Privacy Policy
Access Diagnosis (“we,” “us,” or “our”) respects your privacy. This Privacy Policy explains how we collect, use, and protect your information when you use our website, application, or related services (collectively, the “Service”).
- Purpose of the App
Access Diagnosis is an educational and professional tool designed to assist clinicians, students, and educators in clinical reasoning and diagnostic framework development. It is not intended for personal medical advice, diagnosis, or treatment. The app does not collect, process, or store any protected health information (PHI) or personally identifiable medical data about patients. - Information We Collect
We collect only the minimal information necessary to operate and maintain your account.
Account Information
When you create an account, we collect:
- Name
- Email address
- Password (securely hashed and encrypted)
Subscription Information
When subscribing to a plan, we collect payment-related information through Stripe, our secure payment processor. Stripe manages all payment credentials according to PCI-DSS standards. We do not store your credit card or payment details.
Usage Information
- When you use the search or AI framework features, your queries (e.g., “chest pain,” “elevated ALT”) are processed temporarily to generate a response.
- These queries are not stored in identifiable form after processing.
- Aggregated, non-identifiable analytics (e.g., total searches per day) may be collected to improve service performance.
- Communications If you contact us (for support, feedback, or newsletters), we may store your email address and correspondence to respond effectively.
3. How We Use Your Information
We use the limited data we collect to:
- Provide and maintain your account and subscription.
- Deliver and improve the Service’s features and user experience.
- Communicate updates, account changes, or service notices.
- Ensure system security and compliance with applicable laws.
4. Data Sharing and Disclosure
We do not sell, rent, or trade your personal information. We may share data only in the following limited circumstances:
- Service Providers: Trusted vendors (e.g., Stripe, hosting providers) who assist in operating the Service, bound by confidentiality agreements.
- Legal Compliance: When required by law, regulation, or valid legal request.
We DO NOT share any identifiable usage or query data with third parties.
5. Cookies and Tracking Technologies
We use cookies and similar technologies to operate the Service and maintain your session. The following describes the cookies currently set when you use Access Diagnosis:
| Cookie Name | Purpose | Duration | Set By | Category |
| Session ID | Identifies your current session to keep you logged in while using the app | Expires when browser closes | Bubble (platform) | Strictly Necessary |
| Session Signature | Ensures session integrity and prevents unauthorized tampering with your session | Expires when browser closes | Bubble (platform) | Strictly Necessary |
| User Identifier | Identifies your logged-in account for authentication purposes | Duration of active session | Bubble (platform) | Strictly Necessary |
| Payment Session | Manages your checkout session during subscription purchase | Duration of transaction | Stripe, Inc. | Strictly Necessary |
All cookies listed above are strictly necessary for the operation of the Service. They do not track your behavior across other websites, are not used for advertising, and do not share your data with third parties for marketing purposes.
If we add analytics tools or other integrations that set additional cookies in the future, we will update this table before doing so.
Disabling cookies. You may disable cookies in your browser settings. Because all cookies we use are essential to authentication and session management, disabling them will prevent you from logging in to the Service.
Do Not Track. We do not currently respond to Do Not Track signals from browsers. If this changes, we will update this Policy accordingly.
Third-party cookies. Stripe, Inc. may set its own cookies in connection with payment processing. These are governed by Stripe’s privacy policy, available at stripe.com/privacy. Bubble.io’s cookie practices for the underlying platform are described at manual.bubble.io.
6. Data Retention
- Account data (name, email, subscription) is retained as long as your account is active.
- You may delete your account at any time, and all associated data will be permanently deleted within 30 days.
- Temporary AI queries are deleted automatically after processing or anonymized for internal service performance metrics.
- Aggregated, non-identifiable analytics data may be retained for up to 24 months.
7. Security
We implement administrative, technical, and physical safeguards to protect your data from unauthorized access, disclosure, or misuse. Passwords are encrypted, and all connections use SSL/TLS encryption.
8. Your Rights
Depending on your location, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request that we correct inaccurate or incomplete information.
- Deletion: Request that we delete your personal information, subject to certain legal exceptions.
- Portability: Request your data in a structured, machine-readable format.
- Withdrawal of consent: Where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
- Restriction: Request that we restrict processing of your information in certain circumstances.
- Objection: Object to processing of your information where we rely on legitimate interests as the legal basis.
To exercise any of these rights, contact us at info.accessdiagnosis@proton.me. We will respond to verified requests within 45 days. Where reasonably necessary, we may extend this period by an additional 45 days and will notify you of the extension within the initial 45-day window.
We will not discriminate against you for exercising any of these rights.
California Residents — CCPA/CPRA
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you additional rights. In the past 12 months, we have collected the following categories of personal information:
- Identifiers: Name, email address
- Commercial information: Subscription and billing records (managed by Stripe)
- Internet or network activity: Aggregate, non-identifiable usage analytics
We collect this information for the following business purposes: to provide and maintain your account, process payments, improve the Service, and comply with legal obligations.
We do not sell or share your personal information for cross-context behavioral advertising.
We do not use or disclose sensitive personal information for purposes other than those specified in this Policy.
To submit a CCPA request, contact us at info.accessdiagnosis@proton.me. You may designate an authorized agent to make a request on your behalf by providing written authorization. We will verify your identity before processing any request. We will respond within 45 days of receiving a verifiable request.
For more information about your California privacy rights, visit oag.ca.gov/privacy/ccpa.
9. GDPR — European Users
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) or applicable equivalent law may apply to our processing of your personal information.
Our role. All In Together Now acts as the Data Controller for personal information collected through Access Diagnosis — meaning we determine the purposes and means of processing your data. Bubble.io acts as our Data Processor, operating the technical infrastructure on which the app runs. Stripe, Inc. and our AI model provider act as additional Data Processors for payment and query processing respectively. Each processor is bound by a Data Processing Agreement (DPA) governing how they handle your data.
Legal basis for processing. We process your personal information on the following legal bases:
- Performance of a contract (Article 6(1)(b)): Processing your name, email, and subscription information is necessary to provide you with access to the Service.
- Legitimate interests (Article 6(1)(f)): We process aggregate, non-identifiable usage analytics to improve the Service. We have assessed that this interest is not overridden by your fundamental rights and freedoms.
- Legal obligation (Article 6(1)(c)): We may process your information where required to comply with applicable law.
Your GDPR rights. In addition to the rights described in Section 8, EEA and UK users have the right to lodge a complaint with your local data protection supervisory authority. A list of EU supervisory authorities is available at edpb.europa.eu. UK users may contact the Information Commissioner’s Office at ico.org.uk.
International data transfers. Our servers are located in the United States. Bubble.io has incorporated Standard Contractual Clauses (SCCs) into its Data Processing Agreements and participates in the EU-US Data Privacy Framework as a transfer mechanism for personal data from the EEA to the US. These measures are designed to ensure your personal data receives equivalent protection to that required within the EU. You may request information about the applicable transfer safeguards by contacting us at info.accessdiagnosis@proton.me.
Data breach notification. Under GDPR, we are required to notify the relevant supervisory authority of a personal data breach within 72 hours of becoming aware of it, where feasible, and to notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. See Section 11 for our full breach notification policy.
Data Protection Contact. For GDPR-related inquiries, contact us at info.accessdiagnosis@proton.me. We do not currently have a designated EU Data Protection Officer. Based on the nature and scale of our data processing, we do not believe we meet the threshold requiring a DPO under Article 37 GDPR. If our processing activities change in a way that triggers this requirement, we will appoint a DPO and update this Policy.
Retention periods. We retain your personal data only as long as necessary for the purposes described in this Policy. Account data is retained for the duration of your account and deleted within 30 days of account closure. Aggregate analytics data may be retained for up to 24 months.
10. Artificial Intelligence Disclosure
Access Diagnosis uses artificial intelligence (AI) technology, including large language model APIs, to generate diagnostic framework outputs in response to your queries. You should be aware of the following:
- AI-generated content. The responses you receive are generated by an AI model and have not been individually reviewed by a licensed healthcare professional for your specific query.
- Potential for error. AI models may produce inaccurate, incomplete, or outdated information. Outputs should always be corroborated with current clinical standards of care and your own professional judgment.
- No patient-specific analysis. The AI has no knowledge of any individual patient’s circumstances. Outputs are generalized educational frameworks and must not be applied to individual patients without independent clinical evaluation.
- Query data. Queries you enter are transmitted to our AI model provider for processing. Queries are processed in real time and are not stored in identifiable form after a response is generated. We have data processing agreements in place with our AI provider governing the handling of this data.
- AI provider. We currently use OpenAI’s API to power the diagnostic framework feature. OpenAI’s privacy practices are available at openai.com/privacy. We may change AI providers in the future and will update this disclosure accordingly.
- Feedback and improvement. We may use aggregated, non-identifiable query patterns to improve the Service. We will not use your individual queries to train AI models without separate disclosure and, where required, your consent.
11. Data Breach Notification
In the event of a security incident involving unauthorized access to, or disclosure of, your personal information, we will take the following steps:
- Contain and assess the incident as quickly as possible upon discovery.
- Notify affected users via email to the address on your account within the timeframe required by applicable law. Under Arizona law (A.R.S. §18-552), notification is required within 45 days of discovery of a breach involving Arizona residents’ unencrypted personal information. Under GDPR, we will notify the relevant supervisory authority within 72 hours of becoming aware of a breach. We will comply with the most stringent applicable requirement.
- Notify applicable regulators as required by law, including state attorneys general and EU supervisory authorities where mandated.
- Provide information about what data was affected, what steps we have taken, and what you can do to protect yourself.
If you believe your account has been compromised, contact us immediately at info.accessdiagnosis@proton.me.
We maintain a written incident response plan and conduct periodic security reviews to minimize the risk of a breach.
12. Children’s Privacy
Access Diagnosis is intended for professional and educational use by individuals aged 18 and older. We do not knowingly collect or maintain data from anyone under 18.
13. International Users
Our servers are located in the United States. If you access the Service from outside the U.S., your information may be transferred to and processed in the U.S. European users should refer to Section 9 for specific information about GDPR protections and transfer mechanisms applicable to their data.
14. Updates to This Policy
We may update this Privacy Policy periodically. Changes will be posted with a revised effective date. Continued use of the Service after updates constitutes acceptance of the revised policy.
15. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact:
Access Diagnosis
Email: info.accessdiagnosis@proton.me
Website: https://www.allintogethernow.org/accessdiagnosis
———————————————————————————————————————————————-
Version History
v1.0 — May 5, 2025: Initial publication
v2.0 — June 2026: Added Cookies table (Section 5), expanded CCPA/CPRA rights (Section 8), added GDPR section (Section 9), added AI Disclosure (Section 10), added Data Breach Notification (Section 11), strengthened update notification policy (Section 14). Data sharing section updated to reference DPAs. International users section updated to reference GDPR section.