Privacy policy
Effective August 1, 2026. Questions: [email protected].
The short version: ConsentShot stores clinic sign-in details, staff names, patient names and dates of birth, patient photos, signed consent records, and an audit log of who did what. All of it goes to our servers and nowhere else. The app contains no analytics SDKs and no third-party trackers. We never sell data, and we never use it for advertising. Everything is encrypted in transit and at rest.
Who this policy covers
ConsentShot is a before and after photo and consent app for medical practices. A clinic subscribes, and its staff use the app on clinic devices. That means two kinds of people show up in our records: clinic staff who sign in, and patients whose photos and consent forms the clinic stores. This policy explains what we hold about both.
The clinic is the owner of its patient records. We process them on the clinic's behalf so the app can work. If you are a patient with a question about photos of you, start with your clinic; it controls the record and can show, export, or delete it.
What we collect
- Clinic account email and password. Used to sign the clinic in. Passwords are handled by our authentication provider and we never see them in plain text.
- Staff names and PINs. Each staff member has a name and a personal PIN on the shared clinic device. The PIN exists so the audit log can say which person captured, viewed, or exported a photo.
- Patient names and dates of birth. Entered by clinic staff to identify the patient's record.
- Patient photos. Captured inside the app on the clinic device. They upload to our servers and are not written to the device's camera roll.
- Signed consent records. The consent form text, the patient's finger signature, the signer's name, the permission choices the patient made, a timestamp, and an identifier for the device the form was signed on. The device identifier is part of the record's audit trail; it is not an advertising identifier.
- Audit logs. Our servers record each capture, view, and export, with the staff member who did it and when.
That is the whole list. The app does not read your contacts, your location, or the device camera roll. The camera permission is used only to take clinical photos inside the app.
What we use it for
One purpose: making the product work for the clinic. Photos and consent records exist so the clinic has a clinical record and so the export gate can check the signed consent before anything leaves the app. Sign-in details and PINs exist so the audit log is accurate. We do not use any of this data for advertising, marketing profiles, or model training.
What never happens
- No selling data. Not to anyone, not in anonymized form, not as part of an acquisition of "user insights."
- No third-party analytics or tracking. The app ships with zero analytics, crash-reporting, or advertising SDKs. There is nothing in it that phones home to anyone but us.
- No sharing with third parties, except the infrastructure providers who host our servers and storage (they process data under contract, on our instructions, and cannot use it for their own purposes), and disclosures the law compels, which we would limit to what the law requires.
- No patient photos in our marketing. Ever.
How it is protected
Photos and consent records are encrypted in transit and at rest. Access inside a clinic requires the clinic sign-in plus a personal staff PIN, and every access is logged. Exports are checked server-side against the signed consent: if the form does not cover the use, the export is blocked. If a patient revokes consent, future exports stop immediately.
HIPAA
We designed ConsentShot to be used with protected health information, whether or not a given practice is a HIPAA covered entity. For practices that are, we sign a Business Associate Agreement. Email [email protected] and we will send one.
How long we keep it
For as long as the clinic's account is active, because photos and consent records are the clinic's clinical record. When a clinic closes its account, it can export its records first; after closure we delete the clinic's data from our systems, allowing for a short window in encrypted backups before those cycle out. A clinic can also ask us to delete specific records at any time at [email protected].
Your choices
- Patients: your consent form lists exactly what you allowed, and you can revoke it through your clinic at any time. Revocation blocks future exports the moment it is recorded. For access, correction, or deletion of your photos, contact your clinic; we will support whatever the clinic directs.
- Clinics: you can export or delete your data, or close your account, by emailing us.
- Everyone: depending on where you live, privacy law may give you rights to access, correct, or delete personal information. Email us and we will honor them, working with your clinic where the record belongs to it.
Children
ConsentShot is a professional tool for practice staff, not a consumer app, and we do not knowingly collect information from children. Where a clinic treats a minor, consent works the way it does in the rest of medicine: through the parent or guardian, under the clinic's own policies.
Changes to this policy
If we change this policy, we will update this page and the date at the top. If a change reduces protections in any real way, we will email clinic account holders before it takes effect.
Contact
ConsentShot
[email protected]