Privacy Policy
Last updated: 2 October 2026.
1. What Locum Notes is
Locum Notes is a private work-record, professional library and CPD organiser for locum doctors. It lets you record work sessions, invoices and expenses, save clinical webpages, generate summaries and period reviews, add reflections and CPD hours, store professional evidence, and export selected records. The service is hosted on Lovable Cloud infrastructure.
2. What data we collect
We collect only the data needed to run the service:
- Account data: email address, and optionally your full name, role/grade, and GMC number if you enter them for your exported PDF.
- Reading entries: URLs you save, the extracted page text, AI-generated summaries, key points, tags, your personal reflections, CPD hours, and the date you visited the page. If you choose the extension's history import, the addresses and titles of up to 50 recently visited pages in your selected date range are sent for review; only relevant readable pages are saved as entries.
- Work and calendar records: practices, work sessions, rates, mileage, pension choices, invoices, and other calendar activities you choose to record. Incoming calendar subscription links are stored encrypted. An outgoing private calendar link is checked against a one-way hash. When link recovery is available, its token is also stored encrypted so you can see the link again while signed in. Older links may need to be replaced to show them again.
- Mandatory documents: the professional evidence you choose to upload, such as indemnity certificates, DBS checks, registration evidence and training certificates, together with their filenames, categories, issue/expiry dates and notes. These files are stored in a private, account-scoped storage area.
- Extension token: if you use the browser extension, a hashed token is stored so the extension can save pages to your account. The plain token is shown only once and is not stored readable on our servers. The extension stores the token locally in your browser until you disconnect it.
- Technical data: standard server logs generated by the hosting platform for reliability and security, and an authentication session cookie/localStorage entry to keep you signed in.
3. How we use your data
- To authenticate you and keep your log private.
- To fetch and summarise webpages you choose to save.
- To create a temporary CPD learning review for a period you choose.
- To store your entries, reflections, and CPD hours.
- To generate the PDF export you request.
- To store your professional documents and prepare a ZIP pack only when you request a download.
- To create a private calendar subscription only when you choose to do so.
- To keep the service secure and fix errors.
4. AI processing
Page text is sent to the Lovable AI gateway, which currently uses Google's Gemini model, to produce a title, summary, key points, specialty tags, and a suggested CPD time estimate. When you request a CPD learning review, the relevant saved titles, summaries, key points, reflections, tags, dates, and hours are sent to create that one-off review. The review is not stored separately. When you choose to transcribe a recording or extract text from an image, that file is also sent through the Lovable AI gateway for processing. You can check and correct the returned text before saving. Locum Notes stores the original file only if you choose to keep it as private evidence. Files retained as evidence are removed when you delete their CPD entry. Provider processing is subject to the provider's applicable data-handling terms.
5. Our legal basis
We process your account and record data to perform our contract with you (providing the service you have signed up for). We rely on our legitimate interests in keeping the service secure, preventing fraud and misuse, and fixing errors and improving the product. Where the law requires it, such as for keeping business and tax records, we process data to meet a legal obligation. Where we ever rely on consent, you can withdraw it at any time.
7. International transfers
Some of our providers process data outside the UK and European Economic Area. Where that happens, the transfer is covered by an adequacy decision or by standard contractual clauses together with appropriate technical safeguards, so your data keeps an equivalent level of protection.
9. How long we keep your data
Your entries, profile and uploaded professional documents are kept for as long as your account exists. You can delete individual CPD entries and mandatory documents in the app at any time. If you close your account, we delete or anonymise your personal data once it is no longer needed, other than records we must keep for legal, tax or accounting purposes (normally six years). For account deletion or other deletion requests, email us.
10. Your rights
Under UK data protection law you have the right to access your personal data, to have it corrected or erased, to restrict or object to how we use it, to receive it in a portable form, and to withdraw consent where we rely on it. The easiest way to exercise most of these is through the app: you can edit your profile, export your records and delete entries directly.
For account deletion or any other request, email us and we will respond within one month. If you are unhappy with how we have handled your data, you can complain to the UK Information Commissioner's Office (ico.org.uk).
11. Security
The app requires login for all personal data. Your records are separated from other users by row-level security in the database, and mandatory-document files are stored in a non-public, account-scoped area. Extension tokens are stored as hashes. No system is completely secure, and we rely on the platform provider for infrastructure security.
12. Your responsibility
You control what pages and professional evidence you save, and what you paste or type into the app. Do not save or share patient-identifiable information, confidential clinical details, or any content you are not entitled to record. Before sharing a document pack, check that it contains only the evidence the receiving practice needs.
13. Changes to this policy
We may update this policy as the service changes. The latest version will always be available at this page with the updated date at the top.
14. Contact us
For privacy questions, deletion requests, or to exercise your data rights, please email: