Reflections & privacy
How ARCPeasy handles reflections
Reflections are the most sensitive thing in a portfolio, so they get the strictest handling in ARCPeasy. In short: by default we never keep the text and never send it to an AI. Here is exactly what happens.

The default: metadata only
ARCPeasy looks for reflective content before it does anything else with a document — and it makes that check on its own, without sending your writing to an outside AI to decide whether it is a reflection. Because a Horus or Turas export labels each item by type, most reflections are spotted straight away; for loose files, if there is any doubt, we treat it as a reflection to be safe.
When a reflection is detected, we keep only three things: that it exists, its date, and the checklist item it appears to support. The reflective text itself is discarded as it is ingested. It is not stored hidden, encrypted-but-kept, or tucked away for later — it is not retained at all.
Optional, one-off review — only if you ask
Sometimes you may want a second read of a single reflection: is it complete, is it clear, are there obvious gaps a reviewer might flag. You can request that, one document at a time, as an explicit opt-in. It is off by default.
When you do, the patient-identifiable-information screen runs first, as always. After the review is returned, nothing is kept beyond a content hash — so we can recognise the same file if you upload it again — and whatever summary you choose to save. The reflective text is not retained.
What we never do
- Send reflective text to an AI model without your explicit, per-document opt-in.
- Store reflection text where the policy says metadata-only — this is enforced at the database, not just in the app.
- Use your reflections, or anything else you upload, to train models.
- Put a safety check — anonymisation or PID screening — behind a paywall.
Why we built it this way — the Bawa-Garba case
We will name it plainly, because you already know it: Dr Hadiza Bawa-Garba, the paediatric trainee convicted of gross negligence manslaughter in 2015 after the death of a child in her care. For a generation of doctors it became the moment reflective writing stopped feeling safe — the fear that what you wrote in order to learn could one day be read back to you in a courtroom or a tribunal.
It is widely reported that her written reflections were not in fact used as evidence against her, and guidance since has stressed that reflection is for learning, not liability. The clarification did not undo the fear, and the chilling effect on honest reflection is real and well documented. We would rather build for that reality than pretend it away.
So the safest default is the one you already have here: reflect honestly in your portfolio, and let ARCPeasy hold only the fact that a reflection exists — its date, the competency it supports — never the words. Nothing reflective reaches an AI model unless you explicitly ask, one document at a time.
This page is a plain-English summary of how the product behaves. The full detail — lawful bases, sub-processors, retention, and your rights — lives in our privacy policy, which carries these same reflection commitments through in formal terms.
Read the full privacy policy for the formal detail, or email hello@arcpeasy.uk with any question about how your data is handled.
