Privacy Policy
Effective July 27, 2026
Who we are
CredVault ("we", "us") provides credential and training compliance software for dental practices at credvaultapp.com. This policy explains what we collect, why, and the choices you have. Questions any time: support@credvaultapp.com.
What we collect
- Account data: your name, work email, password (hashed by our authentication provider), and practice details you enter (practice name, state, locations, timezone, phone).
- Employee compliance records you enter: staff names, work emails, roles, birth month (used only to compute state birth-month renewal deadlines), hire dates, license and certificate numbers, expiry dates, CE units, and the documents you upload (license photos, certificates, training records).
- Attestation e-records: when a staff member e-signs an attestation, we record the typed signature, timestamp, IP address, and browser user-agent — this is the point of an attestation: it has to be evidentiary.
- Usage and audit data: an audit log of actions in your workspace (views, uploads, downloads, exports), because auditability is a product feature.
- Never patient data. CredVault is built to store employee credential and training data only. Do not upload patient records or protected health information; our Terms prohibit it.
How we use it
To provide the service: computing renewal deadlines, sending expiry reminder emails to the staff and managers you designate, generating evidence binders, and processing certificate photos you submit through the AI scanner (images are processed server-side to extract credential fields; you review and confirm before anything is saved). We also use your account email to send transactional messages about your account. We do not sell personal information, and we do not use your practice's data to train AI models.
Service providers (subprocessors)
We run on a small set of infrastructure providers who process data on our behalf: Lovable Cloud / Supabase (application hosting, database, file storage, authentication), Resend (email delivery), and an AI gateway (Google Gemini via Lovable's gateway) for certificate-photo extraction. When paid subscriptions launch, Stripe will process payments — we never see full card numbers. Each provider is bound to use data only to provide their service to us.
Security
Every workspace is isolated by database row-level security; staff logins can access only their own records. Uploaded documents live in a private bucket served only through short-lived signed URLs. Access is logged. No method of storage is perfectly secure, but security is designed in, not bolted on. If a breach affecting your data occurs, we will notify you promptly consistent with applicable state breach laws.
Retention and deletion
Compliance records are kept for as long as your account is active — retention is the product (documents are versioned and never silently deleted, so your evidence trail stays intact). If you close your account, you can export your records first (binder exports are never locked); we will delete your workspace data on request to support@credvaultapp.com within 30 days, except where we must retain records to comply with law. Employees of a practice: your employer controls the records in its workspace — direct correction or deletion requests to your practice, and we'll assist them.
Marketing email
If we email your practice about CredVault without an existing relationship, the message identifies us, includes our postal address, and carries a working one-click unsubscribe that we honor immediately.
Your choices
You can access, correct, or export your data in-app; request deletion by email; and unsubscribe from any non-essential email. California residents may exercise applicable CCPA/CPRA rights via support@credvaultapp.com; we do not sell or share personal information as those terms are defined by the CCPA.
Changes
We'll post updates here and note the new effective date; material changes will be announced by email to account owners.