นโยบายความเป็นส่วนตัว WellNote

เวอร์ชัน 1.4 · มีผลตั้งแต่วันที่ 6 สิงหาคม 2569 (6 August 2026)

ผู้ให้บริการและผู้ควบคุมข้อมูลส่วนบุคคล: Cosyntec · ติดต่อ: contact@cosyntec.com

แอปพลิเคชัน: WellNote (Android · com.comed.wellnote) และเว็บแอป WellNote

อ่านตรงนี้ก่อน — สรุปสั้น ๆ

1. เราคือใคร

WellNote พัฒนาและให้บริการโดย Cosyntec (“เรา”) เราเป็นผู้ควบคุมข้อมูลส่วนบุคคลตามพระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 (PDPA) สำหรับข้อมูลที่คุณบันทึกไว้ใน WellNote

ถ้ามีคำถาม ขอใช้สิทธิ หรือต้องการร้องเรียนเรื่องข้อมูลส่วนบุคคล ติดต่อเราได้ที่ contact@cosyntec.com

WellNote เป็นเครื่องมือช่วยจดบันทึก ไม่ใช่เครื่องมือวินิจฉัยหรือสั่งการรักษา อย่าเริ่มยา หยุดยา หรือปรับขนาดยาจากสิ่งที่แอปหรือ AI บอก ให้ปรึกษาแพทย์หรือเภสัชกรเสมอ

2. ข้อมูลที่เราเก็บ

ทั้งหมดนี้คือสิ่งที่คุณกรอกหรืออัปโหลดเข้ามาเอง และสิ่งที่ระบบสร้างขึ้นเพื่อให้แอปทำงานได้

ก. บัญชีและการเข้าสู่ระบบ

ข. โปรไฟล์สุขภาพ

ค. บัตรสุขภาพ

ง. บันทึกการพบแพทย์และบันทึกการรับยา

จ. ไฟล์ที่คุณอัปโหลด

ฉ. ลิงก์แบ่งปัน (QR)

ช. ข้อมูลที่ระบบสร้างขึ้นเอง

ซ. ข้อมูลที่เก็บบนเครื่องของคุณ

3. ข้อมูลที่เราไม่ได้เก็บ

4. AI — สิ่งสำคัญที่สุดที่คุณควรอ่าน

WellNote มีความสามารถที่ใช้ AI อยู่ 6 อย่าง ซึ่งไม่ได้มีครบทั้งสองแอป — เว็บแอปมีครบทั้ง 6 ส่วนแอป Android มีเฉพาะข้อ 2, 3 และ 4 แอป Android ไม่มีข้อ 1 (ถอดเสียงที่เซิร์ฟเวอร์ของเรา) — เสียงจากแอป Android ไม่เคยถูกส่งมาที่เราเลยไม่ว่ากรณีใด และไม่มีข้อ 5 กับข้อ 6 ด้วย

ห้าอย่างแรกทำงานเมื่อคุณสั่งเท่านั้น (กดปุ่ม กดไมค์ หรือเลือกไฟล์) แต่ขอบอกตรง ๆ ว่ามีหนึ่งอย่างที่ไม่ใช่ คือการ์ดสรุปสุขภาพบนหน้าแรกของหน้าจอชุดใหม่ในเว็บแอป (ข้อ 6 ในรายการข้างล่าง) ซึ่งจะขอให้ AI เขียนใหม่เองโดยอัตโนมัติตอนเปิดหน้าแรก ถ้าบันทึกของคุณเปลี่ยนไปตั้งแต่ครั้งก่อน — เกิดขึ้นได้เฉพาะเมื่อคุณกดยินยอมไว้แล้วเท่านั้น ถ้ายังไม่ได้กดยินยอม จะไม่มีอะไรถูกส่งออกไปเลย

ก่อนส่งข้อมูลออกไปครั้งแรก แอปจะถามความยินยอมจากคุณก่อนเสมอ หน้าจอนั้นจะบอกว่าจะส่งอะไรไป ส่งให้ใคร และข้อมูลจะออกนอกประเทศไทย ถ้าคุณยังไม่กดยินยอม เครื่องแม่ข่ายของเราจะปฏิเสธคำขอนั้นเอง ไม่ใช่แค่ซ่อนปุ่มไว้ — ทุกเส้นทางที่จะส่งเนื้อหาของคุณออกไปให้โมเดล (การถอดเสียงในเว็บแอป สรุปการพบแพทย์ ผู้ช่วยตอบคำถาม การอ่านรูปยา และการจัดหมวดหมู่ข้อมูลที่คุณเพิ่มเข้ามา) จะตอบกลับเป็น 403 ai_consent_required มีสามอย่างที่เราเปิดไว้โดยตั้งใจ คือการอ่านและการกดยินยอม/ถอนความยินยอมเอง การกดปุ่ม “รายงาน” คำตอบของ AI ซึ่งใช้ได้เสมอ แม้บัญชีนั้นไม่เคยกดยินยอมอะไรเลย เพราะคุณไม่ควรต้องยอมรับอะไรก่อน จึงจะร้องเรียนเรื่องเนื้อหาได้ และการ์ดสรุปสุขภาพบนหน้าแรกของหน้าจอชุดใหม่ในเว็บแอป ซึ่งไม่ตอบ 403 แต่จะเขียนการ์ดนั้นจากข้อมูลของคุณเองบนเครื่องแม่ข่าย และไม่ส่งอะไรออกไปให้ใครเลย เพราะหน้าแรกที่คุณมีสิทธิ์ดูไม่ควรกลายเป็นข้อความผิดพลาดเพียงเพราะคุณไม่ยอมให้ส่งข้อมูลออก และคุณถอนความยินยอมเมื่อไรก็ได้ที่หน้า “ข้อมูลของฉัน” — ชื่อหัวข้อบนหน้านั้นไม่เหมือนกันในสองแอป คือในแอป Android อยู่ใต้หัวข้อ “ให้ AI ช่วยอ่านข้อมูล” ส่วนในเว็บแอปอยู่ใต้หัวข้อ “ตัวช่วย AI และความเป็นส่วนตัว” แล้วกดปุ่ม “ยกเลิกความยินยอม” เมื่อถอนแล้ว ระบบจะหยุดส่งข้อมูลใหม่ออกไปทันที (แต่สิ่งที่ส่งไปก่อนหน้านั้นเรียกคืนไม่ได้)

ข้อควรทราบเรื่องผู้ให้บริการ AI ที่ WellNote ใช้อยู่ในขณะนี้

ขณะนี้ WellNote ใช้บริการ Google Gemini แบบเสียค่าบริการ (paid tier) ตามเงื่อนไขการใช้งานของ Google สำหรับบริการแบบเสียค่าบริการ Google ระบุว่าจะไม่นำข้อความ รูปภาพ เสียง ไฟล์เอกสาร หรือคำถามที่ส่งไป ไปใช้ฝึกหรือปรับปรุงโมเดลและผลิตภัณฑ์ของ Google และระบุว่าประมวลผลข้อมูลภายใต้ข้อตกลงการประมวลผลข้อมูล (Data Processing Addendum) คือ Google ทำหน้าที่เป็นผู้ประมวลผลข้อมูลตามคำสั่งของเรา ทั้งหมดนี้เป็นสิ่งที่ Google ประกาศไว้เอง เราตรวจสอบการทำงานภายในของ Google แทนคุณไม่ได้

แต่สิ่งที่ไม่ได้เปลี่ยน และเราขอบอกตรง ๆ คือ: ข้อความ รูป เสียงที่อัดในเว็บแอป และไฟล์ PDF ที่คุณเลือกของคุณยังถูกส่งออกไปนอกเซิร์ฟเวอร์ของเรา ไปประมวลผลที่เครื่องของ Google ซึ่งอยู่นอกประเทศไทย และ Google ยังเก็บบันทึกการใช้งานไว้ระยะเวลาหนึ่ง เพื่อตรวจสอบการใช้งานที่ผิดเงื่อนไขและการละเมิดนโยบาย ข้อมูลที่ส่งไปแล้วเราเรียกคืนหรือสั่งลบแทนคุณไม่ได้

ก่อนวันที่ 2 สิงหาคม 2569 WellNote ใช้ Gemini แบบไม่เสียค่าบริการ ซึ่งตามเงื่อนไขในตอนนั้น Google อาจนำเนื้อหาที่ส่งไปไปใช้พัฒนาและปรับปรุงผลิตภัณฑ์ของ Google ได้ และเจ้าหน้าที่ของ Google อาจอ่านได้ การเปลี่ยนมาใช้แบบเสียค่าบริการไม่ย้อนหลัง — สิ่งที่ส่งไปก่อนวันนั้นเราเรียกคืนหรือแก้ไขให้ไม่ได้

ดังนั้น ถ้าคุณไม่ต้องการให้ข้อความ รูป เสียง หรือไฟล์ของคุณออกจากเซิร์ฟเวอร์ของเราเลย กรุณาอย่ากดปุ่มที่ให้ AI ช่วย อย่าใช้หน้าผู้ช่วยตอบคำถาม อย่าถ่ายรูปยาให้ AI อ่าน อย่าแนบไฟล์ PDF เข้าไปในหน้าเพิ่มข้อมูลสุขภาพ และในเว็บแอป ให้พิมพ์แทนการกดไมค์ WellNote ยังใช้บันทึก แก้ไข ย้อนดูบันทึกเก่า เตือนกินยา และแบ่งปันให้ลูกหลานได้ครบทุกอย่างโดยไม่ต้องใช้ AI เลย (ช่องค้นหาบันทึกมีเฉพาะในเว็บแอป)

ข้อความข้างต้นเป็นเงื่อนไขของ Google Gemini แบบเสียค่าบริการ เท่านั้น ไม่ครอบคลุมผู้ให้บริการสำรอง (ดูหัวข้อถัดไป) เราตรวจสอบสถานะบัญชีแบบเสียค่าบริการครั้งล่าสุดเมื่อวันที่ 2 สิงหาคม 2569 หากวันหนึ่งเราต้องกลับไปใช้แบบไม่เสียค่าบริการ ซึ่งผู้ให้บริการอาจนำข้อมูลไปใช้พัฒนาผลิตภัณฑ์ของเขา เราจะแก้ข้อความในหน้านี้และแจ้งให้ทราบก่อน

เรื่องอื่นเกี่ยวกับ AI ที่คุณควรรู้

5. บุคคลภายนอกที่ได้รับข้อมูล และได้รับอะไรบ้าง

นี่คือรายชื่อทั้งหมดที่ข้อมูลของคุณอาจไปถึง

Google — Gemini API (generativelanguage.googleapis.com)

เมื่อไร: เมื่อคุณกดให้ AI สรุป ถามผู้ช่วย ถ่ายรูปยาให้อ่าน เพิ่มข้อมูลสุขภาพให้ระบบจัดหมวดหมู่ (เว็บแอป) เปิดหน้าแรกของหน้าจอชุดใหม่ทั้งที่ยินยอมไว้แล้ว (เว็บแอป) และ — เฉพาะเว็บแอป — ทุกครั้งที่คุณกดไมค์เพื่ออัดเสียง

สิ่งที่ส่งไป: ข้อความถอดเสียงฉบับเต็ม / คำถามของคุณพร้อมสรุปประวัติ ยา นัดหมาย และรายการแพ้ยา / รูปภาพที่ถ่าย พร้อมรายการแพ้ยาและโรคประจำตัว / ไฟล์เอกสาร PDF ที่คุณเลือกแนบในหน้าเพิ่มข้อมูลสุขภาพ / และ — เฉพาะเว็บแอป — ไฟล์เสียงที่อัดได้หนึ่งช่วง พร้อมข้อความที่ถอดไว้ก่อนหน้าไม่เกิน 2,000 ตัวอักษร

เสียงถูกส่งให้ Gemini ในคำขอเดียว ไม่ถูกเขียนลงดิสก์ ไม่ถูกเก็บลงฐานข้อมูล และไม่ถูกเขียนลง log ที่เรา — แต่สิ่งที่เกิดขึ้นหลังจากถึง Google อยู่นอกการควบคุมของเรา · ขณะนี้ใช้แบบเสียค่าบริการ (paid tier) — Google ระบุว่าจะไม่นำข้อมูลไปฝึกโมเดล และประมวลผลในฐานะผู้ประมวลผลข้อมูลแทนเรา แต่ยังเก็บบันทึกการใช้งานไว้ระยะเวลาหนึ่งเพื่อตรวจสอบการใช้ผิดเงื่อนไข — ดูกรอบสีแดงในข้อ 4

OpenAI (api.openai.com)

เมื่อไร: เฉพาะเมื่อผู้ดูแลระบบตั้งค่ากุญแจ OpenAI ไว้ และ Gemini ตอบไม่ได้ ระบบจะสลับให้เองโดยไม่แจ้งบนหน้าจอ

สิ่งที่ส่งไป: ข้อมูลชุดเดียวกับที่ส่งให้ Gemini — ข้อความ รูป และไฟล์ PDF

ยกเว้นอย่างเดียวคือ ไฟล์เสียง: การถอดเสียงเรียก Gemini โดยตรง ไม่ผ่านลำดับผู้ให้บริการสำรอง เสียงของคุณจึงไม่ถูกส่งไปให้ OpenAI ในทุกกรณี

Google Sign-In / Google Identity Services

เมื่อไร: เฉพาะเมื่อผู้ดูแลระบบตั้งค่า Client ID ไว้ เว็บจะโหลดสคริปต์ accounts.google.com/gsi/client ทั้งใน “หน้าเข้าสู่ระบบ” และ “หน้าโปรไฟล์” (ปุ่มเชื่อมบัญชี Google) ส่วนแอป Android ใช้ Credential Manager ของ Google Play Services

สิ่งที่ส่งไป: Google ได้รับข้อมูลการเชื่อมต่อของเบราว์เซอร์/เครื่องคุณตามปกติของ Google (เช่น หมายเลข IP) และคุณต้องเข้าสู่ระบบบัญชี Google ของคุณ · เราได้รับกลับมาเฉพาะ รหัสผู้ใช้ Google อีเมล ชื่อ และลิงก์รูปโปรไฟล์ โดยเซิร์ฟเวอร์ของเราส่งโทเค็นไปตรวจสอบที่ oauth2.googleapis.com

ถ้าไม่ได้ตั้งค่า Client ID ไว้ จะไม่มีการโหลดสคริปต์นี้เลย

Google Play Services — บริการระบุตำแหน่ง (แอป Android)

เมื่อไร: เมื่อคุณกดปุ่ม “หาโรงพยาบาลใกล้ฉัน” และอนุญาตให้เข้าถึงตำแหน่ง

สิ่งที่ส่งไป: แอปใช้ Fused Location Provider ของ Google ซึ่งหาตำแหน่งจากสัญญาณ Wi-Fi และเสาสัญญาณรอบตัวคุณ แปลว่า Google จะได้รับข้อมูลระบุอุปกรณ์/เครือข่ายของคุณตามการทำงานของบริการนั้น

เราขอเฉพาะตำแหน่งแบบคร่าว ๆ (COARSE) ไม่ใช่ตำแหน่งละเอียด และพิกัดที่ได้ไม่ถูกบันทึกไว้ที่เรา

บริการถอดเสียงของเครื่องหรือเบราว์เซอร์ของคุณ (ผู้รับคนละรายกับ Gemini)

เมื่อไร: ในแอป Android: ทุกครั้งที่คุณกดปุ่มพูดเพื่อบันทึก · ในเว็บแอป: เฉพาะเมื่อเส้นทางของเราใช้ไม่ได้ — Gemini ตอบไม่ได้ ใช้เกินโควตา ผู้ดูแลปิดไว้ หรือคุณไม่กดยินยอม — จากนั้นทั้งการอัดที่เหลือในครั้งนั้นจะใช้ตัวถอดเสียงของเบราว์เซอร์

สิ่งที่ส่งไป: เสียงพูดของคุณ ซึ่ง — ขึ้นอยู่กับเครื่องและการตั้งค่าของคุณ — ตัวถอดเสียงนั้นอาจส่งไปประมวลผลที่เซิร์ฟเวอร์ของผู้ให้บริการรายนั้น (เช่น Google หรือ Apple) ในกรณีนี้เสียงไม่ได้ผ่านเราเลย

เราไม่ได้บังคับให้ถอดเสียงแบบออฟไลน์ ทั้งในแอป Android และในเว็บแอป เราจึงยืนยันแทนผู้ให้บริการเหล่านั้นไม่ได้ว่าเสียงอยู่ในเครื่องเสมอ · ข้อจำกัดทางเทคนิคที่บอกตรง ๆ: ตัวถอดเสียงของเบราว์เซอร์ฟังได้เฉพาะไมค์สด ป้อนไฟล์ที่อัดไว้แล้วให้มันไม่ได้ ช่วงเสียงช่วงที่ค้นพบว่าเส้นทางของเราใช้ไม่ได้จึงถอดซ้ำไม่ได้ ระบบจะบอกคุณตรง ๆ ให้พูดช่วงนั้นใหม่ ถ้าคุณกังวล ให้พิมพ์แทนการพูด

OpenStreetMap / Overpass API (overpass-api.de)

เมื่อไร: เมื่อคุณกดค้นหาสถานพยาบาลใกล้เคียง

สิ่งที่ส่งไป: พิกัดของคุณและรัศมีที่ค้นหา — ส่งจากเซิร์ฟเวอร์ของเรา ไม่ใช่จากเครื่องของคุณโดยตรง พร้อมชื่อโปรแกรมของเรา (WellNote) ตามที่นโยบายการใช้งานของเขากำหนด

Google Fonts (fonts.googleapis.com, fonts.gstatic.com)

เมื่อไร: ทุกครั้งที่คุณเปิดเว็บแอป WellNote

สิ่งที่ส่งไป: เบราว์เซอร์ของคุณโหลดฟอนต์จากเซิร์ฟเวอร์ของ Google โดยตรง Google จึงเห็นหมายเลข IP และข้อมูลเบราว์เซอร์ของคุณ ไม่มีข้อมูลสุขภาพส่งไปที่นี่

แอป Android ฝังฟอนต์ภาษาไทย (Sarabun) ไว้ในตัวแอป จึงไม่โหลดฟอนต์ตัวหนังสือจาก Google — แต่ดูรายการถัดไปเรื่องฟอนต์อีโมจิ

Google Play Services — ฟอนต์อีโมจิ (แอป Android)

เมื่อไร: ตอนเปิดแอปครั้งแรก ๆ และเมื่อระบบต้องอัปเดตฟอนต์อีโมจิ

สิ่งที่ส่งไป: ไลบรารีมาตรฐานของ Android (androidx.emoji2) ที่มากับแอป ขอฟอนต์อีโมจิผ่าน Google Play Services ในเครื่องคุณ ซึ่งอาจดาวน์โหลดฟอนต์นั้นจาก Google — ไม่มีข้อมูลสุขภาพหรือข้อมูลบัญชีของคุณส่งไปกับคำขอนี้

เราไม่ได้ใส่ไลบรารีนี้เอง มันมากับชุดเครื่องมือหน้าจอของ Android เราแจ้งไว้เพราะเป็นการติดต่อ Google ที่เกิดขึ้นจริงจากแอป

Google Maps (www.google.com/maps)

เมื่อไร: เฉพาะเมื่อคุณกดลิงก์ “ไม่เจอที่นี่? เปิดดูในแผนที่” ใต้รายชื่อสถานพยาบาล

สิ่งที่ส่งไป: ในเว็บแอป ลิงก์นี้มีพิกัดของคุณอยู่ใน URL (เปิดแผนที่ค้นหาคำว่า “โรงพยาบาล” ที่ตำแหน่งของคุณ) ดังนั้นถ้าคุณกดปุ่มนี้ Google จะได้รับพิกัดของคุณ · ส่วนแอป Android ส่งเพียงคำค้น “โรงพยาบาล” ไปให้แอปแผนที่ ไม่ได้ส่งพิกัดจากเราไปด้วย (แอปแผนที่อาจใช้ตำแหน่งของเครื่องคุณเองตามการตั้งค่าของมัน)

ถ้าไม่ต้องการให้พิกัดของคุณไปถึง Google กรุณาอย่ากดลิงก์นี้ — การเลือกสถานพยาบาลจากรายชื่อ และการพิมพ์ชื่อเอง ทำได้โดยไม่ต้องเปิดแผนที่

ผู้ให้บริการรับส่งอีเมล (SMTP relay) ที่เราตั้งค่าไว้

เมื่อไร: เมื่อคุณสมัคร ขอยืนยันอีเมล หรือขอตั้งรหัสผ่านใหม่

สิ่งที่ส่งไป: อีเมลของคุณ ชื่อของคุณ หัวเรื่อง และเนื้อความซึ่งมีลิงก์ใช้ครั้งเดียว — เราเซ็นอีเมลด้วย DKIM เมื่อกุญแจถูกตั้งค่าไว้

ถ้ายังไม่ได้ตั้งค่าผู้ให้บริการอีเมล ระบบจะไม่ส่งจริงและบันทึกไว้ใน log ของเซิร์ฟเวอร์แทน โดยไม่บันทึกเนื้อความในเครื่องที่ใช้งานจริง

ผู้ให้บริการเครื่องแม่ข่าย (VPS) ที่เราเช่าใช้

เมื่อไร: ตลอดเวลา

สิ่งที่ส่งไป: ข้อมูลทั้งหมดของ WellNote เก็บอยู่บนเครื่องแม่ข่ายที่เราเช่า ผู้ให้บริการรายนั้นเป็นผู้ดูแลเครื่องทางกายภาพ

คนที่คุณส่งลิงก์ QR ให้เอง

เมื่อไร: เมื่อคุณสร้างลิงก์แบ่งปันและส่งให้ใครก็ตาม

สิ่งที่ส่งไป: ดูรายละเอียดในข้อ 6 — เขาจะเห็นเกือบทั้งหมดของบันทึกคุณ

นอกจากรายชื่อข้างต้น เราไม่เปิดเผยข้อมูลของคุณให้ใครอีก เว้นแต่มีคำสั่งตามกฎหมายหรือหมายศาลที่เราต้องปฏิบัติตาม

6. ลิงก์แบ่งปันสำหรับลูกหลาน — สิ่งที่เขาเห็นจริง ๆ

เมื่อคุณสร้างลิงก์แบ่งปัน (QR) ใครก็ตามที่ถือลิงก์นั้นเปิดดูได้โดยไม่ต้องมีบัญชีและไม่ต้องใส่รหัสผ่าน ตัวลิงก์คือกุญแจในตัวมันเอง กรุณาส่งให้เฉพาะคนที่คุณไว้ใจจริง ๆ

ผู้ถือลิงก์จะเห็น:

สิ่งที่คุณเลือกได้มีเพียงสองอย่าง: จะให้ “ดูอย่างเดียว” หรือ “ช่วยเพิ่มบันทึกได้ด้วย” และจะให้ลิงก์อยู่นานแค่ไหน โดยเลือกได้สามแบบคือ ไม่หมดอายุ (ค่าเริ่มต้น) · 30 วัน · 90 วัน คุณเลือกแบ่งเฉพาะบางเรื่องหรือซ่อนบางบันทึกไม่ได้

7. เราเก็บข้อมูลไว้นานแค่ไหน

8. ความปลอดภัย และข้อจำกัดที่เราบอกตรง ๆ

สิ่งที่เราทำ

ข้อจำกัดที่คุณควรรู้ก่อนใช้

9. ทำไมเราถึงเก็บ และฐานทางกฎหมาย

เราไม่ใช้ข้อมูลของคุณเพื่อโฆษณา ไม่สร้างโปรไฟล์การตลาด และไม่ขายข้อมูลให้ใคร

10. สิทธิของคุณ และวิธีใช้สิทธิ

ตาม PDPA คุณมีสิทธิดังนี้ และเราจะตอบกลับภายใน 30 วัน

ใช้สิทธิได้โดยส่งอีเมลจากอีเมลที่คุณใช้สมัครมาที่ contact@cosyntec.com

11. การลบบัญชี

คุณลบบัญชีและข้อมูลทั้งหมดได้ด้วยตัวเองในแอป ที่แท็บ “ฉัน” → หน้า “ข้อมูลของฉัน” → เลื่อนลงล่างสุด → “ลบบัญชีของฉัน” ระบบจะให้คุณยืนยันตัวตนซ้ำด้วยรหัสผ่าน (หรือด้วย Google สำหรับบัญชีที่เข้าระบบด้วย Google) ก่อนเสมอ

เมื่อกดยืนยัน ระบบจะลบข้อมูลต่อไปนี้ทันที โดยข้อมูลในฐานข้อมูลถูกลบรวมเป็นรายการเดียวกันทั้งชุด ถ้าล้มเหลวกลางทาง บัญชีจะยังอยู่ครบเหมือนเดิม ไม่ถูกลบค้างครึ่ง ๆ กลาง ๆ จากนั้นจึงลบตัวไฟล์บนเครื่องแม่ข่ายต่อ หลังการลบข้อมูลชุดนั้นสำเร็จแล้ว ไม่ใช่ลบไปพร้อมกัน เพราะการลบไฟล์ออกจากดิสก์ย้อนกลับไม่ได้ ถ้าลบไฟล์ก่อนแล้วการลบข้อมูลล้มเหลว รูปและเอกสารของบัญชีที่ยังอยู่ก็จะหายไปเปล่า ๆ

12. เด็กและเยาวชน

WellNote ออกแบบมาสำหรับผู้ใหญ่ โดยเฉพาะผู้สูงอายุและลูกหลานที่ช่วยดูแล ขั้นตอนการสมัครไม่ได้ถามอายุ เราจึงไม่สามารถตรวจสอบอายุของผู้สมัครได้ ถ้าผู้เยาว์จะใช้งาน ผู้ปกครองควรเป็นผู้สร้างบัญชีและดูแลการใช้งาน หากทราบว่ามีบัญชีของผู้เยาว์ที่สร้างขึ้นโดยไม่ได้รับความยินยอมจากผู้ปกครอง กรุณาแจ้งเรา แล้วเราจะลบให้

13. การเปลี่ยนแปลงนโยบายนี้

ถ้ามีการเปลี่ยนแปลงที่มีผลต่อคุณอย่างมีนัยสำคัญ — โดยเฉพาะเรื่องผู้ให้บริการ AI ที่กล่าวถึงในข้อ 4 — เราจะปรับข้อความในหน้านี้ พร้อมเปลี่ยนหมายเลขเวอร์ชันและวันที่ด้านบน และแจ้งให้ทราบในแอป

14. ติดต่อเรา

Cosyntec (ผู้ให้บริการ WellNote)
อีเมล: contact@cosyntec.com

เรื่องที่ติดต่อได้: ขอใช้สิทธิตาม PDPA · ขอสำเนาข้อมูล · ขอลบบัญชี · แจ้งปัญหาความเป็นส่วนตัว · สอบถามเรื่องนโยบายนี้


WellNote — Privacy Policy (English)

Version 1.4 · Effective 6 August 2026 · Provider and data controller: Cosyntec · contact@cosyntec.com
Apps covered: WellNote for Android (com.comed.wellnote) and the WellNote web app. This English text is a translation for reviewers; the Thai text above is the operative version.

WellNote is a note-keeping tool. It is not a diagnostic tool and does not direct treatment. Never start, stop or change the dose of a medicine because of something the app or the AI said — always ask a doctor or pharmacist.

1. What we collect

2. What we do not collect

3. AI features and what leaves our server

Six features use AI, and they are not the same on both clients — the web app has all six; the Android app has only numbers 2, 3 and 4. The Android app does not have number 1, the server-side transcription: audio from that app is never sent to us under any circumstances. It does not have 5 or 6 either.

Five of the six run only when you ask for them (a button, the microphone, or choosing a file). One does not, and we would rather say so than let you find out: the health-summary card on the home screen of the web app's newer screens asks the model to rewrite it automatically when that screen loads, if your records have changed since it was last written — and only for an account that has already granted consent. Without consent nothing is sent at all.

Before anything is sent out for the first time, the app asks for your consent. That screen names what will be sent, who receives it, and that the data leaves Thailand. Until you agree, our own server refuses the request — every route that would hand your content to a model (web-app speech transcription, visit summarisation, the assistant, medicine-photo reading and the classification of anything you add) answers 403 ai_consent_required — rather than merely hiding a button, so a client that skips the screen still gets nothing sent on your behalf. Some routes are deliberately left open: reading your consent, granting or withdrawing it, pressing “report” on an AI answer, which still works for an account that has never consented to anything — you should never have to agree to something in order to complain about it — and the home health-summary refresh in the web app, which does not answer 403: without consent it composes that card from your own rows on our server and sends nothing to anyone, because a dashboard you are entitled to read should not become an error message just because you declined to have your data sent abroad. None of those sends anything to an AI provider. You can withdraw at any time on the “ข้อมูลของฉัน” (My information) screen; the heading differs between the two apps — in the Android app it is “ให้ AI ช่วยอ่านข้อมูล”, in the web app “ตัวช่วย AI และความเป็นส่วนตัว” — then press “ยกเลิกความยินยอม” (withdraw consent). Withdrawal stops any further data leaving immediately, but what was already sent cannot be recalled.

Current AI provider terms — please read

WellNote uses the Google Gemini API on a paid tier. Under Google's Gemini API terms for paid services, Google states that it does not use the prompts you submit — text, images, audio or documents — or the responses returned to train or improve its models and products, and states that the processing is governed by a data processing addendum under which Google acts as a data processor on our instructions. All of that is Google's own published statement about Google; we cannot inspect what Google does internally.

What has not changed: your text, your photos, the audio you record in the web app and any PDF you attach still leave our server and are processed on Google's infrastructure, which is outside Thailand, and Google still retains logs for a limited period for abuse monitoring and policy enforcement. Content already sent cannot be recalled or deleted by us on your behalf.

Before 2 August 2026 WellNote used Gemini on the unpaid tier, under whose terms Google could use submitted content to improve Google's products and human reviewers could read it. Moving to the paid tier is not retroactive: anything sent before that date cannot be recalled or changed by us.

So, plainly: if you do not want your text, photos, voice or files to leave our server at all, do not use the AI buttons, the assistant, or the medicine-photo reader, do not attach a PDF when adding a health entry, and in the web app type instead of pressing the microphone. Everything else in WellNote — recording, editing, browsing past records, reminders and family sharing — works fully without them. (A record search box exists in the web app only; the Android app does not have one.)

The paid-tier terms above are Google's and cover Google Gemini only, not the OpenAI failover below. We last verified the billing status of the Gemini project on 2 August 2026. If we ever have to fall back to an unpaid tier, where the provider may use submitted content to improve its own products, we will update this page and tell you first.

4. Every third party, and exactly what reaches it

We disclose your data to no one else, except where we are legally compelled to.

5. What a QR share link actually exposes

Anyone holding the link can open it with no account and no password — the link is the credential. A holder sees your name, the short condition and allergy lists held on your profile (the same two lists the home and profile screens show), your 50 most recent visits (date, hospital, chief complaint, summary, diagnoses), all active medications and all upcoming appointments. Opening a single visit reveals the full verbatim transcript and every attachment, with its original filename. Every visit in that list also carries where it came from and, for a record contributed through a share link, the name of the person who added it (or the label you gave their link, for example “ลูกสาว”) — so each link holder sees the name of every other contributor. Tell them before you hand the link out.

Those two profile lists are a copy, not a live read of your health card: the system rewrites them from the health card whenever you add, change or delete an entry there, keeping only entries you have confirmed — and, for conditions, only those not marked resolved — so an unconfirmed AI suggestion is not written into them. But in the web app you can also type into those two fields directly on the “ข้อมูลของฉัน” screen, and whatever you type is what the link shows until the next health-card change overwrites it. Do not treat any of this as a privacy control: if you are unsure, assume the holder sees everything. Over-estimating what a link exposes costs you nothing but caution; under-estimating it is how health information reaches someone you did not mean to show it to.

The only choices you have are view-only vs contribute, and how long the link lives — never expires (the default), 30 days, or 90 days. You cannot share a subset of your record or hide individual visits. Contributors can add records but never edit or delete existing ones, and their name is stored on what they add. You can revoke a link at any time; revoking also kills every file link that was handed out under it.

6. Retention

7. Security, and the limits we are being honest about

8. Your rights under Thailand's PDPA

We process your health data on your explicit consent (health data is sensitive data under section 26 of the PDPA; sending anything to an AI provider requires a separate consent, and in all but one case is an act you order button-press by button-press — the exception being the home health-summary card in the web app, which refreshes itself for an account that has already consented, see section 3), on contract to run your account and send the reminders you set, on legitimate interests for system security, abuse prevention and fault-fixing (error logs, the mail queue), and on legal obligation where we are lawfully compelled to disclose. We do not use your data for advertising, do not build marketing profiles, and do not sell it.

You may request access and a copy, rectification, erasure, restriction of processing, objection to processing, data portability, and you may withdraw consent at any time. Withdrawing consent does not affect processing already lawfully carried out, and content already sent to an AI provider cannot be recalled by us. You may also complain to Thailand's Personal Data Protection Committee (PDPC).

Email us from the address you registered with at contact@cosyntec.com. We respond within 30 days.

Account deletion: in-app on the “ฉัน” tab → the “ข้อมูลของฉัน” screen → “ลบบัญชีของฉัน” at the bottom, which requires re-authentication (your password, or a fresh Google sign-in for Google-only accounts). It deletes your profile, all visits and transcripts, diagnoses, medications, dose logs, appointments, the whole health card, share links, auth tokens, mail records and AI error logs, and revokes every session. Those database rows are removed in a single transaction, so a failure part-way through leaves the account whole rather than half-erased. The uploaded files are then unlinked from the server's disk after that transaction has committed — not inside it. That order is deliberate: a file deleted from disk cannot be put back by rolling a transaction back, so unlinking first would risk destroying the documents of an account that still exists. It is immediate and irreversible. The last remaining administrator account cannot be deleted until another administrator exists. A public page explaining this is at /delete-account; if you cannot sign in, email contact@cosyntec.com from your registered address and we will delete the account within 30 days.

9. Children

WellNote is intended for adults. Registration does not ask for an age, so we cannot verify it. A parent or guardian should create and supervise any account used by a minor. Tell us if an account was created for a minor without a guardian's consent and we will delete it.

10. Changes and contact

Material changes — particularly to the AI provider terms in section 3 — will be reflected here with a new version number and date, and announced in the app.

Cosyntec · contact@cosyntec.com

นโยบายความเป็นส่วนตัว WellNote · เวอร์ชัน 1.4 · 6 สิงหาคม 2569 (6 August 2026)