Privacy Policy
Last updated: June 2026
Overview
Critical Care Vault is an educational training and reference application for healthcare professionals and students. This policy explains what information is collected, how it is used, and your rights regarding your data.
What we collect
Account Information
If you create an account, we collect your email address and an encrypted password hash. This is used solely to authenticate your identity and enable cloud sync of your progress data.
Progress and Activity Data
The App records your quiz responses, scores, streaks, flagged items, completed questions, daily activity logs, saved library items, and personal study notes. This data is stored locally on your device and, if you are signed in, synced to a cloud database (Supabase) to make your progress and notes available across devices.
Issue Reports
If you submit feedback through Settings → Send Feedback, we collect the message you wrote, the screen you were on, the app version, and your device user-agent string. Signed-in feedback is tied to your account ID. Guest feedback is tied to a random install identifier that is hashed with request context for rate limiting and abuse prevention; we do not store the raw install identifier. Any contact email you enter in the feedback form is included in the submitted message. This diagnostic information helps us reproduce and fix the problem. Feedback is only submitted when you explicitly submit the feedback form.
What we do not collect
- Patient data or protected health information (PHI)
- Location data
- Device contacts
- Camera or microphone access
- Biometric data
- Third-party analytics or advertising identifiers
Patient & protected health information
This App is not designed or intended for the storage, processing, or handling of protected health information (PHI). Users should not enter patient-identifying or protected health information into notes or any free-text areas of the App. All data associated with your account is intended to reflect your personal educational progress only, not patient records.
If you believe PHI has been inadvertently entered, contact us at privacy@criticalcarevault.com to request a review and deletion.
Third-party services
The App relies on the following third-party services, each governed by their own privacy policies:
- Supabase: user authentication and cloud data storage
- Vercel: application hosting and content delivery
- Sentry: crash reporting and performance monitoring. Stack traces, error type, and the route at time of error are transmitted. User identity is limited to a Supabase user ID. No advertising use. Session replay is disabled on clean sessions and masks all text, inputs, and media.
- Vercel Analytics & Speed Insights: included dependencies that remain inactive in the installed iOS app; no analytics or performance beacons are transmitted.
Data retention & deletion
Account data is retained while your account is active. You can delete your account in the App from Settings → Account → Delete account; this removes the account and associated account data. If you need help with deletion, contact us at privacy@criticalcarevault.com.
Users who have not created an account (guest mode) store progress data on their local device. Clearing local app storage or reinstalling removes local guest progress. If a guest submits feedback, that feedback report is transmitted and retained so we can review, rate-limit, and respond to the issue.
Security
We use encrypted connections (HTTPS) and industry-standard authentication practices to protect your data. No security system is completely infallible; please use a strong, unique password.
Changes to this policy
This policy may be updated periodically. Continued use of the App following changes constitutes acceptance of the updated policy. We will not materially reduce protections for data collected under a prior version without notice.