Privacy
Last updated 31 July 2026
This describes how the software behaves. It is not legal advice and it is not a substitute for a data-protection agreement with your hospital or university. If you are entering identifiable patient data, confirm with your institution's information-governance team that this arrangement is acceptable before you begin, and have this document reviewed by a qualified adviser.
Who is responsible for the patient data
You are. Case Vault is a tool you use to keep your own clinical records; the clinician and their institution decide what is entered, for what purpose, and on what legal basis. We provide the software and the hosting, and process that data only to run the service for you.
That means obtaining consent where your jurisdiction requires it, applying your local retention rules, and honouring any request a patient makes about their record are your responsibilities, not ours.
What is stored
Two separate things. First, your account: name, email address, and the professional details you choose to add — degree, specialty, hospital, phone, country — plus your plan and role.
Second, the clinical data you enter: patient identifiers and contact details if you choose to record them, clinical history, diagnoses, treatments, operative notes, follow-up findings, outcome scores, uploaded images and documents, research records, and your personal notes.
You decide how identifiable that is. Nothing forces you to enter a patient's name, phone number or hospital number, and a registry kept under coded identifiers works perfectly well.
Where it is stored, and by whom
Application data and uploaded files are held in a PostgreSQL database and object storage operated by Supabase, and the application is served from Vercel. Both are third-party infrastructure providers acting on our behalf; their own terms and sub-processors apply. The hosting region is set when the database is created.
If you use the option to keep data on your device, that data stays in your browser and is never uploaded. If you send a case to your own Google Drive or another folder, that copy leaves our systems entirely and is governed by that provider and your own settings — once it is there, the protections described here no longer apply to it.
Who can see it
Access is enforced in the database itself, not only in the interface. A record is readable by the clinician who created it, by members of the same institution where one is set, and by an administrator of the deployment. Images and documents are served through links that expire, and are never placed in public storage.
Administrators of a deployment can see account-level information and platform activity, and hold credentials capable of reading the underlying data. If you are using a deployment run by your hospital or university, its administrators are the people with that access.
Changes to records are written to an append-only audit log, so who did what and when can be established after the fact.
What we do not do
- We do not sell your data, or the data you record, to anyone.
- We do not use patient data for advertising or profiling.
- We do not send patient images to any artificial-intelligence service.
- We do not run third-party analytics or advertising trackers inside the application.
Where an assistive feature that involves an external model is offered in future, it will be described plainly, kept optional, and switched off by default.
Payments
Subscriptions are handled by Razorpay and Stripe. Card and UPI details are entered with the payment provider and are never seen or stored by Case Vault. We keep only the plan status and a reference identifying the subscription.
Security
Traffic is encrypted in transit. Access to records is enforced by row-level rules in the database, so a request that should not see a record cannot retrieve it even if the interface is bypassed. Files are served through short-lived signed links. Passwords are handled by the authentication provider and are never stored by the application.
No system is immune to compromise. If a breach affecting your data occurs, we will tell affected account holders promptly and describe what happened and what to do about it.
Keeping and deleting data
Your records stay until you delete them. Deleting a patient removes it from your registry; deleting your account removes your account data and the clinical records you own. Backups may retain copies for a limited period before ageing out.
You can export everything you have entered at any time in CSV, Excel, Word or PDF, so leaving does not mean losing your work.
Children
Accounts are for clinicians and researchers, not patients. A patient's age is irrelevant to that — paediatric cases are ordinary clinical records and are treated like any other.
Contact
Questions about this document, or about data held in a deployment we operate, can be sent through the contact page.