Privacy policy
Privacy policy
Last Updated: 15th April, 2026
1. Introduction and Overview
Physicians Copilot ("the App," "we," "us," or "our") is an AI-powered clinical assistant designed exclusively for licensed healthcare professionals. It is developed and operated by Healthcare3.0 a company incorporated under the laws of Wyoming, USA. Physicians Copilot provides AI-assisted clinical decision support, medical literature search, continuing medical education resources, and a physician job-matching agent (collectively, the "Services").
This Privacy Policy describes, in comprehensive detail, how we collect, use, process, store, share, protect, and delete personal information — including sensitive professional, clinical, and financial data — when you access or use the Physicians Copilot mobile application, web application, backend API, and any related communications (collectively, the "Platform").
Physicians Copilot is intended solely for use by licensed or training healthcare professionals. It is not designed for patients, and it does not create a patient-provider relationship. If you are a patient seeking medical advice, this App is not intended for you.
If you have any questions about this Policy or our data practices, contact us at admin@physicianscopilot.com.
| IMPORTANT NOTICE REGARDING CLINICAL AND PROFESSIONAL DATA Physicians Copilot processes highly sensitive professional data, including your clinical credentials, medical licence information, board certification status, professional CV (including home address), and clinical queries that may involve patient case discussions. By using the App, you explicitly consent to the collection, processing, and transmission of this data as described in this Policy. Do not use the App to input individually identifiable patient health information (PHI under HIPAA or equivalent regulations) unless you have independently verified that doing so complies with all applicable laws and your institution's policies. |
This Policy applies to: all registered and anonymous users of the Physicians Copilot iOS and Android mobile applications, the web application at www.physicianscopilot.com, and all backend Services.
This Policy does not apply to: third-party websites, job boards, or services linked from the App. Those are governed by their own privacy policies.
2. Definitions
| Term | Definition |
|---|---|
| Personal Information / PII | Any information relating to an identified or identifiable natural person, including name, email, phone number, IP address, device identifiers, home address, and GPS coordinates. |
| Professional Data | Information relating to a user's clinical credentials, medical training, specialty, board status, licence states, provider role (MD/DO/PA/NP etc.), years of experience, and workplace details. |
| Sensitive Health / Clinical Data | Data concerning a user's physical or mental health, or data generated in the context of providing or studying clinical care, including medical chat queries, clinical audio recordings, and CV-extracted credential data. |
| CV Data | The contents of an uploaded curriculum vitae or resume document, including full legal name, work history, home address, medical credentials, licence states, board status, and any other information present in the document. |
| Data Controller | Healthcare 3.0. which determines the purposes and means of processing your personal information. |
| Data Processor | A third party that processes personal information on behalf of H3O, such as AI providers, payment processors, and cloud infrastructure providers. |
| Anonymous User | A user who accesses the App via the anonymous login endpoint without creating a registered account. Anonymous users have limited functionality. |
| Firebase UID | The unique identifier issued by Firebase Authentication, used as the primary key across all H3O systems. |
| Job Agent | The AI-powered feature within Physicians Copilot that matches users to physician job postings based on their CV-extracted professional profile, preferences, and location. |
| Subscription Tier | The access level associated with a user's active subscription: Starter, Intermediate, Advanced, Premium, or Test. |
| Shared Chat Session | A chat conversation that a user has explicitly chosen to make accessible via a shareable link, without authentication. |
3. Information We Collect
We collect information directly from you, automatically from your use of the Platform, and from third-party sources (including AI-extracted data from your uploaded CV). The following subsections provide a complete breakdown of all data collected.
3.1 Account Registration and Profile Information
| Data Category | Specific Fields | Collection Method | Required? |
|---|---|---|---|
| Registration | Email address, password (Fernet-encrypted temporarily), email verification token | Sign Up and Email verification endpoint. | Required |
| Core Profile (post-signup) | First name, last name, display name, phone number, country, language, sex, profile picture URL | Profile update endpoint | Optional |
| Professional Profile | Medical institution, role (free-text), specialization, subspecialty, level of training, years of experience (<5 / 5–10 / 10–20 / 20+), profession, professional identity, professional titles | Profile update endpoint | Optional |
| Workplace Details | Institution name, clinic/unit, facility type, city, state, country | Nested Workplace Schema in profile | Optional |
| Subscription and Billing | Stripe customer ID, subscription plan tier, subscription records (plan, start/end date, status), RevenueCat customer ID (mobile) | Payment and subscription flows | Created automatically on first payment |
| Job Agent Profile (CV-extracted) | Full name, email, medical specialty, sub-specialty, years of experience, board status, provider role (MD/DO/PA/NP/CRNA/RN/PharmD/Allied), licence states, visa status, needs-visa-sponsorship flag, home address (raw address string, city, state, ZIP, latitude, longitude), job type preferences, keyword preferences, notification cadence | Extracted from uploaded CV by Google Gemini AI; user-reviewable post-extraction | Optional (Job Agent feature) |
| Anonymous User | Firebase anonymous UID only — no email, name, or profile fields | Anonymous User endpoint. | N/A |
| CV Data — Special Notice When you upload a CV for the Job Agent feature, the entire document (including any home address, work history, credentials, and personal details contained therein) is transmitted to Google Gemini for AI-powered structured extraction. The extracted data — including your home address — is then geocoded to GPS coordinates via OpenCage Geocoding and stored in our database. Please review Section 7 for details. You may delete your CV data at any time. |
3.2 Information Collected Automatically
| Data Category | Specific Fields | Storage Location | Notes |
|---|---|---|---|
| User account metadata | IP address, timezone, geolocation (inferred), device type, browser, browser version, screen resolution | MongoDB Users.metadata (excluded from public API responses) | Captured at login/session start |
| Chat session metadata | IP address, geo-country, geo-region, device type, browser, OS version, network type, user agent, app version, SDK version, channel (web/iOS/Android), total input/output tokens, estimated billing cost, session duration | MongoDB ChatHistory.metadata | Per-session |
| Per-message metadata | IP address (stored per individual message) | MongoDB ChatHistory.messages[].metadata.ip_address | Every user message carries its own IP record |
| Distributed trace data | Firebase UID, chat ID, message count, search query text (up to 200 chars) | Google Cloud Trace (OpenTelemetry) | Exported to GCP for performance monitoring |
| Push notification tokens | FCM device token(s) | MongoDB Profiles.fcm_tokens[] | Multiple tokens per user (multi-device) |
| QR code session data | Session token, Firebase UID, status (pending/completed), expiry | MongoDB QrCodeSessions (5-minute TTL) | Transient — cross-device login only |
| Last login timestamp | Datetime of most recent login | MongoDB Users.last_login | Account management |
3.4 Transaction and Payment Data
| Data Category | Fields Stored by H3O | Payment Processor |
|---|---|---|
| Web subscription (Stripe) | Email, display name, Firebase UID, Stripe customer ID, subscription plan tier, subscription start/end/status, transaction ID, amount, plan, status, timestamp | Stripe, Inc. |
| Mobile in-app purchase (RevenueCat) | RevenueCat customer ID (mapped to Firebase UID), subscription lifecycle events (created/renewed/cancelled/expired) | RevenueCat, Inc. (via Apple App Store / Google Play) |
H3O does not store payment card numbers, bank account details, or any raw payment instrument data. All payment card processing is handled exclusively by Stripe and the respective mobile platform stores, both of which are PCI-DSS compliant.
3.5 Content You Create or Upload
| Content Type | Description | Storage |
|---|---|---|
| AI Chat Messages | Free-text clinical queries, follow-up questions, feedback (like/dislike/comment) on AI responses; may include patient case descriptions typed by the user | MongoDB ChatHistory — plain text, retained indefinitely |
| Uploaded Files (Chat) | Documents attached to chat messages — may include clinical notes, guidelines, protocols, or patient-related documents | MongoDB ChatHistory.messages[].attachments + GCS |
| CV / Resume (Job Agent) | Full CV document uploaded for AI parsing — binary PDF or DOCX stored in GCS bucket (pc_media_files/job_agent_cvs/) | GCS (public URL stored in MongoDB Profiles.cv_file_url) |
| Audio Recordings | Voice recordings submitted for transcription (clinical dictations, voice queries) | GCS temporarily; transmitted to Groq/Deepgram/Gemini for transcription |
| Shared Chat Sessions | Chat sessions explicitly shared by the user via a shareable link — the full conversation becomes accessible without authentication while the share link is active | MongoDB SharedChatSessions + linked ChatHistory |
| Warning: Shared Chat Sessions When you activate the Share feature on a chat session, the full conversation — including any clinical content, questions, and AI responses — becomes accessible to anyone with the link, without requiring login. You should not share sessions containing patient-identifiable information or sensitive clinical discussions. You can deactivate a shared session at any time by disabling the share link. |
3.6 Information We Do NOT Collect
National Provider Identifier (NPI) — not collected or verified against any external registry
Biometric data (fingerprint, Face ID) — authentication biometrics are handled entirely by your device OS
Social Security Number or government-issued ID number
Patient names, patient dates of birth, or other direct patient identifiers (we do not operate as a medical records system)
Advertising IDs or third-party advertising tracking data
Social media profile data or social graph information
4. How We Use Your Information
We use the information we collect only for the purposes described in this section. We do not sell your personal information.
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Account creation, authentication, and session management | Email, Firebase UID, password (via Firebase Auth), QR code session tokens | Performance of contract (Terms of Use) |
| Delivering AI clinical assistant features (chat, literature search, learning resources) | Chat messages, uploaded files, audio recordings — transmitted to Google Gemini | Explicit consent; performance of contract |
| CV parsing and job agent profile construction | Full CV document — transmitted to Google Gemini for structured extraction; home address transmitted to OpenCage for geocoding | Explicit consent (opt-in feature) |
| Physician job matching | Job agent profile (specialty, licence states, board status, location, preferences), matched against job postings scraped from 16 physician job boards | Explicit consent (opt-in feature) |
| Subscription and access tier management | Subscription records, Stripe/RevenueCat webhooks, subscription plan tier | Performance of contract; legitimate interest in enforcing subscription entitlements |
| Payment processing | Email, name, Firebase UID — transmitted to Stripe (web); Firebase UID — transmitted to RevenueCat (mobile) | Performance of contract |
| Push notifications (job matches, reminders, system alerts) | FCM device tokens, notification content | Consent (opt-in at registration/onboarding) |
| Transactional email (verification, payment confirmation, job match alerts, referral confirmation) | Email address, email body content — via Gmail SMTP | Performance of contract; legitimate interest |
| Distributed performance monitoring and distributed tracing | Firebase UID, chat ID, message count, search query text (up to 200 chars) — exported to Google Cloud Trace | Legitimate interest in maintaining service reliability and performance |
| Internal performance alerting | Aggregated AI performance metrics (latency, token counts, cost estimates) — sent to Discord webhook. No PII or clinical content included. | Legitimate interest in operational monitoring |
| YouTube medical education video references in chat | Derived search query (no user identifiers) — transmitted to YouTube Data API v3 | Legitimate interest in enriching AI responses with medical education content |
| Medical literature references in AI chat responses | Derived clinical search query (no user identifiers) — transmitted to PubMed/NCBI API | Legitimate interest in grounding AI responses in peer-reviewed literature |
| Fraud prevention and security | IP address, device fingerprint, Firebase UID | Legitimate interest in preventing unauthorised access |
| App improvement and product analytics | Aggregated, anonymised usage patterns from internal logs | Legitimate interest in improving the product |
5. How We Store Your Information
5.1 Storage Infrastructure
| System | Provider | Primary Data Stored | Location |
|---|---|---|---|
| Primary operational database | MongoDB Atlas (Motor async driver) | All 16 collections: Users, ChatHistory, Profiles, Jobs, UserJobMatches, JobAgents, Transactions, Certificates, AccountVerifications, QrCodeSessions, UploadedFiles, SharedChatSessions, ConversationTables, LearningResources, LearningResourceGroups, RawJobs | MongoDB Atlas cloud |
| Authentication and identity | Google Firebase Authentication | Email address, Firebase UID, account verification status, password hash (managed by Firebase) | Google Cloud |
| File and CV storage | Google Cloud Storage — bucket: pc_media_files | CV/resume binaries (job_agent_cvs/ prefix), audio recordings, uploaded document files | Google Cloud Storage |
| Push notification routing and state | Google Cloud Firestore | In-app notification records and delivery state | Google Cloud Firestore |
| Async job event messaging | Google Cloud Pub/Sub | Job-matching pipeline events (job IDs, user IDs) | Google Cloud Pub/Sub |
| Performance and trace data | Google Cloud Trace (via OpenTelemetry) | Firebase UID, chat ID, message count, search query text (up to 200 chars) | Google Cloud Trace |
| Medical knowledge vector search | Qdrant | Vector embeddings for medical knowledge base queries | Self-hosted Qdrant Cloud. |
| Caching and rate limiting | Redis | Session caches, rate limit counters (no long-term PII storage expected) | Transient (In memory). |
5.2 Data Retention
| Data Category / Collection | Retention Period | Notes |
|---|---|---|
| User profile (Users collection) | Duration of account existence; deleted on account deletion | Includes professional profile and device metadata |
| AI Chat History (ChatHistory) | Duration of account existence; deleted on account deletion. | Includes per-message IP addresses and full conversation text |
| Job Agent Profile (Profiles) | Duration of account existence; deleted on account deletion | Includes home address with GPS coordinates |
| CV File (GCS — job_agent_cvs/) | Until deleted by user or on account deletion | Binary CV document stored in GCS |
| Job Matches (UserJobMatches) | Duration of account existence | Match history and dismissal states |
| Transactions (Transactions) | Duration of account existence; may be retained longer for financial record-keeping obligations | Email, name, payment amounts |
| Account Verification Tokens (AccountVerifications) | 24-hour TTL — automatically deleted on expiry or successful verification | Temporary Fernet-encrypted password |
| QR Code Sessions (QrCodeSessions) | 5-minute TTL — automatically deleted | Transient cross-device login sessions |
| Application logs (GCP Cloud Logging) | Subject to GCP retention settings. | Contains JSON application logs including performance metrics |
| Distributed traces (GCP Cloud Trace) | Subject to GCP Cloud Trace retention policy (default 30 days) | Contains Firebase UID and chat metadata per trace |
| Firebase Authentication records | Retained until account is deleted via Firebase Admin SDK | Deleted as part of account deletion flow |
| Stripe customer records | Retained by Stripe per their data retention policy; H3O retains Stripe customer ID and subscription records indefinitely for billing history | Financial record-keeping obligations may apply |
We are actively developing automated retention and expiry policies for collections currently lacking TTL enforcement. Until those controls are deployed, data in those collections is retained for the lifetime of your account unless you request deletion as described in Section 12.
5.3 Security Measures
We implement the following security controls to protect your information:
TLS/HTTPS in Transit: All communication between your device and our backend is encrypted using TLS.
Firebase JWT Authentication: Every protected API request is authenticated via a Firebase ID token, verified server-side by FirebaseAuthMiddleware on every request. Errors handled include expired, revoked, and invalid tokens.
Password Protection: Passwords are never stored in plaintext. During the email verification window, passwords are temporarily held as Fernet-encrypted ciphertext. After verification, password management is handled entirely by Firebase Authentication.
MongoDB Atlas Encryption at Rest: All data in MongoDB Atlas is encrypted at rest using AES-256 by default.
GCS Encryption at Rest: Files stored in Google Cloud Storage are encrypted at rest by Google using AES-256.
Device Metadata Restricted from Public API: The UserMetadata subobject (IP, geolocation, device fingerprint) is explicitly excluded from public API responses via UserPublicSchema.from_document(), though it remains stored in MongoDB.
Redis Rate Limiting: Redis-based rate limiting is implemented to restrict abusive or anomalous request patterns.
6. How We Share Your Information
We do not sell or rent your personal information. The following describes every category of third-party sharing in the Physicians Copilot platform.
6.1 AI and Transcription Providers
By using the Chat, Job Agent, and Voice Transcription features, you consent to the following transmissions of your data to AI providers:
| Provider | Data Transmitted | Feature | Provider Privacy Policy |
|---|---|---|---|
| Google Gemini (Google LLC) Models: gemini-2.5-flash, gemini-2.0-flash | Full chat message history (verbatim), uploaded file contents, Firebase UID; full CV document binary (PDF/DOCX) for Job Agent parsing; audio files for transcription; medical specialty string for keyword generation | Chat AI, CV Parsing, Audio Transcription, Job Agent | https://policies.google.com/privacy |
| Groq, Inc. Model: whisper-large-v3 | Raw audio recordings (voice queries, clinical dictations) | Voice Transcription | https://groq.com/privacy-policy/ |
| Deepgram, Inc. Model: nova-3 | Raw audio recordings (voice queries, clinical dictations) | Voice Transcription (third option) | https://deepgram.com/privacy |
6.2 Payment Processors
| Provider | Data Transmitted | Purpose | Notes |
|---|---|---|---|
| Stripe, Inc. | Email address, display name, Firebase UID (in Stripe customer metadata), subscription plan and status, transaction amounts | Web subscription billing, payment intent processing, subscription lifecycle management | Stripe is PCI-DSS Level 1 certified. A Data Processing Agreement with Stripe should be confirmed. No clinical data is transmitted to Stripe. |
| RevenueCat, Inc. | RevenueCat customer ID (mapped internally to Firebase UID), subscription lifecycle events from Apple App Store and Google Play | Mobile in-app purchase subscription management | RevenueCat receives subscription events from Apple/Google. No clinical or profile data is transmitted. |
6.3 Cloud and Infrastructure Providers
| Provider | Data Shared | Purpose |
|---|---|---|
| Google Firebase Auth (Google LLC) | Email, Firebase UID, account verification status | User identity and authentication |
| Google Firebase FCM (Google LLC) | Device FCM tokens, push notification title/body | Mobile push notifications |
| Google Cloud Firestore (Google LLC) | In-app notification records | Notification state management |
| Google Cloud Storage (Google LLC) | CV binaries, audio recordings, uploaded files | File storage |
| Google Cloud Pub/Sub (Google LLC) | Job event messages (job IDs, user IDs) | Async job-matching pipeline |
| Google Cloud Trace (Google LLC) | Firebase UID, chat ID, message count, search query text (≤200 chars) | Distributed performance tracing |
| MongoDB Atlas (MongoDB, Inc.) | All structured application data across 17 collections | Primary database |
| Redis (Google Cloud Memorystore for Redis) | Session cache data, rate limit counters | Caching and rate limiting |
| Qdrant (Qdrant Cloud) | Medical knowledge base vector embeddings (not derived from user health data — based on curated medical knowledge) | Vector similarity search for AI medical knowledge retrieval |
6.4 Location and Geocoding Services
When you use the Job Agent and provide a home address for commute-based job matching, your address is transmitted to the following service:
| Provider | Data Transmitted | Purpose | Notes |
|---|---|---|---|
| OpenCage Geocoding (OpenCage GmbH) | Full residential address string (e.g. '123 Main St, Houston, TX 77001') assembled from your home address | Convert home address to GPS latitude/longitude for commute distance calculation in job matching | OpenCage's free tier retains query logs. The resulting GPS coordinates are stored in MongoDB Profiles.home_location.lat/lon. This is the highest-risk PII transmission in the system. Use of a paid plan with data retention disabled is strongly recommended. |
6.5 Healthcare Data and Research APIs
The following external APIs receive derived search queries only — no user PII or account identifiers are transmitted:
NCBI PubMed API — receives AI-derived clinical search queries to retrieve peer-reviewed medical literature references for attachment to AI chat responses. No user ID, email, or clinical context beyond the search query is transmitted.
YouTube Data API v3 (Google LLC) — receives AI-derived medical topic search queries to retrieve educational video references. Read-only access. No user data beyond the derived search query is transmitted.
6.6 Internal Monitoring
Performance metrics are sent to a private Discord channel via webhook for operational alerting. Data sent to Discord includes AI response latency, token counts, estimated billing cost, and subscription lifecycle events (e.g. 'User subscribed to Pro'). No PII, email addresses, clinical chat content, or CV data is included in these Discord notifications.
6.7 Legal and Regulatory Disclosures
We may disclose your personal information without prior notice where required by applicable law, including in response to valid court orders, subpoenas, or law enforcement requests from competent authorities in Wyoming, USA or other applicable jurisdictions; to protect the rights, safety, or property of H3O, our users, or the public; to investigate suspected fraud or illegal activity; or to comply with applicable laws and regulations. Where legally permissible, we will notify you prior to disclosure.
6.8 Corporate Transactions
In the event of a merger, acquisition, asset sale, or other corporate transaction involving H3O, your personal information may be transferred to the acquiring entity. We will provide prior notice before your data is transferred, and the acquiring entity will be required to honour this Policy or obtain fresh consent from you.
7. Third-Party Data Processors — Processing Agreements
All third-party service providers that process your personal information on H3O's behalf are required to handle that data in accordance with applicable data protection law. The following table reflects known DPA status as of the policy effective date:
| Provider | Role | DPA / Compliance Status | Key Notes |
|---|---|---|---|
| Google LLC (Firebase, Gemini, GCS, Firestore, Pub/Sub, Cloud Trace, FCM, YouTube API) | Data Processor (multiple services) | Google Cloud Data Processing Addendum — available at cloud.google.com/terms/data-processing-addendum | Gemini API usage involving PHI-class data requires specific contractual coverage. Confirm BAA eligibility if HIPAA obligations apply. |
| MongoDB, Inc. | Data Processor | MongoDB DPA pending. | MongoDB Atlas is SOC 2 Type II certified. Encryption at rest is enabled by default. |
| Stripe, Inc. | Data Processor (payment) | Stripe DPA pending. | Stripe is PCI-DSS Level 1. Email and name transmitted — DPA should cover this. No clinical data transmitted. |
| RevenueCat, Inc. | Data Processor (mobile payments) | RevenueCat DPA pending. | Receives only subscription lifecycle events and customer ID. No clinical data. |
| Groq, Inc. | Data Processor (audio transcription) | Groq DPA pending. | Raw audio recordings of clinical dictations transmitted. DPA required. |
| Deepgram, Inc. | Data Processor (audio transcription) | Deepgram DPA / BAA pending | Deepgram offers a BAA for HIPAA-covered entities. Clinical audio transmitted. Confirm coverage. |
| OpenCage GmbH | Data Processor (geocoding) | OpenCage DPA pending. | Full residential home address transmitted. Free-tier retains query logs. Paid plan recommended. |
| Qdrant (Qdrant Cloud) | Data Processor (vector search) | Qdrant DPA Pending | Medical knowledge base embeddings — confirm whether any user-derived vectors are stored here. |
| Redis (Google Cloud Memorystore for Redis) | Data Processor (caching) | Redis provider DPA pending | Session and rate limit data. Confirm no PII cached long-term. |
8. Anonymous Users
Physicians Copilot supports anonymous (guest) access via the endpoint POST /api/v1/auth/login/anonymous-user. Anonymous users are assigned a Firebase anonymous UID and may access certain features without providing an email address or creating a full account.
The following applies to anonymous users:
No email address, name, or professional profile is collected at login.
An anonymous Firebase UID is generated and used to associate any data generated during the session.
If an anonymous user creates chat sessions, those sessions are stored in MongoDB ChatHistory under the anonymous UID, including per-message IP addresses and device metadata.
Anonymous users may not access subscription-gated features or the Job Agent.
Anonymous accounts can be deactivated. There is no automatic expiry of anonymous account data.
If you convert an anonymous account to a registered account, your session history may be associated with the new registered account.
If you used Physicians Copilot anonymously and wish to have your data deleted, you may contact admin@physicianscopilot.com with a description of the sessions and approximate timeframe.
9. QR Code Login and Cross-Device Sessions
Physicians Copilot offers a QR code-based cross-device login flow, allowing a user authenticated on a mobile device to log in on a web browser by scanning a QR code displayed on the web interface.
The following data is processed during QR login:
A session token is generated and stored in MongoDB QrCodeSessions with a 5-minute expiry (TTL).
Your Firebase UID is associated with the session token when you authenticate via mobile.
The web client listens for authentication completion via Server-Sent Events (SSE).
On completion, the session record is marked as 'completed' and a Firebase custom token is issued to the web client.
Session records are automatically deleted after 5 minutes regardless of completion status.
No additional personal data beyond your Firebase UID is transmitted or stored during QR login.
10. Cookies and Tracking Technologies
10.1 Mobile Application
The Physicians Copilot mobile app does not use browser cookies. Device-level data collected includes:
FCM Device Tokens: Unique per-device identifiers used exclusively for push notifications. Stored in MongoDB Profiles.fcm_tokens[]. Multiple tokens may be stored if you use more than one device.
Device Fingerprint: Device type, OS version, browser (if web), screen resolution, and user agent are collected and stored as part of account and session metadata for debugging and security purposes.
Firebase Authentication Tokens: JWT session tokens managed by the Firebase SDK. Not stored by H3O beyond the active request.
10.2 Web Application
If you access Physicians Copilot through a web browser:
Firebase Web SDK may store authentication session tokens in browser memory or local storage for session persistence.
OpenTelemetry instrumentation captures all HTTP requests for distributed tracing, including the request path, user ID, and response time. These traces are exported to Google Cloud Trace.
No advertising networks, retargeting pixels, or third-party marketing cookies are used.
No third-party analytics SDK (e.g. Google Analytics, Mixpanel, Amplitude) is installed. All usage insights are derived from internal application logs.
11. Your Rights and Choices
Depending on your jurisdiction, you may have the following rights regarding your personal information. To exercise any right, contact admin@physicianscopilot.com. We will respond to all verifiable requests within 30 days.
| Right | Description | How to Exercise |
|---|---|---|
| Right of Access | Request confirmation of whether we hold your personal data and receive a copy. | Email admin@physicianscopilot.com Subject: 'Data Access Request' |
| Right to Rectification | Correct inaccurate or incomplete personal data. | Update via App Profile Settings, or email admin@physicianscopilot.com |
| Right to Erasure | Request deletion of your personal data where it is no longer necessary, or where you withdraw consent. | Use 'Delete Account' in App Settings, or email admin@physicianscopilot.com — Subject: 'Account Deletion Request' |
| Right to Restrict Processing | Request that we limit how your data is used while accuracy is disputed or an objection is pending. | Email admin@physicianscopilot.com |
| Right to Data Portability | Receive a machine-readable copy of data you provided, where processing is based on consent or contract. | Email admin@physicianscopilot.com — Subject: 'Data Portability Request' |
| Right to Object | Object to processing based on legitimate interests, including profiling (e.g. job matching algorithms). | Email admin@physicianscopilot.com |
| Right to Withdraw Consent | Withdraw consent for consent-based processing at any time. This does not affect prior lawful processing. | Delete your account or email admin@physicianscopilot.com |
| Right to Opt Out of Job Agent | Stop the Job Agent from processing your CV and running job matches, without deleting your account. | Disable Job Agent in App Settings |
| Right to Deactivate Shared Chat Sessions | Revoke public access to any shared chat session. | Toggle share link off within the App |
| Right to Lodge a Complaint | Lodge a complaint with the relevant data protection supervisory authority. | Wyoming Data Protection Authority |
We will not discriminate against you for exercising any of these rights. Requests that are manifestly unfounded or repetitive may be subject to an administrative fee, in which case we will notify you in advance.
12. Account Deletion and Data Deletion
| Data / Collection | Deletion Action | Timeframe |
|---|---|---|
| MongoDB Users document | Hard-deleted | Within 30 days |
| MongoDB ChatHistory sessions | Hard-deleted (all sessions for the user) | Within 30 days |
| MongoDB Profiles / job_agent_profiles | Hard-deleted | Within 30 days |
| MongoDB UserJobMatches | Hard-deleted | Within 30 days |
| MongoDB JobAgents | Hard-deleted | Within 30 days |
| MongoDB Transactions | Hard-deleted (subject to financial record-keeping obligations) | Within 30 days, unless retention required by law |
| MongoDB Certificates | Hard-deleted | Within 30 days |
| MongoDB SharedChatSessions | Hard-deleted; shared links deactivated immediately | Immediate deactivation; document deleted within 30 days |
| MongoDB UploadedFiles metadata | Hard-deleted | Within 30 days |
| GCS CV file (job_agent_cvs/) | Deleted from GCS bucket | Within 30 days |
| GCS audio recordings and uploaded files | Deleted from GCS bucket | Within 30 days |
| Firebase Authentication record | Deleted via Firebase Admin SDK | Immediate on request processing |
| Google Cloud Firestore notifications | Deleted | Within 30 days |
| GCP Cloud Trace spans | Subject to GCP Cloud Trace retention policy (default 30 days). Not individually deletable from trace stream. | Auto-expires per GCP policy |
| Application logs (GCP Cloud Logging) | Subject to GCP log retention settings. Not individually deletable. | Auto-expires per GCP policy |
| Stripe customer record | H3O requests Stripe customer deletion; Stripe may retain records per their own legal obligations. | 30 days (H3O-side); Stripe's policy applies to their records |
To request account deletion, use the 'Delete Account' function in App Settings or email admin@physicianscopilot.com with the subject line 'Account Deletion Request' from the email address associated with your account. We will confirm completion within 30 days.
13. Data Breach Notification
In the event of a personal data breach that is likely to result in risk to the rights and freedoms of affected individuals, H3O will:
Notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, where required by applicable law;
Notify affected users directly, without undue delay, where the breach is likely to result in high risk to their rights and freedoms;
Include in any notification: the nature of the breach, the categories and approximate number of individuals affected, the likely consequences, and the measures taken or proposed.
Given that Physicians Copilot stores highly sensitive professional data — including home addresses with GPS coordinates, CV documents, and clinical chat content — we classify data breaches involving this system as high-priority incidents and maintain a documented incident response procedure.
14. International Data Transfers
H3O is based in Wyoming, USA. Our cloud infrastructure and third-party processors operate in multiple countries, primarily the United States, and potentially others depending on Google Cloud regional configuration. By using Physicians Copilot, your personal information — including sensitive professional and clinical data — may be transferred to and processed in countries outside your country of residence.
Where we transfer personal data internationally, we rely on the following safeguards:
Standard Contractual Clauses (SCCs) or equivalent transfer mechanisms, where required by applicable law;
Data Processing Agreements with service providers incorporating appropriate international transfer protections;
The adequacy of data protection in the destination country, where applicable.
For users in jurisdictions with specific international transfer requirements (EEA, UK, Nigeria under NDPA), please contact admin@physicianscopilot.com for details of the applicable safeguards.
15. Children's Privacy
Physicians Copilot is intended exclusively for licensed healthcare professionals and medical trainees aged 18 and over. We do not knowingly collect personal information from anyone under 18. If we become aware that we have inadvertently collected data from a minor, we will delete that data within 30 days. Please contact admin@physicianscopilot.com if you believe a minor has accessed the service.
16. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices, technology, legal obligations, or new features. When we make material changes, we will:
Update the 'Last Updated' date at the top of this document;
Notify you via a prominent in-app notification and/or email at least 14 days before changes take effect;
Obtain fresh explicit consent for material changes affecting how sensitive professional or clinical data is processed.
Continued use of Physicians Copilot after the effective date constitutes acceptance of the revised Policy. If you do not agree, you may discontinue use and request account deletion as described in Section 12. All prior versions of this Policy are archived and available on request from admin@physicianscopilot.com.
17. Contact Information
| Contact Type | Details |
|---|---|
| Privacy Inquiries & Data Subject Requests | admin@physicianscopilot.com |
| Company Legal Name | Healthcare 3.0 LLC |
| Registered Address | Wyoming, USA |
| Data Protection Officer | Privacy inquiries are directed to the founding team. |
| Response Commitment | We aim to respond to all privacy-related enquiries within 10 business days. |
This Privacy Policy was drafted specifically for Physicians Copilot, a product of Healthcare 3.0 LLC. It reflects the actual data architecture, authentication systems, third-party integrations, and data flows of the application as audited on 15th April, 2026. It is a standalone document separate from the My Health Diary Privacy Policy.
Physicians Copilot Privacy Policy | Healthcare 3.0 LLC | Version 1.0 | Effective 15th April, 2026.