1. Overview
Pocket Gull ("we," "our," or "us") is a real-time medical Care Plan Strategy and AI consultation co-pilot platform engineered with Privacy by Design principles. This Privacy Policy explains how we collect, process, isolate, and safeguard data when you interact with our application at pocketgull.app.
By using Pocket Gull, you accept the clinical privacy practices described in this policy. If you do not agree, please do not use the application.
2. Data We Collect
We adhere to strict data minimization. The table below details all information categories processed by Pocket Gull:
| Category | Details | Storage Boundary |
|---|---|---|
| Account Credentials | Name, email address (via Google Sign-In) | Ephemeral session token in memory |
| Patient Clinical Records | Vitals, symptoms, laboratory biomarkers, clinical history | Local browser storage (AES-256 encrypted) |
| Biometric Streams | Resting heart rate, SpO₂, sleep efficiency summaries | In-memory only via Google Health API |
| Technical Telemetry | Browser engine type, anonymized IP hash (SHA-256) | Server runtime logs (90-day retention) |
3. Health Biometrics (Google Health API)
When you choose to connect your Google Health or Fitbit account, Pocket Gull requests read-only authorization via Google OAuth 2.0 PKCE for the following restricted scopes:
- Resting Heart Rate Summary — daily average bpm (last 30 days)
- Blood Oxygen Saturation (SpO₂) — daily average % (last 30 days)
- Sleep Architecture — sleep duration and sleep stage breakdown (last 30 days)
This integration strictly complies with the Google Health API Developer and User Data Policy.
4. How We Use Your Data
We use processed data exclusively for the following functional purposes:
- Rendering real-time biometric trend graphs and multi-lens radar summaries
- Synthesizing integrative care plan recommendations via Google Gemini models
- Authenticating user sessions and safeguarding API client connections
- Sanitizing outgoing clinical prompts using DOMPurify for HIPAA Safe Harbor compliance
We NEVER: sell user data, monetize health metrics, build advertising profiles, or share personal information with data brokers.
5. AI Processing & Model Disclosures
Clinical intelligence in Pocket Gull is powered by Google Gemini foundation models. When you trigger an AI consultation or care strategy synthesis:
- De-identified patient vitals, symptoms, and selected analysis lenses are transmitted via TLS 1.3 to Google Gemini API endpoints.
- Transmitted data is processed ephemerally under Google's Gemini API Enterprise Terms. API data is not retained by Google to train baseline models.
- AI responses cached locally on your device are protected using Web Crypto AES-GCM encryption.
7. Data Retention
- Patient State & Notes: Retained locally on your physical device until manually purged or cleared via browser storage settings.
- Google Health OAuth Tokens: Ephemeral in RAM — destroyed immediately upon session closure.
- Security Logs: Hashed audit logs retained for 90 days for breach detection and security compliance.
8. Security Safeguards
Pocket Gull implements enterprise-grade technical and organizational safeguards:
- End-to-End TLS 1.3 Encryption: All transit is strictly encrypted over HTTPS.
- AES-256 Browser Storage Encryption: Local patient records are encrypted at rest.
- DOMPurify XSS Shield: All rendered inputs and markdown outputs undergo DOMPurify sanitization.
- OAuth 2.0 with PKCE: Prevents authorization code interception and token leakage.
9. Your Rights & Data Control
You maintain complete control over your health data:
- Instant Data Erasure: Click "Disconnect & Erase Data" in the app header to instantly wipe all cached biometric tokens and local patient state.
- FHIR R4 Bundle Export: Export your complete clinical data record at any time in standardized FHIR R4 JSON or PDF formats.
- Access & Inquiries: Contact our Data Protection Officer at dpo@pocketgull.app for data inquiries.
10. Children's Privacy
Pocket Gull is intended for licensed clinicians, healthcare providers, and adults aged 18 and older. We do not knowingly collect information from children under 18.
11. Policy Changes
We may update this Privacy Policy to reflect evolving regulatory frameworks or platform features. Revisions will be posted here with an updated effective date.
12. Contact Data Protection Officer
For privacy inquiries, audit requests, or security disclosures:
- Data Protection Officer: dpo@pocketgull.app
- Security Disclosures: privacy@pocketgull.app
- Official Website: pocketgull.app