Privacy Policy
Version 0.6.1. Last updated: August 16, 2026.
Privacy Policy
Your privacy matters. This policy explains what information we collect, how we use it, and your rights. It applies to Helix Anesthesia ("the App," "we," "us").
1. Information We Collect
Account Information: Name, professional title, institution (optional), email address, and authentication credentials.
Usage Data: Features used, screens viewed, crash and error reports, app version, device type, operating system version.
AI Chat Queries: The clinical questions you submit and the AI responses generated. Queries are hashed for caching; hashed versions are retained to reduce cost and improve response time.
Documents You Upload (optional): The Library lets you upload reference documents — PDF or Word, up to 10 MB — such as an institutional protocol or a study guide. We store the file and the text extracted from it so you can search it inside the App. These are visible only to you. They are NOT sent to the AI assistant or to any third-party model. We do not scan them for patient information, so the undertaking you made not to enter PHI applies to what you upload as much as to what you type.
Subscription Data: Subscription status and transaction identifiers from Stripe, our payment processor. Card numbers go directly to Stripe and are never received or stored by us.
Voice Input (optional): The AI chat has a microphone button. When you use it, your device’s built-in speech recognition — Apple’s on iOS, Google’s on Android — converts your speech to text. That audio is handled by Apple or Google under their own privacy policies and may be processed on their servers. We never receive, hear, or store the audio itself. We receive only the transcribed text, which is then treated exactly like a question you typed. The microphone is active only while you are holding a voice session open, and the App never listens in the background.
Safety Confirmations: The dosing calculators question a patient weight that looks implausible for the age entered — for example 200 kg for a six-year-old. When that happens we record that the warning appeared, the weight and age on screen, which calculator it was, and whether you confirmed the value or went back and changed it. This is kept as a safety record: it is how we can show that the check works and what it showed. It contains no patient name, medical record number, date of birth, or any other identifier, and it is never used to calculate a dose.
Audit and Legal Records: When you accept legal agreements (Terms of Service, Privacy Policy, Beta Tester Agreement), we record the timestamp, agreement version, your IP address, your device type (user-agent), and your name/email/institution as they appear on your profile at the time of acceptance. This information is retained as a legal compliance record.
2. What We Do NOT Collect
We do not knowingly collect Protected Health Information (PHI). You are instructed not to enter patient identifiers, MRNs, names, DOBs, addresses, or other PHI into the App.
If you submit PHI despite our instructions, we cannot guarantee its protection and you assume all associated risk. The App includes automated filters to detect and prevent common PHI patterns, but these filters are not perfect.
We do not sell your data to third parties for advertising or any other purpose.
3. How We Use Your Data
-
Operate, maintain, and improve the App
-
Process AI queries through our model provider
-
Manage subscriptions and billing
-
Respond to your support requests
-
Send critical service announcements (not marketing)
-
Detect and prevent fraud, abuse, and technical issues
-
Comply with legal obligations
4. Third-Party Service Providers
We use the following subprocessors:
· Anthropic — AI model provider for the chat feature. Queries are transmitted to their API. Review their privacy policy at anthropic.com.
· Supabase — database and authentication infrastructure. Review their policy at supabase.com.
· Apple App Store / Google Play Store — app distribution.
Stripe — payment processing for subscriptions. Your email address and payment details go directly to Stripe; we never receive or store card numbers. Review their policy at stripe.com.
Cloudflare — bot protection on the sign-in screen (Turnstile). Receives your IP address and browser characteristics to confirm the request is human. Review their policy at cloudflare.com.
Resend — delivery of the sign-in code and account emails. Receives your email address and the message contents. Review their policy at resend.com.
· Expo — app delivery and update infrastructure.
· Apple Speech Recognition / Google Speech Services — used only when you tap the microphone button in the AI chat. Your device sends the audio to the platform’s own speech service, which returns text. We never receive the audio. See Apple’s and Google’s privacy policies for how they handle it.
Each provider processes data under their own privacy policies. We select providers with reasonable security practices but cannot guarantee their conduct.
5. Data Security
Data is encrypted in transit (HTTPS/TLS 1.2+) and at rest (AES-256). Passwords are hashed using modern algorithms. We use reasonable industry practices to protect data.
No system is completely secure. We cannot guarantee absolute security against all threats. You are responsible for keeping your account credentials confidential.
6. Your Rights
You have the right to:
-
Access the personal data we hold about you
-
Correct inaccurate data
-
Delete your account and associated data
-
Export your data in a portable format
-
Opt out of non-essential analytics
-
Lodge a complaint with your local data protection authority
Exercise any of these rights by contacting: support@helixanesthesia.com.
7. Data Retention
Documents you upload: Kept until you delete the document or your account, whichever comes first. Deleting either removes both the stored file and the extracted text.
· Account data: Your email address and name are removed IMMEDIATELY when you delete your account — there is no grace period and no 30-day window. Your sign-in is permanently disabled at the same moment. See helixanesthesia.com/delete-account for exactly what is removed and what remains.
· Email hash: A one-way hash of your email address is kept after deletion. It cannot be reversed or sent to. It exists so that if you sign up again with the same address we can offer to restore your account instead of starting you from nothing.
· AI conversations: The threaded conversation you see in the app is stored on your device, not on our servers. Separately, every question asked and every answer returned is recorded on our servers, so that clinical content can be reviewed for accuracy and so we can establish what the assistant said if that is ever questioned. That record carries no user column. However, we also log which account asked which question in order to count queries against your plan, and for a question answered from our cache those two records can be matched. We do not connect the two as a matter of routine. The question log is read by one person — the CRNA who maintains the app — to check that the clinical answers are correct, and it is read as a list of questions rather than a list of people. It is never used for marketing, for profiling, or to look up what any individual has asked, and it is never sold or shared. The one circumstance in which we would connect a question to an account is a legal claim where what the assistant said, and to whom, is genuinely at issue. That is the reason the capability exists and the only reason we would use it.
· Query cache: Retained indefinitely. Cache entries hold the question text and the answer. They carry no user column of their own, but they can be matched to an account through the usage log described above. We keep them for the same reason we keep the question log: to be able to establish what the assistant said, to whom, and when, if that is ever questioned. The assistant itself only reads entries from the last 30 days; the older rows are kept as a record, not used to answer anything.
· Audit records (agreements, code redemptions, student verification): Retained indefinitely and NOT affected by account deletion. Agreement acceptances hold your name, email address, institution and IP address as they were at the moment you accepted. Code redemptions hold the code and the IP it was redeemed from. Student verifications hold your .edu email address, school, program, and the IP addresses the code was requested and confirmed from. Each of these exists to evidence something — what you agreed to, that a code was not shared, that a discount went to someone who qualified — and a record we edited afterwards would evidence nothing. These are therefore the places where your email address and name survive deletion in readable form. They are never used to contact you or to build a profile.
· Usage and safety records: Screen views, and any implausible-weight confirmation shown in a dosing calculator, are retained indefinitely. After account deletion these remain attached to an account identifier that no longer names anyone.
Why we do not delete on a schedule. Helix Anesthesia is a clinical reference tool, and the records above are what would establish what the app displayed, what it warned about, and what you agreed to, if that is ever questioned — including years after the fact. A retention clock that erased them would erase the evidence in exactly the situation it exists for. We therefore keep them, and we would rather tell you that plainly than describe a deletion schedule we do not operate. What account deletion does remove is described on the deletion page and in §6 above: your name, email address and profile stop being readable. The records that remain are attached to an account identifier that no longer names anyone.
· Legal/billing records: Retained as required by law.
8. Children
The App is not intended for individuals under 18. We do not knowingly collect data from minors. If we learn we have collected data from a minor, we will delete it.
9. California Residents (CCPA/CPRA)
California residents have additional rights: to know what categories of personal information we collect, to request deletion, to opt out of "sale" of personal information (we do not sell), and to non-discrimination for exercising rights. Contact support@helixanesthesia.com to exercise these rights.
10. EU/UK Residents (GDPR/UK-GDPR)
Our lawful bases for processing your data include: performance of a contract (operating the App for you), legitimate interest (improving the App, security), and consent (where required). You may object to processing based on legitimate interest and withdraw consent at any time. You have the right to data portability and to lodge complaints with your local data protection authority.
11. International Data Transfers
Our servers and subprocessors may be located in the United States. By using the App, you acknowledge your data may be transferred to and processed in the US, which may have different privacy protections than your country.
12. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated through the App and by email. Continued use after changes constitutes acceptance.
13. Contact
Privacy questions, requests, or concerns: support@helixanesthesia.com.
Privacy questions: support@helixanesthesia.com. View Terms of Service →