Trust

Security at Dash

Last updated August 25, 2026

Dash holds the working records of your business — your tray inventory, your schedule, your surgeon preferences. This page explains, in plain language, how that data is protected. Questions about anything here: support@dashcheck.app.

Not for patient data — by design. Dash is built for trays, schedules, and surgeon preferences — not patients. There are no structured fields for patient names, MRNs, dates of birth, or surgical details; the Terms of Service prohibit entering patient information anywhere, free text and photos included; and Dash screens for apparent patient identifiers and may delete content that contains them. Dash is not intended for PHI and makes no HIPAA claims: it is not a HIPAA business associate and no BAA is offered. Keep patient information out of Dash and there is nothing patient-related here to protect, disclose, or breach.

Encryption

All traffic between your device and Dash is encrypted in transit (TLS), and your data is encrypted at rest in our database and file storage. Connections to dashcheck.app are forced to HTTPS (HSTS).

Account isolation

Every record in Dash is scoped to the account (or team) that created it, and that boundary is enforced by the database itself — row-level security on every table — not just by application code. One rep (or team) cannot read another’s data, and an automated test suite verifies this isolation table by table.

Tray photos

Photos live in private storage — there are no public links. The app hands out short-lived signed URLs (minutes, not days) scoped to your account. Location and camera metadata (EXIF, including GPS) is stripped on our servers before a photo is stored or processed, and only a rolling set of recent photos is kept per tray level — older ones are deleted automatically. Metadata stripping removes location and camera data, not anything visible in the photo itself — keep patients, charts, and identifying signage out of frame.

The AI assistant

The Dash AI assistant is an optional, separate paid add-on — not included in any plan — and is powered by Anthropic. It reads only from your own workspace, images you send it are metadata-stripped and not stored by the provider, and your requests are not used to train models. It never needs — and the app reminds you never to give it — patient information, and workspace notes that appear to contain patient identifiers are withheld from what the assistant sees. You can delete the conversation you have open at any time, clear your whole assistant history from the assistant’s memory screen while your add-on is active, and deleting your account removes it entirely.

Payments

Payments are handled by Stripe. Your card number never touches Dash’s servers — we store only your subscription status, plan, and a customer identifier.

Service providers

A short, deliberate list — each limited to what its function requires:

  • Supabase — database, authentication, and private file storage.
  • Netlify — application hosting and delivery.
  • Stripe — payment processing and subscription management.
  • Resend — transactional email (sign-in links, receipts, service messages).
  • Sentry — error monitoring, so failures are seen and fixed.
  • Anthropic — powers the optional Dash AI assistant (see above).

Deleting your data

Account deletion is self-serve from Settings. It is recoverable for 30 days — sign back in within that window to restore everything — after which your data, including every photo, is permanently removed. Deleting your account also ends your subscription.

If something goes wrong

No method of transmission or storage is perfectly secure, and we won’t pretend otherwise. If a security incident affects your data, we will notify affected users without undue delay, consistent with applicable breach-notification laws, and say plainly what happened and what we did about it.

Found a vulnerability? Report it to support@dashcheck.app — we read every report.