🏥
PraxisMD
  • Products
  • Why PraxisMD
  • Guidelines
  • Blog
  • Pricing
Open App →
Home › Privacy Policy

Privacy Policy

Effective date: January 2024  ·  Last reviewed: January 2024

Summary: PraxisMD is built on a privacy-first principle. We do not see, store, or process your patient clinical data — it stays on your device and in your own chosen cloud storage. The data we do hold is limited to what is necessary to operate your account and verify your professional credentials.

Contents

  1. Who we are
  2. Data we collect
  3. Data we do NOT collect
  4. How data is stored
  5. Third-party services
  6. Data retention
  7. Your rights (GDPR & international)
  8. Cookies
  9. Changes to this policy
  10. Contact us

1. Who We Are

PraxisMD ("we", "us", "our") is a clinical documentation platform built for practising clinicians and medical students. Our website is located at www.praxismd.net and our web application is available at app.praxismd.net.

For the purposes of the General Data Protection Regulation (GDPR) and applicable international data protection laws, PraxisMD acts as the data controller for the personal data described in this policy.

If you have any questions about this policy or how we handle your data, please contact us at: support@praxismd.app

2. Data We Collect

We collect only the minimum personal data necessary to provide, operate, and improve the PraxisMD service. This includes the following categories:

2.1 Account & Identity Data

  • Name — your full name as provided at registration, used to personalise your account and appear on any exported clinical documents.
  • Email address — used to create and authenticate your account, send transactional emails (e.g. subscription receipts, password resets) and respond to support queries.
  • Professional registration number — collected for clinician accounts to support our verification process. This allows us to confirm that clinician-tier users hold valid professional registration with a recognised medical body.

2.2 Verification Documents

  • Clinician accounts require submission of a professional registration certificate or equivalent verification document to confirm active registration status. These documents are reviewed by our team and stored securely in Google Firebase / Firestore with access restricted to authorised PraxisMD personnel.
  • Verification documents are not shared with third parties except where required by law.

2.3 Subscription & Payment Data

  • Subscription status, plan type, billing cycle, and renewal dates are stored in our database (Firebase Firestore).
  • Payment card details and financial transaction data are handled exclusively by Stripe, our payment processor. PraxisMD does not receive or store your full card number, CVV, or bank account information. We receive only a tokenised reference and basic transaction metadata (e.g. payment success, subscription active) from Stripe.

2.4 Usage Analytics

  • We use PostHog to collect anonymised, aggregated analytics data about how users interact with our platform (e.g. which features are used most, session duration, general navigation patterns). This data helps us improve the product.
  • PostHog analytics do not include patient clinical data. Analytics data is collected at the application level and is associated with a pseudonymous user identifier, not with your name or email unless you have explicitly opted in.
  • You can opt out of analytics tracking at any time via the Settings panel within the PraxisMD app.

2.5 Technical & Log Data

  • Standard server and function logs may be generated by Firebase Cloud Functions and Google Cloud infrastructure. These logs may include your IP address, browser type, and timestamp of requests. Logs are used for security monitoring, debugging, and abuse prevention.

3. Data We Do NOT Collect

Patient clinical data is never sent to PraxisMD servers. Your clinical notes, patient records, consultation summaries, prescriptions, referral letters and all other clinical documents are stored exclusively on your device and in your own chosen cloud storage (such as OneDrive, iCloud, or Google Drive). We have no access to this data.

Specifically, PraxisMD does not collect, store, or process:

  • Patient names, dates of birth, or contact details
  • Patient medical histories, diagnoses, or clinical findings
  • Prescription content or drug dosage records
  • Referral letter contents or specialist correspondence
  • Any data that constitutes "special category" health data under GDPR Article 9
  • Biometric data
  • Data from minors — our platform is intended for professional and student use only

Because patient clinical data never leaves your device or your own cloud provider, PraxisMD does not act as a data processor for your patients' personal data. You remain solely responsible for ensuring your own data handling complies with your local healthcare data protection obligations (e.g. GDPR, HIPAA, or equivalent legislation).

4. How Data Is Stored

4.1 Firebase / Firestore (Google Cloud)

Account information, subscription status, clinician verification status, and professional registration data are stored in Google Firebase Firestore, a cloud-hosted NoSQL database operated by Google LLC. Data stored in Firestore is encrypted at rest and in transit. Firebase infrastructure is hosted on Google Cloud Platform in accordance with Google's data processing terms.

4.2 Stripe

All payment card data and billing information is stored and managed by Stripe, Inc., a PCI-DSS Level 1 certified payment processor. PraxisMD stores only the Stripe Customer ID and subscription metadata returned by Stripe's API. Full payment credentials are never transmitted to or stored by PraxisMD.

4.3 localStorage (Device)

Certain application preferences and non-sensitive settings (such as your chosen theme, PIN authentication state, and notification preferences) are stored in your browser's localStorage. This data remains on your device and is not transmitted to our servers. It can be cleared at any time by clearing your browser storage or using the Reset option in the app Settings.

4.4 Security Measures

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include transport layer security (TLS/HTTPS) for all data in transit, Firestore security rules restricting data access to the authenticated account owner, and access controls limiting internal access to personal data on a need-to-know basis.

5. Third-Party Services

PraxisMD uses a small number of carefully selected third-party services to operate the platform. Each service receives only the data necessary for its function.

5.1 Stripe (Payments)

Stripe processes all subscription payments. When you subscribe, your payment details are submitted directly to Stripe's secure servers. Stripe's privacy policy is available at stripe.com/privacy. Stripe is certified to the EU-US Data Privacy Framework.

5.2 Google Firebase (Hosting, Authentication, Database, Cloud Functions)

Firebase provides our authentication system, hosting infrastructure, serverless functions, and Firestore database. Google acts as a data processor on our behalf under a Data Processing Agreement. Google's privacy policy is available at policies.google.com/privacy.

5.3 PostHog (Analytics)

PostHog is an open-source product analytics platform that we use to understand how users interact with the app. PostHog collects pseudonymised event data (e.g. button clicks, page views, feature usage). No patient clinical data is included in any analytics events. You may opt out of PostHog analytics at any time via the Settings panel in the PraxisMD app, which will disable event capture for your session and set a persistent opt-out preference. PostHog's privacy policy is available at posthog.com/privacy.

5.4 Google Fonts

Our website uses Google Fonts to render the Inter typeface. When your browser loads the website, it may send a request to Google's servers to retrieve the font files. This request may include your IP address. You can review Google's privacy practices at policies.google.com/privacy.

We do not sell your personal data to any third party, and we do not use your data for advertising purposes.

6. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes set out in this policy, or as required by law.

  • Account data (name, email, registration number): retained for the duration of your account and for up to 3 years after account closure, for legitimate business, legal, and dispute resolution purposes.
  • Verification documents: retained for the duration of your clinician subscription and for up to 12 months after subscription end, unless a longer period is required by applicable professional or legal regulations.
  • Subscription records: retained for up to 7 years in line with standard financial record-keeping obligations.
  • Analytics data: PostHog event data is retained for up to 12 months on a rolling basis. Aggregated, anonymised data may be retained indefinitely.
  • Server logs: retained for up to 90 days for security and debugging purposes.

Upon account deletion, we will delete or anonymise your personal data within 30 days, except where retention is required by law or legitimate business interest (e.g. outstanding billing obligations or ongoing disputes).

7. Your Rights (GDPR & International)

Depending on your jurisdiction, you may have the following rights with respect to your personal data:

7.1 Right of Access

You have the right to request a copy of the personal data we hold about you. We will provide this within 30 days of a verified request.

7.2 Right to Rectification

You have the right to request correction of inaccurate or incomplete personal data. You may update most account details directly from the app Settings. For verification document corrections, please contact us directly.

7.3 Right to Erasure ("Right to be Forgotten")

You have the right to request deletion of your personal data. You may delete your account at any time from the app Settings. Upon verified request, we will delete your personal data within 30 days, subject to our legal retention obligations.

7.4 Right to Restriction of Processing

You have the right to request that we restrict processing of your personal data in certain circumstances (e.g. while a dispute is resolved).

7.5 Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, machine-readable format (e.g. JSON or CSV) and to request that we transmit it to another controller where technically feasible. This applies to data you have provided to us and that we process on the basis of your consent or a contract.

7.6 Right to Object

You have the right to object to processing of your personal data for direct marketing purposes. You may also object to other processing activities where we rely on legitimate interests as our lawful basis.

7.7 Rights Related to Automated Decision-Making

PraxisMD does not make any decisions about you solely by automated means that produce significant legal or similarly significant effects.

7.8 How to Exercise Your Rights

To exercise any of these rights, please email us at support@praxismd.app with the subject line "Data Rights Request". We may need to verify your identity before processing your request. We will respond within 30 days. If you are unhappy with our response, you have the right to lodge a complaint with your local data protection authority (for example, the Information Commissioner's Office (ICO) in the UK, or the relevant supervisory authority in your EU member state).

8. Cookies & Local Storage

Our website and app use cookies and browser localStorage to function correctly and to collect anonymised analytics. For full details of what we use, why, and how to manage or opt out, please read our Cookie Policy.

In summary: we do not use advertising or tracking cookies. We use functional localStorage for core app features (PIN, preferences, subscription state), and PostHog for anonymised analytics which you can opt out of in app Settings.

9. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the services we offer. When we make material changes, we will update the "Last reviewed" date at the top of this page and, where appropriate, notify you by email or in-app notification.

Your continued use of PraxisMD after any changes constitutes your acceptance of the updated policy. We encourage you to review this page periodically.

10. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, please get in touch:

  • Email: support@praxismd.app
  • Website: www.praxismd.net

We aim to respond to all privacy-related enquiries within 5 business days.

🏥
PraxisMD

Clinical documentation that works as hard as you do. Built for clinicians and medical students worldwide.

in 𝕏 📷

Products

  • PraxisMD Clinician
  • PraxisMD Student
  • Marketplace (coming soon)
  • Courses (coming soon)

Resources

  • NICE Guidelines
  • WHO Guidelines
  • UpToDate
  • ADA Standards
  • Blog (coming soon)

Company

  • Support
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy

© 2024 PraxisMD. All rights reserved. · support@praxismd.app

Privacy Terms Cookies