Tidemark

Privacy Policy

Last updated August 2026

Studystreaks Ltd (“we”, “us”) operates Tidemark. This policy explains what we collect when you use the service, why, how it is protected, and what you can ask us to do with it.

Zero patient data policy

Tidemark never requests, collects, stores or processes patient identifiable data. Do not enter patient names, dates of birth, CHI or NHS numbers, or identifiable clinical detail into any free-text field, note or friction tag.

1. What we collect

We collect the minimum needed to measure and report on clinical workload.

  • Account information. Name, professional email address, job role (GP partner, salaried GP, locum, trainee, ANP, pharmacist, practice nurse or other), practice affiliation and working pattern.
  • Workload and operational data. Session times and durations, time by domain (direct care, triage, indirect care, running the practice, supervision, QI and cluster work, professional responsibilities), patient contact counts by consultation mode, and MDT whole-time-equivalent cover.
  • Self-reported ratings. Cognitive load (1–5), perceived continuity of care (0–5) and IT friction (0–5), recorded by the clinician about their own working day.
  • Uploaded paper sheets. Photographs of the clinician's own tally sheet, stored in a private bucket readable only by that clinician and processed to extract the numbers on it.
  • Billing data. Subscription plan, currency, renewal dates and a payment provider customer reference. No card numbers are stored by us.

We do not use advertising trackers, and we do not build profiles for any purpose other than showing you and your practice your own workload.

2. Why we use it

  • To produce your personal workload reports, session balance, trends and safe working scorecards.
  • To produce practice-level capacity reports for practice leads, always as aggregated totals.
  • To power the written analysis and improvement suggestions. Only operational figures are sent to the AI provider — never names, emails or free-text notes — and those inputs are not used to train models.
  • To manage your subscription, send receipts and tell you about changes that affect your data or your access.

Our lawful bases are performance of a contract (running your subscription), and legitimate interests (providing workload analysis your practice has asked for and keeping the service secure).

3. Anonymity within your team

Practice leads see aggregated totals only. Individual diary entries, notes and self-rated scores are never shown to a colleague. Charts that could identify one person are suppressed until at least three clinicians have contributed to that view, and clinician-level comparisons are shown as unnamed slots.

The one exception is where a lead records a day on behalf of a colleague at that colleague’s request — that entry is attributed to the colleague and visible to them.

4. Anonymised research (opt-in only)

If — and only if — you choose to take part, your anonymised workload figures may be combined with those of other clinicians and used in published research on workload and wellbeing in general practice. Consent is asked once, when you set up your account; it is never assumed, and the lawful basis is your explicit consent (UK GDPR Art. 6(1)(a)), which you can withdraw at any time in Settings.

In scope: workload timings, contact counts, working pattern, role and nation, and your self-rated scores. Never included: your name or email, your practice’s name or location, free-text notes, uploaded sheet images, or anything about patients.

Every published slice pools at least 20 clinicians from at least 5 different practices, so no clinician or practice can be identified. Withdrawing consent stops your data feeding future analyses; results already published in aggregate cannot be withdrawn, because no one can be picked out of them.

5. Comparing with similar practices (opt-in only)

A practice can choose to see how its working patterns compare with similar practices, privately. Joining is always an explicit choice by the practice lead — never assumed, never bundled into normal use — and the practice can leave at any time with no change to any other part of the service. The dashboard works fully with zero data sharing.

Comparison is always against a band, such as similar-sized practices in the same nation — never a named practice — and there are no rankings, league tables or percentiles. A pooled figure appears only once at least 12 practices in the band share that same figure, so no practice can be picked out. The practice lead chooses exactly which figures are shared, a practice only sees a comparison for a figure it shares itself, and safe-working signals stay off unless the practice turns them on.

Comparison figures stay inside the app: they never appear in downloads or reports, and nothing derived from a practice’s data is sent anywhere automatically. Every change to these choices is recorded.

6. Who else processes it

We never sell, rent or trade personal data. We use a small number of vetted providers, each bound by equivalent data protection terms:

  • Supabase (EU (Frankfurt / Ireland)) — Managed Postgres database, authentication and encrypted file storage for uploaded paper sheets.
  • Cloudflare (UK / EU edge locations) — Application hosting, edge delivery, TLS termination and DDoS protection.
  • Stripe (EU / UK (PCI DSS Level 1)) — Subscription payments and invoicing. Card details are entered directly with Stripe and never reach our servers.
  • Lovable AI Gateway (OpenAI / Google models) (EU / US processing under standard contractual clauses) — Reads uploaded paper sheets into numbers, and generates the written workload analysis. Only operational workload figures are sent; inputs are not used to train models and are not retained by the model provider for training.

The full list and our processor commitments are set out in the Data Processing Agreement.

7. Security and storage

  • In transit: TLS 1.3 (HTTPS), with HSTS enforced.
  • At rest: AES-256 at rest, including database backups.
  • Access control: Per-row database authorisation (Row Level Security) scoped to the signed-in clinician.
  • Hosting: UK / EU data centres, served through Cloudflare's edge network.
  • Sign-in: Email and password or Google sign-in, with hashed credentials handled by the managed auth provider.

8. How long we keep it

While your subscription is active we keep your records so you can see long-term trends. After a subscription ends you have 30 days of full access, then read-only download access, and everything is permanently deleted 90 days after expiry.

The full schedule is in the Terms of Service.

9. Your rights

  • Access and portability. Download a complete export of everything we hold about you, as JSON or CSV, at any time from Downloads or Settings — no request needed.
  • Correction. Change your profile, working pattern and any recorded day yourself in Settings and the diary.
  • Erasure. Email hello@studystreaks.co.uk and we will delete your account and personal records within 30 days.
  • Objection and complaint. You can object to processing, and you can complain to the Information Commissioner’s Office (ico.org.uk) at any time.

10. Contact

Studystreaks Ltd, company no. SC865254, D-U-N-S © 234235037. Registered office: Studystreaks Ltd, c/o Smith & Wallace & Co., 1 Simonsburn Rd, Kilmarnock, Scotland, KA1 5LA. Data protection enquiries: hello@studystreaks.co.uk.