Privacy Policy
Effective date: August 11, 2026 · Version 2026-08-11-v6
This Privacy Policy explains how DermPaper LLC (“DermPaper,” “we,” “us”) handles information in connection with the DermPaper service at dermpaper.com (the “Service”).
The short version. DermPaper is built so that no patient data is ever collected. We do not operate patient accounts, forms, or trackers, and the public education pages are not designed to identify the people who read them. The information we do collect is about the physicians and practices who subscribe, so we can run their accounts and bill them. We do not sell personal information, and we do not use third-party advertising trackers.
1. Who this applies to
This policy primarily concerns the subscribing physicians and practices (“you”) who create accounts. Patients and the general public simply view educational pages and are not asked to create accounts or submit personal information.
2. Information we collect
From subscribers, at signup and in the dashboard:
- Identity and professional details: your name, professional degree (MD/DO), and NPI.
- Contact details: email address and, optionally, phone number.
- Practice details: clinic name, website, booking (“Book now”) link, logo, and any custom handouts or photographs you upload.
- Account security data: authentication credentials managed by our provider (we do not store your password in readable form).
- Agreement records: the version of the Terms you accepted and the date, time, IP address, and browser user-agent of that acceptance (kept as an immutable record).
Practice-uploaded patient photographs. A practice may upload before/after photographs of its own patients for display on that practice’s patient pages. These photographs are provided by the practice, not by DermPaper: the practice selects them, is solely responsible for obtaining the patient’s signed written authorization before upload, and retains that authorization in its own records. DermPaper hosts the photographs at the practice’s direction, does not review them, and stores only the image files (renamed to non-identifying file names, with camera metadata removed during upload) plus a record of which practice user attested to the authorization and when. If you are a patient and want a photograph removed, contact the practice directly — or email privacy@dermpaper.com and we will remove it and notify the practice.
Payment information. Subscriptions are processed by Stripe. Stripe collects and processes your payment-card details directly; we do not receive or store your full card number. We receive limited billing status information (such as plan, subscription status, and renewal date).
NPI verification data. We submit your NPI to the public CMS NPPES NPI Registry to confirm you are a physician, and we store the registry’s response with your provider record.
Usage and analytics (no patient identity). We keep aggregate, non-identifying counts — such as QR scans and “Book now” clicks — to show practices how their pages are used. These counts are not tied to any individual reader. We also keep standard server and security logs.
Cookies. We use only the cookies needed to operate the Service, primarily session and authentication cookies so signed-in subscribers stay logged in. We do not use third-party advertising or cross-site tracking cookies.
3. Information we do NOT collect
- No patient data / no PHI. We do not collect patient names, contact information, images, or any Protected Health Information. Subscribers agree not to submit PHI to the Service (see the Terms). Because we do not handle PHI on a practice’s behalf, we are not a HIPAA “Business Associate.”
- No biometric data. We do not collect or use biometric identifiers or information (including under the Illinois Biometric Information Privacy Act).
- No sale of personal information.
4. How we use information
We use the information above to: create and operate your account; verify your NPI; provide, maintain, and improve the Service; process payments and manage subscriptions (via Stripe); send you service, billing, and security communications; keep records of agreement acceptance; protect the security and integrity of the Service; and comply with law.
5. How we share information
We do not sell personal information. We share it only:
- With service providers (subprocessors) who help us run the Service, under contract and only as needed — currently Stripe (payments), Supabase (authentication, database, and storage), and our hosting provider;
- With the CMS NPPES registry (a public U.S. government NPI database) to verify your NPI;
- For legal reasons — to comply with law, respond to lawful requests, or protect our rights, users, or the public; and
- In a business transfer — in connection with a merger, acquisition, financing, or sale of assets, subject to this policy.
6. Data security and retention
We use reasonable administrative and technical safeguards (including access controls, encryption in transit, and row-level database security) to protect information. No method of transmission or storage is perfectly secure. We retain subscriber account information for as long as your account is active and as needed afterward for legal, tax, accounting, and dispute-resolution purposes. Agreement-acceptance records are kept as a permanent compliance record. We will notify affected individuals of a data breach as required by the Illinois Personal Information Protection Act and other applicable laws.
7. Your choices and rights
You may review and update most account information in your dashboard, or contact us at privacy@dermpaper.com to access, correct, or delete your account information, subject to records we must retain by law. You can manage billing and cancel through the Stripe customer portal. Depending on your state, you may have additional rights regarding your personal information; we will honor applicable rights — contact us to exercise them.
8. Children
The Service is intended for licensed physicians and is not directed to children, and we do not knowingly collect personal information from children.
9. Location
We operate in the United States, and information is processed and stored in the United States.
10. Changes to this policy
We may update this policy and will post the updated version with a new effective date. Material changes may also be communicated by email or in the dashboard.
11. Contact
DermPaper LLC — 5440 W. Belmont Ave, Chicago, IL 60641 Privacy: privacy@dermpaper.com · General: support@dermpaper.com