Protocol Guide

Privacy Policy

Last updated: · Operator: TheFireDev LLC.

1. Introduction

Protocol Guide, operated by TheFireDev LLC (“Company,” “we,” “our,” or “us”), explains how we collect, use, disclose, and safeguard information when you use our website, web app, mobile application, and related services (collectively, the “Service”).

This policy applies to all users, including individual EMS clinicians, students, educators, and personnel using the Service through department or agency subscriptions.

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

2.2 Usage Data

We automatically collect:

2.3 Device Information

We may collect:

2.4 Payment Information

Payment processing is handled by Stripe, Inc. (web) and Apple (iOS). We do not store credit card numbers. We retain:

2.5 Voice Data

If you use voice input:

2.6 Messages You Send Us

If you use the contact form or email support, we collect your name, email address, and message so we can reply.

3. How We Use Your Information

We use collected information for:

4. Data Sharing and Service Providers

We do not sell your personal information. We share data with the service providers that run the Service:

Legal Disclosures

Department Customers

If you use Protocol Guide through a department or agency subscription, your agency administrator may have access to aggregated usage reports. Individual search queries are not shared with administrators.

5. Artificial Intelligence (AI) and Large Language Model (LLM) Usage

Protocol Guide uses AI to enhance search and to write summaries of published protocol text. This section describes what data is processed.

AI Services We Use

Data Sent to AI Services

Search Data Boundaries

AI Provider Retention

We use our providers’ commercial API terms, under which submitted content is not used to train their models. Provider retention windows are set by the providers and may change; see their published policies.

Limitations

If you connect Protocol Guide to ChatGPT or Claude, that platform sends your tool query to Protocol Guide and receives protocol excerpts, source citations, and the reference-only disclaimer. Connected searches use the same account access and usage limits as the web and iOS apps.

6. Data Security

We protect data with encrypted connections (HTTPS), access controls on our systems, and the security features of our infrastructure providers. While we strive to protect your data, no method of electronic transmission or storage is 100% secure. You are responsible for maintaining the security of your account credentials. To report a vulnerability, see our security page.

7. Data Retention

We keep data for these periods:

Data may be retained longer if required by law or to resolve a legal dispute. We may keep aggregated statistics that do not identify you.

8. Your Privacy Rights

All Users Have the Right To

To Exercise Your Rights

Email support@protocol-guide.com with the subject “Privacy request.” We will verify your identity before acting on a request.

9. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

To exercise California privacy rights, email support@protocol-guide.com with the subject “California Privacy Request.”

10. European Privacy Rights (GDPR)

If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR).

Legal Basis for Processing

Your GDPR Rights

International Transfers

Your data is processed in the United States. We rely on Standard Contractual Clauses (SCCs) for transfers from the EEA where our providers offer them.

Supervisory Authority

You have the right to lodge a complaint with your local data protection authority.

11. Cookies and Tracking Technologies

You can also manage cookies through your browser settings.

12. Healthcare Regulatory Compliance

Not a HIPAA Covered Entity

Protocol Guide is an education and reference tool and is not a HIPAA-covered entity. Free-text search logs are treated as potentially sensitive because users can enter patient-specific details. Access is restricted to service quality, security, abuse-prevention, support, and reliability needs.

PHI and Patient Data

If PHI Is Inadvertently Submitted

13. Children’s Privacy

The Service is intended for adults (18 and older) who work or study in EMS and is not directed to anyone under 18. We do not knowingly collect personal information from anyone under 18. If you believe we have collected information from a minor, contact us and we will delete it.

14. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or applicable law. We will:

Your continued use of the Service after changes constitutes acceptance of the updated policy.

15. Contact Us

For privacy questions or to exercise your rights:

TheFireDev LLC

Email: support@protocol-guide.com

Also see Support, Terms, and Clinical Disclaimer.