Legal

Privacy policy

Also available alongside our other policies on the About page.

Version 1.3  ·  Last updated: September 24, 2026

Privacy at a glance

The short version of everything below. This summary is for convenience — the numbered sections that follow are the actual policy.

WhatCollected?Details
IdentityYesName, email, role, subspecialty, institution — used to run your account. Never sold, never shared for advertising.
Your contentStored, not readProcedures, steps, surgeon preferences, implants, notes and images sync to encrypted cloud storage so they follow you across your own devices. Visible only to you unless you deliberately join a shared program workspace.
PaymentNo card dataStripe processes payments. We never see or store your card number — only your Stripe customer ID and subscription tier.
Usage analyticsAnonymousPages visited, features used, app version, device OS. Never your notes or procedure content.
Patient data / PHINeverNot collected and not permitted anywhere in the app. OrthoVaultOS is not a HIPAA-covered system.
AI promptsRecent searches onlyIf you enable an AI feature, your questions go from your device straight to the provider whose key you entered. The one exception is Claude in the browser (the AI Assistant, and Literature Search when set to Claude): those questions pass through our server on the way to Anthropic, and we do not store them. AI Assistant conversations are not saved. Your last 8 Literature Search questions are saved to show as recent searches: in your account in the desktop app, and only in that browser in the browser app.
Your API keysStored (desktop app)In the desktop app, stored in your account so one key works on all your desktop installs. Held as plain text, not encrypted at rest — use a scoped key you can rotate. In the browser, saved only in that browser. Used only for the requests you make, and billed to your own provider account.
Data sold or sharedNeverWe do not sell or share your personal information, and we do not use your notes or content to train AI models.
Third-party ad trackingNoneNo advertising networks, no cross-site tracking, no ad profiles.
Deleting your dataAny timeDelete your account and all cloud data is wiped; residual backups purge within 90 days. Export first from Account → Data & Privacy → Export library.

1. Who we are

OrthoVaultOS LLC operates OrthoVaultOS, a personal notes and surgical workflow application available on macOS and Windows. This policy explains how we collect, use, and protect information when you use our app or website.

2. What we collect

Account information

When you create an account, we collect your name, email address, role, subspecialty, and institution, and — if you arrived from a tagged campaign link — the name of that campaign. This is stored in our database (Supabase) and used solely to operate your account.

Usage data

We collect anonymous usage analytics — pages visited, features used, app version, device OS. This never includes your notes, procedure content, or any personal clinical information.

Payment information

Payments are processed by Stripe. We never see or store your card number. We store your Stripe customer ID and subscription tier in our database.

Recent searches

Your last 8 Literature Search questions are saved so the app can show them as recent searches. In the desktop app they are saved to your account; in the browser app they are saved only in that browser.

Cloud storage

If you're signed in, your procedures, steps, surgeon preferences, implants, evidence links, and notes sync to encrypted cloud storage (Supabase) so they follow you across your own devices — on any tier, including Free. Images, documents, and videos you upload are stored the same way on every tier, as are photos sent with phone photo upload (Professional tier). Only you can access your files.

3. What we do NOT collect

We do not collect HPI (History of Present Illness), patient information, clinical data, or protected health information (PHI). OrthoVaultOS is not designed for patient data. If you enter patient information into the app, you do so at your own risk — we are not liable for that data and it is not protected under HIPAA.

4. How we use your information

  • To create and manage your account
  • To process your subscription via Stripe
  • To provide cloud sync of your library and uploaded files across your own devices, and phone photo upload if you are on the Professional tier
  • To send service-related emails (account confirmation, billing receipts, product updates)
  • To improve the app using anonymous aggregate analytics

We do not sell your data. We do not use your notes or content for advertising or training AI models.

5. Third-party services

We use the following third-party services:

  • Supabase — database, authentication, and file storage
  • Vercel — website hosting and anonymous visit analytics
  • Stripe — payment processing
  • Resend — sending account and support emails
  • Google Fonts — typography (loaded from Google's CDN)

Each service has its own privacy policy. We recommend reviewing them.

Literature Search questions are also sent to PubMed, run by the U.S. National Library of Medicine, to find articles.

If — and only if — you turn on an AI feature, one further provider is involved: Anthropic (Claude, for the AI Assistant and, if you choose it, the AI Summary) or Google Gemini (for the AI Summary). See section 6.

6. AI features and your API keys

OrthoVaultOS has two optional AI features, and neither is on by default: the AI Assistant (powered by Anthropic’s Claude) and the AI Summary in Literature Search (powered by Google Gemini, or by Claude if you choose it). To use either, you enter your own API key for that provider.

  • In the desktop app, your API keys are stored in your OrthoVaultOS account. They travel with your account so that one key works on each of your desktop installs without your entering it twice. They are held in our database as plain text and are not encrypted at rest, so use a scoped key you can rotate. In the browser app, your keys are saved only in that browser and are not stored in your account. We use them for nothing other than the requests you yourself make.
  • We do not keep your prompts, with one exception. When you ask the AI something, your question and the relevant contents of the procedure you have open go from your device directly to that provider. Claude in the browser app (the AI Assistant, and Literature Search when set to Claude) takes a different route: those requests pass through an OrthoVaultOS server function that relays them to Anthropic. That relay does not store your prompt or your key. AI Assistant conversations are not saved. The one thing we keep is from Literature Search: your last 8 search questions are saved so the app can show them as recent searches. In the desktop app they are saved to your OrthoVaultOS account; in the browser app they are saved only in that browser.
  • The provider handles that data under its own policy. Anthropic and Google each publish their own privacy policy and data-retention terms, and your usage is billed to your own account with them. We recommend reading whichever applies to you.
  • We do not train on your data. We do not use your notes, content, or AI prompts to train any AI model, and we never will without asking you first.
  • Do not enter patient-identifying information into an AI feature, for the same reason it does not belong anywhere else in the app.

7. Data storage

Your data is stored securely in the cloud, so it's always accessible from any device you're signed in to. We use Supabase encrypted cloud storage to keep your procedures, surgeon profiles, and notes safe and in sync. You can export your library at any time from Account → Data & Privacy → Export library (uploaded files are not included).

8. Shared program workspaces

OrthoVaultOS gives you two separate places to work: your personal vault, which only you can see, and a shared program workspace, which the members of a residency program share. You are only ever in a shared workspace if you deliberately create one or accept an invitation to join one.

What other members can see

Anything you add while working in a shared program workspace — procedures, surgeon preferences, surgical steps, implants, notes, images and attached documents — is visible to every member of that program. Content you create in your personal vault is never visible to anyone else.

What never leaves your personal vault

Regardless of which mode you are working in, these are always kept private to you and are never written to a shared workspace:

  • Any API keys or credentials you enter in Settings. Your keys are stored in your own account or your own browser (see section 6) and are never visible to anyone else in the program.
  • Your case log — which cases you completed, when, and any notes you typed during a case.

Program administrators

Administrators of a program can add and remove members, and can modify or delete content in that program workspace, including content contributed by other members.

Leaving a program

If you leave a program, or an administrator removes you, you lose access to that program's workspace. Content you contributed to it remains in the workspace and does not transfer back to you. Your personal vault is unaffected.

Patient information

Do not enter patient-identifying information anywhere in OrthoVaultOS. This matters especially in a shared workspace, where anything you enter is visible to every member of the program rather than only to you.

9. Data retention

Your account data is retained as long as your account is active. If you delete your account, all of your cloud data is wiped from our systems — export your library first from Account → Data & Privacy → Export library if you want to keep a copy. Residual backups are purged within 90 days.

10. Your rights

You may request access to, correction of, or deletion of your personal data at any time by contacting us at hello@orthovaultos.com. We will respond within 30 days.

11. Security

All of your data is protected via our storage partner, Supabase, using industry-standard encryption in transit (HTTPS/TLS) and at rest (AES-256). However, OrthoVaultOS is not a healthcare-grade system and does not guarantee protection against all forms of data loss or breach.

12. Cookies, tracking, and Do Not Track

We do not use advertising cookies, tracking pixels, or ad networks. We do not build advertising profiles, and we do not allow any third party to collect personally identifiable information about your activity across other websites through our service.

Our website analytics are anonymous by construction: we record which pages were visited and which features were used, with no identifier and no cookie attached to it. One exception: if you arrive from a link tagged with a campaign name, that name is kept in your browser for 30 days, and if you then sign up it is saved with your account so we can tell which campaigns work. Signing in does store a session in your browser so you stay logged in — that is what keeps your account working, not tracking.

Do Not Track signals

Some browsers can send a “Do Not Track” signal. There is still no industry-standard way to interpret it. Our answer is simple: our behavior is the same whether or not you send the signal, because we do not do the cross-site behavioral tracking that Do Not Track was created to stop. We do not track you across other websites either way.

13. International users

The data controller for your personal data is OrthoVaultOS LLC, a California limited liability company. You can reach us about anything in this policy at hello@orthovaultos.com.

OrthoVaultOS is operated from the United States, and your data is stored and processed in the United States. If you use OrthoVaultOS from outside the United States, you are consenting to that transfer. The strongest protection here is structural: we do not collect patient data, we do not sell anything, and we do not profile you.

If you are in the European Economic Area, the United Kingdom, or another jurisdiction with comparable rules, the lawful bases we rely on are: performing our contract with you (running your account and cloud sync), our legitimate interests (keeping the service secure and improving it with anonymous analytics), and your consent where you have given it (marketing emails, which you can withdraw at any time).

You have the right to access, correct, delete, restrict, or object to our use of your personal data, to receive it in a portable format, and to lodge a complaint with your local supervisory authority. Email hello@orthovaultos.com and we will act within 30 days.

14. Children

OrthoVaultOS is intended for licensed or credentialed healthcare professionals aged 18 and over. We do not knowingly collect data from anyone under 18.

15. Changes to this policy

We may update this policy at any time. Material changes will be communicated via email at least 30 days before taking effect. Continued use after changes constitutes acceptance.

16. Contact

For privacy questions, contact us at hello@orthovaultos.com or use the support form. This policy is governed by the laws of California, United States.