Privacy Policy
Last updated: August 12, 2026
Document version: 2026-08-12
This Privacy Policy describes how Equestro Labs (“ProofCare,” “we,” “us”) handles information when you use the ProofCare app (Personal Medical ID) and the proofcareapp.com website. It is intended for US users age 13+.
Related: Your privacy choices · Terms of Use
1. Who we are and entity posture
ProofCare is operated by Equestro Labs. Contact for privacy requests: natalie@equestrolabs.com.
ProofCare is offered as a consumer Personal Medical ID / patient-directed personal health record tool. We do not market the consumer App Store configuration as a HIPAA covered entity. Employer / PEPM features, if any, remain gated until business-associate templates and counsel review are complete.
2. Categories of information
- Clinical records you import (e.g. Epic FHIR / MyChart resources: conditions, medications, allergies, labs, immunizations) and documents you upload.
- Wearable / Apple Health data you authorize (activity, sleep, workouts, and vitals such as heart rate and blood oxygen).
- Oura data you authorize (sleep, activity, readiness, heart metrics, etc.).
- Emergency card fields you enter (name, allergies, medications, contacts).
- On-device audit / share grant metadata you generate in the app.
- Account / device identifiers for optional cloud insights (Firebase Auth UID, device id, FCM token).
- Billing metadata via Stripe when subscriptions are enabled (no clinical records in payment metadata).
- Website beta leads (name, email, role, optional note, and basic server logs) when you submit the join-beta form.
3. Sources and purposes
Sources: you; Apple HealthKit; patient-authorized Epic FHIR / MyChart; Oura OAuth; the website beta form.
Purposes: provide the vault and Personal Medical ID; emergency card; user-initiated sharing; optional wellness insights; beta access operations; billing; security and abuse prevention. We do not use clinical vault data for third-party advertising.
4. Where clinical data is stored
Imported clinical records and uploaded documents are stored in an encrypted local vault on your device (AES-GCM with a key held in the device Keychain / secure storage). OAuth tokens are stored in the device secure enclave / Keychain. Vault files are excluded from iCloud backup where the platform allows. ProofCare does not place protected health information on a public blockchain; integrity or consent metadata, if used, is limited to non-identifying hashes and event types.
“Clinical data stays on your device” applies to the encrypted FHIR vault and uploads. It does not apply if you opt into cloud insights, export or share data, or submit website forms.
5. Optional cloud insights
If you opt in and cloud insights are enabled in your build (production release requires executed vendor BAAs), ProofCare may sync daily wearable aggregates (for example sleep scores, steps, heart-rate averages) under a Firebase Auth UID to Google Firebase (Firestore, Cloud Messaging, App Check) and process them with Google Gemini to generate wellness coaching.
- Aggregates are not clinical FHIR records and are scrubbed of forbidden fields (no raw FHIR JSON, names, emails, or source/device labels).
- They are still health-related and linked to your account and device notification token. They are not HIPAA Safe Harbor de-identified data.
- We configure Gemini / Firebase AI so customer prompts and inputs are not used to train Google’s foundation models, consistent with our BAA checklist.
- Cloud insights may be unavailable or paused until BAAs and counsel gates are complete.
- Wellness coaching only—not diagnosis, treatment, or emergency care.
- Revoke in Settings; we then delete remote aggregates for your account.
We do not sell your health records. We do not use cloud insights data for advertising.
6. Service providers (subprocessors)
Depending on features you use, we may engage:
- Google Firebase / Google Cloud / Gemini — optional cloud insights, auth, messaging, App Check (only when that path is enabled).
- Stripe — subscription billing metadata (no clinical PHI in payment metadata).
- DreamHost — website hosting and beta lead processing for proofcareapp.com.
- OAuth bridge hosting (e.g. Vercel) — short-lived OAuth redirect handling; designed not to retain auth codes/tokens.
- Crash / error tooling — not enabled for health data until a BAA and PHI scrubbers exist.
7. Website and beta interest form
If you request beta access on proofcareapp.com, we process your name, email, role, and optional note to evaluate and contact you about access. Submissions may be emailed to natalie@equestrolabs.com and stored on our website host for that purpose. We do not sell beta lead information.
8. Sharing and export
You control sharing. Access grants you create are purpose-scoped and time-limited. Emergency card PDF export and system share sheets are user-initiated. Until a remote share resolver ships, creating a grant records consent on-device and does not upload your clinical vault to ProofCare servers by itself.
9. Retention and deletion
- Local vault — until you delete it in Settings or uninstall the app.
- Cloud insight aggregates — while opt-in is active; deleted on revoke/wipe. Clients sync limited recent daily batches (on the order of ≤30 days).
- Orphaned cloud accounts — we may delete inactive anonymous cloud profiles on an operational schedule (target: inactive > 180 days).
- Website beta leads — while we operate the pilot list, or sooner if you ask us to delete them.
- On-device audit events — retained for your review until wipe/uninstall.
10. Security (no absolute guarantees)
We use encryption at rest on device for vault data, platform secure storage for keys/tokens, transport encryption (TLS) for network calls, and app-lock options (Face ID / passcode). No security measure is 100% secure. You are responsible for keeping your device locked and for whom you share with. See also our Terms of Use.
11. Children
ProofCare is not directed to children under 13. Do not use the app if you are under 13.
12. Your rights and choices
Depending on your state (including California and similar privacy laws), you may have rights to access, delete, correct, or obtain a copy of personal information, to limit use of sensitive personal information, and to opt out of certain sharing. See Your privacy choices. We do not sell personal information and we do not share personal information for cross-context behavioral advertising.
13. International processing
ProofCare is oriented to US users. If you access the service from elsewhere, your information may be processed in the United States (including US cloud regions used by our providers).
14. Important product statements
- ProofCare uses a HIPAA-aligned architecture. We do not claim to be “HIPAA certified” or “HIPAA compliant” as a certification.
- ProofCare is not a medical device and does not provide medical advice, diagnosis, or treatment.
- Not for emergencies—call emergency services when needed.
- We may consider FTC Health Breach Notification Rule and state breach obligations; notices would be handled per our incident process and applicable law.
15. Changes and versioning
We may update this Policy. The “Last updated” / document version above will change when we do. Material changes may require renewed in-app acknowledgement (consent versioning in the app). Continued use of the website after posting constitutes acceptance of the updated Policy where permitted by law.
16. Contact
Privacy questions and requests:
natalie@equestrolabs.com
Support hub: proofcareapp.com/support