Privacy
Most privacy pages are legalese written to protect the company. This one is short, and written to be checked, because privacy is the architecture here, not the paperwork.
The three rings
Ring 0: raw data never leaves your hands
Bank statements, payslips, reflections, portfolio entries, anything about patients. Locum Manager processes them as plain files on your own Mac. No upload to medrics, no account, no telemetry, no copy we can read. The files live where you put them, your Mac or your own cloud drive. Delete the folder and every trace is gone.
Ring 1: metadata travels only when you send it
Some optional online services need the shape of things. Before anything is sent, one command shows you the exact bytes that would travel. Nothing goes without a consent flag you set yourself.
Ring 2: intelligence flows down freely
Rate cards, app updates, mentor advice, your CPD from our teaching. Downhill is free; uphill is guarded.
Exactly what each service sees
| Service | Sees | Never sees |
|---|---|---|
| Portfolio monitoring | Entry counts by month & type, CPD hours, gaps, goal counts, credential states, deadlines | Titles, reflections, any free text, any money data |
| P87 drafting | The claim lines you previewed & approved: short merchant label, date, amount | Bank statements, balances, account numbers, references |
| Rate cards | Market facts: "site X pays grade Y £Z/hr, seen on date" | Your shifts, your earnings, anything about you |
| CPD auto-transfer | That your email attended a session we ran | Anything else |
The server enforces this at the door: payloads that look like content rather than metadata are rejected even if a client tries to send them.
The one deliberate exception
The assessor sign-off service exists to share one piece of your writing with one named doctor, because that's the point of it. It only happens when you pick the item, see exactly the text that will be sent, and send it yourself. Never automatic, never bulk, capped in size. Think of it as handing one page to a colleague, because that's what it is.
Community data & k-anonymity
Community rate cards publish only when at least 3 different members independently report the same rate. Contributors are stored as one-way cryptographic hashes: nobody, including us, can read a contribution back to a person.
Independently certified
MEDRICS LTD holds Cyber Essentials certification: the UK government-backed security standard, assessed independently and covering the whole organisation. Certified 3 September 2026, valid to September 2027. It sits on top of the architecture above rather than replacing it. Certificate 37718e58-f108-4d5a-8fe0-f676d9b44528 · certification body DigitalXRAID · Cyber Essentials partner IASME.
The test we apply
Before any data leaves a member's machine, one question: is this a market fact (a hospital's advertised rate, fine) or a personal fact (what you earned, worked, or wrote: never, except the single-item sharing you do yourself)? If this page and the software ever disagree, that's a bug. Tell us.