Locum NotesSign in

Privacy Policy

Last updated: 2 October 2026.

Locum Notes is provided by Jonathan Wills, a sole trader established in the United Kingdom, trading as Locum Notes. We are the data controller for the personal data described here, and this page explains how that data is handled.

1. What Locum Notes is

Locum Notes is a private work-record, professional library and CPD organiser for locum doctors. It lets you record work sessions, invoices and expenses, save clinical webpages, generate summaries and period reviews, add reflections and CPD hours, store professional evidence, and export selected records. The service is hosted on Lovable Cloud infrastructure.

2. What data we collect

We collect only the data needed to run the service:

  • Account data: email address, and optionally your full name, role/grade, and GMC number if you enter them for your exported PDF.
  • Reading entries: URLs you save, the extracted page text, AI-generated summaries, key points, tags, your personal reflections, CPD hours, and the date you visited the page. If you choose the extension's history import, the addresses and titles of up to 50 recently visited pages in your selected date range are sent for review; only relevant readable pages are saved as entries.
  • Work and calendar records: practices, work sessions, rates, mileage, pension choices, invoices, and other calendar activities you choose to record. Incoming calendar subscription links are stored encrypted. An outgoing private calendar link is checked against a one-way hash. When link recovery is available, its token is also stored encrypted so you can see the link again while signed in. Older links may need to be replaced to show them again.
  • Mandatory documents: the professional evidence you choose to upload, such as indemnity certificates, DBS checks, registration evidence and training certificates, together with their filenames, categories, issue/expiry dates and notes. These files are stored in a private, account-scoped storage area.
  • Extension token: if you use the browser extension, a hashed token is stored so the extension can save pages to your account. The plain token is shown only once and is not stored readable on our servers. The extension stores the token locally in your browser until you disconnect it.
  • Technical data: standard server logs generated by the hosting platform for reliability and security, and an authentication session cookie/localStorage entry to keep you signed in.

3. How we use your data

  • To authenticate you and keep your log private.
  • To fetch and summarise webpages you choose to save.
  • To create a temporary CPD learning review for a period you choose.
  • To store your entries, reflections, and CPD hours.
  • To generate the PDF export you request.
  • To store your professional documents and prepare a ZIP pack only when you request a download.
  • To create a private calendar subscription only when you choose to do so.
  • To keep the service secure and fix errors.

4. AI processing

Page text is sent to the Lovable AI gateway, which currently uses Google's Gemini model, to produce a title, summary, key points, specialty tags, and a suggested CPD time estimate. When you request a CPD learning review, the relevant saved titles, summaries, key points, reflections, tags, dates, and hours are sent to create that one-off review. The review is not stored separately. When you choose to transcribe a recording or extract text from an image, that file is also sent through the Lovable AI gateway for processing. You can check and correct the returned text before saving. Locum Notes stores the original file only if you choose to keep it as private evidence. Files retained as evidence are removed when you delete their CPD entry. Provider processing is subject to the provider's applicable data-handling terms.

5. Our legal basis

We process your account and record data to perform our contract with you (providing the service you have signed up for). We rely on our legitimate interests in keeping the service secure, preventing fraud and misuse, and fixing errors and improving the product. Where the law requires it, such as for keeping business and tax records, we process data to meet a legal obligation. Where we ever rely on consent, you can withdraw it at any time.

6. Who we share data with

We do not sell your data. We share it only with:

  • Our hosting and infrastructure provider (Lovable Cloud), which provides the backend, authentication, database and private file storage.
  • Our AI processing provider, which generates summaries and reviews from the page text and entries you choose to submit.
  • Paddle.com, our reseller and Merchant of Record, which handles the sale of subscriptions, payments, subscription management, invoicing and tax compliance. Paddle collects your billing details directly at checkout.
  • Professional advisers (such as legal or accounting advisers) and public authorities, where we are required or permitted by law.

If you download a document ZIP pack, Locum Notes prepares it for download but does not send it to a practice or any third party; you decide whether and where to share it. If you add the private Locum Notes calendar link to Google Calendar, Apple Calendar, or another calendar service, that service retrieves the session and activity details contained in the feed. Anyone who has that private link can also view its calendar, so treat it like a password and replace or remove it if needed.

7. International transfers

Some of our providers process data outside the UK and European Economic Area. Where that happens, the transfer is covered by an adequacy decision or by standard contractual clauses together with appropriate technical safeguards, so your data keeps an equivalent level of protection.

8. Cookies and local storage

We use a session cookie/localStorage entry to keep you signed in, and a local offline cache so your entries remain viewable when you do not have an internet connection. These are first-party and essential to the service, so no consent banner is required. We do not use advertising or tracking cookies. Our payment provider may set cookies needed to complete checkout. You can clear or block cookies in your browser settings, though the service will not work properly without the essential ones.

9. How long we keep your data

Your entries, profile and uploaded professional documents are kept for as long as your account exists. You can delete individual CPD entries and mandatory documents in the app at any time. If you close your account, we delete or anonymise your personal data once it is no longer needed, other than records we must keep for legal, tax or accounting purposes (normally six years). For account deletion or other deletion requests, email us.

10. Your rights

Under UK data protection law you have the right to access your personal data, to have it corrected or erased, to restrict or object to how we use it, to receive it in a portable form, and to withdraw consent where we rely on it. The easiest way to exercise most of these is through the app: you can edit your profile, export your records and delete entries directly.

For account deletion or any other request, email us and we will respond within one month. If you are unhappy with how we have handled your data, you can complain to the UK Information Commissioner's Office (ico.org.uk).

11. Security

The app requires login for all personal data. Your records are separated from other users by row-level security in the database, and mandatory-document files are stored in a non-public, account-scoped area. Extension tokens are stored as hashes. No system is completely secure, and we rely on the platform provider for infrastructure security.

12. Your responsibility

You control what pages and professional evidence you save, and what you paste or type into the app. Do not save or share patient-identifiable information, confidential clinical details, or any content you are not entitled to record. Before sharing a document pack, check that it contains only the evidence the receiving practice needs.

13. Changes to this policy

We may update this policy as the service changes. The latest version will always be available at this page with the updated date at the top.

14. Contact us

For privacy questions, deletion requests, or to exercise your data rights, please email:

locumnote@gmail.com