IPMN Compass

Privacy Policy

Effective Date: July 1, 2026 (investigational preview)

IPMN Compass is an investigational app available through TestFlight. It already stores the visit information you enter, as described below. It is not a finished commercial product, and this policy will be reviewed by counsel before any public App Store release.

Overview

IPMN Compass ("the App") is a companion for the journey of living with a pancreatic cyst — supporting patients between and after clinic visits, and supporting clinicians with guideline-anchored reference during them. It is not a calculator and not a medical device. This Privacy Policy describes what information the App collects, how it is stored, and your rights regarding your data.

Your account

When you first open the App, we create an anonymous account for you. This account is not tied to your name or email address — we do not ask for either to use the App today. The account is identified only by a random account ID, and your visit information is linked to that ID.

What we store when you use the App

When you add a visit, the App stores the information you type in, linked to your anonymous account:

This information is stored in the cloud (Google Firestore), as described in "How your data is stored" below.

What stays on your device only

Some information never leaves your device and is not stored in our cloud database:

For clinicians: your patient panel

If you use the App's clinician patient panel, patient names, MRN fragments, and any notes you add are kept only in your device's secure keychain storage, encrypted at rest. They are never uploaded to our servers in readable form.

If you create an account so your panel reaches your other devices, those identifying details sync only as encrypted data — encrypted on your device, with a key we never hold and cannot use to read them.

On the desktop website (clinician.ipmncompass.com), your sign-in lasts only for the browser session and clinical records are held in memory only — nothing is stored on the computer's disk, and closing the tab ends the session. If you set up the optional passkey unlock, patient names are decrypted only in that tab's memory after you approve with Face ID / Touch ID, and lock again when you sign out.

What does reach our cloud is limited to an opaque code for each patient (for example, "IPMN-4Q82") plus the structured clinical details needed to compute guideline-based recommendations — never a name, an MRN fragment, or a note. Server-side rules enforce this by rejecting any panel write that carries an identifying field.

How your data is stored

Your account and visit information are stored using Google Firebase (Firestore for data, Firebase Authentication for your anonymous account), hosted on Google Cloud. Data is encrypted in transit and at rest using our cloud provider's standard encryption. Server-side security rules restrict your data so that it is only readable by your own authenticated account — other users cannot access it.

Server-side rules also reject writes that look like certain patient identifiers (for example, a full date of birth or a plaintext accession number), as a backstop in addition to how the App itself is built.

AI features

AI features are optional. You choose whether to turn them on, and the App's core features work without them.

If you turn AI features on, content you choose to submit — for example, a recorded visit conversation, radiology report text you paste in, or a question you ask in the education section — is sent to our servers and processed using Anthropic's Claude AI model to produce a summary, extracted details, or an answer. We only send content you actively submit for this purpose; we do not automatically scan or send your other stored information to the AI model. You can decline AI processing and still use the rest of the App.

Push notifications

A future version of the App may send push notifications through Apple's and Google's standard notification services. If this ships, lock-screen text will stay generic and will never include your name or clinical details. This feature is not active today.

Research participation

Any research use of App data — for example, a study or a registry — would be strictly opt-in, presented separately from normal use of the App, and would require its own informed consent. No research program is active today. You can use the App fully without ever joining a research study.

Crash reports and analytics

The App uses Sentry to collect crash and error reports so we can fix bugs. These reports do not contain your name, your stored visit details, or other information that identifies you. A future version of the App may also use Firebase Analytics to understand how the App is used (for example, which screens are opened); any such events would carry only general usage categories, not your clinical details or notes.

Data sharing

We do not sell, rent, or trade your personal information. We share information only as needed to run the App:

We do not have any other data-sharing arrangements today.

Your rights

You have the right to:

Children's privacy

The App is not intended for use by individuals under the age of 18. We do not knowingly collect information from children.

Changes to this policy

We will update this policy as features ship. Changes will be posted within the App and at this page, and the effective date will be updated. For substantive changes (new data collection, new vendor) the App will prompt for re-acknowledgment.

Contact us

IPMN Compass Project
Email: TBD-SUPPORT-EMAIL
Interim contact — an institutional address will replace this once the project's institutional / fiscal-sponsor arrangements are finalized.