Privacy Policy
Last updated: August 24, 2026
This Privacy Policy describes how Credential Buddy (“the app,” “we,” “us”) handles your information. Credential Buddy is designed to be private by default: your case log lives on your device, all speech recognition and AI processing happens on-device, and nothing is shared with anyone unless you enable an optional feature that requires it.
Questions? Contact us at hello@credentialbuddy.com.
Summary
- On-device by default. Your cases, credentials, and documents are stored locally on your iPhone. Dictation and case parsing use Apple’s on-device speech and language models — audio and case text are never sent to any cloud AI service.
- Signing in and backing up are free; syncing is not. Creating an account — with Apple or with an email address — costs nothing, as does the encrypted backup the app writes to your own iCloud Drive. Syncing your data through our backend to your other devices requires a Credential Buddy Pro subscription. Sensitive fields (such as credential numbers and case numbers) are end-to-end encrypted with keys only you hold.
- We do not sell your data, we do not show ads, and we do not share your data with data brokers.
Information stored on your device
The app stores the data you enter or dictate: surgical case records (procedure, date, role, patient age band, complications, notes, and similar fields), attending and site lists, credential records (licenses, certifications, DEA registration, and their expiration dates), documents you attach, and your profile settings. Dictated audio is processed on-device and is not retained after transcription.
This data stays on your device unless you enable sync. Deleting the app deletes the local data.
Optional account and sync
Sync is off until you turn it on, and signing in alone does not turn it on. Your data is stored on our backend only while you are signed in and have an active Credential Buddy Pro subscription — a signed-in account without a subscription leaves your data on your device. When sync is on:
- Account. If you sign in with Apple, we receive the Apple-provided user identifier and, if you share it, your name and email (or Apple’s private relay address). If you sign in with an email address, we receive that address. We use these only to operate your account.
- Synced content. Your cases, attendings, sites, credentials, and attached documents are stored on our backend (hosted on Supabase) so they can be restored on your devices. Data is encrypted in transit (TLS) and at rest.
- End-to-end encryption. Sensitive fields — including case numbers and credential numbers — are additionally encrypted on your device before upload, with keys derived from a passphrase only you know. We cannot read these fields, and we cannot recover them if you lose your passphrase.
- Deletion. You can erase your synced data and delete your account from the app’s Settings at any time. Deleting your account removes your data from our backend.
Chrome extension
Credential Buddy for Chrome is an optional browser extension that places your reviewed cases into the ACGME Case Log entry form, one case at a time. It uses the same account and the same synced data as the app, and like sync it requires an active Credential Buddy Pro subscription.
- What it reads. Signed in with your account, the extension reads your synced cases and surgical sites from our backend to build the queue of cases you haven’t yet entered. On the web it runs only on ACGME’s site (apps.acgme.org), where it reads the entry form’s fields so it can place your case’s values into them and report what was filled. It cannot read any other website, and page content is never sent anywhere.
- Case numbers stay end-to-end encrypted. As with sync, your case numbers reach the extension encrypted, and you unlock them with your backup passphrase. The passphrase itself is never stored. The decryption key is kept in the browser’s session storage by default and discarded when the browser closes; you can instead choose to stay unlocked for 1 week or 1 month, in which case the key is stored with an expiry, and “Lock now” discards it immediately. Decrypted case numbers exist only in the open extension popup and are never written to disk.
- Storage lifetimes. Your sign-in session is stored by the extension until you sign out; signing out removes everything the extension has stored.
- Analytics. The extension sends five usage events (signed in, queue loaded, case filled, case marked, form drift detected) with counts only — never case content and never a case number.
- Submission is always manual. The extension cannot submit ACGME’s form. It places values for your review, and you press Submit on ACGME’s page yourself, every time.
iCloud backup
Separately from sync, the app can write an encrypted backup of your log to your own iCloud Drive. This feature is free, is available whether or not you have an account with us, and does not involve our backend — the file goes from your device to your Apple account, and we never receive it or hold a key to it. The backup is encrypted with a passphrase only you know, which is also what restores it; if you lose that passphrase we cannot recover the backup. Apple’s handling of files in your iCloud Drive is governed by Apple’s privacy policy.
Notifications
If you enable renewal reminders, we store your device’s push token so our server can send you expiration reminders. The token identifies your device for notifications only.
Purchases
Subscriptions are processed by Apple. We use RevenueCat to validate subscription status; RevenueCat receives an anonymous app user identifier and purchase receipts, not your name or health-related content. We never see your payment details.
Analytics
We collect limited, event-level usage analytics (for example, “a case was logged” or “an export was created”) through PostHog to understand which features are used and to fix problems. Analytics events never include case content, patient information, credential numbers, dictation text, or any other content you enter. You can disable analytics in Settings.
What we don’t collect
We do not collect patient names or identifiers (the app is designed to be used without them), your location, your contacts, or advertising identifiers. We do not use third-party advertising or tracking SDKs, and we do not “track” you across other companies’ apps or websites as defined by Apple’s App Tracking Transparency policy.
Service providers
We share data only with the processors needed to run the service, each bound by their own data-processing agreements: Apple (sign-in, purchases, push notifications), Supabase (database and file storage for optional sync), RevenueCat (subscription validation), and PostHog (usage analytics, when enabled). We do not sell or rent personal information, and we disclose it otherwise only if required by law.
Data retention
Local data stays until you delete it or the app. Synced data stays until you delete individual records or your account. Analytics events are retained in aggregate form for product improvement.
Security
Data is protected with iOS data protection on device, TLS in transit, encryption at rest on our backend, and end-to-end encryption for sensitive fields. No system is perfectly secure; if we learn of a breach affecting your data we will notify you as required by law.
Children
Credential Buddy is intended for medical professionals and is not directed at children under 13. We do not knowingly collect personal information from children.
Your rights
Depending on where you live, you may have rights to access, correct, delete, or export your personal information. Most of these are available directly in the app (export, erase, account deletion); for anything else, email hello@credentialbuddy.com.
Changes
We may update this policy as the app evolves. Material changes will be reflected on this page with a new “Last updated” date, and significant changes will be highlighted in the app.