Privacy Policy

Last updated 13 September 2026

AuraMedHub helps licensed healthcare professionals track credentials and continuing education requirements. This policy describes what we collect, where it goes, and what you can do about it. It reflects how the product actually works today.

What we collect

  • Account details: your email address, name, and the profession you select at sign-up.
  • Credential records you enter: credential title, license or certificate number, issuing jurisdiction, issue and expiration dates.
  • Documents you upload: photographs or PDFs of certificates and provider cards.
  • Continuing education you mark as completed.
  • Questions you send to the AI study tutor.

We do not collect patient information. AuraMedHub deals with professional licensure records, not medical records, and is not a HIPAA covered entity. Do not upload documents containing patient data.

License verification is public

Anyone who knows a license number can look it up on our verification page and see the credential title, license number, jurisdiction, expiration date and status. This is intentional — it exists so employers can confirm a credential — but it means those five fields are not private.

Your name, email, uploaded documents and continuing education history are never returned by that lookup. Verification results come from a restricted database function that can only return those five fields.

Where your data goes

We use a small number of processors, and your data does not go anywhere else:

  • Supabase — stores your account, credential records and uploaded documents.
  • Vercel — hosts the application and processes requests.
  • Google (Gemini API) — when you scan a certificate, the image or PDF is sent to Google to extract the details. When you use the AI tutor, your question is sent to Google. Google processes these to return a response.
If a certificate contains information you would rather not send to a third party, enter the details manually instead of scanning. The scanner is a convenience, never a requirement.

We do not sell your data, and we do not share it with advertisers or data brokers.

How it is protected

  • Credential records are isolated per account at the database level — one user cannot read another user's records.
  • Uploaded documents are kept in private storage and are reachable only through short-lived links generated for you when you open them.
  • Traffic is encrypted in transit.

No system is perfectly secure, and we will not claim otherwise. If we discover a breach affecting your data, we will tell you.

Your choices

  • You can view and edit every credential record from your dashboard, and delete any of them at any time.
  • You can export a compliance summary as a PDF at any time.
  • You can ask us to delete your account and everything in it by emailing support@auramedhub.com. We will action it within 30 days.

We keep your data for as long as your account exists. Deleting a credential removes it and its uploaded document.

Changes

If this policy changes in a way that affects how we handle your data, we will update the date at the top and notify account holders by email before it takes effect.

Questions about this page? Contact support@auramedhub.com.