Privacy Policy

Privacy Policy Last updated: March 18, 2026 If you have questions about this policy, contact us at privacy@scrubreport.com 1. What This Policy Covers This Privacy Policy explains what data ScrubReport collects, how we use it, how we protect your anonymity, and your rights regarding your data. ScrubReport is operated by ScrubReport LLC, based in Pensacola, Florida. 2. Data We Collect Account Information: Email address (used for authentication and account recovery only) Password (stored as a secure hash — we never see or store your actual password) Username (chosen by you, displayed on your profile) Role/job title (e.g., RN, CNA, Respiratory Therapist) Avatar preferences (style and seed for generated avatars) Account creation date Content You Submit: Hospital reviews (ratings, review text, unit, employment type, experience level) Pay reports (base hourly pay, shift differential, weekly gross for travelers) Questions and answers posted in the Q&A feature Automatically Collected: Device type and operating system IP address (used for rate limiting and abuse prevention — not linked to reviews) General usage data (app opens, screens visited) Location data (only when you use the Map feature, and only with your permission) What We Do NOT Collect: Your real name (we never ask for it) Your employer or workplace (your account is not linked to any hospital) Social Security number, government ID, or financial account information Health information about you or anyone else 3. How We Protect Your Anonymity This is the foundation of ScrubReport. We take anonymity seriously. Reviews are not publicly linked to your account. Your username, email, and profile information are never displayed alongside your reviews or pay reports. Separation of identity and content. While we store a user ID with reviews for moderation and rate-limiting purposes, this connection is never exposed to other users, hospitals, employers, or the public. No employer access. We do not provide hospitals, healthcare systems, or employers with any way to identify who posted a review. Aggregated pay data. Pay information is displayed in aggregate (averages and ranges by role, unit, and experience level). Individual pay submissions are never displayed on their own. 4. How We Use Your Data We use your data to: Operate and maintain the platform Display aggregated, anonymous reviews and pay data Authenticate your account and verify your email Enforce our Terms of Service and Community Guidelines Prevent abuse (rate limiting, spam detection, content moderation) Communicate with you about your account (password resets, verification emails) Improve the platform and fix bugs We do NOT: Sell your personal data to anyone Share your personal data with hospitals, employers, or healthcare systems Use your data for targeted advertising Share your email address with third parties for marketing 5. Data Sharing We may share data only in these limited circumstances: Aggregated, anonymous data: We may share or display aggregated statistics (e.g., average pay for RNs in a region) that cannot identify individual users. Legal requirements: We may disclose information if required by law, subpoena, court order, or government request. If legally permitted, we will notify you before doing so. Business transfers: If ScrubReport is acquired, merged, or sells its assets, user data may be transferred to the new entity. We will notify you before your data is subject to a different privacy policy. Service providers: We use Supabase for backend infrastructure and data storage. Supabase processes data on our behalf under strict data processing agreements. 6. Third-Party Services ScrubReport uses the following third-party services: Supabase — Backend, database, authentication — Privacy Policy Apple Sign-In — Optional authentication — Privacy Policy DiceBear — Avatar generation (no personal data sent) — Privacy Policy Apple MapKit — Map display of nearby hospitals — Privacy Policy We do not use any analytics, advertising, or tracking SDKs. 7. Data Retention and Deletion Account data: Retained as long as your account is active. When you delete your account, your email, username, and profile data are permanently deleted. Review and pay data: When you delete your account, your reviews and pay reports remain on the platform in a fully anonymized state (the user ID link is removed). This preserves the integrity of aggregated data for the community. Full deletion: If you want all of your content removed along with your account, contact us at privacy@scrubreport.com and we will delete everything. 8. Security We take reasonable measures to protect your data, including: Encrypted data transmission (HTTPS/TLS) Secure password hashing (never stored in plain text) Row-level security policies on our database Server-side rate limiting to prevent abuse Role-based access controls for moderation No system is 100% secure. While we work hard to protect your data, we cannot guarantee absolute security. If we discover a data breach that affects your personal information, we will notify you as required by applicable law. 9. Your Rights You have the right to: Access your personal data — view what we have stored about you Correct your personal data — update your email, username, or role Delete your account and personal data through the app or by contacting us Export your data upon request Florida Residents: Under Florida law, you have the right to know what personal data we collect, request deletion, and opt out of the sale of your personal data (we don't sell it). California Residents (CCPA): If you are a California resident, you have the right to know what personal information we collect and share, request deletion, and opt out of the sale of your personal information. We do not sell personal information. To exercise your rights, contact privacy@scrubreport.com. 10. Children's Privacy ScrubReport is not intended for anyone under 18 years of age. We do not knowingly collect personal information from children under 18. If we learn that we have collected data from a child under 18, we will delete it promptly. If you believe a child has provided us with personal information, contact us at privacy@scrubreport.com. 11. Changes to This Policy We may update this Privacy Policy from time to time. We will notify you of material changes through the app or by email. Your continued use of ScrubReport after changes are posted constitutes your acceptance of the updated policy. 12. Contact Us For privacy questions, data requests, or concerns: ScrubReport Scrubreportapp@gmail.com