Physicians' Copilot

Privacy policy

Last Updated: 15th April, 2026

1. Introduction and Overview

Physicians Copilot ("the App," "we," "us," or "our") is an AI-powered clinical assistant designed exclusively for licensed healthcare professionals. It is developed and operated by Healthcare3.0 a company incorporated under the laws of Wyoming, USA. Physicians Copilot provides AI-assisted clinical decision support, medical literature search, continuing medical education resources, and a physician job-matching agent (collectively, the "Services").

This Privacy Policy describes, in comprehensive detail, how we collect, use, process, store, share, protect, and delete personal information — including sensitive professional, clinical, and financial data — when you access or use the Physicians Copilot mobile application, web application, backend API, and any related communications (collectively, the "Platform").

Physicians Copilot is intended solely for use by licensed or training healthcare professionals. It is not designed for patients, and it does not create a patient-provider relationship. If you are a patient seeking medical advice, this App is not intended for you.

If you have any questions about this Policy or our data practices, contact us at admin@physicianscopilot.com.

IMPORTANT NOTICE REGARDING CLINICAL AND PROFESSIONAL DATA Physicians Copilot processes highly sensitive professional data, including your clinical credentials, medical licence information, board certification status, professional CV (including home address), and clinical queries that may involve patient case discussions. By using the App, you explicitly consent to the collection, processing, and transmission of this data as described in this Policy. Do not use the App to input individually identifiable patient health information (PHI under HIPAA or equivalent regulations) unless you have independently verified that doing so complies with all applicable laws and your institution's policies.

This Policy applies to: all registered and anonymous users of the Physicians Copilot iOS and Android mobile applications, the web application at www.physicianscopilot.com, and all backend Services.

This Policy does not apply to: third-party websites, job boards, or services linked from the App. Those are governed by their own privacy policies.

2. Definitions

TermDefinition
Personal Information / PIIAny information relating to an identified or identifiable natural person, including name, email, phone number, IP address, device identifiers, home address, and GPS coordinates.
Professional DataInformation relating to a user's clinical credentials, medical training, specialty, board status, licence states, provider role (MD/DO/PA/NP etc.), years of experience, and workplace details.
Sensitive Health / Clinical DataData concerning a user's physical or mental health, or data generated in the context of providing or studying clinical care, including medical chat queries, clinical audio recordings, and CV-extracted credential data.
CV DataThe contents of an uploaded curriculum vitae or resume document, including full legal name, work history, home address, medical credentials, licence states, board status, and any other information present in the document.
Data ControllerHealthcare 3.0. which determines the purposes and means of processing your personal information.
Data ProcessorA third party that processes personal information on behalf of H3O, such as AI providers, payment processors, and cloud infrastructure providers.
Anonymous UserA user who accesses the App via the anonymous login endpoint without creating a registered account. Anonymous users have limited functionality.
Firebase UIDThe unique identifier issued by Firebase Authentication, used as the primary key across all H3O systems.
Job AgentThe AI-powered feature within Physicians Copilot that matches users to physician job postings based on their CV-extracted professional profile, preferences, and location.
Subscription TierThe access level associated with a user's active subscription: Starter, Intermediate, Advanced, Premium, or Test.
Shared Chat SessionA chat conversation that a user has explicitly chosen to make accessible via a shareable link, without authentication.

3. Information We Collect

We collect information directly from you, automatically from your use of the Platform, and from third-party sources (including AI-extracted data from your uploaded CV). The following subsections provide a complete breakdown of all data collected.

3.1 Account Registration and Profile Information

Data CategorySpecific FieldsCollection MethodRequired?
RegistrationEmail address, password (Fernet-encrypted temporarily), email verification tokenSign Up and Email verification endpoint.Required
Core Profile (post-signup)First name, last name, display name, phone number, country, language, sex, profile picture URLProfile update endpointOptional
Professional ProfileMedical institution, role (free-text), specialization, subspecialty, level of training, years of experience (<5 / 5–10 / 10–20 / 20+), profession, professional identity, professional titlesProfile update endpointOptional
Workplace DetailsInstitution name, clinic/unit, facility type, city, state, countryNested Workplace Schema in profileOptional
Subscription and BillingStripe customer ID, subscription plan tier, subscription records (plan, start/end date, status), RevenueCat customer ID (mobile)Payment and subscription flowsCreated automatically on first payment
Job Agent Profile (CV-extracted)Full name, email, medical specialty, sub-specialty, years of experience, board status, provider role (MD/DO/PA/NP/CRNA/RN/PharmD/Allied), licence states, visa status, needs-visa-sponsorship flag, home address (raw address string, city, state, ZIP, latitude, longitude), job type preferences, keyword preferences, notification cadenceExtracted from uploaded CV by Google Gemini AI; user-reviewable post-extractionOptional (Job Agent feature)
Anonymous UserFirebase anonymous UID only — no email, name, or profile fieldsAnonymous User endpoint.N/A
CV Data — Special Notice When you upload a CV for the Job Agent feature, the entire document (including any home address, work history, credentials, and personal details contained therein) is transmitted to Google Gemini for AI-powered structured extraction. The extracted data — including your home address — is then geocoded to GPS coordinates via OpenCage Geocoding and stored in our database. Please review Section 7 for details. You may delete your CV data at any time.

3.2 Information Collected Automatically

Data CategorySpecific FieldsStorage LocationNotes
User account metadataIP address, timezone, geolocation (inferred), device type, browser, browser version, screen resolutionMongoDB Users.metadata (excluded from public API responses)Captured at login/session start
Chat session metadataIP address, geo-country, geo-region, device type, browser, OS version, network type, user agent, app version, SDK version, channel (web/iOS/Android), total input/output tokens, estimated billing cost, session durationMongoDB ChatHistory.metadataPer-session
Per-message metadataIP address (stored per individual message)MongoDB ChatHistory.messages[].metadata.ip_addressEvery user message carries its own IP record
Distributed trace dataFirebase UID, chat ID, message count, search query text (up to 200 chars)Google Cloud Trace (OpenTelemetry)Exported to GCP for performance monitoring
Push notification tokensFCM device token(s)MongoDB Profiles.fcm_tokens[]Multiple tokens per user (multi-device)
QR code session dataSession token, Firebase UID, status (pending/completed), expiryMongoDB QrCodeSessions (5-minute TTL)Transient — cross-device login only
Last login timestampDatetime of most recent loginMongoDB Users.last_loginAccount management

3.4 Transaction and Payment Data

Data CategoryFields Stored by H3OPayment Processor
Web subscription (Stripe)Email, display name, Firebase UID, Stripe customer ID, subscription plan tier, subscription start/end/status, transaction ID, amount, plan, status, timestampStripe, Inc.
Mobile in-app purchase (RevenueCat)RevenueCat customer ID (mapped to Firebase UID), subscription lifecycle events (created/renewed/cancelled/expired)RevenueCat, Inc. (via Apple App Store / Google Play)

H3O does not store payment card numbers, bank account details, or any raw payment instrument data. All payment card processing is handled exclusively by Stripe and the respective mobile platform stores, both of which are PCI-DSS compliant.

3.5 Content You Create or Upload

Content TypeDescriptionStorage
AI Chat MessagesFree-text clinical queries, follow-up questions, feedback (like/dislike/comment) on AI responses; may include patient case descriptions typed by the userMongoDB ChatHistory — plain text, retained indefinitely
Uploaded Files (Chat)Documents attached to chat messages — may include clinical notes, guidelines, protocols, or patient-related documentsMongoDB ChatHistory.messages[].attachments + GCS
CV / Resume (Job Agent)Full CV document uploaded for AI parsing — binary PDF or DOCX stored in GCS bucket (pc_media_files/job_agent_cvs/)GCS (public URL stored in MongoDB Profiles.cv_file_url)
Audio RecordingsVoice recordings submitted for transcription (clinical dictations, voice queries)GCS temporarily; transmitted to Groq/Deepgram/Gemini for transcription
Shared Chat SessionsChat sessions explicitly shared by the user via a shareable link — the full conversation becomes accessible without authentication while the share link is activeMongoDB SharedChatSessions + linked ChatHistory
Warning: Shared Chat Sessions When you activate the Share feature on a chat session, the full conversation — including any clinical content, questions, and AI responses — becomes accessible to anyone with the link, without requiring login. You should not share sessions containing patient-identifiable information or sensitive clinical discussions. You can deactivate a shared session at any time by disabling the share link.

3.6 Information We Do NOT Collect

National Provider Identifier (NPI) — not collected or verified against any external registry

Biometric data (fingerprint, Face ID) — authentication biometrics are handled entirely by your device OS

Social Security Number or government-issued ID number

Patient names, patient dates of birth, or other direct patient identifiers (we do not operate as a medical records system)

Advertising IDs or third-party advertising tracking data

Social media profile data or social graph information

4. How We Use Your Information

We use the information we collect only for the purposes described in this section. We do not sell your personal information.

PurposeData UsedLegal Basis
Account creation, authentication, and session managementEmail, Firebase UID, password (via Firebase Auth), QR code session tokensPerformance of contract (Terms of Use)
Delivering AI clinical assistant features (chat, literature search, learning resources)Chat messages, uploaded files, audio recordings — transmitted to Google GeminiExplicit consent; performance of contract
CV parsing and job agent profile constructionFull CV document — transmitted to Google Gemini for structured extraction; home address transmitted to OpenCage for geocodingExplicit consent (opt-in feature)
Physician job matchingJob agent profile (specialty, licence states, board status, location, preferences), matched against job postings scraped from 16 physician job boardsExplicit consent (opt-in feature)
Subscription and access tier managementSubscription records, Stripe/RevenueCat webhooks, subscription plan tierPerformance of contract; legitimate interest in enforcing subscription entitlements
Payment processingEmail, name, Firebase UID — transmitted to Stripe (web); Firebase UID — transmitted to RevenueCat (mobile)Performance of contract
Push notifications (job matches, reminders, system alerts)FCM device tokens, notification contentConsent (opt-in at registration/onboarding)
Transactional email (verification, payment confirmation, job match alerts, referral confirmation)Email address, email body content — via Gmail SMTPPerformance of contract; legitimate interest
Distributed performance monitoring and distributed tracingFirebase UID, chat ID, message count, search query text (up to 200 chars) — exported to Google Cloud TraceLegitimate interest in maintaining service reliability and performance
Internal performance alertingAggregated AI performance metrics (latency, token counts, cost estimates) — sent to Discord webhook. No PII or clinical content included.Legitimate interest in operational monitoring
YouTube medical education video references in chatDerived search query (no user identifiers) — transmitted to YouTube Data API v3Legitimate interest in enriching AI responses with medical education content
Medical literature references in AI chat responsesDerived clinical search query (no user identifiers) — transmitted to PubMed/NCBI APILegitimate interest in grounding AI responses in peer-reviewed literature
Fraud prevention and securityIP address, device fingerprint, Firebase UIDLegitimate interest in preventing unauthorised access
App improvement and product analyticsAggregated, anonymised usage patterns from internal logsLegitimate interest in improving the product

5. How We Store Your Information

5.1 Storage Infrastructure

SystemProviderPrimary Data StoredLocation
Primary operational databaseMongoDB Atlas (Motor async driver)All 16 collections: Users, ChatHistory, Profiles, Jobs, UserJobMatches, JobAgents, Transactions, Certificates, AccountVerifications, QrCodeSessions, UploadedFiles, SharedChatSessions, ConversationTables, LearningResources, LearningResourceGroups, RawJobsMongoDB Atlas cloud
Authentication and identityGoogle Firebase AuthenticationEmail address, Firebase UID, account verification status, password hash (managed by Firebase)Google Cloud
File and CV storageGoogle Cloud Storage — bucket: pc_media_filesCV/resume binaries (job_agent_cvs/ prefix), audio recordings, uploaded document filesGoogle Cloud Storage
Push notification routing and stateGoogle Cloud FirestoreIn-app notification records and delivery stateGoogle Cloud Firestore
Async job event messagingGoogle Cloud Pub/SubJob-matching pipeline events (job IDs, user IDs)Google Cloud Pub/Sub
Performance and trace dataGoogle Cloud Trace (via OpenTelemetry)Firebase UID, chat ID, message count, search query text (up to 200 chars)Google Cloud Trace
Medical knowledge vector searchQdrantVector embeddings for medical knowledge base queriesSelf-hosted Qdrant Cloud.
Caching and rate limitingRedisSession caches, rate limit counters (no long-term PII storage expected)Transient (In memory).

5.2 Data Retention

Data Category / CollectionRetention PeriodNotes
User profile (Users collection)Duration of account existence; deleted on account deletionIncludes professional profile and device metadata
AI Chat History (ChatHistory)Duration of account existence; deleted on account deletion.Includes per-message IP addresses and full conversation text
Job Agent Profile (Profiles)Duration of account existence; deleted on account deletionIncludes home address with GPS coordinates
CV File (GCS — job_agent_cvs/)Until deleted by user or on account deletionBinary CV document stored in GCS
Job Matches (UserJobMatches)Duration of account existenceMatch history and dismissal states
Transactions (Transactions)Duration of account existence; may be retained longer for financial record-keeping obligationsEmail, name, payment amounts
Account Verification Tokens (AccountVerifications)24-hour TTL — automatically deleted on expiry or successful verificationTemporary Fernet-encrypted password
QR Code Sessions (QrCodeSessions)5-minute TTL — automatically deletedTransient cross-device login sessions
Application logs (GCP Cloud Logging)Subject to GCP retention settings.Contains JSON application logs including performance metrics
Distributed traces (GCP Cloud Trace)Subject to GCP Cloud Trace retention policy (default 30 days)Contains Firebase UID and chat metadata per trace
Firebase Authentication recordsRetained until account is deleted via Firebase Admin SDKDeleted as part of account deletion flow
Stripe customer recordsRetained by Stripe per their data retention policy; H3O retains Stripe customer ID and subscription records indefinitely for billing historyFinancial record-keeping obligations may apply

We are actively developing automated retention and expiry policies for collections currently lacking TTL enforcement. Until those controls are deployed, data in those collections is retained for the lifetime of your account unless you request deletion as described in Section 12.

5.3 Security Measures

We implement the following security controls to protect your information:

TLS/HTTPS in Transit: All communication between your device and our backend is encrypted using TLS.

Firebase JWT Authentication: Every protected API request is authenticated via a Firebase ID token, verified server-side by FirebaseAuthMiddleware on every request. Errors handled include expired, revoked, and invalid tokens.

Password Protection: Passwords are never stored in plaintext. During the email verification window, passwords are temporarily held as Fernet-encrypted ciphertext. After verification, password management is handled entirely by Firebase Authentication.

MongoDB Atlas Encryption at Rest: All data in MongoDB Atlas is encrypted at rest using AES-256 by default.

GCS Encryption at Rest: Files stored in Google Cloud Storage are encrypted at rest by Google using AES-256.

Device Metadata Restricted from Public API: The UserMetadata subobject (IP, geolocation, device fingerprint) is explicitly excluded from public API responses via UserPublicSchema.from_document(), though it remains stored in MongoDB.

Redis Rate Limiting: Redis-based rate limiting is implemented to restrict abusive or anomalous request patterns.

6. How We Share Your Information

We do not sell or rent your personal information. The following describes every category of third-party sharing in the Physicians Copilot platform.

6.1 AI and Transcription Providers

By using the Chat, Job Agent, and Voice Transcription features, you consent to the following transmissions of your data to AI providers:

ProviderData TransmittedFeatureProvider Privacy Policy
Google Gemini (Google LLC) Models: gemini-2.5-flash, gemini-2.0-flashFull chat message history (verbatim), uploaded file contents, Firebase UID; full CV document binary (PDF/DOCX) for Job Agent parsing; audio files for transcription; medical specialty string for keyword generationChat AI, CV Parsing, Audio Transcription, Job Agenthttps://policies.google.com/privacy
Groq, Inc. Model: whisper-large-v3Raw audio recordings (voice queries, clinical dictations)Voice Transcriptionhttps://groq.com/privacy-policy/
Deepgram, Inc. Model: nova-3Raw audio recordings (voice queries, clinical dictations)Voice Transcription (third option)https://deepgram.com/privacy

6.2 Payment Processors

ProviderData TransmittedPurposeNotes
Stripe, Inc.Email address, display name, Firebase UID (in Stripe customer metadata), subscription plan and status, transaction amountsWeb subscription billing, payment intent processing, subscription lifecycle managementStripe is PCI-DSS Level 1 certified. A Data Processing Agreement with Stripe should be confirmed. No clinical data is transmitted to Stripe.
RevenueCat, Inc.RevenueCat customer ID (mapped internally to Firebase UID), subscription lifecycle events from Apple App Store and Google PlayMobile in-app purchase subscription managementRevenueCat receives subscription events from Apple/Google. No clinical or profile data is transmitted.

6.3 Cloud and Infrastructure Providers

ProviderData SharedPurpose
Google Firebase Auth (Google LLC)Email, Firebase UID, account verification statusUser identity and authentication
Google Firebase FCM (Google LLC)Device FCM tokens, push notification title/bodyMobile push notifications
Google Cloud Firestore (Google LLC)In-app notification recordsNotification state management
Google Cloud Storage (Google LLC)CV binaries, audio recordings, uploaded filesFile storage
Google Cloud Pub/Sub (Google LLC)Job event messages (job IDs, user IDs)Async job-matching pipeline
Google Cloud Trace (Google LLC)Firebase UID, chat ID, message count, search query text (≤200 chars)Distributed performance tracing
MongoDB Atlas (MongoDB, Inc.)All structured application data across 17 collectionsPrimary database
Redis (Google Cloud Memorystore for Redis)Session cache data, rate limit countersCaching and rate limiting
Qdrant (Qdrant Cloud)Medical knowledge base vector embeddings (not derived from user health data — based on curated medical knowledge)Vector similarity search for AI medical knowledge retrieval

6.4 Location and Geocoding Services

When you use the Job Agent and provide a home address for commute-based job matching, your address is transmitted to the following service:

ProviderData TransmittedPurposeNotes
OpenCage Geocoding (OpenCage GmbH)Full residential address string (e.g. '123 Main St, Houston, TX 77001') assembled from your home addressConvert home address to GPS latitude/longitude for commute distance calculation in job matchingOpenCage's free tier retains query logs. The resulting GPS coordinates are stored in MongoDB Profiles.home_location.lat/lon. This is the highest-risk PII transmission in the system. Use of a paid plan with data retention disabled is strongly recommended.

6.5 Healthcare Data and Research APIs

The following external APIs receive derived search queries only — no user PII or account identifiers are transmitted:

NCBI PubMed API — receives AI-derived clinical search queries to retrieve peer-reviewed medical literature references for attachment to AI chat responses. No user ID, email, or clinical context beyond the search query is transmitted.

YouTube Data API v3 (Google LLC) — receives AI-derived medical topic search queries to retrieve educational video references. Read-only access. No user data beyond the derived search query is transmitted.

6.6 Internal Monitoring

Performance metrics are sent to a private Discord channel via webhook for operational alerting. Data sent to Discord includes AI response latency, token counts, estimated billing cost, and subscription lifecycle events (e.g. 'User subscribed to Pro'). No PII, email addresses, clinical chat content, or CV data is included in these Discord notifications.

6.7 Legal and Regulatory Disclosures

We may disclose your personal information without prior notice where required by applicable law, including in response to valid court orders, subpoenas, or law enforcement requests from competent authorities in Wyoming, USA or other applicable jurisdictions; to protect the rights, safety, or property of H3O, our users, or the public; to investigate suspected fraud or illegal activity; or to comply with applicable laws and regulations. Where legally permissible, we will notify you prior to disclosure.

6.8 Corporate Transactions

In the event of a merger, acquisition, asset sale, or other corporate transaction involving H3O, your personal information may be transferred to the acquiring entity. We will provide prior notice before your data is transferred, and the acquiring entity will be required to honour this Policy or obtain fresh consent from you.

7. Third-Party Data Processors — Processing Agreements

All third-party service providers that process your personal information on H3O's behalf are required to handle that data in accordance with applicable data protection law. The following table reflects known DPA status as of the policy effective date:

ProviderRoleDPA / Compliance StatusKey Notes
Google LLC (Firebase, Gemini, GCS, Firestore, Pub/Sub, Cloud Trace, FCM, YouTube API)Data Processor (multiple services)Google Cloud Data Processing Addendum — available at cloud.google.com/terms/data-processing-addendumGemini API usage involving PHI-class data requires specific contractual coverage. Confirm BAA eligibility if HIPAA obligations apply.
MongoDB, Inc.Data ProcessorMongoDB DPA pending.MongoDB Atlas is SOC 2 Type II certified. Encryption at rest is enabled by default.
Stripe, Inc.Data Processor (payment)Stripe DPA pending.Stripe is PCI-DSS Level 1. Email and name transmitted — DPA should cover this. No clinical data transmitted.
RevenueCat, Inc.Data Processor (mobile payments)RevenueCat DPA pending.Receives only subscription lifecycle events and customer ID. No clinical data.
Groq, Inc.Data Processor (audio transcription)Groq DPA pending.Raw audio recordings of clinical dictations transmitted. DPA required.
Deepgram, Inc.Data Processor (audio transcription)Deepgram DPA / BAA pendingDeepgram offers a BAA for HIPAA-covered entities. Clinical audio transmitted. Confirm coverage.
OpenCage GmbHData Processor (geocoding)OpenCage DPA pending.Full residential home address transmitted. Free-tier retains query logs. Paid plan recommended.
Qdrant (Qdrant Cloud)Data Processor (vector search)Qdrant DPA PendingMedical knowledge base embeddings — confirm whether any user-derived vectors are stored here.
Redis (Google Cloud Memorystore for Redis)Data Processor (caching)Redis provider DPA pendingSession and rate limit data. Confirm no PII cached long-term.

8. Anonymous Users

Physicians Copilot supports anonymous (guest) access via the endpoint POST /api/v1/auth/login/anonymous-user. Anonymous users are assigned a Firebase anonymous UID and may access certain features without providing an email address or creating a full account.

The following applies to anonymous users:

No email address, name, or professional profile is collected at login.

An anonymous Firebase UID is generated and used to associate any data generated during the session.

If an anonymous user creates chat sessions, those sessions are stored in MongoDB ChatHistory under the anonymous UID, including per-message IP addresses and device metadata.

Anonymous users may not access subscription-gated features or the Job Agent.

Anonymous accounts can be deactivated. There is no automatic expiry of anonymous account data.

If you convert an anonymous account to a registered account, your session history may be associated with the new registered account.

If you used Physicians Copilot anonymously and wish to have your data deleted, you may contact admin@physicianscopilot.com with a description of the sessions and approximate timeframe.

9. QR Code Login and Cross-Device Sessions

Physicians Copilot offers a QR code-based cross-device login flow, allowing a user authenticated on a mobile device to log in on a web browser by scanning a QR code displayed on the web interface.

The following data is processed during QR login:

A session token is generated and stored in MongoDB QrCodeSessions with a 5-minute expiry (TTL).

Your Firebase UID is associated with the session token when you authenticate via mobile.

The web client listens for authentication completion via Server-Sent Events (SSE).

On completion, the session record is marked as 'completed' and a Firebase custom token is issued to the web client.

Session records are automatically deleted after 5 minutes regardless of completion status.

No additional personal data beyond your Firebase UID is transmitted or stored during QR login.

10. Cookies and Tracking Technologies

10.1 Mobile Application

The Physicians Copilot mobile app does not use browser cookies. Device-level data collected includes:

FCM Device Tokens: Unique per-device identifiers used exclusively for push notifications. Stored in MongoDB Profiles.fcm_tokens[]. Multiple tokens may be stored if you use more than one device.

Device Fingerprint: Device type, OS version, browser (if web), screen resolution, and user agent are collected and stored as part of account and session metadata for debugging and security purposes.

Firebase Authentication Tokens: JWT session tokens managed by the Firebase SDK. Not stored by H3O beyond the active request.

10.2 Web Application

If you access Physicians Copilot through a web browser:

Firebase Web SDK may store authentication session tokens in browser memory or local storage for session persistence.

OpenTelemetry instrumentation captures all HTTP requests for distributed tracing, including the request path, user ID, and response time. These traces are exported to Google Cloud Trace.

No advertising networks, retargeting pixels, or third-party marketing cookies are used.

No third-party analytics SDK (e.g. Google Analytics, Mixpanel, Amplitude) is installed. All usage insights are derived from internal application logs.

11. Your Rights and Choices

Depending on your jurisdiction, you may have the following rights regarding your personal information. To exercise any right, contact admin@physicianscopilot.com. We will respond to all verifiable requests within 30 days.

RightDescriptionHow to Exercise
Right of AccessRequest confirmation of whether we hold your personal data and receive a copy.Email admin@physicianscopilot.com Subject: 'Data Access Request'
Right to RectificationCorrect inaccurate or incomplete personal data.Update via App Profile Settings, or email admin@physicianscopilot.com
Right to ErasureRequest deletion of your personal data where it is no longer necessary, or where you withdraw consent.Use 'Delete Account' in App Settings, or email admin@physicianscopilot.com — Subject: 'Account Deletion Request'
Right to Restrict ProcessingRequest that we limit how your data is used while accuracy is disputed or an objection is pending.Email admin@physicianscopilot.com
Right to Data PortabilityReceive a machine-readable copy of data you provided, where processing is based on consent or contract.Email admin@physicianscopilot.com — Subject: 'Data Portability Request'
Right to ObjectObject to processing based on legitimate interests, including profiling (e.g. job matching algorithms).Email admin@physicianscopilot.com
Right to Withdraw ConsentWithdraw consent for consent-based processing at any time. This does not affect prior lawful processing.Delete your account or email admin@physicianscopilot.com
Right to Opt Out of Job AgentStop the Job Agent from processing your CV and running job matches, without deleting your account.Disable Job Agent in App Settings
Right to Deactivate Shared Chat SessionsRevoke public access to any shared chat session.Toggle share link off within the App
Right to Lodge a ComplaintLodge a complaint with the relevant data protection supervisory authority.Wyoming Data Protection Authority

We will not discriminate against you for exercising any of these rights. Requests that are manifestly unfounded or repetitive may be subject to an administrative fee, in which case we will notify you in advance.

12. Account Deletion and Data Deletion

Data / CollectionDeletion ActionTimeframe
MongoDB Users documentHard-deletedWithin 30 days
MongoDB ChatHistory sessionsHard-deleted (all sessions for the user)Within 30 days
MongoDB Profiles / job_agent_profilesHard-deletedWithin 30 days
MongoDB UserJobMatchesHard-deletedWithin 30 days
MongoDB JobAgentsHard-deletedWithin 30 days
MongoDB TransactionsHard-deleted (subject to financial record-keeping obligations)Within 30 days, unless retention required by law
MongoDB CertificatesHard-deletedWithin 30 days
MongoDB SharedChatSessionsHard-deleted; shared links deactivated immediatelyImmediate deactivation; document deleted within 30 days
MongoDB UploadedFiles metadataHard-deletedWithin 30 days
GCS CV file (job_agent_cvs/)Deleted from GCS bucketWithin 30 days
GCS audio recordings and uploaded filesDeleted from GCS bucketWithin 30 days
Firebase Authentication recordDeleted via Firebase Admin SDKImmediate on request processing
Google Cloud Firestore notificationsDeletedWithin 30 days
GCP Cloud Trace spansSubject to GCP Cloud Trace retention policy (default 30 days). Not individually deletable from trace stream.Auto-expires per GCP policy
Application logs (GCP Cloud Logging)Subject to GCP log retention settings. Not individually deletable.Auto-expires per GCP policy
Stripe customer recordH3O requests Stripe customer deletion; Stripe may retain records per their own legal obligations.30 days (H3O-side); Stripe's policy applies to their records

To request account deletion, use the 'Delete Account' function in App Settings or email admin@physicianscopilot.com with the subject line 'Account Deletion Request' from the email address associated with your account. We will confirm completion within 30 days.

13. Data Breach Notification

In the event of a personal data breach that is likely to result in risk to the rights and freedoms of affected individuals, H3O will:

Notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, where required by applicable law;

Notify affected users directly, without undue delay, where the breach is likely to result in high risk to their rights and freedoms;

Include in any notification: the nature of the breach, the categories and approximate number of individuals affected, the likely consequences, and the measures taken or proposed.

Given that Physicians Copilot stores highly sensitive professional data — including home addresses with GPS coordinates, CV documents, and clinical chat content — we classify data breaches involving this system as high-priority incidents and maintain a documented incident response procedure.

14. International Data Transfers

H3O is based in Wyoming, USA. Our cloud infrastructure and third-party processors operate in multiple countries, primarily the United States, and potentially others depending on Google Cloud regional configuration. By using Physicians Copilot, your personal information — including sensitive professional and clinical data — may be transferred to and processed in countries outside your country of residence.

Where we transfer personal data internationally, we rely on the following safeguards:

Standard Contractual Clauses (SCCs) or equivalent transfer mechanisms, where required by applicable law;

Data Processing Agreements with service providers incorporating appropriate international transfer protections;

The adequacy of data protection in the destination country, where applicable.

For users in jurisdictions with specific international transfer requirements (EEA, UK, Nigeria under NDPA), please contact admin@physicianscopilot.com for details of the applicable safeguards.

15. Children's Privacy

Physicians Copilot is intended exclusively for licensed healthcare professionals and medical trainees aged 18 and over. We do not knowingly collect personal information from anyone under 18. If we become aware that we have inadvertently collected data from a minor, we will delete that data within 30 days. Please contact admin@physicianscopilot.com if you believe a minor has accessed the service.

16. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our practices, technology, legal obligations, or new features. When we make material changes, we will:

Update the 'Last Updated' date at the top of this document;

Notify you via a prominent in-app notification and/or email at least 14 days before changes take effect;

Obtain fresh explicit consent for material changes affecting how sensitive professional or clinical data is processed.

Continued use of Physicians Copilot after the effective date constitutes acceptance of the revised Policy. If you do not agree, you may discontinue use and request account deletion as described in Section 12. All prior versions of this Policy are archived and available on request from admin@physicianscopilot.com.

17. Contact Information

Contact TypeDetails
Privacy Inquiries & Data Subject Requestsadmin@physicianscopilot.com
Company Legal NameHealthcare 3.0 LLC
Registered AddressWyoming, USA
Data Protection OfficerPrivacy inquiries are directed to the founding team.
Response CommitmentWe aim to respond to all privacy-related enquiries within 10 business days.

This Privacy Policy was drafted specifically for Physicians Copilot, a product of Healthcare 3.0 LLC. It reflects the actual data architecture, authentication systems, third-party integrations, and data flows of the application as audited on 15th April, 2026. It is a standalone document separate from the My Health Diary Privacy Policy.

Physicians Copilot Privacy Policy | Healthcare 3.0 LLC | Version 1.0 | Effective 15th April, 2026.