Security and data handling

Know where your data goes.

Your cloud records, private notes on this device and requests to AI services have different paths. Here is what each one means when you use CredentialDoMD.

Updated September 18, 2026 · Invite-only beta

01 · CLOUD RECORDS

Your professional file

Credentials, contracts, work records and invoices sync to Supabase. Uploaded documents use private file storage. Clerk manages sign-in.

Account access rules are designed to separate users’ records. The operator has administrative access to run the service and provide support.

02 · ON THIS DEVICE

Private notes

The separate private note field on a work or case entry stays in this browser. It is excluded from normal cloud sync, invoices, AI requests and cloud backups.

Private notes are readable browser data and are not separately encrypted by the app. Protect your device and browser account.

03 · AI REQUESTS

Content you submit

Scanning, dictation and assistant features send content to Google’s Gemini API or Anthropic’s Claude API. Vera uses Gemini by default; Claude is an optional selection.

The assistant can include your question, a summary of your records, conversation context and any attachment. Review what you submit.

Keep patient identifiers out of uploads and AI inputs.

CredentialDoMD is intended for physician credentials and professional administration. Do not put patient names, medical record numbers or other patient identifiers into synced fields, attachments, support tickets, chats or dictated text.

Document screening and AI instructions can miss identifiers. They do not guarantee that information is removed before it reaches a server or AI provider. A separate local note also does not protect content you paste or dictate elsewhere.

We make no HIPAA compliance claim and do not offer a business associate agreement (BAA). Do not use the service for a workflow that requires a BAA.

Using AI does not require your own API key.

Approved beta accounts can use the service’s shared AI access, subject to availability and usage limits. Those service keys stay on the server. The server forwards your request to the selected provider.

You can optionally add your own Gemini or Anthropic key in Settings. It is kept on this device; requests using it go directly to that provider, and any provider charges belong to you. Provider handling terms apply to submitted content in either route.

Dictation may also use your browser’s speech-recognition service. Review AI output before saving credential details, billing entries or codes.

Local storage needs its own care.

Who can access cloud information?

CredentialDoMD is operated by Eric Whitney, DO, A Professional Corporation. Eric Whitney, DO administers the service for the corporation.

You can access your account records. The operator can access cloud records for support, debugging and operating the service. Support tickets, attachments, feedback and assistant activity logs are available to the operator and may be handled with AI tooling.

Service providers process information needed for the features you use. Sending a document packet shares the selected files with your chosen recipient. See the Privacy Policy for the provider list, sharing, exports and deletion.

This page describes current behavior and its limits. It is not a security certification or a guarantee that every vulnerability has been eliminated.

Report a security concern.

Email [email protected] with a description and steps to reproduce. Leave patient information, passwords and API keys out of the message.

Request beta access

Invite-only beta. No card required. Billing is not open.