Privacy Policy
Version 1.1 · 17 August 2026 · plain-language draft, pending legal review
Who we are
Injury IQ is operated from Australia. Privacy contact: hello@injuryiq.health.
What we collect
Account data: name, email, role, organisation.
Injury management records your organisation's authorised users enter: coded cases, recovery plans, availability, athlete check-ins (soreness, illness marks, session effort, and any free-text notes an athlete adds), testing results and clinical notes.
Scan reports dropped into the diagnosis tool are parsed in your browser — the file itself is not uploaded. Only the structured findings a clinician confirms become part of a case.
Public forms on this site: the waitlist form (name, email, your role, and anything you write in the notes field) and the recovery-kit order form (name, email, phone, practice name and delivery address). Both are stored so we can respond to and fulfil your request.
Health information — handled as the sensitive class it is
Injury records are health information under the Privacy Act 1988 (Cth). We hold them only to provide the service to your organisation, on your organisation's instructions.
Access is role-walled and enforced in the server layer: coaching staff receive availability and category only — never diagnosis text, severity scores, or clinical notes. Clinical detail is restricted to clinical roles.
Athlete check-ins are stored on our servers and shown to your organisation's staff according to their role. An athlete's own device also keeps its local copy. Athlete accounts are not yet served records back: an athlete account receives no athlete's records from the server — including, for now, their own.
Some athletes are minors. Where your organisation records consent on an athlete's profile, we store when and by whom it was recorded. A dedicated guardian-consent flow is being built; until it ships, obtaining valid consent — including a parent or guardian's for a minor — is your organisation's responsibility as the party with the athlete relationship.
Features that use AI and speech providers
Some features send content to third-party processors to work: the consult scribe converts speech to text using your browser's speech service (the browser vendor processes the audio) and sends the transcript — which can include the patient's words, not only the clinician's — to Anthropic, our AI provider, to structure the note. The clinical assistant and help features send the question and the relevant case context to Anthropic to generate the response.
This content is sent to provide the feature you invoked, and our provider agreement does not permit it to be used to train their models. Nothing is sent to these providers unless a user invokes the feature, and the scribe shows what it is doing at the point of use.
Where data lives
Data is stored with our infrastructure providers (currently Supabase/PostgreSQL and Vercel). Storage may occur outside Australia depending on provider regions; we choose reputable providers with contractual safeguards.
What we never do
We do not sell personal information. We do not use your organisation's clinical records to train models. We do not show one organisation's data to another.
Retention, export, deletion
Records are kept while your organisation subscribes. On request at the end of a subscription we export your records in a portable format and delete them, subject to legal retention obligations.
Security
Encrypted in transit, encrypted at rest by our providers, reads shaped by server-verified role, write permissions checked server-side, and audit logging on governance actions. No system is breach-proof; if a breach occurs we will notify affected organisations and the OAIC as the Notifiable Data Breaches scheme requires.
Your rights
You may request access to or correction of your personal information, and complain to us or to the Office of the Australian Information Commissioner (oaic.gov.au).
See also the Terms of Service.