Privacy Policy
Last Updated: August 2026
No patient information — ever
Paramedic Vault is not designed to receive protected health information and is not a HIPAA-covered system. Do not enter patient names, dates of birth, addresses, medical record or incident numbers, or any other identifier into the chat assistant, search, or anywhere else in the app. Ask about the protocol, not about the patient.
1. What We Collect
- Subscription state. The app records whether the device holds an active subscription, which county or counties it covers, and when it renews. This is tied to your app-store account and the device, not to a clinical identity.
- Admin accounts. Name and email, for the small number of people who administer content. The mobile app itself does not require an account.
- Chat prompts. What you type to the assistant, and the answer it returns.
- Server logs. Standard request logs — timestamp, endpoint, response status, a device identifier, coarse client information — retained for operating and securing the service.
2. What We Do With It
To deliver protocol content to entitled devices, to answer your questions, to keep the service running and secure, and to understand which documents are used so the library stays useful. We do not sell your data, and we do not use it for advertising.
3. The AI Assistant and OpenAI
Prompts you send to the assistant are transmitted to OpenAI, which generates the response. That means anything you type leaves your device and is processed by a third party under its own terms and privacy policy. This is the direct reason for the rule at the top of this page: never put patient identifiers in a prompt.
4. Where Data Lives
Application data is stored on Amazon Web Services in the United States, encrypted in transit and at rest. Protocol documents you download for offline use are stored on your own device and can be removed by deleting the app.
5. Third-Party Services
We rely on Apple and Google for purchases and subscription status, OpenAI for the assistant, Amazon Web Services for hosting and storage, and an email provider for transactional messages to administrators. Each processes data under its own privacy policy.
6. Retention
Server logs are kept only as long as they are useful for operations and security. Chat history is retained so you can refer back to a conversation, and can be deleted on request. Subscription records are kept while the subscription is active and for as long afterwards as the app stores require.
7. Your Rights
You may request access to, correction of, or deletion of data associated with you or your device by writing to support@paramedicvault.com. California residents have additional rights under the CCPA, including the right to know what is collected and to request deletion. We do not sell personal information.
8. Children's Privacy
The service is intended for practising EMS clinicians and is not directed to children under 13. We do not knowingly collect personal information from children under 13.
9. Changes to This Policy
We may update this policy. Material changes will be notified in the app or by email before they take effect.
10. Contact Us
For privacy-related inquiries: support@paramedicvault.com