What we collect, and what we never touch
Vouch asks AI assistants and Google what they say about a practice, then tells the practice how to appear more often. Everything below describes what that actually requires.
We never collect patient data
Vouch has no access to your patient records, appointment system, practice management software or any clinical system. We never ask for them and there is nowhere in the product to put them. Everything we analyse is information already published about your practice on the public internet.
If you are assessing us against HIPAA, GDPR Article 9, or an equivalent regime covering health data: we are not a business associate or a processor of patient data, because no patient data reaches us.
What we store
- Your account — email address and a password hash. Passwords are hashed by Supabase; we never see the original.
- Your practice — the name, speciality, city, region and website you type in. All of it is information you publish anyway.
- Check results — the questions asked, the answers received, your score, which competitors were named, and which sources were cited.
- Verification results — for each cited page, whether your practice appears on it. We record “could not check” as its own answer rather than treating an unreadable page as absence.
- Billing state — your plan, its status and renewal date, and an identifier linking to Whop’s record. Card details never reach us.
- A hashed IP address — for rate limiting only, to stop one network exhausting the service. It is a one-way hash, kept 24 hours, and cannot be reversed to an address.
What we send to other companies
Running a check means asking third parties questions about you. Here is every one of them and exactly what they receive.
| Who | What for | What they receive | Where |
|---|---|---|---|
| Supabase | Database, authentication and file storage | Your email address, password (hashed by them, never seen by us), and everything listed under What we store. | United States |
| Netlify | Hosting and content delivery | Standard request logs, including IP addresses, for the site itself. | United States |
| OpenAI | The AI assistant we ask about you | The question text, which contains your practice name, speciality and city. Nothing else. | United States |
| Serper | Google search and local-pack results | The search query — your speciality and city, and your practice name for the local-pack lookup. | United States |
| Whop | Payments and subscription management | Your email address and an identifier linking their record to your account. Card details go to them and their payment processors directly; we never see or store them. | United States |
| Optional sign-in | Only if you choose to sign in with Google: your email address and name, via Supabase. We never receive your Google password. | United States |
These providers are in the United States. If you are in the UK, the EU or another region with transfer rules, that is an international transfer, and you should treat it as one when assessing us.
What we read on the public web
When an assistant cites a page, we fetch it and check whether your practice is listed. We read pages exactly as any visitor would, we do not log in anywhere, and we do not attempt to reach anything behind a password. Some sites refuse us, and we record that as “could not check” rather than guessing.
Sharing a report
A share link is a long unguessable token that anyone holding it can open, without an account. That is the point of it — but it means the link is the only protection, so treat it like a password. You can revoke a link at any time from the report page, and doing so kills it immediately. Shared reports are marked not to be indexed by search engines.
How long we keep things
- Check history — for as long as your account exists. The whole value is the trend line, and deleting old checks destroys it.
- Hashed IP addresses — 24 hours.
- Cached search results — one day, then discarded.
- Billing records — as long as tax and accounting law requires, which is longer than your account may last.
Your rights
You can ask for a copy of everything we hold about you, ask us to correct it, or ask us to delete your account and its data. Deleting an account removes your practices, checks and reports. Write to vouch.airank@gmail.com and we will respond within 30 days.
We do not sell your data, we do not share it for advertising, and we do not use your practice’s results to train AI models.
A limitation we would rather state than hide
We do not currently send a confirmation email when you sign up, which means an email address on an account has not been proven to belong to the person using it. We are fixing this. Until then, do not treat a Vouch account as proof of identity, and use a strong unique password.
Changes
If we change how any of this works we will update this page and the date at the top. Material changes will be emailed to account holders once email is running.
Contact
Vouch, Amman, Jordan. Questions to vouch.airank@gmail.com.