Privacy Policy
Applies to this research deployment of BurnCare, including the BurnCare Android and iOS apps. Last updated September 2026.
What's collected
- Patient case records you enter (name, age, weight, and other clinical fields you choose to fill in).
- Photographs you upload for AI analysis, along with the images and measurements the pipeline generates from them (background-removed images, burn-detection overlays, TBSA and fluid-requirement figures).
- Your account activity on this platform (uploads, processing runs, and clinical notes you record) needed to build the case history and referral reports you use.
- A practitioner certification document and its expiry date, submitted at registration and whenever it's resubmitted, to verify you are an authorized clinician.
- Your training-data consent choice (see "Training-data consent and 24-hour deletion" below) and your Terms of Use acceptance record.
Where it's stored
All patient photographs, case data, and certification documents are stored on institute-controlled servers and are never sent to any third party. Certification documents are stored separately from patient data and are only ever accessible to the account holder themselves and to platform administrators reviewing registration or renewal. There is no external analytics or advertising tracking on this platform.
Who can see it
A case and its photos are visible only to the clinician who created it and to platform administrators. Access requires an authenticated account issued after an access request is approved.
How it's used
Patient data is used to generate the clinical outputs you request (burn detection, TBSA, referral reports). Whether it is additionally used, in de-identified/aggregate form, to train or improve BurnCare's AI models depends entirely on the training-data consent choice you make at registration - see the next section.
Training-data consent and 24-hour deletion
At registration, every clinician explicitly chooses whether to consent to their uploaded patient data being stored and used to help train BurnCare's AI models.
- If you consent: your case data is retained under the normal retention policy described below, and may be used in de-identified/aggregate form for model training and the associated research study.
- If you do not consent: your uploaded case data (photographs, generated images, and analysis results) is automatically and permanently deleted from the server within 24 hours of upload. It is never used for model training. This deletion is enforced by an automated process, not a manual step, so it happens even if you never revisit the case.
This choice does not affect your ability to use the platform - it only affects how long your case data is retained and whether it may be used for training. You can review your current consent status at any time from your account.
Retention and deletion
For accounts that have consented to training-data use, case records and photos are retained for as long as your account and the associated case remain active, following your institution's data retention policy. A clinician can delete a case or an individual upload at any time from within the platform; deletion removes the stored files and their associated metadata. For accounts that have not consented, the 24-hour automatic deletion described above applies instead, regardless of any longer institutional retention window.
Certification documents are retained for as long as your account exists, and are replaced (the previous document deleted) whenever you resubmit a new certificate.
App permissions
The BurnCare Android and iOS apps request the following device permissions, used only for the purposes below and never for advertising or tracking:
- Camera: to capture a patient photograph directly for upload.
- Photos / Media: to select an existing patient photograph to upload.
- Notifications: to alert you when a processing job finishes or a certification is nearing expiry.
- Network access: to send images and case data to the BurnCare server and receive results.
You can decline any of these at the OS level; declining camera or media access simply means that upload method is unavailable.
Third-party sharing and analytics
BurnCare does not use any third-party analytics, advertising, or crash-tracking SDKs, and does not sell or share your data with any third party for their own purposes. Data leaves this platform's own servers only when de-identified/aggregate data is used for the model-training research described above, and only for accounts that consented to that at registration.
Data in transit between the app and the server is encrypted (HTTPS/TLS). Patient photographs and case records are never publicly accessible - every request requires an authenticated clinician or administrator session.
Account and data deletion
To request deletion of your account and all associated data, email your platform administrator (see Contact) from your registered address and state that you are requesting account deletion. Requests are processed within 30 days. Deleting an account removes your case records, uploaded photographs, generated results, and certification documents; it does not retroactively withdraw data already used in an aggregate research dataset before the deletion request.
You do not need an account to request deletion of a specific record you believe concerns you - use the same contact method and reference the case ID or upload date.
Children's privacy
BurnCare is a clinical tool for use by authorized healthcare practitioners only. It is not directed at, and accounts are not knowingly issued to, individuals under 18. Patient data entered by a clinician may concern a patient of any age, but that data is entered and controlled by the treating clinician, not by the patient directly.
Questions about your data
For questions about data handling or to request deletion of a specific record, see the Contact page.