Privacy
Last updated 2 August 2026
Who holds the data
The facility that creates a patient record holds it. Oystar processes it on that facility’s behalf so a referral can reach a specialist and an answer can come back.
What we hold
For patients: the details a clinician enters on a referral. Name, age, sex, an identifier if there is one, and the clinical history relevant to the question being asked. A patient needs no account, no phone and no app.
For users: name, work email, job title, specialty, and the facility you belong to.
Who can see a record
The facility that created it, and the specialist it was sent to. Nobody else. A referral belonging to another facility does not appear, and cannot be reached by guessing its reference.
A specialist’s access exists because the case was sent to them, and it ends when the case closes.
What is logged
Every action on a referral is written to a log that cannot be edited or deleted: who did it, at which facility, and when. The referring facility can see that log.
Reporting
Completion rates by district and specialty are counted from those events. Those figures are totals only. No patient identity is included in them at any level.
Document reading
If you paste notes or upload a document, its contents are sent to a language model to fill in the referral form. The result is shown to you to correct; nothing is sent onward until you press send. Documents are not used to train any model.
Your rights
Patients may ask the facility holding their record for a copy, or for it to be corrected. Requests should go to that facility, which holds the record, rather than to Oystar.
This is an early-access product. These terms will be reviewed by counsel before Oystar is used with real patient records, and this page will be replaced when it is.
