Zanda AI features process customer and patient information to help you save time, doing things like transcribing, summarizing, and refining session notes, drafting emails and letters, and answering questions in plain language. That processing happens entirely within infrastructure Zanda manages and fully controls, under the same access controls and safeguards as the rest of your account.
Where AI processing happens
AI features run entirely inside infrastructure Zanda manages and fully controls end-to-end, within its own private network - never a third-party AI provider’s systems. Unlike pasting information into a consumer AI tool, nothing is sent to an external AI provider - it stays within that same infrastructure throughout.
Processing normally takes place in the same region where your account’s data is stored. In limited circumstances, a newer AI capability may not yet be available in every region, and a request may be processed in another region instead. Even then, Zanda does not retain or store your information outside your home region, does not use it to train any AI model, and does not send it to a third-party AI provider - the same protections apply regardless of which region handles the request. Zanda does not currently give practices a separate notice when this limited exception applies to a specific request, and there is no regional-capability list to check in advance; if you need to know whether a particular capability is available in your region, contact Zanda support.
What information can AI features use
What an AI feature processes depends on the task. Transcribing a session recording, drafting an email or letter, answering a question about a client’s history, and summarizing session notes each draw on different information.
Zanda sends only the information relevant to completing your request, not your full practice record. To answer a natural-language question, Zanda retrieves the relevant information, decrypts it for the task, and provides just that information to the AI model to formulate a response - information stays encrypted while in transit, alongside the other normal safeguards protecting your account.
An AI feature can only use information you could already access with your existing Zanda permissions. If your permissions change, what AI features can access for you updates immediately to match. Using an AI feature does not give Zanda staff any additional access to your account beyond their ordinary, permission-based support access. All of this is also scoped to your own practice: an AI feature cannot access or use another practice’s data.
What happens to your information afterward
Zanda does not use customer or patient information to train AI models. The AI processing itself doesn’t retain anything once a task is finished - for example, once you finish refining a note and exit, none of that information stays in the AI processing.
If you choose to save AI-generated or AI-refined content, that content becomes part of your normal Zanda record from that point on, and follows the same storage, backup, and retention rules as everything else in your account, stored in your account’s own region. If you do not save it, it is not retained.
Separately, Zanda may retain limited de-identified data, in the same region as your practice’s data, to examine how well its AI tools are performing. All identifying information is removed from this data before it is retained - nothing that could identify a patient, another individual, or your practice - and it cannot be traced back to any of them. It is not combined across regions, it is used only internally to evaluate AI performance, and it is not used for model training or made available to practices. It is protected by the same encryption as the rest of your account data, in transit and at rest.
How Zanda approaches AI quality and uncertainty
Zanda carefully tunes the AI models it uses and keeps them updated, instructed to stay grounded in the information actually available rather than inventing, assuming, or implying facts. Where there is genuine uncertainty, the AI is instructed to say so rather than present an uncertain answer as settled. For insights drawn from a client’s history, you can ask an AI feature to show the underlying evidence it used, which is particularly useful when a lot of historical information is involved.
Professional judgment and patient consent
AI features are built to assist practitioners, not to diagnose conditions or prescribe treatment on their own. AI-generated or AI-refined content is not added to a patient or practice record automatically - it is held separately until you take an explicit action to review and save it, so nothing reaches the record on the AI’s own authority.
Because AI is now part of how you may work with patient information, it is worth considering your own obligations to inform patients and obtain their consent before using AI features in their care, alongside your existing professional and regulatory obligations.
Choosing which AI features your practice uses
Some AI capabilities are opt-in at the practice level: a user with administrator permissions chooses which of these to turn on, and can review or change that selection at any time, including opting out of one your practice previously turned on. Other AI capabilities are included and enabled by default, and it is up to you whether to use them when working in your account. You can see which opt-in AI capabilities your practice has turned on from within your account.
Activity involving AI features is recorded in your account’s activity log alongside your practice’s other account activity, noting who took the action, when, and a short description of what happened - not the content of what you asked the AI or what it returned. This is the same log covered in Recording and Reviewing the User Activity Log File. Access to the activity log is limited to particular roles in your practice.
For more on where your data is stored and how it stays separated from other practices, see Data Location and Separation. For how Zanda encrypts data and controls staff access more broadly, see Data Encryption and Access Controls. For the operational controls behind all of this, see Security and Operational Maturity.
Frequently Asked Questions
Does Zanda send my information to an external AI provider, like OpenAI or Google?
No. AI features run entirely on infrastructure Zanda manages and fully controls, inside its own private network, and your information is never sent to an external AI provider to complete an AI task.
Can I turn AI features off for my practice?
It depends on the capability. Some AI capabilities are opt-in, and a user with administrator permissions can turn off any of these your practice previously turned on. Others are included and enabled by default, and it is up to you whether to use them.
Does Zanda use my patient data to train AI models?
No. Zanda does not use customer or patient information to train AI models, under any circumstances.
