Pocket Gull Understory Intelligence
Launch App →
HIPAA Safe Harbor & Privacy By Design

Privacy Policy

Effective date: August 1, 2026  ·  Last updated: August 1, 2026

1. Overview

Pocket Gull is a real-time medical Care Plan Strategy and AI consultation co-pilot platform operated by PocketGull LLC, an Oregon limited liability company based in Portland, Oregon ("we," "our," or "us"). Engineered with Privacy by Design principles, this Privacy Policy explains how we collect, process, isolate, and safeguard data when you interact with our application at pocketgull.app.

By using Pocket Gull, you accept the clinical privacy practices described in this policy. If you do not agree, please do not use the application.

๐Ÿ”’ Local-First Architectural Guarantee: Pocket Gull operates on a local-first paradigm. Patient health information (PHI), clinical notes, and active care plans reside strictly inside your browser's encrypted storage. We do not persist patient records to external cloud databases.
โš•๏ธ Research & Clinical Decision-Support Notice: Pocket Gull is designed to assist licensed clinicians and researchers. It is not an FDA-cleared diagnostic medical device. All AI insights must be reviewed and verified by a licensed medical professional before clinical execution.

2. Data We Collect

We adhere to strict data minimization. The table below details all information categories processed by Pocket Gull:

Category Details Storage Boundary
Account Credentials Name, email address (via Google Sign-In) Ephemeral session token in memory
Patient Clinical Records Vitals, symptoms, laboratory biomarkers, clinical history Local browser storage (AES-256 encrypted)
Biometric Streams Resting heart rate, SpOโ‚‚, sleep efficiency summaries In-memory only via Google Health API
Technical Telemetry Browser engine type, anonymized IP hash (SHA-256) Server runtime logs (90-day retention)

3. Health Biometrics (Google Health API)

When you choose to connect your Google Health or Fitbit account, Pocket Gull requests read-only authorization via Google OAuth 2.0 PKCE for the following restricted scopes:

  • Resting Heart Rate Summary โ€” daily average bpm (last 30 days)
  • Blood Oxygen Saturation (SpOโ‚‚) โ€” daily average % (last 30 days)
  • Sleep Architecture โ€” sleep duration and sleep stage breakdown (last 30 days)
Ephemeral Transit Guarantee: Biometric data fetched from Google Health API is held strictly in volatile server RAM for the active consult session. It is never written to disk, database, or persistent storage, and access tokens are immediately purged upon session disconnect or server restart.

This integration strictly complies with the Google Health API Developer and User Data Policy.

5. How We Use Your Data

We use processed data exclusively for authorized functional clinical purposes:

  • Rendering real-time biometric trend graphs and multi-lens radar summaries.
  • Synthesizing integrative care plan recommendations via Google Gemini models under explicit user initiation.
  • Authenticating user sessions and safeguarding API client connections.
  • Sanitizing outgoing clinical prompts using DOMPurify for HIPAA Safe Harbor ยง164.514 compliance.

We NEVER: sell user data, monetize health metrics, build advertising profiles, or share personal information with data brokers or insurance underwriters.

6. AI Processing & Zero-Data Retention (ZDR)

Clinical intelligence in Pocket Gull is powered by Google Gemini foundation models. When you trigger an AI consultation or care strategy synthesis:

  • 18-Identifier Safe Harbor Scrubbing: Outgoing payloads are stripped of all 18 direct and indirect HIPAA identifiers before transmission.
  • Zero-Data-Retention (ZDR) Attestation: Outgoing requests transmit X-ZDR-Attestation: enabled headers. Transmitted data is processed ephemerally under Google's Gemini API Enterprise Terms. User data is never retained by Google to train foundational base model weights.
  • Encrypted Client Caching: AI responses cached locally on your device are protected using Web Crypto AES-GCM encryption.

7. Data Sharing & Third-Party Services

Pocket Gull does not sell or trade user data. Ephemeral data transit occurs only with essential, cryptographically audited infrastructure providers:

  • Google Cloud Platform (Cloud Run): Secure container hosting and serverless execution under enterprise SOC2 / FedRAMP / HIPAA Business Associate Agreements (BAA).
  • Google Gemini API: Large language model inference for real-time clinical co-pilot insights.

8. Cryptographic Storage Wiping & Retention

To prevent cold-memory forensic data extraction, Pocket Gull implements active cryptographic overwriting:

  • CSPRNG Memory Overwrite: When you click "1-Click State Purge" or "Disconnect & Erase Data", all client-side storage keys are overwritten with cryptographically secure pseudorandom noise (crypto.getRandomValues) before unlinking and deleting.
  • OAuth Tokens: Held strictly in volatile RAM and destroyed immediately upon session disconnect.
  • Hashed Audit Logs: Cryptographic SHA-256 event digests retained for 90 days for statutory breach detection.

9. Security Safeguards

Pocket Gull implements enterprise-grade technical and organizational safeguards:

  • End-to-End TLS 1.3 Encryption: All network transit is strictly encrypted with forward secrecy.
  • CycloneDX 1.6 SBOM Verification: 1,500+ software dependencies are cryptographically audited on every build.
  • Sentinel Security & Egress Guard: Pre-flight continuous analysis scans all source files for unauthorized network egress domains and secret leaks.
  • DOMPurify XSS Shield: All rendered markdown and clinical summaries undergo strict DOMPurify HTML sanitization.
  • OAuth 2.0 with PKCE: Mitigates authorization code interception and token leakage.

10. Your Rights & State Privacy Protections (OCPA & Washington MHMDA)

Whether accessing Pocket Gull under HIPAA, the Oregon Consumer Privacy Act (OCPA), or the Washington My Health My Data Act (MHMDA), you maintain complete sovereignty over your health records:

  • Zero Selling of Consumer Health Data: We do not sell, rent, or trade consumer health data under any circumstances.
  • 1-Click Ephemeral State Purge: Instantly wipe all cached biometric tokens, 3D lesion markups, and local patient records with CSPRNG memory overwriting.
  • FHIR R4 Bundle Export: Export your complete clinical data record at any time in standardized FHIR R4 JSON or Bionic Reading PDF format.
  • Consent Scope Revocation: Dynamically grant or revoke individual data processing permissions at any time.
  • Access & Inquiries: Contact our Data Protection Officer at dpo@pocketgull.app to exercise access, correction, or deletion rights.

11. Pediatric Mode & COPPA Safeguards

For pediatric minor patients, Pocket Gull provides a specialized Child Life Specialist & Pediatric Companion Mode governed by strict Children's Online Privacy Protection Act (COPPA) Safe Harbor protocols:

  • Verifiable Guardian Attestation: Pediatric consultations require explicit guardian attestation and proxy authorization before activation.
  • Edge-Only Speech Processing: Spoken audio is analyzed locally on device with immediate volatile memory release. Voice telemetry is never used as an authentication credential.
  • Child-Friendly Clinical Analogies: AI guidance uses supportive, non-pathologizing analogies (e.g., "friendly defender helpers" for white blood cells) to reduce pediatric clinical anxiety.

12. Five Eyes (FVEY) Regulatory Compliance

Pocket Gull's clinical state exports, consent flows, and emergency vectors are mapped directly to Five Eyes partner nation statutory standards:

Jurisdiction Statutory Mapping Standard Profile
United States HIPAA ยง164.514 Safe Harbor, HITECH, ONC HTI-1 FHIR US Core R4, 988 Crisis Lifeline
United Kingdom NHS DTAC, DSPT, UK-GDPR, NICE ESF FHIR UK Core, NHS 111 Dispatch
Canada PIPEDA, Ontario PHIPA, Alberta HIA FHIR CA Baseline, 988 Suicide Crisis
Australia Privacy Act 1988 (APPs), My Health Record Act 2012, TGA SaMD FHIR AU Base, Lifeline 13 11 14
New Zealand Health Information Privacy Code 2020 (HIPC), NZ HISO 10029/10064 FHIR NZ Base, 1737 Need to Talk

13. FTC Affiliate & Egress Boundary

In compliance with Federal Trade Commission (FTC) guidelines and Amazon Associates Operating Policies:

  • Affiliate Disclosure: As an Amazon Associate, PocketGull earns from qualifying purchases. Supportive products recommended in care plans are evidence-grounded non-prescription tools.
  • Zero PHI in Outbound Links: Affiliate links contain only standard ASIN identifiers (tag=pgdpo-20). Patient names, diagnoses, or condition codes are strictly prohibited from external URLs.
  • No Outbound Push/SMS Links: Raw affiliate links are never transmitted via SMS or push notifications; patients access recommendations exclusively within their authenticated portal.

14. Policy Changes

We may update this Privacy Policy to reflect evolving clinical guidelines, privacy standards, or platform enhancements. Revisions will be posted here with an updated effective date.

15. Contact Data Protection Officer

For privacy inquiries, audit requests, or security disclosures: