When privacy is the point
Some practices choose software the way they'd choose a filing cabinet with a lock: on what it physically cannot leak. This page is the canonical statement of SideClick's privacy argument, claim by mechanism.
- At rest
- SQLCipher AES-256, local keys
- AI
- On-device; no cloud inference path
- In transit
- Ciphertext-only relay
- Compliance wording
- Designed to support — never 'certified'
The claims, each with its mechanism
Every promise here names the machinery that enforces it, because a privacy claim without a mechanism is a hope:
- Records encrypted at rest — SQLCipher (AES-256), keys in hardware-backed custody on your machine
- AI runs on-device — there is no cloud inference path in the product to leak through
- Sync and portal traffic cross a relay that stores ciphertext only
- Tamper-evident audit trail on every access to the record
- Every export path works in every licence state — leaving is always possible
The one-sentence answer for clients
"Your records are encrypted on my computer, and nobody — including the software company — can read them." That sentence is true here, verifiable from the architecture, and short enough to say in the consult room when a client asks. Practices whose clientele choose them for discretion report that the question does get asked.
How a privacy-first setup actually runs
Start on Solo and the posture is maximal by default: one machine, zero external copies. Add sync only when multi-device genuinely earns its place, knowing the relay adds delivery, not readability. Opt into the AI without a data-flow conversation, because there isn't one — inference is local. Keep .cfbak backups on media you control. Each convenience is added with its exact cost visible, and the cost is never 'a vendor can now read the records.'
Compliance posture, honestly worded
SideClick's architecture is designed to support obligations under HIPAA, GDPR and comparable frameworks: encryption at rest, access control, audit trails, consent tracking, subject-access export, breach-resistant key custody. We write "designed to support" and never "certified" or "compliant", because compliance is a property of a practice and its processes — software is the part we can build, and the security page inventories it without inflation.
Questions, answered
What can SideClick-the-company see of my practice?
Licensing metadata (that a key is active) and, if you use sync, ciphertext plus delivery metadata. Clinical content is unreadable to us structurally — there is no key on our side.
Is SideClick HIPAA/GDPR certified?
No software makes a practice compliant, and certifications to that effect are marketing. SideClick is designed to support those obligations — encryption, audit, consent, subject access — and we document the mechanisms rather than claim the outcome.
Where's the biggest remaining risk in a privacy-first setup?
Your own machine and habits: screen locks, backup custody, who has accounts. SideClick shrinks the vendor-side risk to near zero; the practice-side hygiene remains yours, as it always was.
Does using the AI change the privacy posture?
No — that is its defining property here. Inference happens on your hardware with no cloud API behind it, so opting in adds capability without adding a data flow.
Try SideClick free for 30 days
Full capability, no card required. Your data stays on your machine either way.
Start a 30-day trial