Last updated: 17 July 2026 (draft — for review before launch)
CPD Dump helps healthcare professionals collect and organise their own continuing professional development (CPD) evidence. This policy explains what we store, why, and the rules that keep other people's personal information out of it.
CPD Dump is for evidence about your professional development — never about other people. Nothing you upload, forward, dictate or paste should identify anyone else. We scan incoming content for likely identifiers (names, NHS numbers, dates of birth, addresses) and warn you before anything is stored, but the responsibility for anonymising content remains yours. If we identify content that appears to contain personal information, we will flag it for your review and you should delete or edit it.
When you send evidence to your inbox, we pass its content to an AI provider (Anthropic or OpenAI) to extract titles, dates, CPD points and suggested categorisations, and to draft reflections. If you supply your own API key, your content is processed under your own agreement with that provider. Nothing an AI drafts becomes part of your portfolio until you approve it.
"Your drafted entry" means the appraisal entry our AI writes from your evidence — the title, dates, CPD details and reflection you review and approve. It is written without any names, NHS numbers or other identifying details, even if they appeared in what you uploaded. For most upload types, this drafted entry is the only thing we keep — the original recording, email or data is deleted once it has been read.
| You give us | What we do with it | Stored while you review? | Stored after you approve? |
|---|---|---|---|
| A photo or screenshot | We shrink it, convert it to a standard JPEG and remove all hidden data (including location) before saving anything | Yes — the cleaned copy, until you approve or bin it | Only if you tick "keep this file" — otherwise deleted the moment you approve |
| A PDF certificate | Small PDFs kept as-is; big scans are rebuilt as compact copies | Yes, until you approve or bin it | Only if you tick "keep this file" |
| A PowerPoint or Word document | We read the text and key images out of it | Yes, until you approve or bin it | Only if you tick "keep this file" |
| A spreadsheet (Excel/CSV) | We read the data, write your drafted entry (the AI analysis), then delete our copy of the data — the file itself is never saved | No — already gone once read | No — only your drafted entry remains |
| A voice note | We transcribe it and delete the recording immediately. The transcript is kept as your entry's own notes — yours to reread, edit or delete, like a note you typed | Your own words only, as your editable notes | The transcript stays on the entry as your notes until you delete it |
| A recorded lecture | It uploads in ~10-minute parts while you record. Each part's audio is deleted the moment it is transcribed; anything you trim off at the end is deleted without ever reaching the AI. The stitched transcript — with the moments you marked as important — is kept as your entry's own notes | The transcript and any notes you typed during the lecture, both editable | The transcript stays on the entry as your notes until you delete it |
| A forwarded email | We delete the original within seconds of it arriving, and delete its text as soon as it's been read and your entry drafted. Any note you typed yourself above the forward is kept as your entry's own notes | No — already gone once read (attachments follow their own rows above); only your own typed note survives, as your editable notes | No — only your drafted entry remains |
| A link | We read the page's text to write your drafted entry, then delete it; the page is never stored | No — already gone once read | No — only your drafted entry remains |
| Notes you type or paste ("Write a note") | These are your own words: AI distils them into gems (including any to-do actions you flagged), and the notes themselves are kept word-for-word on the entry so you can revisit them. The personal-information check runs on them like any typed text, and "remove personal info" scrubs identifiers from them on request | Yes — they're part of your entry | Yes, until you edit or delete them — they belong to your entry, not to a source file |
| Entries you combine (merge) | The original entries and their files are kept underneath the combined entry, exactly as they were — un-combining restores them. The personal-information check still applies before anything can be combined | — | Yes, hidden inside the combined entry. Deleting a combined entry permanently deletes everything inside it, including files |
| Anything you bin | — | — | Deleted immediately, including any files |
We automatically scan everything for personal information (like NHS numbers) and will stop you approving an item until you've removed it or confirmed it's safe. Files are never kept unless you explicitly choose to keep them — and you can switch to "never keep files" in Settings → Evidence, so CPD Dump stores nothing but your written entries.
Your personal dump address exists only to receive evidence from you. The raw email is deleted within seconds of arriving — we keep only what the table above describes. Do not forward emails containing personal information about others.
If you connect a calendar feed URL, we read event titles, times and organisers on a weekly schedule to suggest draft activities. Feed URLs are stored encrypted and are never shared. You can disconnect a feed at any time, and you can tell us to permanently ignore particular recurring events.
Your evidence is yours. You can export it, and you can delete individual items or your whole account at any time — deletion removes your evidence from our systems. Under UK GDPR you also have rights of access, rectification and portability; contact us at privacy@cpddump.com to exercise them or to complain (you may also complain to the ICO).