CodeScribe EMS

Privacy Policy

Effective October 7, 2026. Replaces the policy of July 23, 2026.

CodeScribe EMS is an iPhone and iPad app for documenting cardiac arrest resuscitations, made by Sasha Lawrence (CodeScribe EMS, Charlottesville, Virginia). This policy says what the app stores, where it goes, who can see it, and how to get rid of it. It is written to be read, not skimmed, because the people who use this app are responsible for patient records and deserve a straight answer.

There are two ways to use CodeScribe EMS, and they are covered separately below.

1. The app on its own

What the app stores on your device

Every code record you create: the start time, each logged intervention and its time, the patient category (adult or pediatric), the outcome, and the optional fields you choose to fill in (age range, estimated downtime, incident or run number, notes). Your button layout, timers and settings. All of it is stored on the device in Apple's standard on-device storage and protected by the device passcode. The app does not use iCloud for records, so records do not sync between devices and are not stored in iCloud except as part of your normal device backup, which you control.

What leaves your device

Nothing, unless you send it. Copying a narrative, sharing a PDF, or sending a record file to your department all start with you tapping Share, and the file goes only where you send it through Apple's share sheet (AirDrop, email, your ePCR, and so on). Once it is there, it is governed by that system's rules, not this policy.

Analytics and tracking

None. The app has no analytics, no advertising, no crash reporting service and no tracking of any kind. We do not know how many people use it, what they tap, or how long a code lasts, unless you tell us.

Shared button setups

A department can share its button layout as a file, or by a code that the app looks up in Apple's iCloud public database. A shared layout contains configuration only: button names, timers, option lists and the department's name. It contains no records and no personal information. Looking up a code sends that code to Apple's servers and nothing else.

App Store purchase

Buying the app or the export unlock is handled entirely by Apple. We receive no name, address or payment information from Apple, only anonymous sales totals.

2. Department and training-program accounts

This section applies only if you sign in and join a department. Until you do, section 1 is the whole story.

Signing in

You sign in with an email address (we send a one-time code) or with Sign in with Apple. We store the email address you sign in with, or the relay address Apple gives us if you choose to hide yours. Sign-in emails are sent through Resend, an email delivery service, which sees your address and the email content for as long as it takes to deliver. We use the address for signing in and, for officers, for messages about the department's account. We do not send marketing email to members.

What your department receives about you

When you join, your department's officers see: the name you entered on the roster, when you joined, which protocol revision your phone has, your app version, and the date of your last check-in (the day, not the time). They do not see your email address unless you are the officer who set the department up.

What your department receives about each code

After a code ends, the app prepares a summary and sends it the next time the app opens with a signal, after a random wait of 12 to 72 hours. The wait exists so that the time the summary arrives cannot be used to work out when the arrest happened. A summary contains exactly these things and nothing else:

A summary never contains the date or clock time of the code, the incident or run number, the notes field, age, weight, any free text, or anything that identifies a patient. The app's own code decides what can be sent, and the server independently refuses anything outside this list, so a future version of the app cannot quietly send more. You can see every field the app would send under Settings, Department account, What your department sees, before you join.

In a training program (an EMT or paramedic course), where every code is a practice scenario with no patient, two things differ: the summary goes up at your next check-in instead of after the wait, and it may carry the scenario name you typed. The server refuses a scenario name from any department that is not a training program.

Taking a summary back

If you delete a code from your phone, or mark it as training, the app withdraws that summary from your department at its next check-in. Officers keep the summaries of codes you have not withdrawn, including after you leave, because they are the department's quality records; they stay linked to your roster name until you delete your account, after which they are unlinked from any name.

Officers and the dashboard

Officers sign in to a web dashboard at app.codescribeems.org and see their department's roster, protocol and summaries. The dashboard also stores: the department's protocol (buttons, timers and option lists) and each revision's publisher and date; which summaries an officer has marked as reviewed and by whom; and a log of department activity (members joining, being approved or removed, protocol revisions) kept as references to roster entries rather than names. Officers can download their department's summaries as a spreadsheet. The dashboard keeps one sign-in token in your browser and nothing else; it has no analytics.

Paying for a department

Department licenses are sold through Stripe. Card details are entered on Stripe's page and never reach us; we receive the buyer's email address, the department name and Stripe's customer and subscription identifiers so we can renew or end the license. Stripe's handling of your payment is covered by Stripe's privacy policy.

Where account data is kept and who can reach it

Account data is stored with Supabase in a database in the eastern United States. Access is enforced in the database itself: a member can read their own department's protocol and roster and write only their own summaries; an officer can read their department's summaries; nobody can read another department's data; the app and dashboard have no access path that bypasses these rules. The website and dashboard are served through Cloudflare, which sees the usual web request information (your IP address and the pages requested) to deliver them. Sasha Lawrence, as the operator, can see account data for support and billing and does not look at summaries except to help an officer who asks.

How long it is kept

Roster entries and summaries are kept while the department's account exists. If you leave a department, your roster entry is removed; your sent summaries stay with the department but are unlinked from your name once you delete your account. If a department's license lapses, its data is kept for twelve months so a renewal picks up where it left off, then deleted. A department can ask to be deleted at any time, which deletes everything about it.

Deleting your account

Settings, Department account, Delete account. This deletes your sign-in, removes you from your department's roster, and unlinks your summaries from any name, immediately. Your records on the phone are not touched; delete those in the app if you want them gone too. You can also email us to delete the account for you.

3. Patient information and HIPAA

CodeScribe EMS is designed to be used without patient names, dates of birth, medical record numbers or other identifiers, and has no fields meant to hold them. Your records on the phone are yours and your service's; treat them as you would any PCR draft, and do not put patient identifiers in the notes field.

The summaries a department receives are designed to contain no protected health information: no identifiers, no dates, no times, no free text. On that basis we do not act as a business associate, and departments have not needed a business associate agreement to use the dashboard. This is our design and our understanding, not legal advice; if your department's counsel wants to review the exact field list, we will send it, and if they conclude an agreement is needed we will discuss one. We will not change what a summary contains without updating this policy first.

4. Your rights

You can see everything the app holds about you on your phone, in the app. For account data, email us and we will send you a copy, correct it, or delete it. If you are in the European Economic Area, the United Kingdom, Canada or another place with a data protection law, the same applies: the lawful basis for processing account data is the agreement you make with us when you join a department, your data is processed in the United States, and you can complain to your local data protection authority if we do not resolve something. We respond within 30 days.

5. Security

Records on the phone are protected by your device passcode and Apple's file protection. Account traffic uses TLS. Membership is proved with a signed token that cannot be forged or altered. Sign-in tokens live in the device keychain. Database access rules are tested on every change. If we ever learn of a breach affecting account data, we will tell affected officers within 72 hours of confirming it.

6. Children

CodeScribe EMS is a professional tool for trained emergency responders and students in accredited EMS programs. It is not directed at children, and we do not knowingly collect information from anyone under 16.

7. Changes

When this policy changes, the new version is posted here with a new effective date, and officers of active departments are told by email before the change takes effect if it affects what a department receives.

8. Contact

CodeScribe EMS, Sasha Lawrence, Charlottesville, Virginia, United States. support@codescribeems.org. Please do not include patient information in any email.