Privacy notice
Pilot release · last updated 17 July 2026
Short version: Scanlog is a personal ultrasound training logbook. It holds your account, profile and the training records you create — no patient-identifiable data. Your logbook is private to you and anyone you explicitly share it with. Data is stored in EU/UK-region systems with row-level security. You can export or delete your data at any time. Questions or requests: privacy@scanlog.co.uk.
Who we are (data controller)
Scanlog is operated by Ratnadeep Ghadge as an individual data controller in the United Kingdom, registered with the ICO (registration ZC168901). For any privacy question or request, contact privacy@scanlog.co.uk.
User roles
Your role controls what you can see and do.
- FAMUS Trainee — records their own logbook and can share it for countersignature.
- FAMUS Supervisor / Accredited — can be given access to a trainee's shared logbook to review, comment and countersign; both track a FAMUS reaccreditation date.
- FAMUS Mentor — a senior clinician who reviews and countersigns shared logbooks; does not use the trainee reporting form. Mentors can also log their own teaching activity, but do not track a reaccreditation date.
You choose your role when you first complete your profile; it is then locked, and changing it needs administrator approval. Your role is visible to administrators and to colleagues you share your logbook with.
What we store
- Account & profile: your email, a hashed password, and your name, grade, specialty and role (your profile is also cached in your browser for faster loading).
- Logbook entries: an auto-generated non-personal scan reference (SC-<your-code>-NNNN), scan type, date, free-text findings, findings tags (trainees only), supervision status, supervisor initials, which leg(s) were scanned (DVT scans only), and any images or short clips you upload. Each entry is "draft" (private to you) or "complete". An unused reference is held against your account and reused rather than skipped, so your numbering has no gaps.
- FAMUS reporting forms (trainees only): for each scan, either an uploaded photo/scan of the paper form or an in-app electronic form (structured answers, form type, draft/complete status and a lock flag). Uploaded forms are held in a private per-user store (scan-forms) with row-level security and short-lived signed-URL access. A scan stays a draft until a form is added. For an unsupervised scan, only a fully countersigned paper form may be uploaded; on upload the scan and form are locked and marked complete without a separate electronic countersignature, and the countersigning supervisor is recorded either by selection from your active logbook shares or, if "Other" is chosen, by their initials entered manually.
- Supervisor attestation (electronic-form supervised scans): the supervising clinician's full name as you enter it (their initials are worked out from it), the timestamp of your supervision declaration, and a signature they draw on your device before the form can be completed. This is visible to you and anyone you share the scan with, appears as initials only in exported logbooks, and is locked once the scan is countersigned. Supervised scans using an uploaded paper form record your supervisor's initials only — their handwritten sign-off on the form remains the evidence. The supervising clinician may not hold a Scanlog account; if you are a supervisor and would like details recorded about you corrected or removed, contact privacy@scanlog.co.uk.
- Review records: when a reviewer countersigns your scan or form, we store their user ID, initials, mandatory comment and timestamps — not their email. Once countersigned, the scan/form is locked, and the record is retained as accreditation evidence even if the reviewer later deletes their account. The same countersignature data (plus the trainee's initials and grade drawn from their profile) is what appears in a reviewer's own supervision summary export (see Exports below). (This is separate from the supervisor attestation above, which you yourself record about who supervised you at the bedside.)
- Sharing: the email address and role of anyone you share your logbook with.
- Teaching log & evidence (Supervisors, Accredited users and Mentors): teaching activity records (type, date, description, optional learner count and link) and optional uploaded evidence files, held in a private per-user store with signed-URL access.
- Support tickets (category, subject, message, the page you were on, browser User-Agent), security/audit logs, and pending requests (sign-ups, password resets, role changes). For administrator actions we additionally record IP address, the country derived from it, and device.
What you must NOT enter
Scanlog is not a clinical record system and is not approved for patient-identifiable data. Do not enter or upload patient names, NHS or hospital numbers, dates of birth, or images/videos showing patient identifiers on the scanner overlay. For teaching evidence, do not upload documents showing learners' or colleagues' names, emails or signatures without permission — redact them or use the learner-count field. The app warns on detected identifier patterns and asks you to confirm each upload, but you remain responsible for anonymising. If identifiable data is entered by mistake, delete it or email privacy@scanlog.co.uk immediately — we will permanently purge it (including from the 30-day recovery store and backups within our providers' cycles) and record the incident.
Lawful basis (UK GDPR)
- Performance of a contract (Art 6(1)(b)) — creating and maintaining your account and storing the records you create, including reaccreditation tracking from the date you provide.
- Consent (Art 6(1)(a)) — optional sharing of your logbook with a named colleague; withdraw at any time by removing the share.
- Legitimate interests (Art 6(1)(f)) — security and audit logging, administrator/approval controls, and essential service emails. Retained countersignature records (no email) rely on this as accreditation evidence for the trainee; the attestation's evidential value depends on being permanent, and the reviewer's limited interest is balanced by the minimal data kept and prior notice here. Supervisor attestation data (full name, declaration and signature on electronic-form supervised scans) relies on the same basis, as necessary accreditation evidence for the trainee, balanced by initials-only exports, private storage, and the supervisor's ability to contact privacy@scanlog.co.uk.
Exports
All exports are initiated from Settings → Export your data. You can download your logbook as a PDF (with an optional filter step for date range, scan type and — for reviewers — a supervision summary), or a full ZIP archive of everything we hold for you (scans, media, FAMUS reporting forms for trainees, and teaching portfolio for Supervisors/Accredited/Mentors). The home-page filters control on-screen display only. Because exports may include another user's personal data (a reviewer's initials and comment, or a trainee's initials and grade), you re‑enter your password first, and every export is recorded in the audit log.
Deleting your account
From Settings → Danger zone. Deletion is not immediate: your account is scheduled for permanent erasure after a 30-day grace period, during which you can sign in and cancel. You are offered a full export before confirming. When the grace period ends, your account, scans, media, reporting forms, teaching activities and evidence are permanently removed, including from the recovery store and file storage. Countersignatures you made on other trainees' scans are retained in full as their accreditation evidence (initials and comment; no email). The last remaining administrator account cannot be deleted until another administrator is appointed.
Where data is stored and who processes it
Your data is held in EU/UK-region managed databases and object storage, with row-level security so only you (and any colleague you explicitly share with) can read your scans. Processors acting on our instructions:
- Supabase — database, authentication, file storage (EU region).
- Lovable — application hosting and delivery.
- Cloudflare — edge network, DNS and CDN (also the source of the country code recorded for administrator actions).
- Mailgun (Sinch) — essential service emails only (sign-in, password reset, approval, admin security alerts); may process delivery metadata in the US.
Some providers may process data outside the UK/EU under appropriate safeguards (UK International Data Transfer Addendum or EU Standard Contractual Clauses).
Security
All data is encrypted in transit (TLS) and at rest. Row-level security means each user reads only their own data and data explicitly shared with them; account-approval status is enforced at the same database layer, so an unapproved account cannot create, change or delete data even if a front-end check is bypassed. Privileged tables (audit log, account‑status, user‑roles and password‑reset requests) are additionally grant‑locked so only trusted server functions can write to them — an authenticated session, including an administrator's, cannot modify these tables from the client. Administrator accounts require multi-factor authentication, and admin actions are logged with IP, country and device. Uploads are validated server-side and image location metadata is removed. If a breach is likely to result in a risk to you, we will notify the ICO within 72 hours and inform affected users without undue delay.
How long we keep it
Your records are kept while your account is active and permanently deleted within 30 days of account deletion (including recovery store and backups within providers' cycles). Deleted scans/teaching items are recoverable for 30 days, then purged. Review records and share links are kept for the life of the related entry. Support tickets and audit logs: up to 12 months during the pilot. Unactioned sign-ups and password-reset requests are removed after 30 days. We will update this notice before changing retention periods.
Your rights
Under UK GDPR you have the right to access, rectification, erasure, restriction of processing, objection, and data portability, and to withdraw consent at any time without affecting earlier lawful processing. Deleting your account removes your scans and media; countersignatures you applied to other trainees' scans are retained (initials, comment, timestamps; no email) under legitimate interests as their accreditation evidence. To exercise any right, contact privacy@scanlog.co.uk — we respond within one month.
Cookies and local storage
Scanlog uses a strictly-necessary session cookie to keep you signed in. We use no advertising cookies, third-party analytics or tracking pixels. Local storage caches your profile and holds any scans saved while offline; signing out clears both (you're warned if scans are still unsynced). On shared or hospital computers, always sign out.
How to complain
Please contact privacy@scanlog.co.uk first if you can. If you remain unsatisfied, you can complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint or 0303 123 1113.
Data controller: Ratnadeep Ghadge · privacy@scanlog.co.uk