Privacy Policy
CredentialDOMD is operated by Eric Whitney, DO, A Professional Corporation. This policy says what the app collects, where it lives, which companies touch it, and how you get it back or delete it. Questions go to [email protected].
CredentialDOMD is in free beta. Features, storage layout, and this policy will change as the product matures. The date above tells you which version you are reading.
1. An account is required
You sign in with an account managed by Clerk (email plus a one-time code, a passkey, or a password, depending on what you set up). Clerk holds the sign-in credentials; we receive your Clerk user id, the email address on the account, and the name you gave at sign-up. Everything you store in the app is keyed to that user id.
2. What you put in the app
- Profile: name, NPI, degree, specialties, contact details, and the states you hold licenses in.
- Credentials: licenses and registrations, DEA, board certifications, CME, hospital privileges, liability insurance, health clearances, education and training, work history, peer references, and malpractice history.
- Locum and case data: case logs, work and billing entries, invoices, and contract terms.
- Documents you upload, plus the fields the app extracts from them.
- Support and feedback: tickets and replies, field proposals, and a log of assistant questions with a one-line summary of each answer.
- Settings. Any AI keys you enter yourself stay on your device and are not stored in the database (section 4). The server keeps a count of your AI calls per day for the shared keys' daily limits.
3. Where it is stored
- On your device. Browser storage holds a cache associated with the signed-in account so records can open offline and sync when you are online. Cached records and private notes are not separately encrypted by the app. Protect access to your device and browser, and sign out when you finish on a shared computer. Export any local private notes you need before signing out.
- Supabase, US region. A Postgres database holds your records, and a private Storage bucket holds uploaded document files in a folder per user. Account access policies are designed to limit access to the appropriate account. The operator has administrative access for support and operations. Traffic is encrypted with TLS and Supabase encrypts data at rest.
- Monthly backups. Unless you turn them off in More > Data & Backup, once a month the server builds a ZIP of your records and your uploaded documents, keeps it in a separate private bucket only you can reach, and emails you when it is ready. The email carries no link to the file. You download it from More > Data & Backup while signed in, through a link that works for 15 minutes, and the server keeps the three most recent months. The archive contains no private vault notes and no AI keys, because neither is ever on the server.
- The private vault. On this device only, never synced. See section 5.
4. AI features
AI features can send content to Google’s Gemini API or Anthropic’s Claude API. Scanning and import features send the text, images or PDFs supplied for that task. Dictation sends the transcript. Vera uses Gemini by default and can use Claude when selected and available; the assistant request includes your question, conversation context, a summary of your records and any attachment. Other coding or dictation features may use either provider, depending on the feature and settings, with Gemini fallback when applicable.
Approved accounts can use shared keys held on the server. Your request passes through our server to the provider. The server records usage metadata such as provider, model, token counts, time and success or failure for usage controls and cost tracking. Separately, assistant activity logs are available to the operator as described below.
You may add your own Gemini key, an Anthropic key, or both in Settings. These keys are stored on the device rather than in the cloud database. Requests using your key go directly to that provider, and you are responsible for charges and the terms attached to the key. Your own key is optional.
Submitted content is processed under the relevant provider’s terms. Dictation also uses the browser’s speech-recognition service, which may process audio outside the device. Keep patient identifiers out of all AI inputs. Review AI output before saving or relying on it.
5. Patient information and private notes
CredentialDOMD is intended for your professional records. Do not upload patient charts or put patient identifiers such as names, medical record numbers, dates of birth, addresses or phone numbers into synced fields, attachments, support tickets, chats or dictated text.
Document screening and AI instructions are limited safeguards. They can miss identifiers and do not guarantee that information is removed before processing by the server or an AI provider.
The private note field on a work or case entry uses separate browser storage. It is excluded from normal cloud sync, AI requests, invoices, shared packets and cloud backups. It is not separately encrypted by the app. You can manually export and restore those notes through Data & Backup; the exported file is readable. Signing out, clearing browser storage or losing the device can remove the local copy. A local note does not protect information you copy, dictate or submit elsewhere.
We make no HIPAA compliance claim and do not offer a business associate agreement (BAA). Do not use the service for a workflow requiring a BAA. Read Security and data handling (credentialdomd.com/security) for practical details.
6. Companies that process your data
- Clerk (clerk.com): sign-in, sessions, and the cookies that keep you signed in.
- Supabase (supabase.com), US region: database, file storage, and the server functions behind tickets and feedback.
- Cloudflare: proxy and CDN in front of credentialdomd.com, and Turnstile, the bot check Clerk shows at sign-in.
- GitHub Pages: static hosting for the site and the app files.
- Resend: transactional email, such as the early-access welcome note and account emails.
- Google (Gemini API) and Anthropic (Claude API): when you use an AI feature, under the shared keys or your own (section 4).
- CMS NPPES registry, CMS provider data (data.cms.gov, the Medicare Care Compare files), NLM Clinical Tables, and NLM PubMed (E-utilities): the NPI and public-register lookups. Public government APIs, called from our server, that receive only what the search is keyed on: your NPI, or the name and state you searched by, or the surname and initials PubMed is matched on.
- Telegram: when you file a support ticket or reply to one, a notification containing your email, the subject, and the start of the message reaches the operator's phone through Telegram.
The register lookups (NPPES, CMS provider data, NLM Clinical Tables and PubMed) run the other way from the rest of this list. They are reads: the app asks a public government register what it already publishes about you, keyed on your NPI or your name, and shows you the answer to accept or ignore. Nothing you have stored in the app is sent to those registers, and they are never written to.
We do not sell your data. Sharing can use your device’s share, email or text controls. Where you choose the server email option, selected files and recipient details pass through our server and email provider, and the app records a share history. Check the recipients and files before sending.
7. Who can see it
- You, in the app.
- The service administrator, Eric Whitney, DO, acts for Eric Whitney, DO, A Professional Corporation and has administrative access to the database and storage for support, debugging, and abuse prevention, and reads tickets, feedback, and the assistant log. Tickets and feedback may be triaged and acted on with AI tooling. Credential data is opened only when needed to run the service.
- The companies in section 6, to the extent needed to provide their service.
- Anyone you choose to share a credential or packet with.
- Authorities, if we are legally required to disclose.
8. Cookies and the marketing site
Inside the app there are no third-party analytics, ad pixels, or trackers; the only cookies are Clerk's session cookies. On the marketing site at credentialdomd.com, a first-party beacon records the page path, referrer, and utm source of each visit, without cookies or identifiers, so we can see which pages are read; those visit counts are kept for 13 months. The site loads the Inter typeface from Google Fonts, which shows Google your IP address the way any hosted font does. If you join the early-access list, we keep the email address (and name, if you gave one) to send your invite.
9. Retention and deletion
- Your records, documents, and backups stay as long as your account does.
- Deleting a record in the app removes it from the database and, for documents, removes the file from storage. A tombstone holding only the record id is kept so the deletion reaches your other devices.
- More > Data Rights > Delete All My Data clears this device and deletes everything the app holds for your account on the server: your records, uploaded documents, monthly backups and their archives, support tickets and their screenshots, feedback, notes from the operator and your replies to them, the assistant log, AI usage rows, and error reports. Your profile is reduced to an account id with no name, email, or other fields, so the sign-in still resolves. It cannot be undone; export first.
- After a cancellation, the same deletion runs automatically 7 days later unless you reactivate before then; the Cancellation page shows the date.
- Operating records have fixed lifetimes whether or not you delete: AI usage rows 90 days, marketing-site visit counts 13 months, the assistant question log 12 months, and error reports 7 days.
- To close the sign-in account itself, or to have anything else removed, email [email protected] from the address on the account.
10. Your rights
- Access and correction: everything you stored is visible and editable in the app.
- Export: More > Data & Backup downloads all of it as JSON, which imports back into CredentialDOMD or any system that reads JSON.
- Deletion: section 9.
- If your state's privacy law gives you additional rights, email us and we will honor them.
11. Changes to this policy
We update this policy as the product changes and move the date at the top. Material changes are announced in the app. Continued use after a change means you accept it.
12. Contact
[email protected]. CredentialDOMD is operated by Eric Whitney, DO, A Professional Corporation.