่ากุญแจ OpenAI ไว้ และ Gemini ตอบไม่ได้ ระบบจะสลับให้เองโดยไม่แจ้งบนหน้าจอ
สิ่งที่ส่งไป: ข้อมูลชุดเดียวกับที่ส่งให้ Gemini — ข้อความ รูป และไฟล์ PDF
ยกเว้นอย่างเดียวคือ ไฟล์เสียง: การถอดเสียงเรียก Gemini โดยตรง ไม่ผ่านลำดับผู้ให้บริการสำรอง เสียงของคุณจึงไม่ถูกส่งไปให้ OpenAI ในทุกกรณี
Google Sign-In / Google Identity Services
เมื่อไร: เฉพาะเมื่อผู้ดูแลระบบตั้งค่า Client ID ไว้ เว็บจะโหลดสคริปต์ accounts.google.com/gsi/client ทั้งใน “หน้าเข้าสู่ระบบ” และ “หน้าโปรไฟล์” (ปุ่มเชื่อมบัญชี Google) ส่วนแอป Android ใช้ Credential Manager ของ Google Play Services
สิ่งที่ส่งไป: Google ได้รับข้อมูลการเชื่อมต่อของเบราว์เซอร์/เครื่องคุณตามปกติของ Google (เช่น หมายเลข IP) และคุณต้องเข้าสู่ระบบบัญชี Google ของคุณ · เราได้รับกลับมาเฉพาะ รหัสผู้ใช้ Google อีเมล ชื่อ และลิงก์รูปโปรไฟล์ โดยเซิร์ฟเวอร์ของเราส่งโทเค็นไปตรวจสอบที่ oauth2.googleapis.com
ถ้าไม่ได้ตั้งค่า Client ID ไว้ จะไม่มีการโหลดสคริปต์นี้เลย
Google Play Services — บริการระบุตำแหน่ง (แอป Android)
เมื่อไร: เมื่อคุณกดปุ่ม “หาโรงพยาบาลใกล้ฉัน” และอนุญาตให้เข้าถึงตำแหน่ง
สิ่งที่ส่งไป: แอปใช้ Fused Location Provider ของ Google ซึ่งหาตำแหน่งจากสัญญาณ Wi-Fi และเสาสัญญาณรอบตัวคุณ แปลว่า Google จะได้รับข้อมูลระบุอุปกรณ์/เครือข่ายของคุณตามการทำงานของบริการนั้น
เราขอเฉพาะตำแหน่งแบบคร่าว ๆ (COARSE) ไม่ใช่ตำแหน่งละเอียด และพิกัดที่ได้ไม่ถูกบันทึกไว้ที่เรา
บริการถอดเสียงของเครื่องหรือเบราว์เซอร์ของคุณ (ผู้รับคนละรายกับ Gemini)
เมื่อไร: ในแอป Android: ทุกครั้งที่คุณกดปุ่มพูดเพื่อบันทึก · ในเว็บแอป: เฉพาะเมื่อเส้นทางของเราใช้ไม่ได้ — Gemini ตอบไม่ได้ ใช้เกินโควตา ผู้ดูแลปิดไว้ หรือคุณไม่กดยินยอม — จากนั้นทั้งการอัดที่เหลือในครั้งนั้นจะใช้ตัวถอดเสียงของเบราว์เซอร์
สิ่งที่ส่งไป: เสียงพูดของคุณ ซึ่ง — ขึ้นอยู่กับเครื่องและการตั้งค่าของคุณ — ตัวถอดเสียงนั้นอาจส่งไปประมวลผลที่เซิร์ฟเวอร์ของผู้ให้บริการรายนั้น (เช่น Google หรือ Apple) ในกรณีนี้เสียงไม่ได้ผ่านเราเลย
เราไม่ได้บังคับให้ถอดเสียงแบบออฟไลน์ ทั้งในแอป Android และในเว็บแอป เราจึงยืนยันแทนผู้ให้บริการเหล่านั้นไม่ได้ว่าเสียงอยู่ในเครื่องเสมอ · ข้อจำกัดทางเทคนิคที่บอกตรง ๆ: ตัวถอดเสียงของเบราว์เซอร์ฟังได้เฉพาะไมค์สด ป้อนไฟล์ที่อัดไว้แล้วให้มันไม่ได้ ช่วงเสียงช่วงที่ค้นพบว่าเส้นทางของเราใช้ไม่ได้จึงถอดซ้ำไม่ได้ ระบบจะบอกคุณตรง ๆ ให้พูดช่วงนั้นใหม่ ถ้าคุณกังวล ให้พิมพ์แทนการพูด
OpenStreetMap / Overpass API (overpass-api.de)
เมื่อไร: เมื่อคุณกดค้นหาสถานพยาบาลใกล้เคียง
สิ่งที่ส่งไป: พิกัดของคุณและรัศมีที่ค้นหา — ส่งจากเซิร์ฟเวอร์ของเรา ไม่ใช่จากเครื่องของคุณโดยตรง พร้อมชื่อโปรแกรมของเรา (WellNote) ตามที่นโยบายการใช้งานของเขากำหนด
Google Fonts (fonts.googleapis.com, fonts.gstatic.com)
เมื่อไร: ทุกครั้งที่คุณเปิดเว็บแอป WellNote
สิ่งที่ส่งไป: เบราว์เซอร์ของคุณโหลดฟอนต์จากเซิร์ฟเวอร์ของ Google โดยตรง Google จึงเห็นหมายเลข IP และข้อมูลเบราว์เซอร์ของคุณ ไม่มีข้อมูลสุขภาพส่งไปที่นี่
แอป Android ฝังฟอนต์ภาษาไทย (Sarabun) ไว้ในตัวแอป จึงไม่โหลดฟอนต์ตัวหนังสือจาก Google — แต่ดูรายการถัดไปเรื่องฟอนต์อีโมจิ
Google Play Services — ฟอนต์อีโมจิ (แอป Android)
เมื่อไร: ตอนเปิดแอปครั้งแรก ๆ และเมื่อระบบต้องอัปเดตฟอนต์อีโมจิ
สิ่งที่ส่งไป: ไลบรารีมาตรฐานของ Android (androidx.emoji2) ที่มากับแอป ขอฟอนต์อีโมจิผ่าน Google Play Services ในเครื่องคุณ ซึ่งอาจดาวน์โหลดฟอนต์นั้นจาก Google — ไม่มีข้อมูลสุขภาพหรือข้อมูลบัญชีของคุณส่งไปกับคำขอนี้
เราไม่ได้ใส่ไลบรารีนี้เอง มันมากับชุดเครื่องมือหน้าจอของ Android เราแจ้งไว้เพราะเป็นการติดต่อ Google ที่เกิดขึ้นจริงจากแอป
Google Maps (www.google.com/maps)
เมื่อไร: เฉพาะเมื่อคุณกดลิงก์ “ไม่เจอที่นี่? เปิดดูในแผนที่” ใต้รายชื่อสถานพยาบาล
สิ่งที่ส่งไป: ในเว็บแอป ลิงก์นี้มีพิกัดของคุณอยู่ใน URL (เปิดแผนที่ค้นหาคำว่า “โรงพยาบาล” ที่ตำแหน่งของคุณ) ดังนั้นถ้าคุณกดปุ่มนี้ Google จะได้รับพิกัดของคุณ · ส่วนแอป Android ส่งเพียงคำค้น “โรงพยาบาล” ไปให้แอปแผนที่ ไม่ได้ส่งพิกัดจากเราไปด้วย (แอปแผนที่อาจใช้ตำแหน่งของเครื่องคุณเองตามการตั้งค่าของมัน)
ถ้าไม่ต้องการให้พิกัดของคุณไปถึง Google กรุณาอย่ากดลิงก์นี้ — การเลือกสถานพยาบาลจากรายชื่อ และการพิมพ์ชื่อเอง ทำได้โดยไม่ต้องเปิดแผนที่
ผู้ให้บริการรับส่งอีเมล (SMTP relay) ที่เราตั้งค่าไว้
เมื่อไร: เมื่อคุณสมัคร ขอยืนยันอีเมล หรือขอตั้งรหัสผ่านใหม่
สิ่งที่ส่งไป: อีเมลของคุณ ชื่อของคุณ หัวเรื่อง และเนื้อความซึ่งมีลิงก์ใช้ครั้งเดียว — เราเซ็นอีเมลด้วย DKIM เมื่อกุญแจถูกตั้งค่าไว้
ถ้ายังไม่ได้ตั้งค่าผู้ให้บริการอีเมล ระบบจะไม่ส่งจริงและบันทึกไว้ใน log ของเซิร์ฟเวอร์แทน โดยไม่บันทึกเนื้อความในเครื่องที่ใช้งานจริง
ผู้ให้บริการเครื่องแม่ข่าย (VPS) ที่เราเช่าใช้
เมื่อไร: ตลอดเวลา
สิ่งที่ส่งไป: ข้อมูลทั้งหมดของ WellNote เก็บอยู่บนเครื่องแม่ข่ายที่เราเช่า ผู้ให้บริการรายนั้นเป็นผู้ดูแลเครื่องทางกายภาพ
คนที่คุณส่งลิงก์ QR ให้เอง
เมื่อไร: เมื่อคุณสร้างลิงก์แบ่งปันและส่งให้ใครก็ตาม
สิ่งที่ส่งไป: ดูรายละเอียดในข้อ 6 — เขาจะเห็นเกือบทั้งหมดของบันทึกคุณ
นอกจากรายชื่อข้างต้น เราไม่เปิดเผยข้อมูลของคุณให้ใครอีก เว้นแต่มีคำสั่งตามกฎหมายหรือหมายศาลที่เราต้องปฏิบัติตาม
6. ลิงก์แบ่งปันสำหรับลูกหลาน — สิ่งที่เขาเห็นจริง ๆ
เมื่อคุณสร้างลิงก์แบ่งปัน (QR) ใครก็ตามที่ถือลิงก์นั้นเปิดดูได้โดยไม่ต้องมีบัญชีและไม่ต้องใส่รหัสผ่าน ตัวลิงก์คือกุญแจในตัวมันเอง กรุณาส่งให้เฉพาะคนที่คุณไว้ใจจริง ๆ
ผู้ถือลิงก์จะเห็น:
- ชื่อของคุณ
- รายชื่อโรคประจำตัวและรายการแพ้แบบย่อที่อยู่ในโปรไฟล์ของคุณ — คือสองรายการเดียวกับที่หน้าแรกและหน้า “ข้อมูลของฉัน” แสดง ลิงก์แบ่งปันส่งสำเนาของสองรายการนี้ออกไป ไม่ได้ไปอ่านจากบัตรสุขภาพโดยตรง ทุกครั้งที่คุณเพิ่ม แก้ หรือลบรายการในบัตรสุขภาพ ระบบจะเขียนสองรายการนี้ขึ้นใหม่จากบัตรสุขภาพ โดยเก็บเฉพาะรายการที่คุณกดยืนยันแล้ว (และสำหรับโรคประจำตัว ต้องเป็นโรคที่ยังไม่ได้ทำเครื่องหมายว่าหายแล้ว) รายการที่ AI เสนอมาแต่คุณยังไม่ได้กดยืนยัน จึงไม่ถูกเขียนลงไป แต่ในเว็บแอปคุณยังพิมพ์ลงสองช่องนี้ได้เองโดยตรงที่หน้า “ข้อมูลของฉัน” และสิ่งที่พิมพ์ไว้คือสิ่งที่ผู้ถือลิงก์เห็น จนกว่าการแก้บัตรสุขภาพครั้งถัดไปจะเขียนทับมัน กรุณาอย่าใช้ข้อนี้เป็นเครื่องป้องกัน: ถ้าไม่แน่ใจ ให้ถือว่าผู้ถือลิงก์เห็นทุกอย่าง การเดาว่าเขาเห็นมากกว่าจริง อย่างมากก็ทำให้คุณระวังตัวเกินไป แต่การเดาว่าเขาเห็นน้อยกว่าจริง คือการเผลอส่งข้อมูลสุขภาพให้คนที่คุณไม่ได้ตั้งใจให้เห็น
- บันทึกการพบแพทย์ล่าสุด 50 รายการ พร้อมวันที่ โรงพยาบาล อาการสำคัญ สรุป และการวินิจฉัย
- ยาที่ใช้อยู่ทั้งหมด พร้อมขนาดและวิธีรับประทาน
- การนัดหมายที่จะถึงทั้งหมด
- เมื่อเปิดดูบันทึกรายการใดรายการหนึ่ง จะเห็นข้อความถอดเสียงฉบับเต็มของบันทึกนั้น และไฟล์แนบทุกไฟล์ พร้อมชื่อไฟล์เดิม
- ที่มาของบันทึกแต่ละรายการ และชื่อของผู้ถือลิงก์คนอื่นที่เป็นคนเพิ่มบันทึกนั้น — บันทึกที่ถูกเพิ่มเข้ามาผ่านลิงก์แบ่งปัน จะถูกส่งออกไปพร้อมกับชื่อของคนที่เพิ่ม (หรือป้ายชื่อที่คุณตั้งให้ลิงก์นั้น เช่น “ลูกสาว”) และผู้ถือลิงก์ทุกคนเห็นชื่อนั้น แปลว่าชื่อของลูกหลานคนหนึ่งถูกเปิดเผยให้ผู้ถือลิงก์อีกคนหนึ่งเห็น กรุณาบอกเขาก่อนส่งลิงก์ให้
สิ่งที่คุณเลือกได้มีเพียงสองอย่าง: จะให้ “ดูอย่างเดียว” หรือ “ช่วยเพิ่มบันทึกได้ด้วย” และจะให้ลิงก์อยู่นานแค่ไหน โดยเลือกได้สามแบบคือ ไม่หมดอายุ (ค่าเริ่มต้น) · 30 วัน · 90 วัน คุณเลือกแบ่งเฉพาะบางเรื่องหรือซ่อนบางบันทึกไม่ได้
- ถ้าให้สิทธิ์ “ช่วยเพิ่มบันทึกได้” ผู้ถือลิงก์จะเพิ่มบันทึกใหม่ให้คุณได้ (แต่ลบหรือแก้ของเดิมไม่ได้) และชื่อของเขาจะถูกเก็บไว้ในบันทึกนั้น
- คุณยกเลิกลิงก์ได้ตลอดเวลา เมื่อยกเลิก ลิงก์เปิดไฟล์ที่เคยส่งให้เขาไปแล้วจะใช้ไม่ได้ทันทีเช่นกัน
- ระบบบันทึกว่าลิงก์ถูกเปิดกี่ครั้งและครั้งล่าสุดเมื่อไร ให้คุณดูได้ในหน้าแบ่งปัน
7. เราเก็บข้อมูลไว้นานแค่ไหน
- บันทึกสุขภาพ โปรไฟล์ บัตรสุขภาพ ยา นัดหมาย และไฟล์แนบ — เก็บไว้จนกว่าคุณจะลบเอง ระบบไม่มีการลบให้อัตโนมัติเมื่อครบกำหนดเวลา เพราะสมุดสุขภาพมีค่าที่ความต่อเนื่อง — คุณจึงเป็นผู้ตัดสินใจเองว่าจะเก็บถึงเมื่อไร ยกเว้นบัญชีทดลองที่ยังไม่ได้ใส่อีเมล ตามข้อถัดไป
- บัญชีทดลอง (กด “ลองใช้งานก่อน ไม่ต้องสมัคร”): เป็นบัญชีส่วนตัวของคุณจริง ๆ มีบันทึกของคุณเอง ไม่ปนกับใคร แต่ยังไม่มีอีเมลและรหัสผ่าน จึงมีทางเข้าเพียงทางเดียวคือกุญแจที่เก็บอยู่ในเบราว์เซอร์เครื่องนั้น ถ้าไม่มีการเปิดใช้งานเลยติดต่อกัน 30 วัน เราจะลบบัญชีทดลองและบันทึกทั้งหมดในนั้นทิ้งอัตโนมัติ เพราะเราไม่ควรเก็บข้อมูลสุขภาพที่เจ้าของเข้าถึงไม่ได้แล้วไว้เรื่อย ๆ วิธีหยุดกำหนดเวลานี้คือใส่อีเมลและรหัสผ่านเพื่อเก็บบัญชีไว้ (แท็บ “ฉัน” → “เก็บบันทึกนี้ไว้”) เมื่อใส่แล้วบัญชีจะกลายเป็นบัญชีปกติทันที บันทึกเดิมอยู่ครบ และไม่มีการลบอัตโนมัติอีกต่อไป
- คิวอีเมลขาออก: เนื้อความถูกลบทันทีที่ส่งเสร็จหรือเลิกส่ง ส่วนข้อมูลว่าเคยส่งอะไรไปที่ไหนเมื่อไร เก็บไว้ 30 วันแล้วลบอัตโนมัติ
- โทเค็นยืนยันอีเมล (อายุ 24 ชั่วโมง) และโทเค็นตั้งรหัสผ่านใหม่ (อายุ 1 ชั่วโมง): ลบอัตโนมัติหลังหมดอายุแล้ว 7 วัน
- ลิงก์เปิดไฟล์แนบ: มีอายุ 30 นาที (ปรับได้ในระบบ สูงสุด 24 ชั่วโมง) แล้วใช้ไม่ได้อีก
- กุญแจเข้าใช้งาน (session): อายุ 30 วัน และถูกยกเลิกทันทีเมื่อเปลี่ยนรหัสผ่าน ถูกระงับบัญชี หรือลบบัญชี
- บันทึกความผิดพลาดของ AI: เก็บไว้จนกว่าผู้ดูแลระบบจะกดล้าง และถูกลบทันทีเมื่อคุณลบบัญชี
- ไฟล์เสียงที่อัดในเว็บแอป: เราไม่เก็บไว้เลย จึงไม่มีระยะเวลาเก็บ — เสียงอยู่ในหน่วยความจำของเครื่องแม่ข่ายเฉพาะช่วงคำขอที่ส่งไปให้ Gemini ไม่ถูกเขียนลงดิสก์ ไม่ถูกเก็บลงฐานข้อมูล ไม่ถูกเขียนลง log และไม่ถูกสำรองไว้ในสำเนาสำรอง แต่สิ่งที่เก็บไว้กับ Google หลังจากนั้นเป็นอีกเรื่องหนึ่ง — อ่านข้อถัดไป
- ข้อความ รูป เสียง และไฟล์ PDF ที่ส่งให้ผู้ให้บริการ AI อยู่นอกการควบคุมของเรา — สำหรับบริการแบบเสียค่าบริการ Google ระบุว่าจะไม่นำไปใช้ฝึกโมเดล แต่ยังเก็บบันทึกไว้ระยะเวลาหนึ่งเพื่อตรวจสอบการใช้งานที่ผิดเงื่อนไขและการละเมิดนโยบาย เราไม่ทราบระยะเวลาที่แน่นอน และลบข้อมูลนั้นแทนคุณไม่ได้ การลบบัญชีที่ WellNote ลบเฉพาะข้อมูลที่อยู่กับเรา
- สำเนาสำรอง (backup) ของฐานข้อมูลถูกจัดทำอัตโนมัติทุกคืน เวลาประมาณ 03:15 น. เพื่อกันข้อมูลสูญหาย และสำเนาที่เก่ากว่า 30 วันจะถูกลบทิ้งอัตโนมัติ ข้อมูลที่คุณลบไปแล้วจึงอาจยังค้างอยู่ในสำเนาสำรองได้นานที่สุด 30 วัน ก่อนจะหายไปทั้งหมด
8. ความปลอดภัย และข้อจำกัดที่เราบอกตรง ๆ
สิ่งที่เราทำ
- การรับส่งข้อมูลทั้งหมดผ่านการเข้ารหัส HTTPS (TLS)
- รหัสผ่านเก็บเป็นค่าคำนวณทางเดียวด้วย scrypt พร้อมค่าสุ่มเฉพาะราย
- ไฟล์แนบไม่เปิดสาธารณะ การเปิดไฟล์ต้องใช้ลิงก์ที่เซิร์ฟเวอร์เซ็นรับรองและมีอายุสั้น ลิงก์ที่ออกให้ผู้ถือ QR จะถูกตรวจกับสถานะของลิงก์แบ่งปันทุกครั้ง ยกเลิกหรือหมดอายุเมื่อไร ไฟล์ปิดทันที และไฟล์ถูกส่งแบบห้ามแคช (
private, no-store) - ระบบตรวจสอบว่าไฟล์ที่อัปโหลดผูกกับบันทึกของคุณจริงก่อนเขียนลงเครื่องแม่ข่าย และรับเฉพาะไฟล์ภาพ (JPEG, PNG, WebP, HEIC) กับ PDF เท่านั้น โดยตัดสินจากลายเซ็นในตัวไฟล์เอง ไม่ใช่จากชนิดไฟล์ที่เครื่องของคุณแจ้งมาและไม่ใช่จากนามสกุลในชื่อไฟล์ ถ้าสองอย่างนี้ไม่ตรงกัน ระบบจะปฏิเสธไฟล์นั้น และนามสกุลของไฟล์บนเครื่องแม่ข่ายมาจากชนิดไฟล์ที่ตรวจแล้วเท่านั้น ชื่อไฟล์เดิมของคุณไม่เคยถูกใช้ตั้งชื่อไฟล์บนเครื่องแม่ข่าย — ข้อจำกัดที่บอกตรง ๆ: ไฟล์ที่อัปโหลดไว้ก่อนที่เราจะเพิ่มการตรวจนี้ ไม่ได้ถูกตรวจย้อนหลัง เราจึงส่งไฟล์เก่าที่ไม่รู้จักกลับไปเป็นไฟล์ดาวน์โหลดเปล่า ๆ ไม่ใช่เอกสารที่เบราว์เซอร์จะเปิดแสดงเอง
- ลิงก์ยืนยันอีเมลและตั้งรหัสผ่านใหม่ใช้ได้ครั้งเดียว มีวันหมดอายุ เก็บในระบบเป็นค่าแฮช และเนื้อความอีเมลถูกเข้ารหัสระหว่างรอส่ง แล้วลบทิ้งเมื่อส่งเสร็จ
- การเปลี่ยนรหัสผ่านจะตัดการเข้าใช้งานของทุกเครื่องที่ล็อกอินอยู่ก่อนหน้านั้น
- การลบบัญชีต้องยืนยันตัวตนซ้ำด้วยรหัสผ่าน (หรือด้วย Google สำหรับบัญชีที่ใช้ Google) เสมอ
ข้อจำกัดที่คุณควรรู้ก่อนใช้
- ฐานข้อมูลไม่ได้เข้ารหัสขณะจัดเก็บ — ข้อมูลของคุณเก็บในไฟล์ฐานข้อมูล SQLite บนเครื่องแม่ข่ายซึ่งไม่ได้ถูกเข้ารหัสในตัวมันเอง ผู้ที่เข้าถึงเครื่องแม่ข่ายหรือสำเนาสำรองได้ จะอ่านข้อมูลได้
- ยังไม่มีปุ่มดาวน์โหลดข้อมูลของคุณ — WellNote ยังไม่มีฟังก์ชันส่งออกข้อมูลเป็นไฟล์ ถ้าคุณต้องการสำเนาข้อมูลของคุณ ให้อีเมลมาขอ เราจะจัดทำให้ (ดูข้อ 10)
- ระบบไม่ลบบันทึกสุขภาพให้เองตามเวลา — ข้อมูลจะอยู่จนกว่าคุณจะลบเอง
- ระบบจะถามความยินยอมคุณใหม่ในเวอร์ชันนี้ — โดยปกติระบบถือว่าความยินยอมเดิม “หมดอายุ” ก็ต่อเมื่อรายชื่อผู้รับเปลี่ยนไป และการถอดเสียงส่งไปให้ Google (Gemini) ซึ่งเป็นผู้รับรายเดิม กติกาข้อนั้นเพียงข้อเดียวจะทำให้ความยินยอมที่คุณเคยกดไว้สำหรับข้อความและรูป ครอบคลุมเสียงพูดไปด้วยโดยไม่ถามคุณอีก เราไม่ยอมให้เป็นแบบนั้น — ความยินยอมต่อข้อความ ไม่ใช่ความยินยอมต่อเสียง จึงเลื่อนหมายเลขเวอร์ชันของข้อความขอความยินยอมด้วย ผลคือทุกบัญชีที่เคยกดยินยอมไว้ จะถูกถามใหม่ก่อนใช้ความสามารถ AI ครั้งถัดไป และหน้าขอความยินยอมฉบับใหม่ระบุไฟล์เสียงและไฟล์ PDFไว้ในรายการสิ่งที่ถูกส่งออกไปแล้ว ถ้าคุณไม่ต้องการให้เสียงของคุณออกไป ให้พิมพ์แทนการพูด หรือถอนความยินยอมได้ทุกเมื่อ (ข้อ 4)
- ผู้ดูแลระบบของเราเข้าถึงข้อมูลบางส่วนได้ — หน้าจอผู้ใช้ของผู้ดูแลแสดงรายชื่อผู้ใช้ อีเมล ปีเกิด เพศ ส่วนสูง น้ำหนัก กรุ๊ปเลือด รายการโรคประจำตัวและการแพ้ยาแบบย่อ และสรุปบันทึก (วันที่ โรงพยาบาล คำสรุป การวินิจฉัย ยาที่ใช้อยู่ และนัดหมายที่จะถึง — เฉพาะนัดที่ยังไม่ถูกกดปิดและยังไม่เลยวันเวลานัด) เพื่อการดูแลระบบและตอบปัญหาการใช้งาน หน้าจอนั้นไม่แสดงข้อความถอดเสียง ไม่แสดงเบอร์โทรและที่อยู่ ไม่แสดงเนื้อความอีเมล และไม่แสดงลิงก์ตั้งรหัสผ่านใหม่ ผู้ดูแลระบบสามารถระงับหรือลบบัญชีได้
- แต่ยังมีอีกทางหนึ่งที่ผู้ดูแลระบบเห็นได้มากกว่านั้น คือคิวรายงานเนื้อหา — เมื่อคุณกดปุ่ม “รายงาน” ที่คำตอบของ AI ระบบจะเก็บข้อความที่ AI ตอบคุณ ยาวได้ถึง 2,000 ตัวอักษร ไว้ พร้อมชื่อและอีเมลของคุณ หน้าจอที่กดรายงาน และเหตุผลที่พิมพ์เอง และเมื่อมีการรายงานบันทึกที่คนอื่นเพิ่มให้ผ่านลิงก์แบ่งปัน ระบบจะเก็บชื่อของผู้เพิ่มบันทึกคนนั้นไว้ด้วย หน้ารายการคิวไม่แสดงตัวข้อความที่ถูกรายงาน — แสดงเพียงว่าเป็นรายงานชนิดใด ของบัญชีใด มาจากหน้าจอไหน ใครเป็นคนกดรายงาน เมื่อไร และมีข้อความรออ่านยาวกี่ตัวอักษร ตัวข้อความจะปรากฏก็ต่อเมื่อผู้ดูแลระบบกดเปิดรายงานนั้นเป็นรายรายการ และการกดเปิดแต่ละครั้งถูกบันทึกไว้ใน log ว่าผู้ดูแลคนใดเปิดรายงานของใคร ขอบอกตรง ๆ ว่าคำตอบของ AI มักเป็นการเรียบเรียงเนื้อหาจากข้อความถอดเสียงของคุณ ถ้าคุณกดรายงาน ผู้ดูแลระบบจึงเปิดอ่านเนื้อหานั้นในรูปคำตอบของ AI ได้ แม้หน้าจอผู้ใช้ของผู้ดูแลจะไม่แสดงข้อความถอดเสียงก็ตาม — สิ่งที่เปลี่ยนไปคือเขาต้องตั้งใจกดเปิดและมีร่องรอยไว้ ไม่ใช่เห็นผ่านตาไปเฉย ๆ ตอนเปิดคิว รายการนี้เกิดขึ้นเฉพาะเมื่อมีการกดรายงานเท่านั้น และถูกลบเมื่อคุณลบบัญชี
- ไม่มีระบบใดปลอดภัย 100% เราจะแจ้งให้คุณและสำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคลทราบตามที่กฎหมายกำหนด หากเกิดเหตุละเมิดข้อมูล
9. ทำไมเราถึงเก็บ และฐานทางกฎหมาย
- ความยินยอมโดยชัดแจ้ง — ข้อมูลสุขภาพเป็นข้อมูลอ่อนไหวตามมาตรา 26 ของ PDPA เราประมวลผลได้ก็ต่อเมื่อคุณสมัครใช้งานและบันทึกข้อมูลเข้ามาเอง การส่งข้อมูลให้ผู้ให้บริการ AI ต้องอาศัยความยินยอมที่คุณกดแยกต่างหาก และเกือบทุกครั้งเป็นการกระทำที่คุณสั่งเป็นครั้ง ๆ ด้วยการกดปุ่มหรือกดไมค์ ยกเว้นการ์ดสรุปสุขภาพบนหน้าแรกของหน้าจอชุดใหม่ในเว็บแอป ซึ่งทำงานเองเมื่อคุณยินยอมไว้แล้ว (ดูข้อ 4)
- การปฏิบัติตามสัญญา — เพื่อสร้างบัญชี ยืนยันตัวตน ให้คุณเข้าใช้งาน และส่งการแจ้งเตือนที่คุณตั้งไว้
- ประโยชน์อันชอบด้วยกฎหมาย — เพื่อความปลอดภัยของระบบ ป้องกันการสวมสิทธิ์ ป้องกันการใช้ในทางที่ผิด และแก้ไขข้อขัดข้อง (เช่น บันทึกความผิดพลาดและคิวอีเมล)
- การปฏิบัติตามกฎหมาย — เมื่อมีหน้าที่ต้องเปิดเผยตามคำสั่งที่ชอบด้วยกฎหมาย
เราไม่ใช้ข้อมูลของคุณเพื่อโฆษณา ไม่สร้างโปรไฟล์การตลาด และไม่ขายข้อมูลให้ใคร
10. สิทธิของคุณ และวิธีใช้สิทธิ
ตาม PDPA คุณมีสิทธิดังนี้ และเราจะตอบกลับภายใน 30 วัน
- ขอดูและขอสำเนาข้อมูล — ดูได้เองในแอปทุกเมื่อ ถ้าต้องการเป็นไฟล์สำเนา ให้อีเมลมาขอ (ยังไม่มีปุ่มดาวน์โหลดในแอป)
- ขอแก้ไขให้ถูกต้อง — แก้ได้เองทุกช่องในแอป
- ขอลบ — ลบทีละรายการได้ในแอป หรือลบทั้งบัญชีได้เอง (ข้อ 11)
- ขอให้ระงับการใช้ข้อมูล และ คัดค้านการประมวลผล — อีเมลมาแจ้งเรา
- ถอนความยินยอม — หยุดใช้ความสามารถที่ใช้ AI ได้ทันทีโดยไม่ต้องแจ้งใคร (แค่ไม่กดปุ่มเหล่านั้น) และถอนความยินยอมทั้งหมดได้ด้วยการลบบัญชี การถอนความยินยอมไม่กระทบการประมวลผลที่ทำไปแล้วโดยชอบก่อนหน้านั้น และข้อมูลที่ส่งให้ผู้ให้บริการ AI ไปแล้วเราเรียกคืนไม่ได้
- ขอให้โอนย้ายข้อมูล — อีเมลมาขอ เราจะจัดทำสำเนาในรูปแบบที่อ่านได้ด้วยเครื่องให้
- ร้องเรียน — หากไม่พอใจการดำเนินการของเรา ร้องเรียนต่อสำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล (สคส./PDPC) ได้
ใช้สิทธิได้โดยส่งอีเมลจากอีเมลที่คุณใช้สมัครมาที่ contact@cosyntec.com
11. การลบบัญชี
คุณลบบัญชีและข้อมูลทั้งหมดได้ด้วยตัวเองในแอป ที่แท็บ “ฉัน” → หน้า “ข้อมูลของฉัน” → เลื่อนลงล่างสุด → “ลบบัญชีของฉัน” ระบบจะให้คุณยืนยันตัวตนซ้ำด้วยรหัสผ่าน (หรือด้วย Google สำหรับบัญชีที่เข้าระบบด้วย Google) ก่อนเสมอ
เมื่อกดยืนยัน ระบบจะลบข้อมูลต่อไปนี้ทันที โดยข้อมูลในฐานข้อมูลถูกลบรวมเป็นรายการเดียวกันทั้งชุด ถ้าล้มเหลวกลางทาง บัญชีจะยังอยู่ครบเหมือนเดิม ไม่ถูกลบค้างครึ่ง ๆ กลาง ๆ จากนั้นจึงลบตัวไฟล์บนเครื่องแม่ข่ายต่อ หลังการลบข้อมูลชุดนั้นสำเร็จแล้ว ไม่ใช่ลบไปพร้อมกัน เพราะการลบไฟล์ออกจากดิสก์ย้อนกลับไม่ได้ ถ้าลบไฟล์ก่อนแล้วการลบข้อมูลล้มเหลว รูปและเอกสารของบัญชีที่ยังอยู่ก็จะหายไปเปล่า ๆ
- ชื่อ อีเมล เบอร์โทร ที่อยู่ วันเกิด กรุ๊ปเลือด และสิทธิการรักษา
- บันทึกการพบแพทย์ทั้งหมด รวมข้อความถอดเสียง การวินิจฉัย ยา บันทึกการกินยา และการนัดหมาย
- บัตรสุขภาพ: โรคประจำตัว การแพ้ยา การผ่าตัด วัคซีน และผู้ติดต่อฉุกเฉิน
- ไฟล์ที่อัปโหลดไว้ ทั้งรายการในระบบและตัวไฟล์บนเครื่องแม่ข่าย
- ลิงก์แบ่งปันทุกลิงก์ โทเค็นยืนยันทั้งหมด รายการอีเมลที่เคยส่งถึงคุณ และบันทึกความผิดพลาดของ AI ที่ผูกกับบัญชีคุณ
- การเข้าใช้งานทุกเครื่องจะถูกตัดทันที
- ลบแล้วกู้คืนไม่ได้ กรุณาบันทึกหรือพิมพ์สิ่งที่ต้องการเก็บไว้ก่อน
- บัญชีที่เป็นผู้ดูแลระบบคนสุดท้ายจะลบไม่ได้จนกว่าจะตั้งผู้ดูแลระบบคนอื่นก่อน
- ถ้าคุณเข้าแอปไม่ได้แล้ว ส่งอีเมลจากอีเมลที่ใช้สมัครมาที่ contact@cosyntec.com พร้อมข้อความ “ขอลบบัญชี” เราจะดำเนินการภายใน 30 วันและตอบกลับเมื่อเสร็จ
- สำเนาสำรองอาจยังมีข้อมูลของคุณอยู่ได้นานที่สุด 30 วัน ก่อนจะถูกลบทิ้งอัตโนมัติ (ดูข้อ 7)
- ข้อมูลที่เคยถูกส่งให้ผู้ให้บริการ AI ไปแล้ว เราเรียกคืนหรือสั่งลบแทนคุณไม่ได้
12. เด็กและเยาวชน
WellNote ออกแบบมาสำหรับผู้ใหญ่ โดยเฉพาะผู้สูงอายุและลูกหลานที่ช่วยดูแล ขั้นตอนการสมัครไม่ได้ถามอายุ เราจึงไม่สามารถตรวจสอบอายุของผู้สมัครได้ ถ้าผู้เยาว์จะใช้งาน ผู้ปกครองควรเป็นผู้สร้างบัญชีและดูแลการใช้งาน หากทราบว่ามีบัญชีของผู้เยาว์ที่สร้างขึ้นโดยไม่ได้รับความยินยอมจากผู้ปกครอง กรุณาแจ้งเรา แล้วเราจะลบให้
13. การเปลี่ยนแปลงนโยบายนี้
ถ้ามีการเปลี่ยนแปลงที่มีผลต่อคุณอย่างมีนัยสำคัญ — โดยเฉพาะเรื่องผู้ให้บริการ AI ที่กล่าวถึงในข้อ 4 — เราจะปรับข้อความในหน้านี้ พร้อมเปลี่ยนหมายเลขเวอร์ชันและวันที่ด้านบน และแจ้งให้ทราบในแอป
14. ติดต่อเรา
Cosyntec (ผู้ให้บริการ WellNote)
อีเมล: contact@cosyntec.com
WellNote — Privacy Policy (English)
WellNote is a note-keeping tool. It is not a diagnostic tool and does not direct treatment. Never start, stop or change the dose of a medicine because of something the app or the AI said — always ask a doctor or pharmacist.
1. What we collect
- Account: email (lower-cased), name, password stored only as a one-way scrypt hash, Google user id and Google profile picture URL if you use Google Sign-In, email-verification timestamp, last-password-change timestamp, account role (user/admin), disabled flag, your display-mode preference (basic/advanced), and — once you agree to it — the date and time you granted AI consent plus the version string of the disclosure you agreed to, which embeds the recipients that were named to you at the time (for example
gemini+openai) so that adding a new recipient invalidates the stored consent and you are asked again. - Health profile: date/year of birth, gender, height, weight, blood type, phone number, home address, healthcare coverage, and a denormalised short list of chronic conditions and allergies.
- Health card: conditions, allergies (substance, reaction, severity), surgeries, vaccinations (including next-dose date), and emergency contacts — a third party's name, relationship and phone number. Each AI-suggested entry records which visit it came from and when you confirmed it.
- Visits and medicine pick-ups: date, hospital, department, doctor name, the full verbatim transcript (including every later addition, timestamped), input method, a “doctor acknowledged” flag with its timestamp, chief complaint, summary, key advice, health notes, status, plus diagnoses (with ICD-10 where present), medications, per-dose logs and appointments. When a record is contributed through a share link, the contributor's name is stored on the record — third-party personal data.
- Uploaded files: JPEG/PNG/WebP/HEIC/PDF up to 15 MB, plus the original device filename, which is frequently clinical and is also shown to share-link holders, the MIME type, the size, the file's location on our server, and a category label the app sets for you — not one you choose: neither client offers any way to tag a file, so anything attached from the visit screens is stored as
documentand a photo taken in the web app's medicine-pick-up screen is stored asphoto(the Android app always sendsdocument). The label is never shown to you, and the server stores whatever string the client sends without validating it. There is a field for marking a file as face-blurred, but no face-blurring exists in the system, so it is alwaysfalse— no code anywhere ever writes it; we say so rather than let it imply a feature. - Share links: your label for them, view-vs-contribute, expiry, revocation date, use count and last-used time. The share token itself is stored in plaintext (unlike verification and reset tokens, which are hashed) because it is a capability you hand out deliberately and the share screen has to re-display the same QR.
- System records: outbound-mail queue (recipient, subject, kind, status, attempts, next-retry and sent timestamps, truncated relay error; both the plain-text and the HTML message body are encrypted while queued and erased once delivered or abandoned), verification/reset tokens stored only as SHA-256 hashes with their kind, expiry, redemption time and destination address, AI error logs (provider, operation, error class, user id, and a 300-character provider message that can echo back parts of what we sent, readable by an administrator), the content-report queue (written only when you, or a holder of your share link, press "report": your user id, the report kind, which screen it came from, up to 2,000 characters of the AI answer that was reported, the reported visit id, the contributor's name, the free-text reason typed by the reporter up to 500 characters, whether the reporter was the account holder or a share-link holder — and for a share-link holder, the id of that link and the label you gave it (for example “ลูกสาว”), plus a review status and the time it was reviewed — an administrator can read the whole row, but only by opening that one report, which is logged; see section 7; deleted when you delete your account), created/updated timestamps on every record, ordinary server operation logs (with normal request logging switched off on the nearby-hospital route, because that URL contains your coordinates), and an operator settings table (for example AI provider keys) which holds no user data — listed so this account covers every table in the database.
- On your device: the web app keeps a 30-day session token, your display mode and the time you dismissed the “verify your email” banner in localStorage; the Android app stores its session token and display mode locally and disables Android Auto Backup so none of it is copied to Google Drive. The Google Play build requests 8 permissions — internet, microphone, camera, notifications, exact alarms for dose reminders, vibration, boot-completed (to re-arm reminders) and COARSE location — and does not request install permission (REQUEST_INSTALL_PACKAGES) and cannot update itself; updates come from Google Play only. The self-update checker, the install permission and a stored last-update-check timestamp exist only in the APK we hand out directly, outside Google Play.
2. What we do not collect
- No stored audio file — and a correction to what this policy used to say. Version 1.3 said “WellNote never receives your voice, never writes it to disk and never stores it”. That sentence is no longer true of the web app, and rather than leave it standing we are replacing it with the narrower statement the code actually enforces.
- Web app: when you press the microphone, one recorded segment is uploaded to our server and forwarded to Google (Gemini) to be transcribed, within that same request. What the code guarantees, and all it guarantees: the audio is held in memory for the life of one request, is never written to disk, never written to the database, and never written to a log (the log line records the byte size, the container type and the number of characters returned — not the audio and not the transcript). When the request ends the audio is gone. What is kept in your record is the transcribed text only. We are not claiming the audio is encrypted at rest or deleted after some number of days — there is nothing stored that would need deleting.
- Android app (com.comed.wellnote), the Google Play build: it does not use that route at all. Your audio never reaches us from that app, in any circumstance.
- Your device's own recogniser is still a recipient too, and a different one. On Android it does all the transcribing. In the web app it takes over when our route cannot answer — Gemini out of quota or down, an operator having removed it, or you declining the AI disclosure. We do not force offline recognition on either client (the Android app sets no
EXTRA_PREFER_OFFLINE; the web fallback uses the browser's Web Speech API). So in those cases your audio IS sent to that provider's servers instead — usually Google's, under their terms, not ours. If you do not want your voice to leave your device at all, type instead of speaking (details in section 4). - No stored location. Coordinates used for the nearby-hospital lookup are never written to the database and that route's normal request logging is switched off because the URL contains them. Only a cache key rounded to two decimals (~1 km) is held in memory for six hours. This is about storage — for where a coordinate is sent, see section 4.
- No advertising trackers or behavioural analytics. We do not sell or trade your data.
- No card or payment details. WellNote takes no money in the app.
3. AI features and what leaves our server
Six features use AI, and they are not the same on both clients — the web app has all six; the Android app has only numbers 2, 3 and 4. The Android app does not have number 1, the server-side transcription: audio from that app is never sent to us under any circumstances. It does not have 5 or 6 either.
Five of the six run only when you ask for them (a button, the microphone, or choosing a file). One does not, and we would rather say so than let you find out: the health-summary card on the home screen of the web app's newer screens asks the model to rewrite it automatically when that screen loads, if your records have changed since it was last written — and only for an account that has already granted consent. Without consent nothing is sent at all.
Before anything is sent out for the first time, the app asks for your consent. That screen names what will be sent, who receives it, and that the data leaves Thailand. Until you agree, our own server refuses the request — every route that would hand your content to a model (web-app speech transcription, visit summarisation, the assistant, medicine-photo reading and the classification of anything you add) answers 403 ai_consent_required — rather than merely hiding a button, so a client that skips the screen still gets nothing sent on your behalf. Some routes are deliberately left open: reading your consent, granting or withdrawing it, pressing “report” on an AI answer, which still works for an account that has never consented to anything — you should never have to agree to something in order to complain about it — and the home health-summary refresh in the web app, which does not answer 403: without consent it composes that card from your own rows on our server and sends nothing to anyone, because a dashboard you are entitled to read should not become an error message just because you declined to have your data sent abroad. None of those sends anything to an AI provider. You can withdraw at any time on the “ข้อมูลของฉัน” (My information) screen; the heading differs between the two apps — in the Android app it is “ให้ AI ช่วยอ่านข้อมูล”, in the web app “ตัวช่วย AI และความเป็นส่วนตัว” — then press “ยกเลิกความยินยอม” (withdraw consent). Withdrawal stops any further data leaving immediately, but what was already sent cannot be recalled.
- 1. Speech-to-text — web app only, new in version 1.4. When you press the microphone, the recorded segment is uploaded to our server and forwarded to Google (Gemini) to be turned into text, together with up to 2,000 characters of what has already been transcribed so that drug names and proper nouns stay spelled the same way across segments. Audio goes to Gemini and to Gemini only — there is no case in which a recording is passed on to OpenAI, unlike every other feature in this list. If Gemini cannot answer (no credit, over quota, an outage, or an operator having taken it out of the chain) the server tells the app to use the browser's own recogniser instead, and never invents a transcript — and the browser's recogniser is a different recipient; see section 4. Limits: one segment is capped at 5 minutes and 4 MiB, and 40 segments per 15 minutes per account. The Android app does not have this feature and never sends audio to us.
- 2. Visit summarisation sends the entire transcript of that visit (both clients).
- 3. Assistant sends your question plus context assembled from your own records: up to 50 recorded allergies, up to 50 active conditions, your 30 most recent visits (date, hospital, diagnoses, key advice, and the summary — where a visit has no summary yet, which is the case for every draft and every medicine pick-up, your chief complaint is sent in its place), up to 50 active medications, and up to 20 upcoming appointments — counted as those still flagged not-yet-done whose date and time have not already passed; an appointment nobody ever marked done is no longer sent once its date is behind you — plus the last 6 messages of the on-screen conversation (6 messages in total, not 6 question-and-answer pairs). That 6-message limit is now enforced by our server, not only by the app on your device: if more conversation is submitted, the server keeps only the last 6 messages and truncates each one to 2,000 characters before any of it is forwarded to an AI provider.
- 4. Medicine photo reading sends the photo as soon as it is taken, together with your allergy and condition list so the model can warn you (both clients).
- 5. Classifying and structuring anything you add — the web app's newer screens only, new in version 1.4. When you add one health entry, we send the text you spoke or typed (up to 20,000 characters) and/or the photo you took and/or the PDF document you chose, together with your allergy and condition list, so the model can decide what kind of entry it is and draft it for you to check. PDF documents are new here: before this version no document of yours had ever been sent to an AI provider — only text and photos. An image is capped at about 6 MB and a PDF at about 7.5 MB per request, 30 requests per 15 minutes per account. Nothing is written to the database at this step until you have read the draft and pressed save.
- 6. The home health-summary card — the web app's newer screens only, new in version 1.4. Sends up to 30 recent records, up to 50 active medications, up to 20 upcoming appointments, up to 50 allergies, up to 50 active conditions, and your approximate age and gender for the model to write a short summary (your name, phone number, home address and healthcare coverage are deliberately not sent). This is the one that runs without you pressing anything — on opening the home screen, when your records have changed since it was last written, and only if you have already granted consent. Without consent that card is composed from your own rows on our server and nothing leaves.
Current AI provider terms — please read
WellNote uses the Google Gemini API on a paid tier. Under Google's Gemini API terms for paid services, Google states that it does not use the prompts you submit — text, images, audio or documents — or the responses returned to train or improve its models and products, and states that the processing is governed by a data processing addendum under which Google acts as a data processor on our instructions. All of that is Google's own published statement about Google; we cannot inspect what Google does internally.
What has not changed: your text, your photos, the audio you record in the web app and any PDF you attach still leave our server and are processed on Google's infrastructure, which is outside Thailand, and Google still retains logs for a limited period for abuse monitoring and policy enforcement. Content already sent cannot be recalled or deleted by us on your behalf.
Before 2 August 2026 WellNote used Gemini on the unpaid tier, under whose terms Google could use submitted content to improve Google's products and human reviewers could read it. Moving to the paid tier is not retroactive: anything sent before that date cannot be recalled or changed by us.
So, plainly: if you do not want your text, photos, voice or files to leave our server at all, do not use the AI buttons, the assistant, or the medicine-photo reader, do not attach a PDF when adding a health entry, and in the web app type instead of pressing the microphone. Everything else in WellNote — recording, editing, browsing past records, reminders and family sharing — works fully without them. (A record search box exists in the web app only; the Android app does not have one.)
The paid-tier terms above are Google's and cover Google Gemini only, not the OpenAI failover below. We last verified the billing status of the Gemini project on 2 August 2026. If we ever have to fall back to an unpaid tier, where the provider may use submitted content to improve its own products, we will update this page and tell you first.
- Silent failover. If Gemini cannot answer and an OpenAI key has been configured by an administrator, the same content — text, photos and PDFs — is sent to OpenAI instead. Nothing on screen tells you this happened. The paid-tier terms above are Google's; a request served by OpenAI is governed by OpenAI's own terms. Audio is the one exception: web-app transcription calls Gemini directly and does not run through this failover chain, so a recording of your voice is never passed to OpenAI. When Gemini cannot transcribe, the browser's own recogniser takes over instead (section 4).
- The AI is never required, and when it fails we do not guess on your behalf. The offline fallback on our own server no longer structures a record. It used to try to pull drug names, doses and appointment dates out of the text by keyword matching, which read unfamiliar drug names dangerously wrongly, so it was removed. What happens instead: your words are kept exactly as you said or typed them, with nothing inferred, the screen says plainly that the AI has not summarised this entry, and it asks you to fill in the medicines (name, dose, instructions) yourself before saving. An empty medicine list therefore means nobody has read it yet, not that there are no medicines. For privacy this direction is the better one — less is inferred about you — and saving a record is never blocked by the AI.
- The AI can read things wrong. Anything it proposes for your health card is not treated as real until you confirm it, and every summary asks you to check it before saving.
- No de-identification. Text, audio, photos and files are sent as they are, including anyone else's name you mention. A recording also carries what the text does not — your voice itself, and the voices of anyone else speaking in the room, including the doctor. Type instead of speaking if you do not want that sent.
- AI providers process the content on their own infrastructure, which is outside Thailand.
4. Every third party, and exactly what reaches it
- Google Gemini API (generativelanguage.googleapis.com) — transcripts, questions with record context, photos with your allergy/condition list, PDF documents you attach when adding a health entry, and — web app only — one recorded audio segment every time you press the microphone, with up to 2,000 characters of what has already been transcribed. That audio is forwarded within one request and is never written to disk, to the database or to a log on our side; what happens to it once it reaches Google is outside our control. Paid tier: Google states it does not train on the content and acts as a data processor, but it still logs the content for a limited period for abuse monitoring. See the box above.
- OpenAI (api.openai.com) — the same text, photos and PDFs, only when an OpenAI key is configured and Gemini fails. Never audio: transcription calls Gemini directly and does not pass through the failover chain.
- Google Sign-In / Google Identity Services — only when a Client ID is configured. The web app loads
accounts.google.com/gsi/clienton the login page and on the profile page (the “link your Google account” card). Android uses Credential Manager withcredentials-play-services-authand thegoogleidlibrary. Google receives the usual connection data (including your IP) and authenticates you; our server verifies the ID token atoauth2.googleapis.comand receives your Google user id, email, name and profile-picture URL. - Google Play Services Location (Android) — the “find hospitals near me” button uses the Fused Location Provider, which resolves your position from surrounding Wi-Fi and cell towers, so device/network identifiers reach Google. We request COARSE location only, never FINE, and the resulting coordinate is not stored by us.
- Your device's or browser's speech service — a different recipient from Gemini. On Android this does all the transcribing, every time you press the microphone; WellNote itself receives no audio from that app. In the web app it is used only when our own route cannot answer — Gemini out of quota or down, an operator having disabled it, or you declining the AI disclosure — after which the rest of that recording session uses the browser's recogniser. Either way the transcription is performed by the operating system's or browser's own speech service, which may send your audio to its provider (for example Google or Apple), without passing through us. We do not force offline recognition on either client, so we cannot promise on those providers' behalf that audio stays on the device. Being honest about a technical limit: the browser's recogniser can only listen to a live microphone — an already-recorded segment cannot be fed to it — so the one segment that discovers our route is unavailable cannot be re-transcribed; the app says so and asks you to say it again. Type instead of speaking if this concerns you.
- OpenStreetMap / Overpass API (overpass-api.de) — receives your coordinates and search radius from our server, not from your device, along with a User-Agent identifying WellNote as their usage policy requires.
- Google Fonts (fonts.googleapis.com, fonts.gstatic.com) — the web app loads fonts directly from Google on every page, so Google sees your IP address and browser details. No health data is sent. The Android app bundles its text font (Sarabun) and does not make this request.
- Google Play Services — emoji font (Android) — a standard Android library that ships inside the app (androidx.emoji2) asks Google Play Services on your device for the emoji font, which Play Services may download from Google. We did not add this library; it comes with Android's UI toolkit. No health data and no account data is sent with that request, but it is a real connection to Google made by the app, so we name it.
- Google Maps (www.google.com/maps) — only if you tap the “open in maps” link under the facility list. In the web app that link carries your own coordinates in the URL, so tapping it hands your position to Google. The Android app passes only the search word “โรงพยาบาล” to whichever map app is installed and sends no coordinate of ours; that app may of course use the device's own location. Choosing a facility from the list, or typing its name, never opens a map.
- Our outbound mail relay (SMTP) — your email address, name, subject and the message body containing a one-time link. Mail is DKIM-signed when a key is configured. If no relay is configured, nothing is sent and only metadata is written to the server log.
- Our hosting provider (rented VPS) — physically holds the server and therefore the database and uploaded files.
- Anyone you give a share link to — see section 5.
We disclose your data to no one else, except where we are legally compelled to.
5. What a QR share link actually exposes
Anyone holding the link can open it with no account and no password — the link is the credential. A holder sees your name, the short condition and allergy lists held on your profile (the same two lists the home and profile screens show), your 50 most recent visits (date, hospital, chief complaint, summary, diagnoses), all active medications and all upcoming appointments. Opening a single visit reveals the full verbatim transcript and every attachment, with its original filename. Every visit in that list also carries where it came from and, for a record contributed through a share link, the name of the person who added it (or the label you gave their link, for example “ลูกสาว”) — so each link holder sees the name of every other contributor. Tell them before you hand the link out.
Those two profile lists are a copy, not a live read of your health card: the system rewrites them from the health card whenever you add, change or delete an entry there, keeping only entries you have confirmed — and, for conditions, only those not marked resolved — so an unconfirmed AI suggestion is not written into them. But in the web app you can also type into those two fields directly on the “ข้อมูลของฉัน” screen, and whatever you type is what the link shows until the next health-card change overwrites it. Do not treat any of this as a privacy control: if you are unsure, assume the holder sees everything. Over-estimating what a link exposes costs you nothing but caution; under-estimating it is how health information reaches someone you did not mean to show it to.
The only choices you have are view-only vs contribute, and how long the link lives — never expires (the default), 30 days, or 90 days. You cannot share a subset of your record or hide individual visits. Contributors can add records but never edit or delete existing ones, and their name is stored on what they add. You can revoke a link at any time; revoking also kills every file link that was handed out under it.
6. Retention
- Health records, profile, health card, medications, appointments and uploaded files are kept until you delete them. There is no automatic purge.
- Mail-queue rows: body erased on delivery or abandonment; the remaining metadata is deleted after 30 days.
- Verification tokens (24 h) and password-reset tokens (1 h) are deleted 7 days after expiry.
- Signed attachment links live 30 minutes by default (configurable, maximum 24 hours). Sessions live 30 days and die on password change, account suspension or deletion.
- AI error logs remain until an administrator clears them, and are deleted immediately when you delete your account.
- Audio recorded in the web app is not retained by us at all, so it has no retention period. It lives in our server's memory only for the request that carries it to Gemini: not written to disk, not written to the database, not written to a log, and not present in any backup. What Google keeps afterwards is a separate matter — see the next item.
- Content sent to the AI provider — text, photos, audio and PDFs — is outside our control. On the paid tier Google states it does not train on it, but it is still retained in logs for a limited period for abuse monitoring and policy enforcement. We do not know the exact window and cannot delete it on your behalf; deleting your WellNote account removes only what is held by us.
- Database backups run automatically every night at about 03:15, and copies older than 30 days are deleted automatically, so deleted data may persist in a backup copy for at most 30 days.
7. Security, and the limits we are being honest about
- HTTPS/TLS in transit; scrypt password hashing; re-authentication required for account deletion; a password change invalidates all existing sessions.
- Attachments are not public:
/uploads/requires a short-lived HMAC-signed URL, share-minted links are re-checked against the share record on every request so revoking or expiring a share kills its file links immediately, and files are servedprivate, no-store. - Uploads verify that the target visit belongs to the caller before any bytes are written to disk, and only images (JPEG, PNG, WebP, HEIC) and PDFs are accepted — decided by the file's own signature bytes, not by the Content-Type your device declares and not by the extension in the filename. If the declared type and the bytes disagree, the upload is refused. The name on disk is derived from the validated type alone; your original filename is never used to name a file on the server. Being honest about the limit: files uploaded before this check existed were not re-validated, so an unrecognised older file is served as an opaque download rather than as a document the browser will render.
- The SQLite database is not encrypted at rest. Anyone with access to the server or to a backup can read it.
- There is no data-export feature. Ask us by email and we will produce a copy.
- There is no automatic retention or purge of health records.
- You will be asked for consent again in this version. Stored consent is normally invalidated only by a change in the list of recipients, and transcription goes to Google (Gemini), who was already on that list. That rule on its own would have let a consent you gave for text and photos silently cover a recording of your voice. We did not accept that — consent to text is not consent to voice — so the version number of the disclosure itself was raised. The effect is that every account that had already agreed is asked again before its next AI action, and the new consent sheet lists audio files and PDFs among the things that are sent. If you do not want your voice sent: type instead of speaking, or withdraw consent at any time (section 3).
- Administrators can see, on the user screen: user lists, email addresses, birth year, gender, height, weight, blood type, the short condition and allergy lists, and record summaries (dates, hospitals, summaries, diagnoses, active medications, and upcoming appointments — those still marked not-done whose date has not yet passed) for support and operations, and can suspend or delete an account. That screen does not show transcripts, phone numbers, home addresses, mail bodies or password-reset links.
- One other place shows an administrator more than that: the content-report queue. When you press “report” on an AI answer, we store up to 2,000 characters of the answer the model gave you, along with your name and email, which feature it came from, and the reason typed by the reporter; reporting a record contributed through a share link also stores that contributor's name. The queue list itself does not carry the reported text — it shows only the kind of report, whose account it concerns, which screen it came from, who reported it and through what, when, and how many characters are waiting to be read. The text appears only when an administrator deliberately opens that one report, and each such opening is written to the server log naming which administrator opened whose report. Being honest about what this still means: an AI answer is usually a paraphrase of your own transcript, so if you press report, an administrator can read that content in the form of the AI's answer — even though the user screen above does not show transcripts. What changed is that doing so is now a deliberate, recorded act rather than something every operator reads in passing on opening the console. Nothing is written unless someone presses report, and the queue rows are deleted when you delete your account.
- No system is 100% secure. If a data breach occurs we will notify you and Thailand's Personal Data Protection Committee as the law requires.
8. Your rights under Thailand's PDPA
We process your health data on your explicit consent (health data is sensitive data under section 26 of the PDPA; sending anything to an AI provider requires a separate consent, and in all but one case is an act you order button-press by button-press — the exception being the home health-summary card in the web app, which refreshes itself for an account that has already consented, see section 3), on contract to run your account and send the reminders you set, on legitimate interests for system security, abuse prevention and fault-fixing (error logs, the mail queue), and on legal obligation where we are lawfully compelled to disclose. We do not use your data for advertising, do not build marketing profiles, and do not sell it.
You may request access and a copy, rectification, erasure, restriction of processing, objection to processing, data portability, and you may withdraw consent at any time. Withdrawing consent does not affect processing already lawfully carried out, and content already sent to an AI provider cannot be recalled by us. You may also complain to Thailand's Personal Data Protection Committee (PDPC).
Email us from the address you registered with at contact@cosyntec.com. We respond within 30 days.
Account deletion: in-app on the “ฉัน” tab → the “ข้อมูลของฉัน” screen → “ลบบัญชีของฉัน” at the bottom, which requires re-authentication (your password, or a fresh Google sign-in for Google-only accounts). It deletes your profile, all visits and transcripts, diagnoses, medications, dose logs, appointments, the whole health card, share links, auth tokens, mail records and AI error logs, and revokes every session. Those database rows are removed in a single transaction, so a failure part-way through leaves the account whole rather than half-erased. The uploaded files are then unlinked from the server's disk after that transaction has committed — not inside it. That order is deliberate: a file deleted from disk cannot be put back by rolling a transaction back, so unlinking first would risk destroying the documents of an account that still exists. It is immediate and irreversible. The last remaining administrator account cannot be deleted until another administrator exists. A public page explaining this is at /delete-account; if you cannot sign in, email contact@cosyntec.com from your registered address and we will delete the account within 30 days.
9. Children
WellNote is intended for adults. Registration does not ask for an age, so we cannot verify it. A parent or guardian should create and supervise any account used by a minor. Tell us if an account was created for a minor without a guardian's consent and we will delete it.
10. Changes and contact
Material changes — particularly to the AI provider terms in section 3 — will be reflected here with a new version number and date, and announced in the app.
Cosyntec · contact@cosyntec.com