Casebook

Privacy policy

Casebook is operated by Keplr Labs LLC. Last updated 20 September 2026.

About the people you assess

No name, no medical record number, no email, no telephone number, no address. Not in any table that holds patient data, and a test fails the build if a column with one of those names appears. The one direct identifier Casebook does store, when you enter it, is a date of birth — from which the age at each testing is computed. A person is otherwise a pseudonymous code you assign, and the mapping from that code to a name stays with you.

What is kept: a date of birth if you enter one, the scores, the instrument each came from, the age in years and months at testing, the date of testing, the school grade, who answered a rating scale, and terms you pick from a controlled list. Two fields are free text; text carrying an identifier with a recognizable shape is refused outright, and a name-shaped phrase is flagged to you as you write it.

A report you upload is read for that one request and kept nowhere. There is no column for the source text, no cache and no copy on disk. The full account is on the security page.

A word on HIPAA

The records Casebook holds are protected health information: a case may store a date of birth, the one direct identifier the schema keeps, from which the age at each test is computed. Every other HIPAA identifier — name, record number, address, contact detail — still has no column, and a build fails if one appears. Because a date of birth is held, a business-associate agreement is the appropriate arrangement, and we will sign one.

The service runs on HIPAA-eligible AWS infrastructure under a business-associate agreement with AWS, with the records encrypted at rest and in transit, held in a private network the database has no route out of, and every change to a case recorded in an audit log. Because the records are protected health information, a business-associate agreement with Keplr Labs LLC is the appropriate arrangement — write to us and we will send it.

Keeping it minimal still depends on you: the codes you assign must not be derived from the person, and beyond the date of birth the two free-text fields must not carry identifying detail. If any other identifier goes in, you — not Casebook — have introduced it, and you remain the covered entity responsible for it.

About you

Your email address, so you can sign in and so we can reach you about the account. Your practice name. A record of what was done in your practice — which case was opened, changed, deleted or exported, by whom and when — which is a security control and is readable by everyone in your practice. Payment is handled by Stripe; we never see or store a card number.

Who else sees it

Nobody. We do not sell data, we do not share it with advertisers, and we run no third-party analytics or tracking on the pages where your records are. The service runs on Amazon Web Services, and Stripe processes payments; those are the only two processors involved.

One practice cannot see another. That is enforced on every database query rather than checked per screen, and a query that somehow arrives without a practice in scope fails rather than returning everything.

Where it is and how long it stays

In the United States, encrypted at rest and in transit, in a private network the database has no route out of. Backups are kept 30 days. Your records stay as long as your practice does; closing it deletes them, including the access log, and that cannot be undone.

Getting it back, or getting rid of it

Export everything at any time from the Practice page, as CSVs with a codebook describing every column. Delete any case whenever you like, including when a subscription has lapsed. Close the practice and it all goes.

Cookies

One, which keeps you signed in. It is not used to track anybody and there are no others.

If something goes wrong

If data is exposed in a way that affects you, we will tell you what happened, what was affected and what we did, without waiting to be asked.

Your rights over your information

Depending on where you are, privacy law may give you rights over information held about you — to see it, correct it, or have it deleted. For the information about you that we hold, which is your email address and practice details, write to us and we will honor those rights. For the records inside your practice you already hold every such right directly: you can export or delete them yourself at any time, without asking.

Changes to this policy

If we change this policy in a way that matters, we will write to the address on your account before it takes effect.

Getting in touch

support@casebookclinical.com