Privacy

Last updated 5 September 2026

This describes how the software behaves. It is not legal advice and it is not a substitute for a data-protection agreement with your hospital or university. If you are entering identifiable patient data, confirm with your institution's information-governance team that this arrangement is acceptable before you begin, and have this document reviewed by a qualified adviser.

Who is responsible for the patient data

You are. Case Vault is a tool you use to keep your own clinical records; the clinician and their institution decide what is entered, for what purpose, and on what legal basis. We provide the software and the hosting, and process that data only to run the service for you.

That means obtaining consent where your jurisdiction requires it, applying your local retention rules, and honouring any request a patient makes about their record are your responsibilities, not ours.

What is stored

Two separate things. First, your account: name, email address, and the professional details you choose to add — degree, specialty, hospital, phone, country — plus your plan and role.

Second, the clinical data you enter: patient identifiers and contact details if you choose to record them, clinical history, diagnoses, treatments, operative notes, follow-up findings, outcome scores, uploaded images and documents, research records, and your personal notes.

You decide how identifiable that is. Nothing forces you to enter a patient's name, phone number or hospital number, and a registry kept under coded identifiers works perfectly well.

Where it is stored, and by whom

Application data and uploaded files are held in a PostgreSQL database and object storage operated by Supabase, and the application is served from Vercel. Both are third-party infrastructure providers acting on our behalf; their own terms and sub-processors apply. The hosting region is set when the database is created.

If you use the option to keep data on your device, that data stays in your browser and is never uploaded. If you send a case to your own Google Drive or another folder, that copy leaves our systems entirely and is governed by that provider and your own settings — once it is there, the protections described here no longer apply to it.

Who can see it

Access is enforced in the database itself, not only in the interface. A record is readable by the clinician who created it, by members of the same institution where one is set, and by an administrator of the deployment. Images and documents are served through links that expire, and are never placed in public storage.

There is a fourth route, and only you can open it. You can send one specific case to another Case Vault user by their email address — at any institution, not only your own. Nothing reaches them until they accept the invitation. Once they do, they can read that whole case, including its images and video, until you withdraw the share or they hand it back. Their access is read-only — they cannot change or delete anything — and it covers only the cases you sent, never the rest of your registry.

Administrators of a deployment can see account-level information and platform activity, and hold credentials capable of reading the underlying data. If you are using a deployment run by your hospital or university, its administrators are the people with that access.

Creating, updating and deleting a patient record, exports, sharing, and account and administrative changes are written to an append-only audit log, so who did what and when can be established after the fact. It is not a complete history of a case: the individual clinical entries, images, videos and follow-ups added inside one are not each logged.

What we do not do

  • We do not sell your data, or the data you record, to anyone.
  • We do not use patient data for advertising or profiling.
  • We do not send patient images to any artificial-intelligence service.
  • We do not run third-party analytics or advertising trackers inside the application.

Where an assistive feature that involves an external model is offered in future, it will be described plainly, kept optional, and switched off by default.

Payments

Subscriptions are handled by Razorpay and Stripe. Card and UPI details are entered with the payment provider and are never seen or stored by Case Vault. We keep only the plan status and a reference identifying the subscription.

Security

Traffic is encrypted in transit. Access to records is enforced by row-level rules in the database, so a request that should not see a record cannot retrieve it even if the interface is bypassed. Files are served through short-lived signed links. Passwords are handled by the authentication provider and are never stored by the application.

No system is immune to compromise. If a breach affecting your data occurs, we will tell affected account holders promptly and describe what happened and what to do about it.

Keeping and deleting data

Your records stay until you delete them. Deleting a patient removes it from your registry. You can delete your whole account, and every clinical record it owns, from Profile → Delete this account; it takes effect immediately. If you can no longer sign in, write to us from the address the account is registered to and we will do it within 30 days. Backups may retain copies for a limited period before ageing out.

You can export your own records as CSV at any time, on any plan, so leaving never means losing your work. The Excel, Word and PDF exports are part of Premium.

Children

Accounts are for clinicians and researchers, not patients. A patient's age is irrelevant to that — paediatric cases are ordinary clinical records and are treated like any other.

Contact

Questions about this document, or about data held in a deployment we operate, can be sent through the contact page.

Privacy — Case Vault · Case Vault