Version 2026-09-15 · Last updated September 15, 2026
TrainTrack handles two very different kinds of information, and the difference decides almost everything else in this policy. There is information about you — your email address, your sign-in, your institution’s billing record — which this policy covers. And there is the case-log data your program uploads, which describes residents and the procedures they logged. We process that second kind only on your institution’s instructions, as its service provider. This policy explains what we collect, when we access it, how long we keep it, and what you can ask us to do with it.
This policy covers information about site visitors, prospective customers, and the coordinators, directors, and other authorized users of a TrainTrack account, in connection with signing up for and managing that account.
It does not cover the contents of the ACGME case logs an institution uploads. We process those on the instructions of the residency program that uploaded them; that program is the controller, and our obligations for that data are set by our agreement with it and the applicable Business Associate Agreement rather than by this policy. If you are a resident or attending whose procedures appear in a case log and you have questions about how your information is used, contact your residency program.
We have never sold personal information and we will not.
Identity and access. When you sign up, we collect your email address and, if you provide one, your display name, so we can create your account, sign you in, and send you essential product email. Authentication itself is handled by Google Cloud Identity Platform, which processes your credentials, sign-in links, and session tokens. We do not store your password.
Institution details. We store the residency program you select or name at signup, its ACGME program code where one applies, and the resident headcount you declare. This is what creates your workspace and selects your subscription tier.
Billing information. Payments are processed by Stripe. Card details go to Stripe directly and never reach TrainTrack’s servers. We store the Stripe customer and subscription identifiers, your subscription status and tier, and renewal dates, so we can tell you what you are subscribed to and let a run proceed.
Case-log data you upload. An uploaded ACGME export is scrubbed server-side against an allowlist of analytical columns before it is persisted, so identifying columns are removed rather than retained. Large files pass briefly through a private storage bucket in their original form and are permanently deleted, across every stored generation, as soon as scrubbing completes. What remains is the allowlisted analytical data, the merged case history built from it, and the reports generated from that.
Operational logs. We record request, job, and program identifiers so we can trace a failure to the run that caused it, along with sign-in events for security and fraud prevention. Logs are written so that they do not contain case-log rows, names drawn from reports, access tokens, signed URLs, or secrets.
To run the service. We use third-party subprocessors to operate TrainTrack: Google Cloud Platform for compute, database, and storage; Google Cloud Identity Platform for authentication; Vercel for serving the web application; Stripe for payments; and Resend for run-notification email. We will update this policy before adding or replacing a subprocessor.
By our staff. No one at TrainTrack reads your case-log data or your reports as a matter of course. We access a program’s data only where it is necessary to resolve a specific failure or a support request you have raised, and destructive or platform-wide operations require recent re-authentication and are recorded in an append-only audit log.
When required by law. We will respond to a government or law enforcement request only where we are compelled by valid legal process. Where we are permitted to, we will notify the affected customer before disclosing anything.
Aggregated and de-identified data. We may use aggregated, de-identified information about how the service is used to operate and improve it. We do not use the contents of your case logs or reports to develop or train artificial intelligence or machine learning models.
If the company is acquired. If TrainTrack is acquired by or merges with another company, we will notify you before any personal information is transferred or becomes subject to a different privacy policy.
You can ask us what personal information we hold about you, get a copy of it, have it corrected, or have it erased. You can object to or ask us to restrict how we process it, and you can complain to your data protection authority. We apply these rights to every customer, wherever they are.
Some of this you can do yourself: your email address and display name are editable in Account Settings, and an account owner can delete the account and its program from the same place. For anything else, or to verify a request, contact us at traintrackanalytics@gmail.com. We may need to verify your identity before we act, and we may need to retain some information to meet a legal obligation or to keep providing the service.
Erasing information may make the service unusable for you, in which case the request will result in closing your account. We will not charge you differently or give you worse support for exercising any of these rights.
Data is encrypted in transit and at rest, including database backups. Report files and uploads are never public: they are reached through short-lived signed URLs issued to an authenticated, authorized user.
Each program’s data is isolated in the database itself, by row-level security, rather than only by application code. The API connects as a database role that owns no tables and that is scoped to the signed-in user for the duration of each transaction, so a query that forgot to filter by program still cannot return another program’s rows.
The API, the job worker, the task invoker, and the migration runner each have their own least-privilege service account. We review platform administrator membership, cloud permissions, secret access, and production support access at least quarterly.
Deleting an account or a program records the request first, then enumerates every stored object belonging to it — uploads, merged case histories, reports, and the working files of any run — and permanently deletes every stored generation of each, verifying afterward that nothing remains. Soft delete is disabled on our storage buckets specifically so that a deletion is immediate and total rather than leaving a recoverable copy behind. Database references are removed last. We retain only the minimum record needed to show that the deletion happened.
Deleted content also ages out of encrypted database backups. Those backups exist so we can recover from a failure and they expire on a fixed schedule: we keep at least 30 automated backup copies, plus seven days of point-in-time recovery logs. Content deleted at your request is gone from live systems immediately and is purged from backups as those backups expire.
Original large uploads are deleted immediately after scrubbing, with an automatic backstop that removes any that survive within 24 hours.
Superseded uploads, case histories, reports, and walkthrough copies are recoverable for seven days, then permanently deleted.
Your program’s current analytical data and reports are kept while your account is active, and until a verified account or program deletion request.
Failed renders and abandoned uploads are cleaned up immediately, with a bounded automatic backstop.
Billing records are kept for seven years to meet tax and accounting requirements. Security and audit logs are kept for at least one year.
TrainTrack is operated in the United States and your information is stored there. If you are outside the United States, using the service means your information is transferred to and stored in the United States. TrainTrack does not currently offer service to customers in the EEA or UK.
We will update this policy as our practices and the applicable regulations change. When a change is significant, we will update the date at the top of this page, publish it under a new version, and ask you to accept it. Questions about this policy, your data, or your rights: traintrackanalytics@gmail.com.
Adapted from the Basecamp open-source policies / CC BY 4.0.