← Back to EchoProb

Privacy Policy

Effective: April 11, 2026 · Version 1.0

1. Who We Are

EchoProb is a web-based clinical decision support (CDS) tool created by Andrew Malashock, RDCS, FASE. EchoProb accepts numeric echocardiographic measurements and returns probability-weighted grading assessments based on published guidelines. It is exempt from FDA device regulation under the 21st Century Cures Act (2016) Section 3060.

2. What We Collect

Data TypeExamplesStorageRetention
Account dataEmail, name, credential, institutionSupabase (PostgreSQL, AWS us-east-1)Until account deletion
Echocardiographic measurementsEROA, VC, RegVol, LVEF, TAPSENot stored. Processed in memory, returned to your browser, then discarded.None (stateless)
Study snapshotsSaved module results and numeric measurements, de-identifiedYour device (browser localStorage) and Supabase (account-scoped, RLS-protected) so your studies sync across devices. A client-side scrub redacts common PHI patterns before any sync.Until account deletion
Quiz Mode attemptsSubmitted grade, score, difficultySupabaseUntil account deletion
API audit logsEndpoint, user ID, module, IP, statusSupabase90 days, then deleted
Billing dataSubscription status, trial datesSupabase (status only); Stripe (payment details)Per Stripe retention policy
AnalyticsAnonymous page views, feature eventsPlausible Analytics (EU-hosted, cookieless)Per Plausible retention policy

3. What We Do NOT Collect

Your Responsibility

You are instructed at first login and at study creation to never enter protected health information. Use de-identified case labels (e.g., "Case A" or "EP-042"), not patient names or MRNs.

4. How Grading Works (Data Flow)

When you submit measurements, your browser sends them to our serverless grading function. The function processes the values in memory, computes a probability distribution, returns the results to your browser, and discards the input values. Measurement data is never stored, logged, or persisted on our servers.

5. Cookies and Analytics

EchoProb uses the following cookies and similar technologies:

We do not use advertising cookies, tracking pixels, or third-party remarketing.

6. Third-Party Processors

ServicePurposeData Shared
SupabaseDatabase, authenticationAccount data, quiz attempts, audit logs
NetlifyHosting, serverless functionsHTTP requests (no measurement data persisted)
StripePayment processingEmail, subscription status
SentryError monitoringError stack traces (no PII or measurements)
ResendTransactional emailEmail address (welcome email)
Plausible AnalyticsUsage analytics (cookieless)Anonymous page views, feature events

7. Data Security

8. HIPAA

EchoProb is not currently HIPAA-compliant and does not process, store, or transmit PHI. For institutional deployments requiring HIPAA compliance, a Business Associate Agreement (BAA) is planned for Q4 2026. The architecture is HIPAA-ready: measurement data is stateless, audit logging is in place, and all data is encrypted in transit.

9. Your Rights

You may:

When you delete your account, we permanently remove your profile, quiz history, learning stats, referral records, and audit log entries. Study snapshots stored on your device are not affected (they were never on our servers).

10. Data Retention

DataRetentionDeletion
Account dataUntil deletion or 2 years of inactivityAccount deletion (Profile page or email request)
Study snapshotsYou control (device storage)Clear browser data or delete in-app
Quiz attemptsUntil account deletionCascade deleted with account
API audit logs90 daysScheduled cleanup
Rate limit records5 minutesAuto-purged

11. International Users

EchoProb is hosted in the United States (AWS us-east-1 via Supabase, Netlify CDN). If you access EchoProb from outside the US, your data may be transferred to and processed in the US. By using EchoProb, you consent to this transfer.

For EU/EEA users: we process data under legitimate interest (providing the service you requested) for essential functions, and under consent for analytics. You may exercise your GDPR rights by deleting your account in the app or contacting us.

12. Children

EchoProb is a professional clinical tool. It is not intended for users under 18.

13. Changes to This Policy

We will update this policy as features change (particularly for institutional licensing, HIPAA BAA, and international deployments). Material changes will be communicated via email or in-app notice. The effective date at the top of this page will always reflect the latest version.

14. Contact

Questions about this policy: amalashock@gmail.com