Privacy Policy
1. Introduction
This Privacy Policy explains how CaseReels, a MyPracticeOnline company ("CaseReels," "we," "us," or "our") collects, uses, discloses, and protects information in connection with the CaseReels platform at casereels.ai and related services (the "Service").
By using the Service, you agree to this Policy. If you do not agree, do not use the Service.
2. Scope — Two Different Kinds of Information
This distinction matters and applies throughout this Policy.
2.1 Account information (we are the controller)
Information about you as an account holder — your name, email address, mobile number, practice details, billing information, and how you use the Service. We determine how this information is used, and this Policy governs it.
2.2 Patient content (we are a processor and business associate)
Video, images, transcripts, and clinical information about your patients that you upload to or create with the Service. We process this material solely on your instructions, as a service provider to your practice. Your practice — not CaseReels — is the covered entity responsible for that information under HIPAA and for obtaining patient authorization.
Where the Service processes protected health information, we act as a business associate, and a separate Business Associate Agreement governs that processing. Where a BAA conflicts with this Policy, the BAA controls for protected health information.
If you are a patient of a practice that uses CaseReels and have questions about how your information is used, contact that practice directly. We cannot access, modify, or delete a practice's content at a patient's request without instruction from the practice.
3. Information We Collect
3.1 Information you provide at registration
- Name
- Email address (required — used to deliver login codes)
- Mobile phone number (required)
- Practice or organization name
- Role or title
3.2 Authentication information
Because the Service does not use passwords, we collect and process: - One-time login codes, stored only as a cryptographic hash and deleted shortly after use or expiry - The destination the code was sent to (email address or mobile number) - Session identifiers stored on your device - IP address and browser/device information at login and during sessions - Timestamps of authentication events, including successful and unsuccessful attempts - Counts of login-code requests and failed verification attempts, associated with your email address, phone number, and IP address, retained for rate limiting and abuse prevention
We use this information to verify identity, maintain your session, prevent automated attacks against login, detect abuse, and let you review and revoke active sessions.
We never ask for your login code. No CaseReels employee, contractor, or support agent will ever request a login code from you by phone, email, text, or chat. Anyone asking for your code is attempting to gain unauthorized access to your account. Do not share login codes with anyone, including practice colleagues.
3.3 Content you upload or create
Video and audio recordings, images, scripts, transcripts, generated written content, and any patient information contained in them. See §2.2.
3.4 Usage information
Pages viewed, features used, actions taken, timestamps, referring URL, approximate location derived from IP address, and error and diagnostic logs.
3.5 Billing information
For paid plans, our payment processor collects and stores payment card details. We do not store full payment card numbers on our systems.
3.6 Communications
Records of support requests and correspondence with us.
4. Why We Collect Your Mobile Number
Your mobile number is required at registration for these purposes:
- Account identification and support — verifying you when you contact us
- Account recovery — providing a route to reach you if you lose access to your email
- Login codes by SMS — available only after you verify the number and opt in (§6)
- Service notifications — only if you separately opt in
A phone number that has not been verified cannot be used to log in and receives no messages from us. Providing your number at registration does not by itself enroll you in SMS.
5. How We Use Information
- Provide, operate, and maintain the Service
- Authenticate you and maintain your sessions
- Process, transcode, and store recordings
- Generate transcripts and written content from your recordings
- Publish content to destinations you designate
- Send transactional messages (login codes, account and billing notices, security alerts)
- Respond to support requests
- Detect, investigate, and prevent fraud, abuse, and security incidents
- Monitor and improve performance and reliability
- Comply with legal obligations and enforce our Terms
We do not use patient content or account content to train, fine-tune, or improve machine learning models, and we do not sell personal information.
6. Text Message (SMS) Program — A2P Disclosures
6.1 Message types
We send two categories, which you control separately:
Login codes (transactional). One-time numeric codes sent when you request access to your account. Sent only in response to your own login attempt. Frequency depends entirely on how often you log in.
Account and service notifications (optional). Updates about your account and activity — for example, that a recording finished processing or content is ready for review. Frequency varies with your usage. You may decline these and still use the Service fully.
6.2 How you opt in
Providing your number at registration does not enroll you in SMS. Enrollment requires a separate, affirmative opt-in.
The opt-in works as follows: in your account settings, you check an unchecked consent box next to disclosure language stating the message types, that frequency varies, that message and data rates may apply, and that consent is not a condition of using the Service. We then send a one-time confirmation message to the number, and you enter the code to confirm you control it. You then select which message types you wish to receive.
We record the date, time, IP address, and the exact disclosure text shown at the moment you gave consent, and retain that record for as long as your enrollment remains active.
We do not accept consent given verbally, by a third party, on your behalf by your practice, or through any purchased or imported list. Each number is enrolled only by the person who controls it.
6.3 Consent is not required
Consent to receive text messages is not a condition of creating an account, purchasing any product, or using any feature of the Service. Login codes are always available by email.
6.4 Opting out
Reply STOP to any message to opt out. We will send one confirmation message and then stop sending SMS to that number. Opting out does not close your account or restrict access; login codes revert to email delivery.
If you later wish to resume SMS, you may re-enroll at any time by repeating the verification process described in §6.2. Re-enrollment requires the same affirmative opt-in as the first time.
You may also manage SMS preferences in your account settings or by contacting mypracticeonline@gmail.com.
6.5 Getting help
Reply HELP to any message. You will receive a reply containing our phone number, email address, and website. You may also contact us directly at mypracticeonline@gmail.com.
6.6 Message and data rates
Message and data rates may apply, depending on your mobile plan. Message frequency varies.
6.7 Carrier limitations
We do not control mobile carrier networks. Neither we nor mobile carriers are liable for delayed or undelivered messages.
6.8 No sharing of mobile information
We do not sell, rent, lease, or share mobile phone numbers, SMS opt-in data, or consent records with any third party or affiliate for marketing or promotional purposes.
Mobile numbers are disclosed only to the messaging service providers that transmit messages on our behalf, solely for the purpose of delivering the messages you have requested, and those providers are contractually prohibited from using the information for any other purpose.
This restriction applies to all mobile information collected through the Service, including numbers collected at registration.
6.9 Number changes
Notify us if your mobile number changes or is reassigned, so that codes and notifications are not delivered to a number you no longer control.
7. Cookies, Local Storage, and Similar Technologies
7.1 What we use
Because the Service uses passwordless authentication, cookies are not optional convenience features — they are how the Service knows you are logged in. Without them, you would have to request and enter a login code on every page load.
| Name | Type | Purpose | Duration |
|---|---|---|---|
[SESSION_COOKIE_NAME] |
Strictly necessary | Keeps you signed in after you enter a login code. Contains a random session identifier only — no name, email, or phone number. | Up to [365] days, extended each time you use the Service |
[CSRF_COOKIE_NAME] |
Strictly necessary | Protects against cross-site request forgery on account actions | Session |
[PREFERENCE_COOKIE_NAME] |
Functional | Remembers interface preferences | [1] year |
Replace the bracketed names and durations with the actual cookies your application sets, and delete any row that doesn't apply. A cookie table that doesn't match what the browser receives is a liability, not a compliance measure.
Our session cookie is set with HttpOnly (inaccessible to JavaScript), Secure (transmitted only over HTTPS), and SameSite protections.
7.2 Local and device storage
[IF APPLICABLE:] The Service may use browser local storage to hold recording drafts and in-progress uploads on your device so that work is not lost if a page reloads or a connection drops. This data stays on your device and is cleared when the recording is submitted or discarded. [DELETE THIS SECTION IF THE APPLICATION DOES NOT USE LOCAL STORAGE.]
7.3 Analytics
[IF YOU RUN ANALYTICS: name the provider, state what it collects, and state whether it sets cookies. If it does set cookies, you need a consent mechanism for users in states and jurisdictions that require one — add it before launch.]
[IF YOU DO NOT: "We do not use analytics cookies, advertising cookies, or cross-site tracking technologies."]
7.4 Controlling cookies
Most browsers let you block or delete cookies through their settings. Blocking or deleting our session cookie will log you out and require a new login code. Blocking cookies entirely will prevent the Service from functioning.
You can delete our cookies at any time through your browser, which has the same effect as logging out on that device. To end sessions on devices you no longer have access to, use the session revocation control in your account settings — this works server-side and does not depend on the device cooperating.
7.5 Do Not Track and Global Privacy Control
We do not use tracking cookies or serve advertising, and we do not build cross-site advertising profiles.
[IF YOU RUN NO ANALYTICS: "Because we do not engage in tracking or sale of personal information, browser Do Not Track and Global Privacy Control signals do not change how we handle your information — we already do not undertake the practices those signals are designed to stop."]
[IF YOU DO RUN ANALYTICS OR ANY THIRD-PARTY TAGS: "We honor Global Privacy Control (GPC) signals as a valid opt-out request under applicable state privacy laws." — and make sure the application actually does so, because this is enforceable.]
8. How We Share Information
We do not sell personal information. We share it only as follows.
8.1 Service providers (subprocessors)
We use third-party providers to operate the Service. Each is bound by contract to protect information and use it only to provide services to us. Categories include:
| Category | Purpose | Data involved |
|---|---|---|
| SMS and voice delivery | Login codes, notifications | Mobile number, message content |
| Email delivery | Login codes, account notices | Email address, message content |
| Cloud hosting and storage | Running the Service, storing recordings | All categories |
| Video processing | Transcoding and encoding | Recordings |
| AI content generation | Transcripts, written case studies | Recording content, transcripts |
| Payment processing | Billing | Name, email, payment details |
| Website publication | Publishing approved content | Approved output only |
REPLACE THIS TABLE with your actual named providers before publishing — e.g. Twilio, Mux, Anthropic, your hosting provider, your payment processor. Naming them is standard practice for a platform handling health information and is likely required by your BAA obligations. A generic table invites questions from any practice that does diligence on you.
8.2 At your direction
We publish content to destinations you configure, including your website and marketing channels.
8.3 Legal requirements
We may disclose information where required by law, subpoena, court order, or lawful government request, or where necessary to protect our rights, safety, or property, or that of our users or the public. Where legally permitted, we will notify you first.
8.4 Business transfers
In a merger, acquisition, financing, or sale of assets, information may be transferred, subject to this Policy or a successor policy with notice to you.
8.5 With your consent
Otherwise, only with your consent.
9. Security
We implement administrative, technical, and physical safeguards including:
- Encryption in transit (TLS) and at rest for stored recordings
- Passwordless authentication with hashed, single-use, short-lived login codes
- Rate limiting and abuse detection on authentication endpoints
- Access controls limiting internal access to those who need it
- Server-side session management allowing immediate revocation
- Logging and monitoring of authentication events
No method of transmission or storage is completely secure. We cannot guarantee absolute security.
Your responsibilities with passwordless login
Because access depends on receiving a code rather than knowing a password:
- Anyone with access to your email inbox can obtain a login code and access your account. Secure that inbox with a strong password and multi-factor authentication.
- Login codes may appear in device notification previews. Our emails and text messages include the code in the subject line or message preview so you don't have to open them, which means the code can be visible on a locked screen. Configure your device to hide notification content if this concerns you.
- Sessions on shared devices remain active. If you log in on a shared or public computer, log out when finished, or revoke that session from your account settings afterward.
- Never share a login code. We will never ask you for one.
If we become aware of a breach affecting your information, we will notify you as required by applicable law and any executed BAA.
10. Data Retention
| Data | Retention |
|---|---|
| Login codes | Deleted on use or within [10] minutes of issue |
| Rate-limit and abuse-prevention records | [30] days |
| SMS consent records (timestamp, IP, disclosure text shown) | Duration of enrollment, plus [4] years after opt-out |
| Session records | Until expiry, logout, or revocation (up to [365] days of inactivity) |
| Authentication logs | [12] months |
| Account information | For the life of your account |
| Uploaded recordings and content | For the life of your account, or until you delete it |
| Content after account closure | Available for export for [30] days, then deleted |
| Billing records | As required by tax and accounting law, typically [7] years |
| Backups | Deleted content persists in backups until those backups expire, typically [30] days |
Verify each of these against what your system actually does before publishing. Bracketed values are drafting defaults, not commitments you have made.
We retain information longer where required by law, or where necessary to resolve disputes or enforce agreements.
11. Your Rights and Choices
11.1 Available to everyone
- Access and correct your account information in account settings
- Delete individual recordings and content at any time
- Export your content
- Revoke sessions on any device, and review the devices, approximate locations, and times at which your account was accessed
- Opt out of SMS by replying STOP or via account settings
- Close your account at any time
Contact mypracticeonline@gmail.com to exercise any of these.
11.2 California residents (CCPA/CPRA)
If you are a California resident, you may request: the categories and specific pieces of personal information we collected; the sources; our purposes; the categories of third parties to whom we disclosed it; correction of inaccurate information; and deletion, subject to legal exceptions.
We do not sell or share personal information for cross-context behavioral advertising, and we do not process sensitive personal information for purposes requiring a right to limit.
We will not discriminate against you for exercising these rights. Submit requests to mypracticeonline@gmail.com. We will verify your identity before responding, typically by confirming control of the email address on your account.
11.3 Other state privacy laws
Residents of states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and Florida — may have comparable rights to access, correct, delete, and obtain a portable copy of personal information, and to appeal a denied request. Submit requests to mypracticeonline@gmail.com.
11.4 Patients
If you are a patient whose information appears in content on the Service, direct requests to the practice that created the content. We act on the practice's instructions and will refer patient requests to them.
12. HIPAA and Protected Health Information
The Service is designed for practices that are HIPAA covered entities.
- A Business Associate Agreement must be executed before any protected health information is uploaded. Contact mypracticeonline@gmail.com.
- Your practice is responsible for obtaining valid written patient authorization under 45 C.F.R. § 164.508 before uploading patient material for marketing use.
- We do not verify that authorizations have been obtained.
- Where an executed BAA conflicts with this Policy, the BAA controls for protected health information.
13. Children's Privacy
The Service is intended for use by dental and medical professionals and is not directed to children. We do not knowingly collect personal information from anyone under 18 as an account holder. If we learn we have collected such information, we will delete it.
Patient material may depict minors. Practices are responsible for obtaining parental or guardian authorization before uploading such material.
14. International Users
The Service is operated in the United States and intended for use by U.S.-based practices. If you access it from outside the United States, your information will be transferred to and processed in the United States, where privacy laws may differ from those in your jurisdiction.
15. Third-Party Links
The Service may link to third-party sites and services. We are not responsible for their privacy practices. Review their policies before providing information.
16. Changes to This Policy
We may update this Policy. For material changes, we will provide notice by email or in-product at least thirty (30) days before they take effect and update the "Last Updated" date. Continued use after the effective date constitutes acceptance.
17. Contact Us
CaseReels, a MyPracticeOnline company
Privacy inquiries: mypracticeonline@gmail.com General support: mypracticeonline@gmail.com
For SMS help, reply HELP to any message or contact us at the number above. To stop messages, reply STOP.