Privacy Policy
This Privacy Policy explains how A Patient Case ("we", "us") collects, uses, and shares information when you use the A Patient Case iOS application (the "App"). By using the App you agree to the practices described here.
1. Information we collect
Information you provide
- Account information: your name, email address, password, and National Provider Identifier (NPI) number, which we use to verify that you are a licensed clinician.
- Profile information: your specialty, credentials (for example MD, DO, PA), a short bio, and an optional profile photo.
- Invitation codes: the code you use to register and any codes you generate to invite colleagues.
- Case content: videos, thumbnails, supporting documents, titles, descriptions, tags, diagnoses, medications, and procedures that you add to a case, along with any video responses you post.
- Sharing and activity: which clinicians you follow, cases you like or bookmark, cases you share directly with other users and any message you attach, and reports or blocks you submit about other users.
- Support messages: anything you send us when you contact support.
Information collected automatically
- Push notification token: a device token so we can deliver notifications, and an unread badge count.
- Notification history: records of the notifications sent to you (for example, when a case is shared with you or someone follows you).
- Usage counts: view, like, and response counts on cases, and follower/following counts on profiles.
- Timestamps: when your account, cases, and other records were created or updated.
- Service data: our backend provider (Google Firebase) may collect device and diagnostic information needed to operate authentication, storage, and messaging. See "Third-party services" below.
Device permissions
The App may ask for access to your camera and microphone (to record case videos), and to your photo library (to import images into a case or set a profile photo). You can change these permissions at any time in iOS Settings.
2. Patient information
A Patient Case is designed for de-identified case studies only. You are responsible for removing all patient-identifying information from any case before uploading it. Do not upload protected health information (PHI). We do not review case content for identifying information before it is stored or shared.
3. How we use information
- To create and secure your account and verify your clinician status through the NPI Registry.
- To store, display, and share cases according to the visibility settings you choose.
- To show your public profile, follower counts, and activity to other verified members.
- To send push notifications about shares, follows, responses, and similar activity.
- To review reports, enforce our Terms, and act on blocks.
- To respond to support requests and to maintain, debug, and improve the App.
4. How information is shared
- With other members: your profile (name, specialty, credentials, bio, photo, follower counts) is visible to other verified members. Cases are visible according to the visibility you set: private (only you), community (all verified members), or directly shared (only the recipients you choose). Your email address and NPI number are not shown on your public profile.
- With service providers: we use Google Firebase (Authentication, Cloud Firestore, Cloud Storage, Realtime Database, Cloud Functions, and Cloud Messaging) to run the App, and Apple Push Notification service to deliver notifications. We use the U.S. NPI Registry (NPPES) to verify NPI numbers; your name and NPI number are sent to that service during registration.
- For legal reasons: when required by law, legal process, or to protect the rights, safety, or property of our users or others.
- Business transfers: if A Patient Case is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
We do not sell your personal information, and we do not use advertising networks in the App.
5. Third-party services
Firebase is operated by Google LLC. Information stored in Firebase is subject to Google's privacy practices. See Firebase Privacy and Security and the Google Privacy Policy. NPI verification uses the public NPPES NPI Registry operated by the U.S. Centers for Medicare & Medicaid Services.
6. Data retention and deletion
We keep your information for as long as your account is active. You can delete your account at any time from the Profile screen in the App. Deleting your account removes your login, your profile, your cases and their media, and your related records (likes, bookmarks, follows, shared cases, and notifications) from our systems. Some information may persist for a limited time in backups or where we are required to retain it by law.
7. Security
Data is transmitted over encrypted connections and stored with our hosting provider, which encrypts data at rest. Access to cases is controlled by server-side security rules based on ownership, sharing, and visibility settings. The App detects active screen recording and hides case content while recording is in progress. No system is completely secure, and we cannot guarantee absolute security.
8. Children
The App is intended for licensed healthcare professionals and is not directed to anyone under 18. We do not knowingly collect information from children.
9. Your choices
- Edit your profile information in the App at any time.
- Change a case's visibility or delete a case you created.
- Turn push notifications on or off in iOS Settings.
- Delete your account from the Profile screen.
- Contact us to ask about, correct, or delete information we hold about you.
10. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and change the effective date above. Continued use of the App after an update means you accept the revised policy.
11. Contact
Questions about this policy or your information can be sent to apatientcase@gmail.com.