CRC Run Sheet

Privacy Policy

CRC Run Sheet is operated by Carbonic Software LLC, a Virginia limited liability company (carbonicsoftware.com). This policy covers the personal data we hold — which is data about you and your site staff, not about patients.

Version 2026-09-03 · Effective September 3, 2026

1.The short version

We hold three kinds of data: who logs in, what you pay, and the study schedules you enter. We do not hold patient identities — the Service has no fields for them, and the Terms forbid entering them. We are not a HIPAA Business Associate.

2.What we collect

Account data — via Clerk, our authentication provider: your name, email address, and login activity (times, IP address, and device/browser information used to secure the account).

Billing data — via Stripe: your billing contact details and subscription status. Card numbers go directly to Stripe; we never receive or store them.

Study data you enter — protocol and visit schedules, procedures, site-assigned subject identifiers, visit dates and windows, visit status and deviation notes, free-text operational notes, and your study configuration.

Documents you attach — the sponsor's protocol and manuals as PDFs, if you choose to upload them, with a title and a version label. Never a document that names a patient.

Site staff data you enter — the names, roles, credentials, and delegation records of your own team, mirroring your signed delegation-of-authority log. This is personal data about your staff, and you are responsible for having a basis to enter it.

Usage data — pages visited and actions taken, in aggregate, to understand which features are used.

Technical logs — request logs kept by our hosting provider for security and debugging.

3.What we do not collect

No patient names. No dates of birth. No addresses, phone numbers, or email addresses for patients. No medical record numbers. No insurance or payment identifiers. No clinical findings, lab values, or diagnoses. No treatment assignments.

There are no database fields for any of these. They are absent from the schema, not merely discouraged.

Free-text notes are free text, and software cannot prevent someone typing a name into a notes box. The Service warns against it at every free-text field and the Terms forbid it, but the accurate statement is that the no-PHI position depends on your site following that instruction. We would rather say that plainly than publish a guarantee we cannot technically enforce.

4.Why we process it

To provide the Service, authenticate you, take payment, keep the Service secure and working, communicate about your account, and understand aggregate usage so we can improve the product. We do not sell personal data, and we do not use your study data to advertise to you or anyone else.

5.AI processing — read this one

When you choose to paste or upload a protocol schedule for parsing, that text is sent to Anthropic’s API to extract the schedule structure.

  • It is sent only when you invoke the parsing feature. Nothing is sent in the background.
  • It is not used to train models.
  • Protocol schedule text is confidential to your sponsor. Check your confidentiality obligations before pasting sponsor documents into any tool, including this one.

If your site cannot permit that, the Service is fully usable without the parser — you can enter the schedule by hand.

6.Subprocessors

Every third party that touches customer data:

ProviderPurposeData
VercelApplication hosting and delivery (US region)All data in transit; request logs
NeonPostgreSQL database (US region)All study, schedule, delegation, and account data at rest
CloudflareObject storage (R2, Eastern North America) for the nightly encrypted database backup and for the protocol documents you uploadA compressed copy of the whole database, once a day, purged on a rolling 30-day cycle; and the PDFs you attach to a study, kept until you remove them or the study
GitHubRuns the nightly backup job on a GitHub-hosted runnerThe database copy exists on the runner only for the length of the job (under a minute) and is not retained there
ClerkAuthentication and account identityYour name, email address, and login activity
StripePayment processing and subscription billingBilling contact and payment details (we never receive card numbers)
AnthropicAI parsing of protocol schedules you choose to paste or uploadThe protocol schedule text you submit for parsing. Not used to train models.
ResendTransactional email (account and notification messages)Your email address and message contents
Google AnalyticsAggregate usage measurement on the marketing site and appPseudonymous usage events, IP-derived coarse location
SentryError monitoring — diagnostics when something in the app failsError messages, stack traces, browser and page URL. Configured not to collect IP addresses, cookies, or request bodies, and session replay is off.
PostHogProduct analytics — which features get usedA fixed list of seven events (sign-up, study created, schedule parsed, subject added, visit recorded, export, nickname set) with counts and flags only. No names, subject IDs, or free text are sent.

We will update this list before adding a new subprocessor that touches customer data.

7.Where data lives

The application runs on Vercel with a Neon PostgreSQL database, both in US regions. A nightly copy of the database is kept in Cloudflare R2 object storage (Eastern North America), encrypted at rest, and purged on a rolling 30-day cycle. The copy is made by a job on a GitHub-hosted runner and is not retained there. Protocol documents you attach to a study are stored in the same R2 service, encrypted at rest, opened through links that expire within an hour, never sent to the AI parser, and deleted when you remove them or delete the study.

8.Retention and deletion

We keep your data while your account is active. On termination we retain it for 60 days so you can export it, after which it is deleted from the live database. Routine encrypted backups are purged on a rolling 30-day cycle, so a copy may persist in backup for up to 30 days beyond live deletion. You may request earlier deletion at support@crcrunsheet.com.

9.Your rights

You can access and export your data at any time from within the Service. You may request correction or deletion by emailing us. Depending on where you live you may have additional rights (for example under the Virginia Consumer Data Protection Act or the GDPR) including access, correction, deletion, portability, and the right to complain to a supervisory authority. We do not sell personal data or use it for targeted advertising, and we do not carry out profiling with legal effects.

10.Security

Data is encrypted in transit and at rest by our hosting and database providers. Authentication is handled by Clerk; we never see your password. Access to production data is limited to the operator. See Security & data for the detail your IT team will ask for.

11.HIPAA

The Service is not designed to receive protected health information and is not offered as a HIPAA Business Associate service. No Business Associate Agreement is in place or implied.

12.Children

The Service is for professional use and is not directed to anyone under 18.

13.Changes

We may update this policy. The version and effective date above will change, and material changes will be notified by email or in-app.

14.Contact