Privacy Policy

Effective date: 15 July 2026

1. Who we are

RadReporter (“we”, “us”) provides a radiology reporting platform at rad-reporter.comused by healthcare facilities and their staff (radiologists, sonographers, typists, and administrators) to manage ultrasound scans and generate diagnostic reports. For patient data processed on the platform, the healthcare facility is the data fiduciary and RadReporter acts as a data processor on the facility’s instructions, consistent with the Digital Personal Data Protection Act, 2023 (India).

2. Data we collect

Account data (from facility staff): name, email address, role, facility name, and authentication credentials (passwords are stored as salted hashes; we never store them in plain text).

Patient data (entered by facility staff): patient name, age, sex/gender, medical record number, phone number, medical history, ultrasound images, dictated audio transcripts, and diagnostic report content. This is sensitive health data — it is collected and processed solely so the facility can produce diagnostic reports.

Technical data: IP address and basic request logs used for security (e.g. rate limiting and abuse prevention) and error monitoring.

3. How we use data

  • To operate the reporting workflow: patient registration, scan scheduling, image storage, dictation transcription, and report generation.
  • To authenticate users and send sign-in emails (magic links / one-time codes).
  • To draft report text using AI services (see section 5).
  • To secure the platform, prevent abuse, and diagnose errors.

We do not sell personal data, use patient data for advertising, or use patient data to train AI models.

4. Where data lives

  • Database: patient records and reports are stored in a PostgreSQL database managed by us on DigitalOcean infrastructure.
  • Images: ultrasound images are stored in Cloudflare R2 object storage.
  • Application hosting: the web application runs on Vercel.

5. Third-party processors

We share only the minimum data needed with the following sub-processors:

  • Sarvam AI / Deepgram — dictated audio is sent for speech-to-text transcription.
  • OpenRouter / Anthropic — dictation transcripts and report field content are sent to draft report text. Requests are not used by these providers to train models under our API terms.
  • Resend — sends authentication emails (sign-in links and codes) to staff email addresses.
  • Clerk / Google — optional staff sign-in via Google account.
  • Sentry — error monitoring (technical error context; not patient report content).

6. Security

All traffic is encrypted in transit (TLS/HTTPS with HSTS). Access to patient data requires authentication and is restricted by role and by facility. Passwords are hashed. Administrative access to production systems is limited to authorized personnel.

7. Retention

Patient records and reports are retained for as long as the facility’s account is active or as required by applicable medical record-keeping regulations, whichever is longer. Facilities may request deletion of their data by contacting us; we will delete or anonymize it unless retention is legally required.

8. Your rights

Under the DPDP Act 2023, data principals have the right to access, correct, and request erasure of their personal data, and to grievance redressal. Patients should direct requests to their healthcare facility (the data fiduciary); we will support facilities in fulfilling them. Staff users may contact us directly at privacy@rad-reporter.com.

9. Changes

We may update this policy as the product evolves. Material changes will be notified to facility administrators by email and reflected in the effective date above.

10. Contact

Questions or grievances: privacy@rad-reporter.com