WorkIntelMD ("we," "our," or "us") operates the WorkIntelMD application available at app.workintelmd.com. This Privacy Policy explains what data we collect, why we collect it, how we store and protect it, and what rights you have over your data.
We built WorkIntelMD for physicians and other shift-based clinicians. We understand that your professional information is sensitive. This policy is written to be direct and specific — not vague boilerplate.
By creating an account and using WorkIntelMD, you agree to the data practices described in this policy.
We collect the data you directly provide to us, along with technical and operational data required to operate, secure, and support the service — such as device and browser information, authentication and security logs, and account activity needed for billing and troubleshooting.
| Data type | What it includes | Why we collect it |
|---|---|---|
| Account information | Email address, name, specialty | Creating and identifying your account |
| Profile settings | Earnings goals, combined income-tax rate, minimum rate preference, country/region | Personalizing earnings tracking, tax estimates, and (optional) AI tax-rate suggestions |
| Shift data | Facility names, dates, hours, pay rates, itemized reimbursements and expenses | Earnings tracking, tax estimates, and shift-offer comparison |
| Job & tax settings | Pay structure, W-2/1099/locum classification, job-specific tax overrides, business-expense records | Job-level earnings and tax calculations |
| Employer records | Job title, facility, city, pay structure | Organizing shifts by workplace |
| Credential metadata | Credential name, issuing body, expiry date, alert settings | Credential tracking and expiry alerts |
| Credential files | PDF or image files you upload to the vault | Secure private document storage |
| Subscription data | Plan type, trial status, billing status | Managing your subscription |
| Usage data | AI call count (per day), session activity | Enforcing fair-use rate limits |
| Push notification subscription | Device push endpoint and encryption keys | Delivering push notifications for credential alerts and shift reminders. Stored only if you enable notifications; cleared when you disable them. WorkIntelMD currently maintains one active notification-device subscription per account. Enabling notifications on another device may replace the previously registered device. |
We want to be explicit about what WorkIntelMD does and does not ask for or store directly, and about a limitation worth understanding for uploaded credential documents.
No patient data. WorkIntelMD is a tool for managing your work operations, not patient care. WorkIntelMD is not designed or intended to collect or store patient information or PHI, and you must not submit it through any field, note, text, or uploaded document.
Credential identifiers. For credential metadata — the structured fields you fill in — we only ask for the credential name and expiry date. We do not have a field for your license number, DEA registration number, NPI, or other government-issued identifier, and we do not ask you to enter one. However, if you upload a credential document (such as a PDF or photo of a license) to the vault, that document may itself contain such identifiers as part of its content. Uploaded documents are stored as you provided them, in your private vault — see "Where your data is stored" below.
No payment card data. All billing is processed directly by Stripe. WorkIntelMD does not receive or store your full card number or CVV. WorkIntelMD stores limited Stripe identifiers and subscription-status information needed to manage access.
WorkIntelMD has three AI-assisted features, each of which uses an external AI service provider to process a specific, limited input: AI Smart Text (shift-schedule text you paste), AI Document Import (a schedule document or photo you upload), and an optional AI Tax Rate Helper (a suggested income-tax rate). WorkIntelMD does not automatically send your credential vault, full profile, or unrelated account data to AI providers for these features.
What is sent to AI: For Smart Text and Document Import — only the text you enter or the document you upload, along with any related text needed to process your request. For the Tax Rate Helper, which you must initiate yourself from Profile → Tax Settings (or a job's tax override) — your country, state/province or region, and estimated annual income, along with your filing status, specialty, current saved rate, and (for a job-level request) the job name, when available, are sent to generate a reference suggestion. Estimated annual income is required for US and Canada. Only this specific request context is sent — not your full shift history, credential vault, or unrelated account data.
What is not automatically sent to AI: WorkIntelMD does not automatically send your credential vault, full profile, or unrelated account data to AI providers. Only the information submitted or selected for the specific AI request is sent — for example, a document you choose to upload for AI Document Import is sent for that request, so avoid uploading documents containing information you don't want processed.
Where provider controls allow, WorkIntelMD does not enable use of submitted data for AI model training. External AI providers may process and retain submitted inputs according to their own terms, privacy, and retention policies.
When you use AI Document Import, the file you upload is transmitted for AI processing to extract shift details. WorkIntelMD does not intentionally save the uploaded source document itself to your credential vault or your permanent account data as part of this import process — only the shift details you review and confirm are saved. The uploaded file may be subject to the external AI provider's own processing and retention policies.
Database and authentication: Your account data, shift records, employer records, and credential metadata are stored in Supabase, hosted on AWS in the us-east-1 region (Northern Virginia, USA).
Credential files: Files you upload to the credential vault are stored in a private Supabase Storage bucket on the same infrastructure. Files are not publicly accessible. Access requires a signed URL generated fresh for each view, which expires after 60 minutes.
Payments: Billing is handled by Stripe. Stripe stores your payment card and billing history under its own privacy practices. WorkIntelMD stores limited Stripe identifiers and subscription-status information needed to manage access.
Email: Authentication emails (signup confirmation and password reset) are delivered via Resend. Resend processes your email address for delivery purposes, subject to Resend's own privacy and data-handling practices.
No third-party analytics: We do not use Google Analytics, Meta Pixel, Mixpanel, or any behavioral analytics platform. We do not sell or share your data with advertisers.
WorkIntelMD is built with security as a design requirement, not an afterthought.
All data is transmitted over HTTPS. Database rows are protected by Row Level Security — your data is isolated to your account at the database level, not just the application level. Credential files are stored in a private bucket with no public access. Signed URLs are generated per-request and expire within one hour. We do not log the contents of credential files.
No member of the WorkIntelMD team has routine access to the content of your credential files or shift records. Administrative access to the database requires deliberate action and is not used in normal operations.
Shared and public devices. A signed-in session may remain active for your convenience. If you use WorkIntelMD on a shared or public device, sign out when you're finished — anyone who uses that device afterward may be able to access the information available through your account until you do.
You have the following rights regarding your data at any time.
Access. You can view all of your shift records, employer records, and credential metadata directly within the WorkIntelMD app. WorkIntelMD also maintains limited operational, account, security, and subscription records — such as authentication logs, billing status, and security event logs — that support the service but are not part of your visible in-app records.
Deletion. You can delete individual shifts, credentials, and employer records from within the app at any time. To request full account deletion — including all stored data and credential files — email us at hello@workintelmd.com. We will confirm once your deletion request has been completed.
Export. You can export your shift and earnings data directly within the app as CSV, structured JSON, or a printable summary, filtered by date or employer. If you need a different format or a copy of data not covered by the in-app export, contact us at hello@workintelmd.com and we will provide it in a readable format.
Correction. You can edit your profile, shift records, and credential details directly within the app.
WorkIntelMD is a personal productivity tool for physicians and other shift-based clinicians — it is not a covered entity under HIPAA and is not intended or authorized to handle PHI. The app has no fields for patient data of any kind.
If you are using WorkIntelMD through an employer-sponsored arrangement, please check with your employer regarding any applicable data policies. As an individual user, WorkIntelMD's relationship is with you personally, not with any hospital or health system you work for.
Do not enter patient names, dates of birth, diagnoses, medical record numbers, or any other patient information into WorkIntelMD under any circumstances.
If we make material changes to this Privacy Policy, we will notify you by email at the address associated with your account before the changes take effect. The effective date at the top of this page will be updated whenever the policy changes.
Continued use of WorkIntelMD after a policy change takes effect constitutes acceptance of the updated policy.
Privacy questions, data deletion requests, and data export requests should be sent to: