Scrub Out is a productivity application for orthopedic medical device sales professionals, operated by CaseReady LLC ("CaseReady," "we," "us," or "our"). This Privacy Policy explains what personal information we collect when you use Scrub Out (the "Service"), how we use it, how we share it, how long we keep it, and the rights and choices you have. By creating an account or using the Service, you acknowledge you have read and understood this policy.
We collect personal information in three ways: information you provide directly, information we collect automatically when you use the Service, and information we receive from third parties.
We use your personal information to:
We do not sell your personal information for monetary or other valuable consideration, and we do not share it with advertisers for cross-context behavioral advertising.
We share personal information only in the following limited circumstances:
We rely on the following providers, each of which processes only the minimum data needed for its function. We have data processing agreements in place with each:
| Subprocessor | Purpose | Data shared | Privacy policy |
|---|---|---|---|
| Supabase, Inc. | Database, authentication, file storage | Account info, all user-created content | supabase.com/privacy |
| Stripe, Inc. | Subscription billing | Email, name, payment method (we don't see card numbers) | stripe.com/privacy |
| Vercel, Inc. | Application hosting | HTTP request metadata | vercel.com/legal/privacy-policy |
| Resend, Inc. | Transactional email delivery | Email addresses, email content | resend.com/legal/privacy-policy |
| PostHog, Inc. | Product usage analytics | Product-interaction events linked to your account ID, IP address | posthog.com/privacy |
| Functional Software, Inc. (Sentry) | Error monitoring | Stack traces, error context, IP address | sentry.io/privacy |
| Apple Push Notification Service | iOS push delivery (if opted in) | Encrypted notification payloads | apple.com/legal/privacy |
| Google Firebase Cloud Messaging | Android/Chrome push delivery (if opted in) | Encrypted notification payloads | policies.google.com/privacy |
| Cloudflare, Inc. | DNS, network security, email routing | HTTP request metadata, DNS queries | cloudflare.com/privacypolicy |
Your data is stored on Supabase infrastructure, primarily in the United States (AWS us-east-1). We use industry-standard safeguards including:
No system is perfectly secure. If we ever detect a breach affecting your data, we'll notify you by email within 72 hours, in keeping with applicable breach-notification laws.
| Data type | Retention period |
|---|---|
| Account information (name, email, profile) | Until you delete your account, then 30 days |
| User-created content (facilities, trays, prefs, schedule, notes) | Until you delete it or your account, then 30 days |
| Peel pack compliance photos (after marked received) | 7 days, then automatically deleted — unless marked "Keep," which retains the pack until you remove it or delete your account |
| Inventory sheets you upload | Until you delete them or your account, then 30 days |
| Push notification subscriptions | Until you toggle off, sign out, or revoke browser permission |
| Billing records (invoices, payments, tax records) | 7 years (IRS requirement for business tax records) |
| Authentication logs (logins, password resets) | 90 days |
| Application error logs (Sentry) | 90 days |
| Product usage analytics (PostHog) | 1 year, then aggregated |
| Email delivery logs (Resend) | 90 days per Resend's retention policy |
You can request immediate deletion of your account at any time by contacting [email protected]. We will complete deletion within 30 days, except for data we're legally required to retain (such as billing records).
Do not enter Protected Health Information (PHI) into Scrub Out. PHI under HIPAA includes patient names, medical record numbers, dates of birth, addresses, phone numbers, dates of service, diagnoses, treatment information, insurance information, account numbers, biometric identifiers, photographs of identifiable patients, or any other identifier that could be linked to an individual receiving care.
What is acceptable to enter: facility names (publicly listed hospitals), surgeon names (publicly listed via the NPPES NPI Registry), tray names, vendor names, equipment serial numbers, peel pack photos of equipment only, your own schedule and notes about workflows, and any data not connected to identifiable patients receiving care.
Any user who enters PHI into the Service does so in violation of our Terms of Service and assumes all liability for that conduct. If you discover PHI in your account or your team's account, contact [email protected] immediately and we will help you remove it.
We do not actively monitor user content for PHI. If we become aware that PHI has been entered, we reserve the right to remove it and to suspend or terminate the account that entered it.
Regardless of where you live, you have the following rights:
To exercise any of these rights, email [email protected] with your account email and what you'd like to do. We will respond within 30 days. We may need to verify your identity before fulfilling certain requests; usually this means confirming you control the account email.
If you are a California resident, you have specific rights under the California Consumer Privacy Act of 2018 (CCPA), as amended by the California Privacy Rights Act of 2020 (CPRA).
| CCPA category | Examples in Scrub Out |
|---|---|
| A. Identifiers | Name, email address, IP address, device identifier, account ID |
| B. Customer records (Cal. Civ. Code § 1798.80(e)) | Name, email address, phone (if provided), employment information |
| C. Protected classifications | None collected |
| D. Commercial information | Subscription status, billing history (via Stripe), products purchased |
| E. Biometric information | None collected |
| F. Internet or network activity | App pages visited, buttons clicked, login times, browser/OS, error events |
| G. Geolocation | Approximate (city-level) inferred from IP address |
| H. Sensory information | None collected |
| I. Professional or employment-related | Territory, company, vendors, job role |
| J. Education | None collected |
| K. Inferences | Aggregate usage patterns; no behavioral profiles built about individuals |
| L. Sensitive personal information | Account credentials (password hash). We do not collect SSN, driver's license, geolocation more precise than city, race, religion, health data, sex life, biometric identifiers, or genetic data |
Sources: directly from you (account creation, in-app activity); automatically from your device (analytics, error monitoring); from third parties (Stripe payment confirmations, NPPES NPI Registry).
Purposes: operating the Service, processing payments, customer support, security, fraud prevention, product improvement, legal compliance.
Categories disclosed for a business purpose to subprocessors: A, B, D, F, G, I, L (limited to the subprocessors listed in Section 5 above, each only what they need).
To exercise California rights, email [email protected]. You may also designate an authorized agent to act on your behalf in writing; we will require the agent to provide proof of authorization and may verify your identity directly.
"Shine the Light" disclosure (Cal. Civ. Code § 1798.83): California residents may request information about disclosures of personal information to third parties for those parties' direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes.
If you are in the European Economic Area, the United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) and related laws apply.
Data controller: CaseReady LLC, 30 N Gould St Ste N, Sheridan, Wyoming 82801, United States. Contact: [email protected].
Lawful basis for processing: we process personal information based on (a) the contract between you and us (to provide the Service you signed up for); (b) our legitimate interests (improving the Service, securing it, preventing fraud), balanced against your rights; (c) your consent (for optional features like push notifications and marketing emails, if any); and (d) compliance with legal obligations (tax records, lawful requests).
Your GDPR rights include access, rectification, erasure, restriction, portability, objection, and the right to withdraw consent. You also have the right to lodge a complaint with your local supervisory authority.
We do not have a designated EU representative because Scrub Out is targeted to United States medical device sales professionals and we do not actively market to or systematically monitor individuals in the EU.
Scrub Out is operated from the United States. When you use the Service from outside the United States, your personal information will be transferred to and processed in the United States. The U.S. may not have data protection laws as comprehensive as those in your country. By using the Service, you consent to this transfer. Where required, we rely on Standard Contractual Clauses or other lawful transfer mechanisms in our agreements with subprocessors.
We use a small number of first-party cookies and equivalent technologies:
We do not use advertising cookies, social-media tracking pixels, or third-party trackers for marketing purposes. You can clear cookies and localStorage at any time in your browser settings; doing so will sign you out and reset your preferences.
Push notifications are off by default. If you opt in via Settings → Notifications, your browser or device asks for permission, and (with your consent) registers a subscription endpoint with us. You can disable notifications at any time by toggling them off in the app, by revoking permission in your browser/device settings, or by uninstalling the app — any of which removes you from delivery.
Transactional emails (sign-up confirmation, password reset, billing receipts, security alerts, trial-ending reminders) are essential to the Service and cannot be opted out of as long as you have an active account, except by deleting your account.
Marketing emails: we don't send marketing emails as of this writing. If we ever start, we will require you to explicitly opt in, and every such email will contain an unsubscribe link.
Scrub Out is designed for medical device sales professionals and is not intended for use by anyone under 18. We do not knowingly collect personal information from children under 13 (or under 16 in the EU/UK). If you believe we have inadvertently collected personal information from a child, contact us at [email protected] and we will delete it.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email (using the address on your account) at least 14 days before they take effect. The "last updated" date at the top reflects the most recent revision. Continued use of the Service after the effective date of a change constitutes acceptance.
CaseReady LLC
30 N Gould St Ste N
Sheridan, WY 82801
United States
Email: [email protected]