1. Overview
Pocket Gull is a real-time medical Care Plan Strategy and AI consultation co-pilot platform operated by PocketGull LLC, an Oregon limited liability company based in Portland, Oregon ("we," "our," or "us"). Engineered with Privacy by Design principles, this Privacy Policy explains how we collect, process, isolate, and safeguard data when you interact with our application at pocketgull.app.
By using Pocket Gull, you accept the clinical privacy practices described in this policy. If you do not agree, please do not use the application.
2. Data We Collect
We adhere to strict data minimization. The table below details all information categories processed by Pocket Gull:
| Category | Details | Storage Boundary |
|---|---|---|
| Account Credentials | Name, email address (via Google Sign-In) | Ephemeral session token in memory |
| Patient Clinical Records | Vitals, symptoms, laboratory biomarkers, clinical history | Local browser storage (AES-256 encrypted) |
| Biometric Streams | Resting heart rate, SpOโ, sleep efficiency summaries | In-memory only via Google Health API |
| Technical Telemetry | Browser engine type, anonymized IP hash (SHA-256) | Server runtime logs (90-day retention) |
3. Health Biometrics (Google Health API)
When you choose to connect your Google Health or Fitbit account, Pocket Gull requests read-only authorization via Google OAuth 2.0 PKCE for the following restricted scopes:
- Resting Heart Rate Summary โ daily average bpm (last 30 days)
- Blood Oxygen Saturation (SpOโ) โ daily average % (last 30 days)
- Sleep Architecture โ sleep duration and sleep stage breakdown (last 30 days)
This integration strictly complies with the Google Health API Developer and User Data Policy.
4. Consent-as-Code & Granular Scopes
Pocket Gull implements Consent-as-Code inspired by Nishant Bhajaria's Privacy Engineering standard. Rather than treating consent as an all-or-nothing binary toggle, patients and clinicians maintain granular, independent control across distinct clinical data scopes:
- Symptoms & Conditions (
symptoms): Longitudinal symptom tracking, anatomical site tags, and severity logs. - 3D Spatial Lesion Markup (
spatialLesions): Procedural 3D anatomical surface coordinates, morphology, and SNOMED CT identifiers. - Vitals & Telemetry (
vitalsTelemetry): Heart rate, blood pressure, SpOโ, glucose, and continuous biomarker streams. - Live Audio Streaming (
audioStreaming): Bidirectional multimodal speech streaming with Dr. Gulliver. - Optical Camera & Vision (
cameraVision): Edge-based optical scanning of documents and physical exam points. - FHIR R4 Interoperability (
fhirExport): Export of standardized HL7 FHIR US Core / UK Core / CA Baseline bundles. - Actuarial Longevity Scoring (
actuarialScoring): Occupational hazard assessment and healthspan calculations.
null with zero caching delay.
5. How We Use Your Data
We use processed data exclusively for authorized functional clinical purposes:
- Rendering real-time biometric trend graphs and multi-lens radar summaries.
- Synthesizing integrative care plan recommendations via Google Gemini models under explicit user initiation.
- Authenticating user sessions and safeguarding API client connections.
- Sanitizing outgoing clinical prompts using DOMPurify for HIPAA Safe Harbor ยง164.514 compliance.
We NEVER: sell user data, monetize health metrics, build advertising profiles, or share personal information with data brokers or insurance underwriters.
6. AI Processing & Zero-Data Retention (ZDR)
Clinical intelligence in Pocket Gull is powered by Google Gemini foundation models. When you trigger an AI consultation or care strategy synthesis:
- 18-Identifier Safe Harbor Scrubbing: Outgoing payloads are stripped of all 18 direct and indirect HIPAA identifiers before transmission.
- Zero-Data-Retention (ZDR) Attestation: Outgoing requests transmit
X-ZDR-Attestation: enabledheaders. Transmitted data is processed ephemerally under Google's Gemini API Enterprise Terms. User data is never retained by Google to train foundational base model weights. - Encrypted Client Caching: AI responses cached locally on your device are protected using Web Crypto AES-GCM encryption.
8. Cryptographic Storage Wiping & Retention
To prevent cold-memory forensic data extraction, Pocket Gull implements active cryptographic overwriting:
- CSPRNG Memory Overwrite: When you click "1-Click State Purge" or "Disconnect & Erase Data", all client-side storage keys are overwritten with cryptographically secure pseudorandom noise (
crypto.getRandomValues) before unlinking and deleting. - OAuth Tokens: Held strictly in volatile RAM and destroyed immediately upon session disconnect.
- Hashed Audit Logs: Cryptographic SHA-256 event digests retained for 90 days for statutory breach detection.
9. Security Safeguards
Pocket Gull implements enterprise-grade technical and organizational safeguards:
- End-to-End TLS 1.3 Encryption: All network transit is strictly encrypted with forward secrecy.
- CycloneDX 1.6 SBOM Verification: 1,500+ software dependencies are cryptographically audited on every build.
- Sentinel Security & Egress Guard: Pre-flight continuous analysis scans all source files for unauthorized network egress domains and secret leaks.
- DOMPurify XSS Shield: All rendered markdown and clinical summaries undergo strict DOMPurify HTML sanitization.
- OAuth 2.0 with PKCE: Mitigates authorization code interception and token leakage.
10. Your Rights & State Privacy Protections (OCPA & Washington MHMDA)
Whether accessing Pocket Gull under HIPAA, the Oregon Consumer Privacy Act (OCPA), or the Washington My Health My Data Act (MHMDA), you maintain complete sovereignty over your health records:
- Zero Selling of Consumer Health Data: We do not sell, rent, or trade consumer health data under any circumstances.
- 1-Click Ephemeral State Purge: Instantly wipe all cached biometric tokens, 3D lesion markups, and local patient records with CSPRNG memory overwriting.
- FHIR R4 Bundle Export: Export your complete clinical data record at any time in standardized FHIR R4 JSON or Bionic Reading PDF format.
- Consent Scope Revocation: Dynamically grant or revoke individual data processing permissions at any time.
- Access & Inquiries: Contact our Data Protection Officer at dpo@pocketgull.app to exercise access, correction, or deletion rights.
11. Pediatric Mode & COPPA Safeguards
For pediatric minor patients, Pocket Gull provides a specialized Child Life Specialist & Pediatric Companion Mode governed by strict Children's Online Privacy Protection Act (COPPA) Safe Harbor protocols:
- Verifiable Guardian Attestation: Pediatric consultations require explicit guardian attestation and proxy authorization before activation.
- Edge-Only Speech Processing: Spoken audio is analyzed locally on device with immediate volatile memory release. Voice telemetry is never used as an authentication credential.
- Child-Friendly Clinical Analogies: AI guidance uses supportive, non-pathologizing analogies (e.g., "friendly defender helpers" for white blood cells) to reduce pediatric clinical anxiety.
12. Five Eyes (FVEY) Regulatory Compliance
Pocket Gull's clinical state exports, consent flows, and emergency vectors are mapped directly to Five Eyes partner nation statutory standards:
| Jurisdiction | Statutory Mapping | Standard Profile |
|---|---|---|
| United States | HIPAA ยง164.514 Safe Harbor, HITECH, ONC HTI-1 | FHIR US Core R4, 988 Crisis Lifeline |
| United Kingdom | NHS DTAC, DSPT, UK-GDPR, NICE ESF | FHIR UK Core, NHS 111 Dispatch |
| Canada | PIPEDA, Ontario PHIPA, Alberta HIA | FHIR CA Baseline, 988 Suicide Crisis |
| Australia | Privacy Act 1988 (APPs), My Health Record Act 2012, TGA SaMD | FHIR AU Base, Lifeline 13 11 14 |
| New Zealand | Health Information Privacy Code 2020 (HIPC), NZ HISO 10029/10064 | FHIR NZ Base, 1737 Need to Talk |
13. FTC Affiliate & Egress Boundary
In compliance with Federal Trade Commission (FTC) guidelines and Amazon Associates Operating Policies:
- Affiliate Disclosure: As an Amazon Associate, PocketGull earns from qualifying purchases. Supportive products recommended in care plans are evidence-grounded non-prescription tools.
- Zero PHI in Outbound Links: Affiliate links contain only standard ASIN identifiers (
tag=pgdpo-20). Patient names, diagnoses, or condition codes are strictly prohibited from external URLs. - No Outbound Push/SMS Links: Raw affiliate links are never transmitted via SMS or push notifications; patients access recommendations exclusively within their authenticated portal.
14. Policy Changes
We may update this Privacy Policy to reflect evolving clinical guidelines, privacy standards, or platform enhancements. Revisions will be posted here with an updated effective date.
15. Contact Data Protection Officer
For privacy inquiries, audit requests, or security disclosures:
- Data Protection Officer: dpo@pocketgull.app
- Security Disclosures: privacy@pocketgull.app
- Official Website: pocketgull.app