Skip to content

Terms of Use

The deal, in plain words: keep patients out of it, your data stays yours, and anonymized statistics make training better for everyone.

Last updated September 13, 2026 · version 2026-09-13 — the date this version took effect. This is the agreement you accept in the app. How your data is handled, field by field, is spelled out in the Privacy Policy.

The short version

Patients stay out of it

The case log records the kind of case, never whose. Patient details belong only in the encrypted private note and plan fields, nowhere else.

Your data makes Capnolog better

De-identified cases and app activity are used to run the app and improve it, including its study and progress tools.

Anonymized statistics may be shared

Cases from many trainees are combined into anonymized statistics, like average case counts, that may be shown to residency programs, medical students, and the public. Small groups are suppressed, and you are never named.

You stay in control

Nothing that identifies you goes to your program unless you explicitly choose to share it. Export or erase everything in Settings, anytime.

One free account links your devices

You'll need one free account to use Capnolog, and it links your devices and the browser extension. It holds an id, your training program, specialty, and class year — never your name, and never your cases, which stay on your phone. Logging and export are always free.

The ACGME extension acts only for you

It fills the ACGME Case Log form in your own account only when you ask, never presses Submit, and reads only your own records, your program's site and attending lists, and how the form is built, to keep your log accurate and autofill working. Never for statistics. Capnolog is independent of the ACGME.

The short version is a summary. The sections below are the agreement.

What changed

The plain-words summary of this revision — the same one the app shows when it asks you to accept again.

What changed on September 13, 2026

  • Disputes are resolved by individual arbitration. Section 24 now says that a dispute we cannot settle by email goes to binding arbitration under the American Arbitration Association's consumer rules, on an individual basis and not as a class action, with a small-claims carve-out for either side. You can opt out of arbitration by emailing us within 30 days of first accepting this version, and nothing else in the terms changes if you do.
  • Copyright and what is ours, stated fully. Section 17 is now a complete DMCA notice-and-counter-notice procedure with a named copyright agent. Section 15 says plainly what belongs to Chockstone Labs LLC: the apps, the site, the extension, the study content, the calculators and evidence summaries, and the de-identified and aggregated data and statistics derived from what users share. Your own entries still belong to you, and nothing about what the app collects changed.
  • Automated features and company changes, disclosed. Section 8 names the automated systems the app uses — on-device speech recognition and case parsing, the study scheduler, and the progress projections — and says they can be wrong and send nothing to an outside AI provider. Section 25 says that if the company or the Service is sold or merged, your data goes with it under the same Privacy Policy and you will be told.

What changed on September 8, 2026

  • Capnolog is a trade name of Chockstone Labs LLC, an Ohio limited liability company, which now operates the service. It is the same developer, now with a company name and a mailing address for legal notices. Nothing about how the Service works or how data is handled changed.
  • Form structure, so autofill keeps working: while the extension is paired it reads how the ACGME Case Log form is built, meaning its fields and the options the ACGME offers, never what you typed, and sends that structure to Capnolog so filling keeps matching the form when the ACGME changes it. Agreeing to these terms covers this; there is no separate prompt.
  • Programs can sign in, through the new Program Console. A named person at a program — a chief resident, program director, coordinator, or an attending the department designates — is invited individually and can publish the department's schedule and read the roster and OR board the department publishes. The console has no route to your case log: it cannot open your log, and it cannot pick you out of anonymized statistics.
  • An account is now required to use Capnolog. Section 3 used to say you could decline the ask and carry on; that is no longer how the app works. Signing in is part of setting it up, and one free account is what holds your program and the extras you have been given and carries them to a new phone or your Mac. Logging and export are still free, your cases still stay on your phone, and the account still holds an id, your program, specialty and class year — never your name.

What changed on August 22, 2026

  • Accounts: one free Capnolog account — Sign in with Apple or a personal email — now links your devices. Logging and export stay free forever, your cases stay on your phone, and the account holds an opaque id and your training program, never your name or your institutional email address. Delete it any time; your cases stay where they are.
  • Declining these terms: the app keeps working for logging and progress on your phone; sync, the extension, research sharing, and analytics pause until you accept.
  • Consent records: we keep a receipt of what you agreed to (or declined), when, and from which app, tied to your device — never your name.
  • Your choices, separated: accepting these terms is required to use the app. Case sync, research sharing, usage analytics, and crash reports each have their own switch in Settings, and you can log cases with every one of them off.
  • Who it is for: Capnolog is for medical students, residents, and fellows training in the United States, and the programs that train them. Outside the US it is not directed at you and we do not support it.
  • Medical students: Capnolog now works for medical students too — rotation logging, a season notebook, end-of-rotation wrap-ups, and an ERAS summary built from your own counts. The interviews, letters, and people you write down stay on your phone and in your encrypted iCloud backup; we cannot read them.
  • Program verification, for students: if you ask the residents at a program to confirm a rotation, the app sends the name you choose to show, the program and dates, and your counts — the one place Capnolog sends your name to our servers. Only residents at that program see it, it is deleted after 90 days, and you can take it back any time. A resident who confirms may leave a short evaluation; their name and year are never attached.
  • Invites, class groups, and ambassadors: an invite link tells us which link brought you in, never who you are. A student class group sends your school and class year, nothing else. Ambassadors and invited colleagues may receive free time on a paid tier as a thank-you; nothing is ever offered for an App Store review.
  • What we collect, in one place: the Privacy Policy now lists every piece of data we hold, how long we keep it, and how to delete all of it.
  • Cookies and tracking: capnolog.com sets no advertising or tracking cookies, and the apps do no cross-app tracking. The Privacy Policy says exactly what local storage we use and why.
  • Your privacy rights: new sections cover the rights you have wherever you live, including the EU, the UK, and US states with privacy laws.
  • Calculators and evidence summaries are study tools, not medical advice: they show their formulas and sources so you can check them, and your clinical judgment governs.
  • The ACGME extension: it works only in your own ACGME account, at your direction, and never presses Submit. You are responsible for your ACGME account and for following the ACGME's terms; the ACGME may act on accounts it believes break its rules.
  • What we read from the ACGME: only your own case records and your program's site and attending lists, only to keep your log accurate. Never for statistics or analytics — cases imported from ACGME are excluded from anonymized statistics.
  • What never leaves your browser: your ACGME password, cookies, or session. We may pause or turn off the extension at any time, including if the ACGME asks us to.

1. What this agreement covers

These Terms of Use are an agreement between you and Chockstone Labs LLC ("we", "us"). Capnolog is a trade name of Chockstone Labs LLC, an Ohio limited liability company, which operates the service. These terms cover the Capnolog iPhone, Android, and Mac apps, the Capnolog browser extension, capnolog.com, and everything else we provide around them (together, the "Service").

Who you are actually agreeing with, stated plainly: Chockstone Labs LLC, a limited liability company formed in Ohio, doing business under the trade name Capnolog. Legal notices can be mailed to Chockstone Labs LLC, 46 Shopping Plaza, PMB 5052, Chagrin Falls, OH 44022, USA. Written notice to us goes to support@capnolog.com for anything under these terms and privacy@capnolog.com for anything about privacy (section 26); the mailing address above works for both.

By downloading the app, tapping agree, or using any part of the Service, you accept these terms and acknowledge the Privacy Policy. If you do not agree, do not use the Service. If you got the app through Apple's App Store, Apple's standard Licensed Application End User License Agreement also applies; where the two conflict, these terms govern as between you and us. If you got it through Google Play, Google Play's Terms of Service also govern that download and any purchase you make through it; where they conflict, these terms govern as between you and us.

2. Who can use Capnolog

Capnolog is a professional tool for adults, built for one audience: medical students, residents, and fellows training in the United States, and the US programs that train them. You must be at least 18 years old to use it. A trainee who finishes training may keep using Capnolog for their own log — the requirements it is built around are the ones you trained under.

Outside the United States, the Service is not directed at you and we do not support it. We do not tailor it to another country's training requirements, we do not translate it, and we cannot tell you whether it fits the rules that govern your training. Using it anyway is not prohibited; if you do, these terms and the law of the United States apply to that use, and the Privacy Policy explains how we handle a request from someone outside the US.

You are responsible for your device, your iCloud account, and anyone you allow to use them.

3. Your Capnolog account

Using Capnolog requires one free Capnolog account, and the same account links every device you use. You sign in when you set the app up. Logging your cases and exporting them are free — the account is what the Service requires of you, not a payment — and everything that reaches our servers runs on it: recognising a second device or a new phone as yours, the browser extension, syncing between your own devices, the OR board, and anything a program shares with you. If your phone cannot reach us, because it has no signal or our sign-in provider is unavailable, the app keeps working and asks again when it can.

You sign in with Apple, or with a personal email address. Use a personal address rather than your institutional one; your hospital or university mailbox is not the right home for a personal logbook, and we do not want it. Sign-in is operated for us by Clerk, a US authentication provider acting as our processor, which holds the credential — the email address or Apple relay address you sign in with, and any name Apple chooses to share — while we receive an opaque user id and never see a password.

What the account holds is deliberately small, and this is the whole of it: an opaque account id; the ids of the devices you have linked to it; your training program, your specialty, and your class year; whether you hold a beta or early-access grant, which is an operational flag and not a fact about you; and, if you verified your program, the evidence of that verification. Where you verified by institution email that evidence is a one-way HMAC of the address and the email domain, never the address itself. We keep an audit record of the changes made to the account. We never store your name or your institutional email address; our sign-in provider Clerk holds the email or Apple relay address you sign in with. The account holds none of your cases: your case log stays on your phone, and the de-identified subset that syncs is keyed to your device identity rather than to your account — but we should be plain about what that is worth. Once a device is linked to your account, the link between the two is in our database, so anyone with access to both tables can associate that synced subset with your account. Keying it to the device keeps your account out of the sync path and limits what any one table shows; it is not a wall between the two, and we will not describe it as one. The Privacy Policy describes each of these and how long we keep them.

You are responsible for the sign-in method you use and for anyone who can reach it. Tell us if you believe someone else has access to your account. One person, one account: do not share an account, and do not create one for someone else.

Verifying your program is optional, and it is done outside sign-in — by a code sent to an institution email address (delivered for us by an email-delivery provider acting as our processor, which handles the address only to deliver the code), or by your appearance on a program roster we observe. Where we verify by institution email we keep a one-way HMAC of the address and the email domain, never the address itself. Once your program is verified it is locked to the account and stops being a field you can edit, because a verified program is a statement someone else may rely on; write to us if you move programs or we have it wrong.

Unlinking a device removes only that device's link to the account. The account, your other devices, and the cases on the unlinked device are untouched.

You may delete your account at any time from Settings. Deleting removes the account record — the account id, your training program, specialty and class year, and any beta grant — along with the linked device ids and the verification evidence, and it is idempotent — asking twice is not an error, and an account already deleted reports success. Deleting your account does not delete the cases on your phone: they are yours and they are not stored in the account. It also does not delete your consent receipts, which we retain for the reason given in the Changes section and in the Privacy Policy. We may suspend or delete an account under section 18.

4. Independent from the ACGME

Capnolog is an independent product. It is not affiliated with, endorsed by, or sponsored by the ACGME, the ABA, the AMA, Apple, your residency program, or any other organization; their names appear only to describe what the app works with. ACGME and all other trademarks belong to their owners.

ACGME® is a registered trademark of the Accreditation Council for Graduate Medical Education. We have no data-sharing arrangement, partnership, license, or other relationship with the ACGME, and we do not act on its behalf.

Nothing in Capnolog is provided, reviewed, certified, or approved by the ACGME: not the case categories, not the targets or forecasts, not the study material, and not the browser extension. Where Capnolog and the ACGME disagree, the ACGME is right.

5. Keep patient information out

Capnolog is not intended to receive patient identifiers, and its case log is de-identified by design: there is no field for a patient name, MRN, date of birth, or any other patient identifier. You agree not to enter patient-identifying information anywhere in the Service except the private note and plan fields designed for it, which stay encrypted on your device as the Privacy Policy describes.

You are responsible for using Capnolog in line with the law and with your hospital's and program's policies, including any rules your institution has about clinical information on personal devices. Those policies may impose stricter obligations than these terms do; where they do, they govern what you may put in the app. Capnolog is a personal logbook and study tool for your own education, not a medical record. We do not currently provide a business associate agreement, and we do not represent that using Capnolog satisfies your institution's compliance requirements — that determination is your institution's to make, not ours. Our operating model may change, and we will update these terms and the Privacy Policy if it does.

If you put patient-identifying information somewhere it does not belong, you are responsible for it and should delete it promptly.

6. Your data, and what you let us do with it

Everything you log belongs to you. You can export it or erase it at any time, and the Privacy Policy explains exactly what lives where. This section is the permission you give us to handle that data, and it is written to track the switches in the app: what you leave on is what we may do. Within that scope you grant us a worldwide, non-exclusive, royalty-free license to handle your entries.

First, and required by your acceptance of these terms, to operate the Service. That is the machinery the app cannot run without: the attestation that proves a real install, the consent receipts described in section 23, your entitlements, the app configuration the app fetches on launch, and your Capnolog account if you create one. None of it carries a case or anything about a patient.

Second, case sync — a choice, and one that is on by default. A de-identified subset of your case log, the same fields your CSV export carries plus whether each case has been filed, syncs through our servers so your devices agree with each other. The app discloses this once, the first time it is usable, and that notice carries the button that turns it off; the same switch lives in Settings → Data, backup & export, and turning it off in either place purges our copy. While it is off, the Log tab says so. The browser extension and cross-device tracking depend on sync; with it off, the app works on your device alone and you can still export.

Third, to improve the Service. We use the de-identified entries that reach our servers through the switches you leave on, and how the app is used, to debug, develop, and improve features — including the parsers that structure your cases and any study and learning features, current or future. What stays on your device is not used for this, because we never receive it.

Fourth, to build anonymized statistics — and these come only from the case facts shared while research sharing is on. Research sharing is its own switch in Settings; turning it off deletes what that install shared rather than merely stopping new sharing. While it is on, we may combine those facts with other users' into aggregated statistics, such as average case counts, case mix, pacing, and study activity, and we may analyze, display, publish, and share them with third parties, including residency and fellowship programs, medical students and residency applicants, researchers, and the public.

Fifth, usage analytics and crash reports. Each has its own switch, on the same Settings screen, and each can be turned off on its own. What they carry is listed in the Privacy Policy: which features were used, a random identifier the app generates for itself, your training year, your program, and your app and OS version — never a case, never your name, never anything about a patient.

Sixth, to personalize, which happens on your device. Your own case history and study activity tailor what the app shows you, such as progress projections and suggested study material, and that work is done on the phone.

What this adds up to, said plainly: you can log cases and export them with every optional switch off. Accepting these terms is required to use the Service. Case sync, research sharing, usage analytics, and crash reports are not, and each is a separate decision you can change in Settings at any time. Declining a new version of these terms puts the app in the limited mode described in section 23, which pauses all of them at once.

About the word anonymized. Before anything is published we apply safeguards designed to reduce the risk of re-identification: aggregation, suppression of small groups, and removal of direct identifiers. The public statistics we publish today are withheld entirely unless at least 25 trainees stand behind them, nothing about a single program is shown until a minimum number of that program's trainees have shared, and a person reviews a report before it is released. No de-identification method can guarantee zero risk in every circumstance, and we will not tell you one does.

Three things this license deliberately does not cover. Your private notes and plans are end-to-end encrypted; we cannot read them, and they are excluded from everything above. Nothing that identifies you is shared with your program or anyone else unless you separately and explicitly choose to share it, and the app shows you exactly what it is about to send when you do; today the one such feature is a medical student's program-verification request (section 10). And we do not sell your personal information.

A fourth exclusion, specific to the ACGME. Cases imported from your ACGME record — the history import the browser extension runs at your request — are used only to keep your Capnolog log accurate: matching them against what you already logged, preventing duplicates, and setting your starting counts. They are excluded from the anonymized-statistics license in this section. The statistics we build, publish, and share come only from cases you logged in Capnolog, never from what we read out of the ACGME.

Anonymized, aggregated statistics that no longer identify you are not personal data, and they may be retained and continue to be used after you delete your data or stop using the Service; a published average cannot be unpublished.

7. ACGME submissions and the browser extension

The official ACGME Case Log System is the system of record for your training. Capnolog is a personal tool that helps you capture cases and file them; it does not replace the official system, and your program and the ACGME rely on what you submit there, not on what Capnolog shows.

The extension acts only for you. It fills the ACGME Case Log form in your own ACGME account, in your own browser, at your direction, and only when you ask it to. It never presses Submit. You review every entry and submit it yourself, and you are responsible for the accuracy of everything you file. You agree to use the extension only on your own account.

What it reads is limited on purpose: your own case records, and the site and attending lists your program publishes on the form so a filled field can match the exact option the ACGME expects. It reads them only to keep your log accurate, never to build statistics or analytics. Your ACGME username, password, cookies, and session never leave your browser and are never sent to us — we cannot sign in as you, and we never hold your ACGME credentials.

It also reads how the form itself is built: the fields it shows and the options the ACGME offers, never the values you typed. That structure is sent to Capnolog so the extension keeps matching the form when the ACGME changes it. Agreeing to these terms covers this; the extension does not ask separately.

The ACGME's own terms of use restrict automated access to its systems. You use the extension on your own account and at your own responsibility, and the ACGME may take action on an account it believes violates its rules, including suspending or removing access. Capnolog cannot prevent that and is not responsible for it. If you are unsure whether the extension fits the rules that govern your access, do not use it — enter your cases by hand.

The extension is not approved, authorized, or endorsed by the ACGME. We built it, we maintain it, and we have no arrangement with them about it (section 4).

Websites we do not control change without warning. We may pause, limit, or discontinue the extension at any time, including if the ACGME asks us to, if its site changes, or if continuing would create problems for you or for us. We can do that remotely and quickly: the extension checks a configuration we control roughly once an hour, so a pause we publish reaches every install within about that long, whether or not anyone updates. A pause stops the extension from acting; it never deletes or alters your data, and it lifts on its own when the reason for it is gone. When the extension is unavailable you can always export your log and enter cases by hand.

8. Study tools, calculators, and evidence summaries are educational, not advice

This section covers everything Capnolog shows you that is not simply your own logged data: progress tracking, targets, and forecasts; the study and question features; the clinical calculators; and the evidence summaries and landmark-paper library. All of it is educational. It is built on the numbers you enter and on published requirements and published research that change over time, and it is provided for planning and studying, not as professional, legal, or medical advice.

We do not guarantee that Capnolog's counts match the official system, that a target reflects your program's current requirements, or that any outcome, such as passing an exam or graduating, will follow from using the app. Verify anything that matters against official sources; where a requirement conflicts with what Capnolog shows, the requirement wins.

The calculators compute published formulas from the numbers you type. Each one shows the formula it used and cites the source it came from, so you can check the arithmetic yourself — that is why they are shown. A calculator does not know your patient. It cannot see the chart, the monitor, or the room, and it has no way to know whether the number you typed is the right number. What it returns is not a diagnosis, not a prescription, and not a substitute for your clinical judgment, your institution's protocols, or a drug label.

The evidence summaries are our own plain-English descriptions of published research, each with a link to the source. A summary is a pointer to a paper, never a replacement for one: read the paper before you rely on it. Populations, doses, and endpoints matter, we can be wrong about which of them matter to you, and the evidence itself changes.

None of this is intended to diagnose, treat, cure, or prevent any disease, and Capnolog is not a medical device. Nothing in the study content, and nothing a calculator returns, is guidance for treating a patient.

You are the licensed clinician, and that responsibility cannot be moved onto a tool. Before a number touches a patient, verify it against a primary source.

Automated systems, named. Parts of the Service are automated: speech recognition and the parser that turns what you say or type into a structured case both run on your device; the study scheduler decides what to show you next from your own activity; and the progress projections are arithmetic over your counts and published requirements. None of this sends your words, your cases, or your notes to an outside artificial-intelligence provider — as of this version, no such provider is in the path, and the Privacy Policy lists every company that is. Automated output can be wrong, incomplete, or out of date, and it carries no clinical judgment: review every parsed case before you save it, and treat a projection or a study suggestion as a planning aid, not a determination. If we ever add an automated feature that sends your data to a third party to process, we will name that provider in the Privacy Policy and, where the change is material, ask you to agree again under section 23.

9. Free tier, subscriptions, and purchases

The core of Capnolog is free. Some features require a paid subscription or purchase, bought as an in-app purchase — through Apple's App Store on iPhone, and through Google Play on Android — and billed to the Apple or Google account you bought it with. Subscriptions renew automatically until you cancel, in your App Store settings or in your Google Play subscriptions, at least 24 hours before the end of the current period; Apple and Google each handle billing and refunds for their own store, under their own terms.

Prices and what is included in each tier can change; if a change materially reduces what you already paid for, we will say so before it takes effect. Beta features are previews and may change or end without notice.

Features that depend on a website we do not control — the browser extension above all — may be changed, moved between tiers, or withdrawn as described in section 7, and we will honor the refund policies of the store you bought through — Apple's or Google's — where that affects a period you already paid for.

Free time on a paid tier that we grant through an invite or the ambassador program (section 11) is a gift from us, not a purchase: neither Apple nor Google is involved in it, it has no cash value, and there is nothing to refund because nothing was paid.

10. Medical students: the notebook, program verification, and class groups

Capnolog also works for medical students: rotation logging, a season notebook for the interviews and the people you meet, end-of-rotation wrap-ups, a rank-list draft, and an ERAS summary built from your own counts. Everything in this section is optional, and a student who only logs cases is covered by the rest of these terms. The parts that mention residents apply to a resident who answers a student's request.

The notebook is yours and stays on your device and in your end-to-end-encrypted iCloud backup. It can hold other people's names — interviewers, attendings, residents, letter writers — because that is what a notebook is for; we cannot read it, and it is excluded from everything in section 6. You are responsible for what you write about other people: keep it factual, keep patients out of it, and remember that an exported notebook or ERAS summary is a file you control and can hand to anyone.

You can ask the residents at a program to confirm that you rotated there. When you send that request, the app sends to our servers, and shows to residents at that program who use Capnolog, the name you choose to display, the program and dates you entered, your counts — cases, procedures, clinic days, call shifts, and firsts — and, if you add them, your medical school, class year, and a short note. This is the one place the app sends your name to our servers. It happens only when you tap send, the app shows you exactly what it is about to send before you do, and nothing from your case log travels with it. The request is deleted after 90 days, and you can take it back earlier from Settings, which deletes it along with every answer to it. What you send must be yours and true: a request that names a program you did not rotate at, or counts you did not earn, misrepresents you to the residents you are asking and is a misuse of the Service.

A resident who sees your request can answer yes or no. One who answers yes may also leave a short evaluation — a few rating scales, a handful of preset words, and one line of text — which the app shows to you as coming from a resident at that program, never with the resident's name or year. An evaluation is that resident's own opinion, written by a colleague and not by us; we do not endorse, verify, or guarantee it, and we do not promise that anyone will answer. If you are the resident: answer only about a student you actually worked with, keep an evaluation professional and free of anything that identifies a patient or a third person, and write nothing you would not say to the student directly. Every evaluation is screened for patient-shaped details and abusive terms before it is accepted, you can edit yours for 24 hours and it is frozen after that, and it is deleted when the student deletes the request. A student may keep a copy of an evaluation in their own records and chooses whether it appears in their ERAS summary.

Students can also join a class group for their school and class year. Joining sends your school and class year, nothing else; what the group shows is how many classmates have joined, never who. A class invite link carries a random code, not your identity, and whoever created it can revoke it.

None of this is an official record. A confirmation is a colleague's word that you were there, not a transcript; an ERAS summary is a list of your own counts, assembled on your phone from your own log; and Capnolog is not affiliated with ERAS, the AAMC, the NRMP, any medical school, or any residency program, and submits nothing to any of them. What you put in an application, and what you say about yourself in it, is your responsibility.

11. Invites and the ambassador program

Capnolog spreads by word of mouth, and the app helps with that: any user can share an invite link, and a resident can sign up as an ambassador for their program. An invite link carries a random code that tells us which link brought a new user in and which program it belongs to. It carries nothing about the person who opens it, and the page it opens shows at most a rough sense of how many residents at that program already use Capnolog — never an exact number and never a name. If you install through someone's link, we record that your device redeemed it, so the person who shared it can be credited; we do not tell them who you are.

An ambassador tells us their program and class year and picks, from a short list, why they are doing it. Ambassadors speak for themselves: they are not our employees or agents, they cannot make promises on our behalf, and nothing an ambassador says makes Capnolog an official or program-endorsed tool. We may end an ambassadorship at any time; write to us if you want to step down.

We may thank ambassadors and invited colleagues with free time on a paid tier — for example, a paid tier until the end of the academic year for an ambassador whose program takes Capnolog up, or an extended trial for someone who installs through an invite. These are gifts, not wages and not a purchase: they are granted through Capnolog's own entitlement system, have no cash value, cannot be transferred or exchanged, and end on the date set when they are granted. What earns a grant, and what a grant is worth, can change; a grant you already hold keeps its end date. Whether a program has taken Capnolog up is measured by us from de-identified usage — whether colleagues who installed keep logging — and we will explain the count if you ask. Nobody is paid per install, and we never offer anything in exchange for an App Store or Google Play review or rating.

If we ever quote an ambassador publicly, on capnolog.com or anywhere else, we will ask first, show the exact words we intend to publish, label them as an ambassador's words, and stop using them when asked.

12. Programs and program data

Programs appear throughout Capnolog, so it is worth saying exactly what a program is and is not here. A program can sign in, through the Program Console. A named person at the program — a chief resident, a program director, a coordinator, or an attending the department designates — is invited and confirmed individually, agrees to these terms in their own name for that program, and can be revoked at any time.

A program shows up in three roles. First, as a data contributor: its roster and its OR board, as the department itself publishes them. Those carry staff names — attendings, residents, the rooms they are assigned to — and never patients, and we handle them separately from the patient-free case data trainees log. Second, through the Program Console, as the author of its own schedules and the reader of its own department material and of program-level totals: what the console shows is the department's material and aggregate counts, and it has no route to an individual case log. Third, as a possible recipient of anonymized statistics, and nothing beyond that.

What that means if you are a student, a resident, or a fellow. Your program cannot open your log, cannot see your individual cases, and cannot pick you out of aggregate reporting, which is built under the safeguards described in section 6. A program gains no ownership of, and no license to, the logs its trainees create; those belong to the person who made them, and they stay that way after training ends.

If we ever build identifiable reporting to programs — a named resident's counts shown to their program — it will be a separate feature with its own consent at the moment of use, and these terms will be updated before it ships. Today the only place the app sends your name anywhere off your device is a medical student's own program-verification request (section 10), which you send yourself and can take back.

13. Sharing files with colleagues

Capnolog lets you share templates and notes with colleagues as a file. Share only what you have the right to share, and never include patient-identifying information in shared content. What a colleague sends you is theirs, not ours; review it before importing. The same goes for a notebook export or an ERAS summary: it is your file, and where it goes is your decision.

14. Acceptable use

You agree not to misuse the Service. That includes: breaking the law; interfering with or overloading our systems; probing, scraping, or harvesting data from the Service by automated means; reverse engineering the apps except where the law says we cannot forbid it; misrepresenting Capnolog output as an official record; using the Service to violate someone else's privacy; sending a program-verification request, an evaluation, or an invite that is false, misleading, or abusive; and reselling the Service. We may throttle or block activity that threatens the Service or other users.

15. Intellectual property

The Service belongs to Chockstone Labs LLC or its licensors and is protected by copyright, trademark, trade-secret, and other law. That includes the apps, the browser extension, capnolog.com, the Program Console, and their software, design, structure, and look; the content we authored, including the study material, the questions and explanations, the calculators and their presentation, the evidence summaries, the specialty and program directories we compiled, and the targets and pacing models; and the name Capnolog, the logo, and the marks. Nothing in these terms transfers any of it to you, and nothing you do in the app — logging, exporting, sharing, or paying — gives you an interest in it.

The data we derive is ours too. The de-identified case data that reaches our servers through the switches in section 6, the aggregated and anonymized statistics we build from it, the corrections and usage patterns that train and tune the parsers and study tools, and every dataset, model, report, and improvement derived from them belong to us, and we may use and retain them as section 6 describes, including after you delete your data or stop using the Service. What stays yours is what you logged: your own entries, notes, plans, and exports are your data (section 6), you keep every right in them, and the license you grant us there is the whole of what we take.

We grant you a personal, non-exclusive, non-transferable, revocable license to install and use the apps and the extension, on devices you own or control, for their intended purpose and in line with these terms. You may not copy, modify, distribute, sell, lease, sublicense, or create derivative works from any part of the Service, remove any proprietary notice, or use our names or marks to suggest an affiliation or endorsement we have not given in writing. If you send us feedback or ideas, we can use them without obligation to you.

16. What you send us

Capnolog gives you a few ways to send something our way: suggesting a topic or a paper for the evidence library, telling us a summary or a number is wrong so we can correct it, sending feedback, and handing your templates and notes to a colleague. We call all of that your submissions.

Two rules matter most. Keep patient information out of anything you send — a suggestion, a correction, a bug report, or a file for a colleague is never the place for it. And do not send us text you do not have the right to send: do not paste the full text of a copyrighted article, book, or question bank. A link and your own words are what we want, and they are more useful to us than a copy would be.

You keep ownership of what you send. By sending it, you grant us a worldwide, non-exclusive, royalty-free license to use, store, adapt, edit, translate, and publish it within the Service, including in the study content and evidence summaries other trainees read.

We are under no obligation to publish anything. We may edit a submission, decline it, or take it down later. A person reads every submission before anything from it appears in the Service — nothing you send is published automatically.

Program-verification requests, residents' evaluations, and class groups are not submissions in this sense; section 10 covers them. They are shown only to the people they are addressed to, and we never publish them.

Everything you send or share is user content, and you are responsible for it. You represent that you own it or have the right to send it, that it contains no patient-identifying information, and that it does not infringe anyone's copyright, privacy, or other rights or break any law. We do not endorse user content, we are not obliged to monitor it, and a colleague's file, a resident's evaluation, or a submission we publish is that person's statement and not ours. We may remove, edit, decline, or refuse to carry any user content at any time, with or without notice, if we believe it violates these terms, the law, or someone's rights, or for any other reason, and we are not liable for doing so.

18. Ending things

You can stop using Capnolog at any time: export your data if you want a copy, erase all data in Settings, have our copy of your de-identified case log purged (turn case sync off in Settings, or write to us), delete your account (section 3), and delete the app. We may suspend or end your access to the Service if you violate these terms or if we discontinue the Service, and where practical we will give you notice so you can export your data first. Sections that by their nature should survive, including the anonymized-statistics part of section 6, the ownership paragraphs of section 15, and sections 19 through 25 (the arbitration agreement in section 24 included), survive.

Declining an updated version of these terms is not termination. The app keeps working in the limited mode described in section 23, your data stays on your device, and you can export it or erase it at any time.

19. Disclaimers

The Service is provided as is and as available, without warranties of any kind, express or implied, including merchantability, fitness for a particular purpose, and non-infringement. We cannot promise the Service will be uninterrupted, error-free, or lossless, and we are not responsible for what third parties, including Apple, iCloud, and the ACGME website, do or change.

Durability is a design goal, and we describe it as one. Where Capnolog or capnolog.com says a lost phone is not a lost log, or that your data survives a lost phone, that describes how the app is built — an encrypted database on the device plus, on iPhone, an end-to-end-encrypted backup in your own iCloud or, on Android, an encrypted backup file in a folder you choose — and not a warranty that it will always work. The backup depends on your iCloud account and on Apple, or on the folder you chose and whatever holds it, all outside our control; a restore can be incomplete when the backup location is unavailable, when it has no space, or when the most recent changes had not yet been backed up.

Keep your own exports of anything you cannot afford to lose. Some jurisdictions do not allow certain warranty disclaimers, so parts of this section may not apply to you.

20. Limitation of liability

To the fullest extent the law allows, we will not be liable for indirect, incidental, special, consequential, or punitive damages, or for lost data, lost profits, or lost opportunities, arising out of or relating to the Service. Our total liability for all claims combined is capped at the greater of fifty US dollars or the amount you paid us in the twelve months before the claim. Nothing in these terms limits liability that the law does not allow to be limited.

21. Indemnification

You will indemnify, defend, and hold harmless Chockstone Labs LLC and its members, officers, employees, contractors, and agents from third-party claims, and from the damages, losses, and reasonable attorney's fees that come with them, to the extent they arise from: your material breach of these terms; your fraud or willful misconduct; your violation of any law or of any third party's rights, including a patient's privacy rights or another person's intellectual-property rights; your user content and submissions (sections 13 and 16); or your use of the browser extension on the ACGME's systems. Concretely: entering patient-identifying information where these terms say it does not belong, using the browser extension on an account that is not yours, sending a program-verification request that misrepresents where you trained, or sharing a file that infringes someone's copyright.

Two limits on that, deliberately. This does not cover anything caused by our own negligence, our own security failures, or our own misconduct — those stay ours. And it does not enlarge any limit on liability: nothing in this section raises or works around the cap in section 20.

We will tell you promptly about a claim we want covered, we will not settle one without your agreement, and you may take over its defense with counsel of your choosing.

22. Apple App Store and Google Play terms

Because the apps are distributed through Apple's App Store: this agreement is between you and us, not Apple, and Apple is not responsible for the Service or its content. Apple has no obligation to provide maintenance or support for the app. If the app fails to conform to an applicable warranty, you may notify Apple and Apple will refund the purchase price; to the maximum extent permitted by law, Apple has no other warranty obligation. Apple is not responsible for addressing any claims relating to the app, including product liability claims, regulatory claims, and consumer-protection claims, or for third-party claims that the app infringes intellectual-property rights.

You represent that you are not located in a country subject to a US government embargo and are not on any US government list of prohibited or restricted parties. Apple and its subsidiaries are third-party beneficiaries of these terms and may enforce them against you.

And because the Android app is distributed through Google Play: this agreement is likewise between you and us, not Google. Google is not a party to it, is not responsible for the Service or its content, and has no obligation to provide maintenance, support, or any warranty for the app. Anything you buy through Google Play is subject to Google Play's own terms and refund policy, and Google — not us — handles that billing.

23. Changes to these terms

We may update these terms as the Service evolves. For material changes, we will tell you in the app and ask you to agree again before you continue; for minor changes, the updated terms take effect when posted here, and continued use means acceptance. What changed in the current version is summarized at the top of this page. The version in force and the date it took effect are shown at the top of this page and in the app under Settings → About.

If you decline an updated version, the app keeps working for what it does on your own device: logging cases, your plans and notes, progress, and study. The features that reach the network pause until you accept — de-identified case sync, the browser extension, sharing for research, and usage analytics. This is what we call limited mode. Your iCloud Backup is never paused by a declined version, because it runs between your own devices and your own iCloud and needs nothing from us. You can accept the new terms later in Settings, and everything that paused resumes.

Consent records. Each time you accept or decline, we write one append-only receipt: the version of these terms, the decision, the time, and whether it came from the app or the browser extension. The receipt is tied to your device identity — the same de-identified identity the case sync uses — and never to your name. It exists for one reason: so that both of us can prove what you agreed to, and when. Receipts are never used for statistics or advertising, and we keep them for as long as we need to show the history of your consent.

24. Governing law and disputes

Governing law. These terms, and any dispute between you and us about them or the Service, are governed by the laws of the State of Ohio and the federal law of the United States, without regard to conflict-of-law rules. The Federal Arbitration Act governs the arbitration agreement below.

Talk to us first. Before either of us starts arbitration or a lawsuit, we agree to try to resolve the dispute informally: you email support@capnolog.com (or write to the mailing address in section 26) describing the problem and what you want, we do the same to the email or address we have for you, and both of us then have 30 days to work it out. Most problems are fixable in one conversation. Neither of us may file until those 30 days have passed.

Binding individual arbitration. If we cannot settle it, you and we agree that any dispute, claim, or controversy arising out of or relating to these terms, the Privacy Policy, or the Service — including whether a claim is subject to arbitration, and including claims that arose before you accepted this version — will be resolved by binding arbitration rather than in court, except as the next paragraph says. The arbitration is administered by the American Arbitration Association (AAA) under its Consumer Arbitration Rules in force when the claim is filed, before a single arbitrator. You can read those rules and file a claim at adr.org. The arbitrator's decision is final and binding, may be entered as a judgment in any court with jurisdiction, and the arbitrator may award any relief a court could award to you individually. Filing and arbitrator fees are set by the AAA's consumer fee schedule; if the arbitrator finds your claim was not frivolous, we will reimburse the filing fee you paid. The arbitration takes place in the county where you live, by video, by telephone, or on the papers if you prefer, or anywhere else you and we agree.

What stays out of arbitration. Either of us may bring an individual claim in small-claims court if it qualifies there. Either of us may seek an injunction or other equitable relief in court to protect intellectual-property rights or to stop unauthorized use of the Service. Nothing here prevents you from bringing a matter to a federal, state, or local agency, and nothing here waives a right that the law does not allow to be waived. Any claim that is not arbitrated, and any action to enforce an arbitration award, is brought in the state or federal courts located in Ohio, whose jurisdiction you and we consent to.

No class actions. You and we agree to bring claims only in an individual capacity, not as a plaintiff or class member in any purported class, collective, consolidated, or representative proceeding, and the arbitrator may not consolidate claims of more than one person or preside over any form of class or representative proceeding. If a court decides that this paragraph cannot be enforced for a particular claim, then that claim — and only that claim — proceeds in court rather than in arbitration, and the rest of this section stays in force. If 25 or more similar claims are filed against us by or with the help of the same law firm or group, they will be batched and heard in groups of no more than 25, one arbitrator per batch, with the AAA's rules for coordinated proceedings applied where they exist; any statute of limitations is paused while a claim waits for its batch.

Your right to opt out. Arbitration is not a condition of using Capnolog. You can reject this arbitration agreement by emailing support@capnolog.com from the address on your account, or writing to the mailing address in section 26, with the subject line "Arbitration opt-out", your Capnolog account email, and a statement that you opt out, within 30 days of the first time you accept a version of these terms that contains it. If you opt out, the rest of these terms — including the governing-law and Ohio-courts paragraphs above — still apply, and we will not treat you differently for it. Opting out of a later version is not needed once you have opted out.

Changes to this section. If we change this arbitration agreement after you accept it, you may reject the change by emailing us within 30 days of the change taking effect, in which case the version you last accepted continues to apply to disputes between you and us. Whether or not you continue to use the Service, this section survives the end of our relationship (section 18).

25. General terms

These terms, together with the Privacy Policy, are the whole agreement between you and us about the Service, and they replace anything either of us said about it beforehand.

If a court finds part of these terms unenforceable, that part is narrowed to what the law allows, or trimmed if it cannot be, and everything else stays in force. If we do not enforce something right away, we have not given it up — we can still enforce it later.

You may not assign these terms or transfer your rights under them. We may assign them to a successor, such as someone who acquires Chockstone Labs LLC, the Capnolog product, or substantially all of its assets, in a merger, acquisition, reorganization, sale of assets, or similar transaction, and the agreement carries over unchanged. In that event the data we hold about you — the account, the consent receipts, the de-identified case data you left switched on, and whatever else the Privacy Policy lists — may be transferred to the successor as part of the transaction, and the successor may use it only under this agreement and the Privacy Policy in force when the transfer happens; we will tell you in the app or by email before or promptly after such a transfer, and if the successor wants to change how your data is used it must ask you under section 23.

Notices. We reach you in the app, and by email if you have given us one. You reach us at support@capnolog.com, which is the address for anything these terms ask you to send us. If you would rather send something on paper, or the law requires it, mail it to Chockstone Labs LLC, 46 Shopping Plaza, PMB 5052, Chagrin Falls, OH 44022, USA.

Neither of us is responsible for a failure caused by something outside our reasonable control: an outage at a provider we depend on, a network or hosting failure, a change or outage at a website we do not run, a natural disaster, or an act of government.

Section headings are there to help you find things. They do not change what a section says.

26. Contact

Questions about these terms: support@capnolog.com. Questions about privacy: privacy@capnolog.com.

By mail: Chockstone Labs LLC, 46 Shopping Plaza, PMB 5052, Chagrin Falls, OH 44022, USA.

The line the whole agreement rests on: Capnolog records the kind of case, never whose case.