1. Who we are (data controller)
RN PocketPal is operated by Charles Enterprises, LLC, a Maryland limited liability company (“RN PocketPal,” “we,” “us”), which is the data controller for the Website (rnpocketpal.com) and the iOS app. The Android app on Google Play is published by Tech Genius Solutions Ltd, a separate legal entity, which is the data controller for personal data collected through that app; the two act as joint controllers for the shared cloud-backed features described below, apply this single policy, and answer privacy requests through the same contact points. Mailing information for either entity is available upon verified legal request. Controlled data includes what you provide through the Website and the App (together, the “Service”), plus cloud-backed features such as Marketplace, support, AI requests, product analytics, and optional rhythm-strip contribution.
If you are in the European Economic Area or the United Kingdom, you can contact us at the email address in section 14.
2. What personal data we collect
We collect only the data we actually need to operate the service. There is no analytics SDK, no advertising network, no tracking pixel. The full list:
From the Website
- Beta signup form — email address, role (e.g., RN, LPN, Student), specialty (e.g., Telemetry, ICU), optional biggest-pain and launch-platform preferences, first-party campaign/UTM fields from the link you clicked, and an SHA-256 hash of your IP for rate-limiting only. We never store the raw IP.
- First-party website analytics — page views, CTA clicks, App Store / Google Play outbound clicks, and signup-state events tied to a random browser install ID and campaign fields. This is opt-in: nothing is stored in your browser or sent to us until you choose “Allow analytics” on the consent banner, and you can withdraw at any time from the Cookie Policy. No third-party analytics SDK, ad pixel, cookie sync, or user-entered clinical text is ever collected.
- Support form — email address, the subject and description of your support request, and the same IP-hash rate-limit. Do not include PHI. We auto-redact patterns that look like SSNs, MRNs, dates, and phone numbers before storing or emailing, but redaction is not a substitute for removing identifiers before submission.
- Server logs — your IP address may appear in standard webserver access logs (LiteSpeed access logs at our hosting provider) for security and abuse-prevention purposes. These logs are not used for tracking.
From the App
- Account data — email address or Apple/Google sign-in identifier, nursing role + specialty, subscription state, and Marketplace identity needed to operate account-only features.
- Local clinical content — your brain sheet, notes, calculator inputs, and saved templates live on your device in iOS Keychain / encrypted Core Data or Android encrypted storage/Room. We do not have access to local-only content unless you intentionally use a cloud-backed feature.
- Marketplace, Connect, and community content — listings, messages, profile fields, photos, reports, and similar submissions you choose to send to the live service. These surfaces prohibit PHI and are not for clinical care, handoff, charting, or urgent communication.
- Rhythm strip images — rhythm review runs on-device where available. If you separately opt in to contribute a strip for model improvement, the App asks you to confirm de-identification and authorization, strips metadata where possible, and sends the image to a private review queue. Do not contribute strips containing patient or facility identifiers.
- AI feature inputs — when you use the Ask AI assistant or the other AI-assisted features (Note Writer, Care Plan, Legal Reference, etc.), the input text is scrubbed for PHI patterns on-device before transmission, then sent over TLS to our server and on to the AI provider for that feature. For the assistant, the current conversation is sent as well so the answer has context; nothing else stored in the App — your brain sheets, shift log, CEU records or account details — is included. Scrubbing is best-effort and you remain responsible for not entering PHI. See section 5 for which provider receives which feature.
- Product analytics and session replay (Android app only) — to understand how features are actually used and to reproduce bugs, the Android app can send usage events and screen recordings of your session to PostHog, a third-party analytics provider (see section 5). This is off by default and nothing is collected unless you turn it on in Profile → Privacy → “Help improve the app.” If you turn it on and later turn it off, recording stops immediately and anything captured but not yet sent is discarded. Recording is limited by a fail-closed allowlist: a screen is recorded only if it has been explicitly approved as containing no clinical or patient-related content, and every screen that is not on that list is excluded automatically. Text you type into input fields is masked. Brain sheets, notes, shift logs, AI inputs, Marketplace messages, and any screen carrying clinical content are never recorded. This feature is not present in the iOS app or on the Website. Setting Privacy mode to Maximum privacy disables it outright, regardless of the toggle.
- Crash reports — anonymized crash traces with no user-entered clinical content, used solely to fix bugs if crash reporting is enabled.
- Uploaded photos — for Pill Imprint, Rhythm capture, Marketplace listings, and any other photo-bearing feature, we strip EXIF metadata (geolocation coordinates, device identifier, original timestamp, lens / serial information) on-device before the photo is stored on our servers or transmitted to any third-party processor. The visible image content is preserved; embedded metadata is not. Do not photograph anything that visually shows a patient identifier — that content is not in EXIF and cannot be stripped automatically.
What we explicitly do NOT collect
- We do not intentionally collect patient names, medical record numbers, dates of birth, room numbers tied to a real person, or Protected Health Information.
- Your location, contacts, photos, calendar, or biometric data.
- Third-party tracking identifiers (Apple Tracking Transparency: we do not request the IDFA).
3. Why we collect it (legal bases under GDPR)
For visitors and users in the EU/EEA/UK, our lawful bases under Article 6 of the GDPR are:
- Consent (Art. 6(1)(a), and Art. 5(3) ePrivacy / UK PECR) — for the beta signup form, and for first-party website analytics, which stays off unless you opt in on the consent banner and which you can withdraw at any time.
- Legitimate interests (Art. 6(1)(f)) — for responding to support requests, fixing bugs via anonymized crash reports, and rate-limiting / abuse prevention. We balance these against your rights and you can object at any time (section 7).
- Contract (Art. 6(1)(b)) — for delivering Pocketpal Pro features and processing your subscription.
- Legal obligation (Art. 6(1)(c)) — for retaining transaction records required by tax law.
Health data we incidentally see (none, by design — see section 9) is not used as “special category data” under Article 9.
4. How long we keep it
- Beta signup data — until 90 days after public launch, or until you ask us to delete it, whichever is sooner.
- Prelaunch analytics — aggregate dashboard data may be retained for product planning; event-level browser identifiers are retained for up to 13 months, then deleted or aggregated.
- Support tickets — 2 years after the ticket is closed, then deleted. Anonymized aggregate metrics (e.g., total tickets per month) may be retained longer.
- Subscription / billing records — 7 years to comply with US tax-records requirements (IRS recommends 7).
- Server access logs — 90 days, then rotated and discarded.
- Crash reports — 1 year, then deleted.
- Account data — for as long as your account is open, then deleted or de-identified within 30 days of account deletion, except records we must keep for tax, legal, safety, or dispute-resolution reasons.
- Marketplace, Connect, ratings, and other content you post — until you delete it or your account, then removed from public surfaces promptly and purged from routine backups within 90 days. Copies other users saved or that we must preserve for a legal, safety, or dispute reason persist as described in Terms § 11.3.
- Product analytics and session recordings (Android) — event-level data and recordings are retained for up to 12 months, then deleted or aggregated. Recordings tied to a deleted account are deleted with it.
- Rhythm-strip contributions — retained while they remain in the reviewed teaching set; rejected or withdrawn contributions are deleted within 30 days.
6. International transfers
Our hosting is in the United States. If you are in the EU/EEA/UK, your data will be transferred to the US. The transfer is covered by Standard Contractual Clauses (Module 1: Controller-to-Processor) under Commission Implementing Decision (EU) 2021/914, plus supplementary technical and organizational measures (encryption in transit and at rest, the on-device-first architecture described in section 2).
Our AI backend runs on Cloudflare’s network, which executes each request at the edge location nearest you before forwarding it to the AI provider named in section 5. The stored data behind those features — device identifiers, usage counters, and app data — sits in the United States.
Of the two AI providers disclosed in section 5, one is hosted in China: DeepSeek, which serves the older AI-assisted tools. The Ask AI assistant routes to OpenAI in the United States instead, so that transfer route does not apply to it. AI features are optional. Before any text is sent, it is scrubbed for PHI patterns on your device and we transmit only the minimum needed for the feature. We are assessing this transfer route — including a transfer risk assessment — with counsel, and will issue a specific addendum, change providers, or disable affected features in regions where that route is not appropriate under applicable law.
7. Your rights
You have the following rights, depending on where you live:
Everyone
- Right to know — what data we have about you.
- Right of access — a copy of that data.
- Right to correction — fix anything that’s wrong.
- Right to deletion — remove your data (subject to retention obligations).
- Right to withdraw consent — for anything we process on a consent basis.
If you’re in the EU/EEA/UK (GDPR)
- Right to portability — receive your data in a machine-readable format.
- Right to object — to processing based on legitimate interests.
- Right to restrict — limit how we process your data in specific cases.
- Right not to be subject to automated decisions — including profiling. We don’t do this anyway.
- Right to lodge a complaint — with your local Data Protection Authority. For UK, that’s the ICO (ico.org.uk).
If you’re in California (CCPA / CPRA)
- Right to know + access — described above.
- Right to delete — described above.
- Right to correct — described above.
- Right to opt out of “sale” or “sharing” — we do not sell or share personal information for cross-context behavioural advertising, so there is nothing to opt out of. We disclose this explicitly here.
- Right to limit use of sensitive personal information — we do not use sensitive personal information for purposes beyond what is necessary to provide the service.
- Right to non-discrimination — exercising your rights will never affect your access to the service or the price you pay.
If you’re elsewhere in the US
Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), and other state laws grant overlapping rights. We honor them the same way we honor CCPA rights. If your state isn’t named here and you have a right under your state’s law that we missed, contact us and we’ll handle it.
Consumer health data — Washington, Connecticut, and similar states
RN PocketPal is not a HIPAA-covered entity, which means certain state consumer-health-data laws apply to us in addition to general privacy laws. If you are a resident of Washington State, the Washington My Health My Data Act (effective March 2024) gives you specific rights with respect to “consumer health data” as that act defines it, including:
- Consent before collection or sharing of consumer health data. We obtain consent at signup for any health-adjacent data we collect (role, specialty), and we do not share consumer health data with third parties for advertising or behavioral analytics under any circumstance.
- The right to know what consumer health data we hold about you.
- The right to delete your consumer health data.
- The right to withdraw consent at any time, with deletion of any data we collected on the basis of that consent.
- No sale of consumer health data. We do not sell consumer health data under WA MHMD’s definition of sale, and we do not sell consumer health data under any other state’s definition either.
Similar consumer-health-data rights exist under the Connecticut Data Privacy Act’s health-data provisions, the Colorado Privacy Act, the Virginia Consumer Data Protection Act, the Oregon Consumer Privacy Act, and other emerging state laws. We honor all of these rights through the same data-request channel described below.
We will continue updating this section as state consumer-health-data laws and healthcare privacy requirements evolve.
How to exercise these rights
Email support@rnpocketpal.com with the subject line [DATA REQUEST], or use the form at /data-requests. We respond within 30 days (45 in complex cases, with a heads-up). We never charge you to exercise these rights, and exercising them never affects your access to the service.
Deleting your account
You can request deletion of your account and the data tied to it at /delete-account or /data-requests. Deleting your account removes your profile, Marketplace and Connect content, ratings, and account-linked analytics. Content other users already saved or reshared, and records we are required to keep for tax, legal, safety, or dispute-resolution reasons, persist as described in section 4 and in Terms § 11.3. Deletion is permanent and cannot be undone.
8. Children
RN PocketPal is a professional tool for licensed nurses, nursing assistive personnel, and nursing students. The Website and App are not directed to children, are not intended for anyone under 16, and are not “directed to children” within the meaning of the Children’s Online Privacy Protection Act (COPPA, 15 U.S.C. § 6501 et seq.). We do not knowingly collect personal data from anyone under 16. Nursing students should be adults enrolled in a nursing program; we do not request school-records data and are not a school service provider under state student-privacy laws.
Creating an account requires you to confirm you are 16 or older. If we learn that we have collected personal data from someone under 16, we delete it promptly. A parent or guardian who believes we hold data about their child can write to privacy@rnpocketpal.com with the subject [UNDER-16], and we will delete the account and its data and confirm back. Where local law sets a higher age of digital consent (for example 16 in parts of the EU/EEA), that higher age applies.
9. Health data & HIPAA
RN PocketPal is not a HIPAA-covered entity in its consumer-app capacity, and we do not intentionally collect or process Protected Health Information. The App is designed so bedside identifiers in brain sheets stay in encrypted local storage by default, and cloud-backed features prohibit PHI.
If RN PocketPal ever enters a hospital/system arrangement that would make us a Business Associate, or if we provide services on behalf of a covered entity or business associate, we will execute a Business Associate Agreement before that engagement starts and will update this policy. That is not the case for the consumer App.
Health-related or professional preferences you tell us about yourself (your nursing role, your unit specialty) are professional descriptors rather than “special category data” under GDPR Article 9. We do not infer health conditions from this data.
10. Unintended PHI submissions
Do not send RN PocketPal protected health information, patient identifiers, medical-record numbers, dates of birth, room numbers tied to a real person, facility screenshots with patient banners, or any information you are not authorized to disclose.
If PHI or patient-identifying information is submitted to us by mistake — in a support ticket, a marketplace listing photo, a feedback form, an email, an AI prompt our on-device scrubber did not catch, a Connect post, a rhythm contribution, a crash report, or any other channel — you authorize us to process that information only as needed to secure it, identify the affected submission, delete it, redact it, return it to you, comply with law, investigate abuse or security incidents, and maintain a minimal audit record. We do not use unintended PHI for model training, marketing, analytics, product improvement, marketplace features, or social features.
Specifically, our inbound-PHI handling protocol is:
- We do not retain it. The message, attachment, or record is purged from our active systems within 72 hours of detection. We make best-effort attempts to remove it from short-term backups within 30 days. We do not export it. We do not analyze it. We do not train any model on it.
- We do not republish it. We do not quote inbound PHI back to you in our reply. We do not forward it to a third party. We do not share it with a vendor, contractor, or affiliate. If we need to ask a clarifying question, we do so without referencing the patient information you sent.
- We notify you to delete it on your end. Within one business day of detecting inbound PHI, we ask you to delete the message from your sent folder and any other place you kept a copy, and we provide instructions for your platform where we can.
- We log the incident without the content. We retain a redacted record of date, channel, and PHI category (not the PHI itself) for our own audit purposes for one year, then delete that record too.
- The disclosure burden stays with the sender. Because we are not a HIPAA-covered entity and have no Business Associate Agreement with your facility, sending us PHI does not create an authorized disclosure under HIPAA. If you sent PHI without your facility’s authorization, the unauthorized disclosure is yours to report to your facility’s privacy officer. Our handling above limits downstream harm; it does not retroactively make the disclosure compliant.
If you are a facility or hospital privacy officer: contact us at security@rnpocketpal.com and we will work with you in good faith on incident scope, retention timelines, and documentation you need for OCR notification calculations.
RN PocketPal is not a HIPAA secure-messaging system, electronic health record, designated record set, or substitute for your facility’s approved documentation systems. You remain responsible for complying with your employer’s policies, HIPAA obligations, state nursing rules, and minimum-necessary requirements.
These timelines are designed to reduce retention of unintended PHI while preserving a minimal security and abuse-prevention record.
11. Security
We protect personal data with technical and organizational measures appropriate to its sensitivity. Specifically:
- TLS 1.2+ for all data in transit, HSTS enforced.
- On-device encryption for any clinical content (iOS Data Protection “complete when locked”).
- IP addresses hashed (SHA-256 with a non-public salt) before storage. Raw IPs are not retained beyond standard webserver logs.
- Server-side input validation, parameterized queries, and PHI-shaped-pattern auto-redaction on submitted free-text.
- Content Security Policy, X-Frame-Options DENY, Referrer-Policy strict-origin-when-cross-origin, and Permissions-Policy that denies camera/mic/geolocation by default.
- No third-party advertising SDKs, ad pixels, or cookie syncing in either the Website or the App, and no third-party analytics SDK on the Website or in the iOS app. The Android app uses one third-party product-analytics SDK (PostHog), scoped by the fail-closed allowlist described in section 2 and disclosed in section 5.
No system is perfectly secure. If we discover a personal-data breach, consumer-health-data breach, or breach of unsecured individually identifiable health information that we maintain, we will evaluate and provide notices required by applicable federal, state, and international laws, including consumer health breach-notification rules where they apply.
13. Changes to this policy
We will update this policy as the product evolves. When we make a material change (e.g., a new processor, a new data category, a new lawful basis), we will:
- Update the “Last updated” date at the top of this page.
- Post a notice in the App and on the Website 30 days before the change takes effect, where the change is significant.
- If we’re relying on consent for a new purpose, ask you for that consent before processing.
Effective date of this version: May 28, 2026.
14. Contact us
For privacy questions, data-access requests, or to exercise any of the rights above:
- Email: support@rnpocketpal.com (subject line [DATA REQUEST])
- Web form: /data-requests
- Mail: Mailing address available upon verified legal request.
- EU/UK representative: Not currently appointed. We are reviewing, with counsel, whether a GDPR Article 27 representative is required for our processing; until then, direct EU/UK privacy requests to support@rnpocketpal.com.
- Data Protection Officer: We have not designated a DPO. We are reviewing, with counsel, whether Article 37 requires one; in the meantime, send any data-protection question to support@rnpocketpal.com.
A note from the founder.
This policy is written to be clear about what RN PocketPal does today and may evolve as the product, legal review, and privacy requirements evolve. If you spot something that seems wrong, please email support@rnpocketpal.com with subject [POLICY FEEDBACK] — we’d rather hear from you than miss it.

12. Social media & Instagram messaging
We run RN PocketPal accounts on social platforms, including Instagram. On our own posts we sometimes invite followers to comment a keyword (for example, “SHEET”) if they want a free resource shown in the post, such as a nursing brain-sheet template. This section explains what happens with your data if you take us up on that.
When you comment that keyword on one of our posts, we use Meta’s Instagram API to send you one private reply (a direct message) with the resource you asked for. This is opt-in and user-initiated: you choose to comment, and we reply once.
What we process, and why
Our lawful basis is your consent and our legitimate interest in responding to a request you initiated (GDPR Art. 6(1)(a)/(f)). Instagram and Meta process this data as the messaging platform under Meta’s Privacy Policy; the direct message is delivered through Meta’s systems. We do not sell this data, and we do not use it for advertising, profiling, or any unrelated messaging.
Retention & your choices
We keep the interaction record (your username, the comment, and the keyword matched) for up to 24 months for content analytics, then delete or aggregate it. You can ask us to delete it sooner at any time by emailing support@rnpocketpal.com with the subject [DATA REQUEST], or through /data-requests. You can also revoke our access to your Instagram interactions at any time from Instagram → Settings → Apps and websites.