ConsentShot Pricing

Privacy policy

The short version: ConsentShot stores clinic sign-in details, staff names, patient names and dates of birth, patient photos, signed consent records, and an audit log of who did what. All of it goes to our servers and nowhere else. The app contains no analytics SDKs and no third-party trackers. We never sell data, and we never use it for advertising. Everything is encrypted in transit and at rest.

Who this policy covers

ConsentShot is a before and after photo and consent app for medical practices. A clinic subscribes, and its staff use the app on clinic devices. That means two kinds of people show up in our records: clinic staff who sign in, and patients whose photos and consent forms the clinic stores. This policy explains what we hold about both.

The clinic is the owner of its patient records. We process them on the clinic's behalf so the app can work. If you are a patient with a question about photos of you, start with your clinic; it controls the record and can show, export, or delete it.

What we collect

That is the whole list. The app does not read your contacts, your location, or the device camera roll. The camera permission is used only to take clinical photos inside the app.

What we use it for

One purpose: making the product work for the clinic. Photos and consent records exist so the clinic has a clinical record and so the export gate can check the signed consent before anything leaves the app. Sign-in details and PINs exist so the audit log is accurate. We do not use any of this data for advertising, marketing profiles, or model training.

What never happens

How it is protected

Photos and consent records are encrypted in transit and at rest. Access inside a clinic requires the clinic sign-in plus a personal staff PIN, and every access is logged. Exports are checked server-side against the signed consent: if the form does not cover the use, the export is blocked. If a patient revokes consent, future exports stop immediately.

HIPAA

We designed ConsentShot to be used with protected health information, whether or not a given practice is a HIPAA covered entity. For practices that are, we sign a Business Associate Agreement. Email [email protected] and we will send one.

How long we keep it

For as long as the clinic's account is active, because photos and consent records are the clinic's clinical record. When a clinic closes its account, it can export its records first; after closure we delete the clinic's data from our systems, allowing for a short window in encrypted backups before those cycle out. A clinic can also ask us to delete specific records at any time at [email protected].

Your choices

Children

ConsentShot is a professional tool for practice staff, not a consumer app, and we do not knowingly collect information from children. Where a clinic treats a minor, consent works the way it does in the rest of medicine: through the parent or guardian, under the clinic's own policies.

Changes to this policy

If we change this policy, we will update this page and the date at the top. If a change reduces protections in any real way, we will email clinic account holders before it takes effect.

Contact

ConsentShot
[email protected]