Privacy Policy
1. Introduction
Protocol Guide, operated by TheFireDev LLC (“Company,” “we,” “our,” or “us”), explains how we collect, use, disclose, and safeguard information when you use our website, web app, mobile application, and related services (collectively, the “Service”).
This policy applies to all users, including individual EMS clinicians, students, educators, and personnel using the Service through department or agency subscriptions.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Name and email address
- Authentication credentials (password hash or OAuth tokens)
- Agency affiliation (if provided)
- Professional role and certification level (optional)
2.2 Usage Data
We automatically collect:
- Search queries, the county or agency you searched, and protocol views
- Feature usage patterns (bookmarks, protocol views, upgrades)
- Session duration and navigation paths
- Device type, operating system, browser, and app version
- IP address for security and abuse-prevention checks
2.3 Device Information
We may collect:
- Device identifiers for analytics and security
- Push notification tokens (with your permission)
- Crash reports and performance data
2.4 Payment Information
Payment processing is handled by Stripe, Inc. (web) and Apple (iOS). We do not store credit card numbers. We retain:
- Stripe customer ID (for subscription management)
- Subscription status and billing history
- Invoice records as required by law
2.5 Voice Data
If you use voice input:
- Foreground microphone audio is uploaded to server-side storage so it can be transcribed
- The audio is sent through our transcription proxy to our speech-to-text provider (OpenAI Whisper) solely to generate text
- Transcribed text is treated as a standard search query
- Recordings are stored with your account. You can request deletion at support@protocol-guide.com
2.6 Messages You Send Us
If you use the contact form or email support, we collect your name, email address, and message so we can reply.
3. How We Use Your Information
We use collected information for:
- Service delivery: to provide, maintain, and improve the Service
- Authentication: to verify your identity and manage your account
- Payment processing: to process subscriptions and manage billing
- Personalization: to customize your experience based on your county, agency, and preferences
- Analytics: to understand usage patterns and improve the Service
- Communication: to send service updates, security alerts, and support messages
- Safety and security: to detect fraud, abuse, and security threats
- Legal compliance: to comply with applicable laws and regulations
5. Artificial Intelligence (AI) and Large Language Model (LLM) Usage
Protocol Guide uses AI to enhance search and to write summaries of published protocol text. This section describes what data is processed.
AI Services We Use
- Anthropic Claude: writes AI summaries from the protocol excerpts retrieved for your question
- Google Gemini embeddings: provide semantic search through text embeddings
- OpenAI Whisper: transcribes voice input
Data Sent to AI Services
- Search queries and questions you submit
- Relevant protocol content to generate responses
- Conversation context within a single session
- Voice audio, for voice input only
Search Data Boundaries
- Your name, email, account credentials, payment, and billing information are not sent to AI services for search responses
- Do not include patient-specific or identifiable information in searches
- Free-text search logs are treated as potentially sensitive because users can enter patient-specific details. Access is restricted to service quality, security, abuse-prevention, and support needs
AI Provider Retention
We use our providers’ commercial API terms, under which submitted content is not used to train their models. Provider retention windows are set by the providers and may change; see their published policies.
Limitations
- AI responses are for education and reference only, not clinical advice
- Always verify information against the cited protocol document
If you connect Protocol Guide to ChatGPT or Claude, that platform sends your tool query to Protocol Guide and receives protocol excerpts, source citations, and the reference-only disclaimer. Connected searches use the same account access and usage limits as the web and iOS apps.
6. Data Security
We protect data with encrypted connections (HTTPS), access controls on our systems, and the security features of our infrastructure providers. While we strive to protect your data, no method of electronic transmission or storage is 100% secure. You are responsible for maintaining the security of your account credentials. To report a vulnerability, see our security page.
7. Data Retention
We keep data for these periods:
- Account data (profile, preferences, bookmarks, history): until you delete your account. Deleting your account in Profile > Account > Delete Account removes it
- Search query logs (queries, AI prompts and responses, retrieved excerpts): 12 months, then deleted or de-identified
- Contact form submissions and support email: 24 months
- Billing records: as long as tax and accounting law requires
- Voice audio: stored with your account. You can request deletion at support@protocol-guide.com. Transcribed text follows the search query log period
- Error and performance data: according to Sentry’s retention settings for our account
Data may be retained longer if required by law or to resolve a legal dispute. We may keep aggregated statistics that do not identify you.
8. Your Privacy Rights
All Users Have the Right To
- Access your personal data
- Correct inaccurate data
- Delete your account and associated data
- Export your data in a portable format
- Withdraw consent for optional processing, including analytics cookies
To Exercise Your Rights
Email support@protocol-guide.com with the subject “Privacy request.” We will verify your identity before acting on a request.
9. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to know: the categories and specific pieces of personal information we collected, the sources, the business purposes, and the categories of third parties we share it with
- Right to delete your personal information, subject to exceptions
- Right to correct inaccurate personal information
- Right to opt out of sale or sharing: we do not sell personal information. If this changes, we will provide a “Do Not Sell or Share My Personal Information” link
- Right to non-discrimination for exercising your rights
- Authorized agents: you may designate an authorized agent with written authorization
To exercise California privacy rights, email support@protocol-guide.com with the subject “California Privacy Request.”
10. European Privacy Rights (GDPR)
If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR).
Legal Basis for Processing
- Contract: to provide the Service you requested
- Legitimate interest: to improve security and prevent fraud
- Consent: for optional analytics and marketing communications
- Legal obligation: to comply with applicable laws
Your GDPR Rights
- Right of access (Art. 15)
- Right to rectification (Art. 16)
- Right to erasure (Art. 17)
- Right to restrict processing (Art. 18)
- Right to data portability (Art. 20)
- Right to object (Art. 21)
- Right to withdraw consent (Art. 7)
International Transfers
Your data is processed in the United States. We rely on Standard Contractual Clauses (SCCs) for transfers from the EEA where our providers offer them.
Supervisory Authority
You have the right to lodge a complaint with your local data protection authority.
12. Healthcare Regulatory Compliance
Not a HIPAA Covered Entity
Protocol Guide is an education and reference tool and is not a HIPAA-covered entity. Free-text search logs are treated as potentially sensitive because users can enter patient-specific details. Access is restricted to service quality, security, abuse-prevention, support, and reliability needs.
PHI and Patient Data
- Do not enter patient-specific or identifiable information
- The Service is not designed for patient documentation
If PHI Is Inadvertently Submitted
- Search queries are handled under the search data boundaries above
- Your content is not used to train AI models
- Notify us immediately at support@protocol-guide.com so we can review it
13. Children’s Privacy
The Service is intended for adults (18 and older) who work or study in EMS and is not directed to anyone under 18. We do not knowingly collect personal information from anyone under 18. If you believe we have collected information from a minor, contact us and we will delete it.
14. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or applicable law. We will:
- Post the updated policy with a new “Last updated” date
- Notify you of material changes with an in-app notice
Your continued use of the Service after changes constitutes acceptance of the updated policy.
15. Contact Us
For privacy questions or to exercise your rights:
TheFireDev LLC
Email: support@protocol-guide.com
Also see Support, Terms, and Clinical Disclaimer.