Privacy Policy

Last Updated: March 2026

1. Overview

PsychLog ("the App") is a web-based encounter logging tool designed for psychiatry residents to track de-identified patient encounters during their training. PsychLog is operated by PsychLog LLC ("we," "us," or "our"). This Privacy Policy describes what data we collect, how we use it, and your rights regarding that data.

2. What Data We Collect

Account Information: When you create an account, we collect your name, email address, residency program name, and PGY year. This is used solely to authenticate your identity and associate your data with your account.

Encounter Data: You voluntarily enter encounter information including patient age (not date of birth), sex, race/ethnicity, diagnoses, medications, therapies, and clinical notes. This data is designed to be de-identified and should never contain Protected Health Information (PHI) such as patient names, medical record numbers, dates of birth, or other HIPAA-defined identifiers.

Usage Data: We may collect basic analytics such as login frequency and feature usage to improve the App. We do not use third-party advertising trackers.

3. What We Do NOT Collect

PsychLog is explicitly designed to avoid collecting Protected Health Information (PHI). The App does not collect or store patient names, medical record numbers (MRN), dates of birth, Social Security numbers, addresses, phone numbers, email addresses of patients, photographs of patients, or any other of the 18 HIPAA identifiers. Users are responsible for ensuring they do not enter PHI into any field of the App.

4. How Data Is Stored

All data is stored in Google Firebase (Firestore), a cloud database operated by Google LLC. Data is encrypted in transit (TLS) and at rest. Each user's data is isolated and protected by security rules that prevent any user from accessing another user's encounters. Firebase's infrastructure is SOC 2 certified and compliant with major security standards.

5. Who Can Access Your Data

You: Only you can view, edit, and delete your own encounter data.

Program Directors: If your residency program subscribes to PsychLog's institutional plan, designated program administrators may access aggregate, anonymized statistics about your program's encounter data (e.g., total encounters by rotation, diagnosis distribution). They cannot view individual encounter details or notes.

PsychLog Administrators: We may access data for technical support, debugging, or legal compliance. We will never sell, share, or monetize your data.

No Third Parties: We do not sell, rent, or share your personal data or encounter data with any third party for marketing, advertising, or any other commercial purpose.

6. Data Retention and Deletion

Your data is retained as long as your account is active. You may delete individual encounters at any time. If you wish to delete your entire account and all associated data, please contact us at support@psychlog.app. Upon account deletion, all encounter data and profile information will be permanently removed within 30 days.

7. HIPAA Disclaimer

PsychLog is not a HIPAA-covered entity and does not store Protected Health Information. The App is designed as an educational case-logging tool for residency training purposes. Users should not enter any information that could identify individual patients. If PHI is inadvertently entered, users should immediately edit or delete the relevant encounter. PsychLog is not a substitute for official medical record systems.

8. Security Measures

We implement the following security measures:

9. Children's Privacy

PsychLog is intended for medical professionals and trainees. We do not knowingly collect data from individuals under 18 years of age.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify users of material changes via the App or email. Continued use of the App after changes constitutes acceptance of the updated policy.

11. Contact Us

For questions about this Privacy Policy or to request data deletion, contact us at: support@psychlog.app