Last updated 13 August 2026
Opselia is used by a medical practice to run its own administration. This describes what the software stores, what it deliberately does not, and who can reach it. It is written to be checked against the product rather than to reassure.
One database per practice, holding the practice's own operating records:
No patient data. No names, dates of birth, member or subscriber identifiers,
diagnoses, addresses or telephone numbers. Real claim numbers are replaced before anything is
uploaded, by a label of the form WL-A1B2C3D4. The translation between a label and
the real number is held on one computer inside the practice and is never sent to Opselia.
Imports refuse columns that look like patient identifiers rather than dropping them quietly, so a file that should not be uploaded is stopped with an explanation instead of being partially accepted.
A practice may connect Opselia to its own Google Drive. Opselia asks for one permission,
drive.file, which is the narrowest Google offers: it grants access to files the
application itself created and to nothing else in that Drive. This is enforced by Google, not
by us.
When reading a spreadsheet, Opselia names the columns it wants and receives those columns. On the denial worklist it asks for the label, the note and its own status column, and never the claim number column. A read that named a patient or claim column is refused before the request is built.
The permission can be withdrawn at any time from the practice's own Google security page, without asking us.
Opselia uses a model to read messages and short written notes, so that a task can say what the work actually is. This happens only for mailboxes a practice has explicitly enabled, the choice is recorded against the person who made it, and it can be turned off per mailbox.
Text sent for reading goes to Google's Gemini. Where a practice's mail already sits in Gmail, this means no new company sees that mail. Anything that looks like it carries patient detail is not sent at all.
It is not used to train anything. Opselia sends this on a paid Google plan, where Google's terms say prompts and responses are not used to improve their models and are not read by human reviewers. The free plan does allow both, which is why Opselia does not use it.
Opselia runs on Cloudflare. Each practice has its own isolated database; no practice can reach another's. Backups are taken nightly and the most recent fourteen are kept.
The records are the practice's own and are kept while the practice uses Opselia. On request they are exported in full and deleted.
Only sign-in accounts the practice creates. Roles limit what each account can reach, pay and sensitive identifiers are restricted to administrators, and every change is recorded against a name. Opselia's operators do not read a practice's records in the ordinary course of running the service.
Write to support@opselia.com.