Trust
Data & privacy
Plain-language summary of what stays on your device, what we store when you sign in, and how to reach us.
On your device
Patient information stays local
Disposition workflow data — including safety screens, clinical notes you enter, patient identifiers, and saved plans — is stored in your browser on this device only. We do not upload patient PHI to our servers.
Clearing browser data or switching devices removes local plans unless you export or print them yourself. Guest users can clear local data from Settings.
Signed in
What Supabase stores
If you create an account, Supabase stores your clinician profile (email, display name), plan templates (scaffold defaults and resource selections — no patient fields), and account preferences. Templates never include names, dates of birth, MRNs, or chart content.
Sign-in today uses Supabase Auth: a one-time link to your work email. We do not store passwords. You can export or delete account data from Settings.
HIPAA
Honest positioning — not a covered BA by default
In the current product, patient workflow data stays on your device. PsychDispo does not receive, store, or transmit PHI through our cloud stack in normal use. That means the core guest and signed-in workflow is not structured as a Business Associate relationship with your covered entity.
We do not display “HIPAA certified” badges or imply SOC 2 / HITRUST certification we have not earned. Trust is earned through architecture and transparency, not stickers.
Business Associate Agreements: If a future enterprise phase stores PHI in cloud infrastructure, integrates with institutional EHR/SSO, or processes identifiable data on our servers, a BAA would be available under an enterprise contract. That is not offered for the current free clinician tier.
Enterprise
Single sign-on (Phase 2)
Hospital and health-system SSO (SAML/OIDC through your identity provider) is planned for a later enterprise phase — not available yet. Institutional rollout would include security review, data-flow documentation, and BAA terms where PHI touches our systems.
Until then, use the email sign-in link as above. If your organization needs SSO before Phase 2, contact us and we will note your interest.
Guest mode
No account required
You can use the full disposition workflow without signing in. Guest templates and saved plans remain on this device under a guest key. Signing in lets you sync templates across browsers that use the same account.
Clinical use
Decision support, not medical advice
PsychDispo organizes disposition planning, verified community resources, and documentation helpers. It does not replace your clinical judgment, local protocols, supervision, or emergency evaluation.
For life-threatening emergencies, call 911 or your local crisis line.
Security
Responsible disclosure
If you believe you found a security vulnerability, please report it responsibly. Email KristenPalmerMD@gmail.com (clinician-operated mailbox while a dedicated security alias is configured) or use our security.txt contact.
Please include steps to reproduce, affected URLs, and your preferred contact. We aim to acknowledge reports within five business days and will not pursue legal action against good-faith researchers who avoid privacy violations, data destruction, and service disruption.
Subprocessors
Infrastructure partners
- Supabase — authentication and cloud template storage (US region).
- Vercel — application hosting and content delivery.
These providers process account and template metadata only. Patient workflow data is not sent to them.
Contact
Questions or corrections
Resource updates, product questions, or privacy concerns: KristenPalmerMD@gmail.com
privacytermstrustaboutchangelogaccessibilityFull policy: Privacy Policy. Reference only — not a substitute for clinical judgment. Life-threatening emergency: 911.