What KeisenVPA Can Collect

Event registry version 2026-08-06.2 · Last updated: August 6, 2026

Usage statistics are off unless you turn them on. If you never opt in, KeisenVPA collects nothing at all — no identifier is even created. This page lists the complete set of things it could send if you do opt in. Nothing outside this list can be transmitted: the app validates against it before anything leaves your device, and our server independently rejects anything that is not on it.

Never collected — under any setting

The complete event list (39 events)

Every event also carries: your app version, operating-system name and version, CPU type, interface language, a random installation identifier created only if you opt in (resettable in Settings), and the hour it happened — never the exact time.

EventValues it can carry
action_retried
  • component — generation | transcription | ehr | licensing | updater | batch | save | ui | other
analytics_opted_inno properties
analytics_opted_outno properties
api_key_resolved
  • source — builtin | user_key | env | none
app_crashed_previous_run
  • exc_class — error type name (never the message)
  • fingerprint — anonymous code
app_launched
  • first_launch — yes / no
  • time_of_day — night | morning | afternoon | evening
  • window_width — one of: <1024 | 1024-1440 | 1440-1920 | >1920
app_updated
  • from_version — version number
batch_completed
  • outcome — all_succeeded | partial | all_failed | cancelled
  • size — one of: 0 | 1-5 | 6-15 | 16-30 | >30
batch_started
  • size — one of: 0 | 1-5 | 6-15 | 16-30 | >30
chat_message_sent
  • has_attachment — yes / no
dialog_dismissed
  • dialog — api_key | settings | license | analytics_consent | update | ehr_settings | patient_search | other
  • method — accept | cancel | escape
draft_discardedno properties
draft_generated
  • visit_type — problem | well | other
draft_pushed
  • latency_since_generation — one of: <1h | 1-4h | 4-24h | >24h
ehr_login_completed
  • ehr — athena_prod | athena_preview | epic_sandbox | custom
  • error_class — none | oauth_denied | token_error | network | config | other
  • method — smart | v1
  • result — success | failure
ehr_settings_saved
  • ehr — athena_prod | athena_preview | epic_sandbox | custom
  • has_credentials — yes / no
error_occurred
  • component — generation | transcription | ehr | licensing | updater | batch | save | ui | other
  • exc_class — error type name (never the message)
  • fingerprint — anonymous code
feature_used
  • feature — scratchpad | template_manager | custom_prompt | visit_type_mapping | model_changed | settings_opened | pi_setup | layout_reset
generation_cancelled
  • mode — chat | batch
generation_failed
  • error_class — auth | rate_limit | overloaded | network | timeout | payload_too_large | other
  • http_status_class — 4xx | 5xx | network | none
  • mode — chat | batch
license_activated
  • variant — monthly | annual | lifetime | unknown
license_activation_failed
  • error_code — invalid_key | activation_limit | network | other
note_generated
  • attachments — none | images | pdf | mixed
  • chart_context — yes / no
  • input_tokens — one of: <1k | 1-4k | 4-16k | 16-64k | >64k
  • latency — one of: <5s | 5-15s | 15-30s | 30-60s | 1-3m | >3m
  • mode — chat | batch
  • model — claude-fable-5 | claude-opus-5 | claude-opus-4-8 | claude-sonnet-5 | other
  • note_length — one of: <100 | 100-300 | 300-600 | 600-1200 | >1200
  • output_tokens — one of: <1k | 1-4k | 4-16k | 16-64k | >64k
  • reasoning — yes / no
  • streaming — yes / no
  • template — default | enhanced | custom | none
  • time_of_day — night | morning | afternoon | evening
note_pushed
  • error_class — none | permission | validation | network | other
  • result — success | failure
  • target — full_note | sections | diagnoses
note_saved
  • chat_turns — one of: 1 | 2-3 | 4-6 | 7-10 | >10
  • demographics_source — chart | parsed | none
  • note_length — one of: <100 | 100-300 | 300-600 | 600-1200 | >1200
  • time_of_day — night | morning | afternoon | evening
  • trigger — auto | manual
panel_toggled
  • panel — ehr | scratchpad
  • visible — yes / no
patient_context_loaded
  • fhir_fallback — yes / no
  • source — schedule | search
patient_search_performed
  • result — found | not_found | error
  • source — v1 | fhir
purchase_page_opened
  • source — settings | license_dialog | trial_banner | expiry_dialog
recording_completed
  • duration — one of: <30s | 30s-2m | 2-5m | 5-15m | >15m
  • source — mic | watcher
schedule_loaded
  • appointments — one of: 0 | 1-5 | 6-15 | 16-30 | >30
  • trigger — auto_post_login | manual
session_ended
  • duration — one of: <5m | 5-15m | 15-60m | 1-4h | >4h
  • events_dropped — a count (0–999)
  • notes_generated — a count (0–999)
transcription_completed
  • duration — one of: <5s | 5-15s | 15-30s | 30-60s | 1-3m | >3m
transcription_failed
  • error_code — service_down | timeout | format | other
transcription_loaded
  • via — past_hour | past_day | file_picker
trial_expired_shownno properties
trial_startedno properties
update_prompt_shown
  • action — download | skip | dismissed
whisper_service_checked
  • status — running | not_running | unreachable

Turning it off

Settings → Privacy, in the app. Turning it off stops collection immediately, deletes the installation identifier, and removes anything still queued on your device. You can also reset the identifier at any time without turning statistics off.

See the privacy policy for how this fits with license verification and the other network activity in the app.