Privacy Policy
Last updated: August 19, 2026
1. Information We Collect
When you create an account, we collect your email address, school, year, and role (student or resident). For residents, we also collect your NPI number to verify your identity. Resident Insider itself does not store your full legal name on your profile, and never stores your phone number or physical address. (Your name from the public NPI registry, and in one case the name read off your government ID, appear in internal review notifications a person reads — when your account goes to manual review, when an automated check flags something, and once when you go live so we can check you against your program’s roster. Where it is stored rather than emailed, it is deleted with your account — see Section 8.)
Residents additionally complete identity verification through Stripe Identity, which involves submitting a government-issued photo ID directly to Stripe. Resident Insider never receives or stores the ID document itself. We do receive the name Stripe reads off it, which we compare against the name on your NPI registry record — unless an operator has already verified you by hand, in which case that comparison is skipped — to confirm that registry entry is yours; that name is never stored on your profile and is never shown to other users. Residents also connect a bank account through Stripe Connect to receive payouts; those banking details are held by Stripe, not by us.
Externship Ratings. When a verified DPM student submits an externship rating, we store the structured letter grades, a 'would rank' response, and the externship's academic year. Your identity is linked to a rating only to enforce one rating per program, let you edit or withdraw it, and prevent abuse — it is never shown to other users. Ratings are surfaced to other students only as anonymized, pooled aggregates (averages and counts) per program; your name and the date you submitted are never displayed. Where only one extern has rated a program, the pooled average necessarily reflects that one set of grades — the extern count shown beside it makes that visible.
Find Your Fellowship. When a verified DPM resident saves a fellowship to their shortlist in Find Your Fellowship, we store the saved program references linked to your account so the list persists across sessions. The list is visible only to you, you can remove saved programs at any time, and it is deleted when you delete your account.
2. How We Use Your Information
Your information is used to:
- Verify your identity as a student or resident
- Match you with the correct programs and degree track
- Process payments and payouts
- Communicate important account updates
- If you opt in, send you the Resident Insider Weekly newsletter (an unsubscribe link in every issue)
For the newsletter specifically, we store your email address, the source you signed up from (e.g., the homepage signup card or platform signup), your opt-in / unsubscribe state, and bounce / spam-complaint metrics needed for deliverability hygiene. This data lives in a separate table from your account profile — newsletter unsubscribes and bounces never affect your account, payout, or verification emails.
3. Anonymity
Resident Insider is built on anonymity. Students never see a resident's name, email, or NPI number. Residents never see a student's name, email, school, or year. This anonymity is enforced inside the database, not by the website’s code: row-level security confines every account to its own record, so a request from a browser can only ever return that person’s own row, and what a signed-in student can read about a resident comes from a separate restricted view holding only the fields listed below. A client request cannot reach past it.
Public listings of residents (e.g. the public program directory) are served from a restricted database view. It exposes the program or programs a resident is listed under, whether the position is a preliminary or intern year, the bio they choose to write, and — only if they turn it on — their PGY year. Name, email, NPI, medical school, graduation year, and IMG status are never exposed publicly, and a resident's legal name is never stored on their profile at all.
A bio is optional and is written to be read by students, so treat anything in it as public: keep it anonymous, and leave out details that could identify you.
4. NPI Verification
We verify resident NPI numbers against the publicly available NPPES registry maintained by the U.S. Department of Health & Human Services. We store your NPI number securely but never display it to other users.
5. Payment Information
Payments, resident payouts, and identity verification are all handled through Stripe — Stripe Payments for card processing, Stripe Connect for resident payouts, and Stripe Identity for government-ID verification. We never store your full card number, CVV, bank account details, or government ID on our servers; Stripe handles payment security in compliance with PCI-DSS standards.
Question content is never sent to Stripe as part of payment metadata. The text of your question is held in our own database during the checkout round-trip and is not visible in the Stripe dashboard.
6. Data Storage & Security
Your data is stored securely using Supabase with row-level security policies. All data is encrypted in transit via HTTPS. Access to personal information is strictly limited and role-based.
7. Third-Party Services
We use the following third-party services:
- Supabase — Authentication and database
- Stripe — Payment processing, resident payouts, and identity verification
- Resend — Transactional and newsletter email delivery
- Vercel — Hosting, infrastructure, and privacy-friendly usage analytics
- NPPES Registry — NPI verification
- Anthropic — AI analysis for the Contract Decoder. When you use that optional tool, the extracted text of your uploaded contract is sent to Anthropic’s API to generate the analysis. It is never used to train their models, and Anthropic retains it only for a limited period (up to 30 days) for abuse monitoring. The file itself is never stored on our servers or theirs.
8. Data Retention
Your account data is retained as long as your account is active. Accounts that never finish signup are removed automatically: an unconfirmed email address with no profile after 30 days, and a profile still missing its school and training year after 60 days — unless any verification step has already succeeded, in which case it is kept for human review instead. A verified resident or student account is never removed automatically. If you delete your account, your identifying information — your name-linked profile, email, and verification data — is permanently erased from our systems. Stripe retains its own record of the identity check it performed, under Stripe’s privacy policy; we do not hold a copy. Deletion can be held, never refused: while a question payment on the account is still being processed, while a resident is still owed earnings we have not managed to send, or — rarely — while several question payments cannot be confirmed as complete, in which case our team is notified and releases the hold. In each case you are told which, and the deletion completes once it clears. Past question-and-answer content and any ratings you submitted are retained with your identity severed: the text of the exchange stays so the other party keeps the Q&A they paid for or the ratings they earned, but it is no longer linked to you. We also keep an anonymized deletion record (role, degree, school, and aggregate usage counts such as questions asked and answered — no identifying information) for analytics. One exception delays — but does not refuse — a resident’s deletion: if you have earnings we have not yet been able to send you, we hold the deletion rather than complete it, because erasing the account the payment is heading to would make that money unrecoverable. We show you the amount at the time. Payouts in transit clear on their own; a genuinely stuck one is settled with you directly by emailing support@myresidentinsider.com, and your deletion then proceeds exactly as described above.
If you join the waitlist for a full residency program before creating an account, we store your email address, the program you asked about, and your degree type so we can tell you when a spot opens. If you claim a spot, that entry is deleted once you are verified. Entries that are spent — claimed, or expired — are deleted automatically once they are at least 90 days old. You can ask us to remove you from a waitlist at any time by emailing support@myresidentinsider.com.
9. Your Rights
You may request to view, update, or delete your personal data at any time by contacting us at support@myresidentinsider.com. We will respond within 30 days.
10. The Lounge
The Lounge is a private discussion space for verified MD/DO and DPM residents. Conversations there are visible only to other verified residents — never to students, residency programs, hospitals, or the public. Beside each handle, other members can see a coarse indicator of whether that member has been active in the past week — a simple yes/no with no timestamp attached. There are no read receipts and no online-now presence. (Messages themselves, like any chat, display the time they were posted.) MD/DO and DPM members are kept in separate audience-segregated Lounges — a verified MD/DO resident never sees DPM activity, and vice versa. This access restriction is enforced at the database level and cannot be bypassed by client requests.
Within the Lounge, residents post under an automatically assigned pseudonym. Your real name, email, and program are never attached to your posts. Your specialty and PGY year are — the pseudonym is built from them, so a post reads like “Derm Insider R2-001”. Some specialties are shortened, others appear in full, and for DPM residents the first half is simply the degree: “DPM Insider R2-001”. That is visible only to other verified residents in your own Lounge, never to students or visitors.
Resident Insider does not monitor Lounge conversations as a matter of course, and does not read them except when a member reports a message for a House Rules violation, which an administrator then reviews. Administrators hold clearly identified Lounge accounts — named “Resident Insider,” not resident-style pseudonyms — in order to act on those reports.
11. Contract Decoder
When you upload a contract to the Contract Decoder, the file is read in memory on our server to extract its text and is never written to disk or any storage — we do not keep the file or its contents. The extracted text is sent to Anthropic to produce the analysis: it is never used to train their models, and they retain it only for a limited period (up to 30 days) for abuse monitoring. What we save is the resulting plain-English analysis, encrypted at rest (AES-256-GCM) and protected by row-level security so that only you can access it. You can delete any analysis at any time from the tool, every analysis is automatically and permanently deleted 30 days after you run it, and deleting your account deletes your analyses. Alongside it we keep a one-way fingerprint of the extracted text (so re-uploading the same contract doesn’t charge you twice) and the date, model and degree — never the contract or its terms.
12. Cookies & Tracking
Resident Insider uses a small number of essential cookies and browser storage items.
Cookies. A sign-in cookie that keeps you logged in between visits, and a cookie set while a password reset is in progress. Cookies are sent to our servers with each request — that is how they keep you signed in.
Local storage, which stays on your device and is not transmitted to us: a cached copy of your role to speed up page loads; interface preferences such as notices you have dismissed and your progress through the Attending Leap checklist; cached counts; a marker for a Contract Decoder decode or purchase in progress so a refresh does not lose your place; and a marker recording which answers you have already opened.
Session storage, which your browser clears when you close the tab: a draft of anything you have part-way typed into signup (including your NPI number, if you have entered it), and a draft of an in-progress Find Your Specialty survey — so a refresh does not make you start over.
Clearing your browser data removes all of it. We do not use advertising cookies or cross-site trackers.
For usage analytics we use Vercel Analytics, which collects privacy-friendly, aggregate metrics (such as page views and referrers) without cookies and without personally identifying you.
13. Children’s Privacy
Resident Insider is intended only for users who are at least 18 years old (see our Terms of Service). We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with information, contact us and we will delete it.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes are posted here with an updated date at the top of this page. Continued use of the platform after changes constitutes acceptance.
Contact
Questions about privacy? Email us at support@myresidentinsider.com