Privacy Policy
POTS Compass ("the App," "we," "our") is an educational web application for people with POTS or POTS-like symptoms. This Privacy Policy explains what data we handle, how we handle it, and what choices you have.
1. Who we are
POTS Compass is operated by Spangler Development LLC, based in North Carolina, USA. Contact: support@spanglerdevelopment.com.
2. The short version
- Almost everything you put into POTS Compass (symptom notes, visit prep, care plan, health data) stays on your device. We never see it.
- When you talk with Emery (our AI coach), your messages are sent to Anthropic's Claude API to generate a response. We do not link those messages to your name or email.
- We log a small set of anonymous safety events (when Emery recommends urgent care). These contain no message content and no identifiers.
- If you submit beta feedback, we store what you wrote (and your email only if you choose to include it).
- We store a record of your beta consent acknowledgment under a random per-device identifier, not your name.
- The web version counts visits anonymously — no cookies, no cross-site tracking, no identifiers.
- We do not sell your data. We do not show ads.
3. What data we handle, and where it lives
3a. Local-only data (stays on your device)
The following are stored exclusively on the device you're using — in your browser's IndexedDB on the web, or in the app's local storage in the iOS and Android apps. We do not see, transmit, or store this data on a server:
- Your symptom notes and entries
- Visit prep responses and questions
- Care plan items and reminder schedules
- Health readings you connect in the iOS and Android apps — heart rate, heart rate variability, resting heart rate, sleep, and steps from Apple Health (iOS) or Health Connect (Android). These are read with your permission, stay on your device, and are never uploaded. You can revoke access anytime in your device's health settings.
- Imported health data (e.g., Apple Health export)
- Demo wearable data
- Provider/insight content
- Your preferences (language, theme, etc.)
If you clear your browser data or uninstall the app, this data is deleted. Because we never receive this data, we also have no technical means to recover it for you — once it is gone from your device, it is gone. Use Settings → Your data → Export to keep your own backup.
3b. Data sent to Anthropic when you use Emery
When you send a message to Emery:
- Your message text and the conversation history for that session are sent to Anthropic's Claude API in order to generate a response.
- We do not attach your name, email, IP, account ID, or any other identifier to those requests beyond what is required for the API to function.
- Anthropic's handling of API data is governed by Anthropic's Privacy Policy and Commercial Terms.
3c. Anonymous safety events
When Emery responds to your message with an urgent-care recommendation, we log a single row to our database containing:
- A timestamp (set by the server, not your device)
- A coarse length bucket of your message ("short", "medium", "long")
- The conversation turn number
- An event type label (e.g. "urgent_care_recommendation")
We do not log: your message content, your name, email, IP address, location, device fingerprint, or any other identifier.
We use this data to monitor whether the safety system is firing as expected and to detect abuse.
3d. Beta feedback you submit
If you use the in-app Feedback form, we store what you submit in our database:
- Your feedback message and category (bug, idea, etc.)
- An optional 1–5 rating
- Your email address, only if you choose to provide it so we can follow up
- The area of the app you were in, the app version, and your browser's user-agent string
We use feedback to improve the app. We will not quote you publicly without asking you first.
3e. Beta consent records
When you acknowledge the beta terms, we store a record of that acknowledgment in our database: the consent version you saw, the date, and whether you opted in to marketing-quote outreach. This record is tied to a randomly generated per-device identifier (created via anonymous authentication), not to your name, email, or any of your health data. We keep these records as the audit trail of what each user agreed to.
To prevent automated abuse, this step is protected by hCaptcha, which runs an invisible bot check in your browser. hCaptcha's processing is governed by hCaptcha's Privacy Policy. We do not receive any data from hCaptcha beyond pass/fail.
3f. Weather (optional)
If you turn on the weather feature, your device sends your approximate coordinates directly to Open-Meteo (a weather data provider) to fetch the forecast. We do not receive or store your location on our servers. Your saved location preference stays on your device.
3g. Anonymous visit analytics (web version)
The web version of the App uses Vercel Web Analytics to understand how many people visit and which pages they view. This tool is cookieless and does not track you across sites. It records aggregate, anonymized information such as page views, country, device type, browser, and referring site; visitors are counted using a temporary hash that cannot be tied back to you and is discarded after 24 hours. We never see your identity, and none of your health data is involved. Vercel's processing is governed by Vercel's Privacy Policy. The iOS and Android apps do not include this analytics tool.
3h. Server logs
When your browser communicates with our backend (/api/chat, /api/safety-event, /api/feedback) or our database provider (Supabase), the hosting providers (Vercel, Supabase) automatically record standard server logs that may include your IP address and user agent for a short retention window. We do not link these logs to your identity or to your symptom data.
4. What we do not do
- We do not sell or rent your data.
- We do not show third-party ads.
- We do not use your data to train AI models.
- We do not share your data with insurance companies, employers, or marketers.
- We do not use advertising or tracking SDKs. There is no Google Analytics, no Meta/Facebook SDK, no ad network, and no crash-reporting service in the App.
- We do not have a clinician-patient relationship with you, and we are not HIPAA-covered.
5. Children's privacy
POTS Compass is intended for users aged 13 and older. If you believe a child under 13 has used the app, please contact us at support@spanglerdevelopment.com and we will take appropriate action.
6. International users
If you use the App from outside the United States, your AI requests are processed by Anthropic's infrastructure in the United States. By using the App, you understand and consent to this transfer.
7. Consumer health data (Washington and similar state laws)
Some U.S. states — including Washington (My Health My Data Act), Nevada, and Connecticut — give consumers specific rights over "consumer health data." We apply the same practices to everyone, regardless of state:
- What we collect and why is described in full in Section 3. Almost all health data stays on your device and never reaches us.
- We do not sell consumer health data, and we do not share it for advertising. No exceptions.
- The only server-side records we hold are the ones in Sections 3c–3e: anonymous safety events (which contain no identifiers and cannot be linked to any person, so they cannot be produced or deleted on a per-person basis), beta consent records (tied to a random per-device identifier), and feedback you choose to submit.
- To exercise access or deletion rights over server-side records, contact support@spanglerdevelopment.com. For data on your device, you are already in full control: Settings → Your data.
8. Your choices
- Export: You can export your local data at any time from Settings → Your data → Export.
- Delete: You can clear all local data from Settings → Your data → Clear all. You can also clear your browser's site data.
- Disable AI: Don't use the Emery tab. The rest of the app works without sending anything to a server.
- Weather: The weather feature is off by default. If you never enable it, no location data is ever requested or sent.
9. Security
We use HTTPS for all network communication. The Anthropic API key required to communicate with Claude is held only on our server, never exposed to your browser. No system is perfectly secure, and we cannot guarantee that data sent over the internet will never be intercepted.
10. If POTS Compass shuts down or changes hands
If we ever discontinue POTS Compass, or if it is acquired or transferred to another operator, your health data is unaffected — it lives on your device and stays there no matter what happens to us. Before any such change, we will notify users in the App, delete server-side records that are no longer needed, and give you the chance to export your data. Any successor operator would be bound by this policy until it is changed with notice under Section 11.
11. Changes to this policy
We may update this policy. If we make material changes, we will note them on this page with a new effective date. Continued use of the App after a change indicates acceptance of the new policy.
12. Contact
Questions about this policy: support@spanglerdevelopment.com