Privacy Policy
Last updated: June 1, 2026
AnesthesiApp ("we", "our", or "us") operates the AnesthesiApp web application. This page informs you of our policies regarding the collection, use, and disclosure of personal data when you use our Service and the choices you have associated with that data.
1. Information Collection and Use
We collect several different types of information for various purposes to provide and improve our clinical simulation and case logging Service to you.
Types of Data Collected:
- Personal Profile Information (Google OAuth): When registering or authenticating via Google Sign-In, we collect your email address, full name, and your Google account profile picture URL. This is used solely to construct your account and customize your dashboard.
- Clinical Case Logs: Information regarding the cases you document (procedure details, anesthetics used, diagnostics, post-operative outcome rooms, and optional attached clinical images). All clinical logs must be fully anonymized or fictionalized by the user. You must never upload real-world Patient Names, actual Medical Record Numbers (MRN), or any other direct patient identifiers anywhere in the application.
- Simulation Statistics: History of your CBT exam answers, OSCE completion checklists, scores, time elapsed, and reviews or discussion board comments.
2. Supabase Storage & Data Encryption
All data is stored securely using Supabase database tables and storage systems.
- Row-Level Security (RLS): The database implements strict Row-Level Security policies. This ensures that your private case logs and custom test questions are accessible only to you.
- Storage Buckets: Images attached to CBT questions or your user profile avatar are uploaded to secure Supabase storage buckets. Avatar updates are restricted to folders matching your user UUID.
- TLS/SSL Encryption: All network traffic between your browser and the Supabase API is encrypted using secure protocols.
3. Use of Google OAuth Scopes
AnesthesiApp uses Google OAuth APIs to authenticate users. We strictly limit our request to basic profile scopes:
openid: To verify account authenticity.https://www.googleapis.com/auth/userinfo.email: To access your email address and associate your clinical logs to a verified identity.https://www.googleapis.com/auth/userinfo.profile: To fetch your name and profile avatar, preventing local database duplicates and streamlining account creation.
We do not request offline API access, Google Drive files, or calendar read/writes. We do not sell or share Google Auth profiles with any advertisement networks or third parties.
4. Cookies & Local Storage
We use cookies and local storage tokens to keep you logged in and preserve session credentials.
- Session Cookies: Required for Supabase Auth to track tokens (access tokens and refresh tokens) across page transitions.
- Local Storage Drafts: Used locally on your device to auto-save case logging wizard forms, preventing data loss if you refresh the browser mid-procedure.
5. User Rights & Data Deletion
We respect your privacy and give you full control over your information.
- Access and Export: You can browse all your logged cases directly inside your personal dashboard page.
- Account Deletion: If you decide to remove your account, you have the right to request a complete wipe of all your case logs, profile credentials, CBT/OSCE attempts, and storage bucket files.
To request account deletion, please send an email from your registered address to [email protected]. We will verify and purge all associated records from the Supabase databases within 7 business days.
6. Changes to Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.
Questions & Support
For questions regarding data processing, to submit a GDPR/UU PDP/HIPAA deletion request, or to report accidental PII uploads, please reach out directly to our support team at [email protected].