Security & privacy
Built to PHIPA and PIPEDA. Records stored in Canada.
Your clinic is trusted with your patients’ information. Here is exactly how gema protects it.
Where your data lives
Your records are stored in Canada — the database in a Canadian data centre, and the server that handles your live phone call in Toronto. Some processing — the phone network, application hosting, speech and language AI, email delivery — happens outside Canada as calls and messages are handled and as your team works in gema. Our privacy policy names every provider.
See every service provider →Your conversations don’t train our AI
We do not use your conversations to train AI, and the AI providers that talk with your patients are contractually prohibited from training on your data.
Encrypted in transit and at rest
Encrypted in transit and at rest.
Contact details masked by default
Patient email, phone and date of birth stay masked until someone on your team chooses to reveal them — and every reveal is logged.
The right access for each person
Owners, admins and clinicians each see what their role needs. Clinicians see their own patients.
Support access, locked down
When our team needs to help inside your account, access is: Role-limited, requires a stated reason, time-limited, session recorded.
An access log you can read
Opening a patient record in our internal tools writes an append-only log entry you can read back. Your clinic’s owners and administrators can see it.
Questions, answered
Our privacy officer answers at privacy@generalmagic.ai. Our privacy policy explains how we handle a breach, what we keep and for how long.
Read the privacy policy →Request a demo
See gema running your clinic.
Give us your website and we build you a working demo on your real services, practitioners and hours — then email you the link. No call to sit through, no card, nothing to install.

