Trust Centre

Privacy Centre.

Your professional information belongs to you. This page describes exactly how we treat it.

Australian hosting

Clinical Confidence data is stored on Australian infrastructure. Your reflections, CPD entries and evidence never leave the country as part of normal operation.

Encryption

All traffic between your browser and Clinical Confidence is encrypted in transit with TLS. Data at rest is encrypted at the storage layer.

Secure storage

Uploaded documents are held in a private storage bucket that is not publicly reachable. Files are accessed only through short-lived signed URLs generated for the signed-in owner.

Signed URLs

When you preview a document, Clinical Confidence generates a time-limited URL scoped to that single file, valid for a few minutes. Once expired, the link stops working — even if it was shared or bookmarked.

Row-level security (RLS)

Every record — CPD entry, goal, reflection, document — is stored with a policy that only the owner can read or modify it. This is enforced by the database itself, not just by the application.

Data ownership

You own everything you create in Clinical Confidence. We do not claim rights over your reflections, evidence or portfolio content.

Deleting information

You can delete any individual record from within the app. You can also request full account deletion — we will remove your records and associated files.

Downloading information

Portable export is on the roadmap. Until then, you can request a copy of your data by contacting us. We do not lock your career inside our platform.

Patient information policy

Do not upload patient-identifiable information. Clinical Confidence is designed for your professional record, not for clinical documentation.

Future AI processing

When we introduce AI-assisted features, only the specific content required for a suggestion is sent to the model. Your data is not used to train third-party models. Every AI feature is documented in the AI Transparency Centre before it goes live.

Privacy by Design

Privacy is not a review that happens at the end. It is a constraint we apply at the beginning — in the data model, the storage layer, the access policies and the interface itself.