Effective Date: July 1, 2026 (investigational preview)
IPMN Compass is an investigational app available through TestFlight. It already stores the visit information you enter, as described below. It is not a finished commercial product, and this policy will be reviewed by counsel before any public App Store release.
IPMN Compass ("the App") is a companion for the journey of living with a pancreatic cyst — supporting patients between and after clinic visits, and supporting clinicians with guideline-anchored reference during them. It is not a calculator and not a medical device. This Privacy Policy describes what information the App collects, how it is stored, and your rights regarding your data.
When you first open the App, we create an anonymous account for you. This account is not tied to your name or email address — we do not ask for either to use the App today. The account is identified only by a random account ID, and your visit information is linked to that ID.
When you add a visit, the App stores the information you type in, linked to your anonymous account:
This information is stored in the cloud (Google Firestore), as described in "How your data is stored" below.
Some information never leaves your device and is not stored in our cloud database:
If you use the App's clinician patient panel, patient names, MRN fragments, and any notes you add are kept only in your device's secure keychain storage, encrypted at rest. They are never uploaded to our servers in readable form.
If you create an account so your panel reaches your other devices, those identifying details sync only as encrypted data — encrypted on your device, with a key we never hold and cannot use to read them.
On the desktop website (clinician.ipmncompass.com), your sign-in lasts only for the browser session and clinical records are held in memory only — nothing is stored on the computer's disk, and closing the tab ends the session. If you set up the optional passkey unlock, patient names are decrypted only in that tab's memory after you approve with Face ID / Touch ID, and lock again when you sign out.
What does reach our cloud is limited to an opaque code for each patient (for example, "IPMN-4Q82") plus the structured clinical details needed to compute guideline-based recommendations — never a name, an MRN fragment, or a note. Server-side rules enforce this by rejecting any panel write that carries an identifying field.
Your account and visit information are stored using Google Firebase (Firestore for data, Firebase Authentication for your anonymous account), hosted on Google Cloud. Data is encrypted in transit and at rest using our cloud provider's standard encryption. Server-side security rules restrict your data so that it is only readable by your own authenticated account — other users cannot access it.
Server-side rules also reject writes that look like certain patient identifiers (for example, a full date of birth or a plaintext accession number), as a backstop in addition to how the App itself is built.
AI features are optional. You choose whether to turn them on, and the App's core features work without them.
If you turn AI features on, content you choose to submit — for example, a recorded visit conversation, radiology report text you paste in, or a question you ask in the education section — is sent to our servers and processed using Anthropic's Claude AI model to produce a summary, extracted details, or an answer. We only send content you actively submit for this purpose; we do not automatically scan or send your other stored information to the AI model. You can decline AI processing and still use the rest of the App.
A future version of the App may send push notifications through Apple's and Google's standard notification services. If this ships, lock-screen text will stay generic and will never include your name or clinical details. This feature is not active today.
Any research use of App data — for example, a study or a registry — would be strictly opt-in, presented separately from normal use of the App, and would require its own informed consent. No research program is active today. You can use the App fully without ever joining a research study.
The App uses Sentry to collect crash and error reports so we can fix bugs. These reports do not contain your name, your stored visit details, or other information that identifies you. A future version of the App may also use Firebase Analytics to understand how the App is used (for example, which screens are opened); any such events would carry only general usage categories, not your clinical details or notes.
We do not sell, rent, or trade your personal information. We share information only as needed to run the App:
We do not have any other data-sharing arrangements today.
You have the right to:
The App is not intended for use by individuals under the age of 18. We do not knowingly collect information from children.
We will update this policy as features ship. Changes will be posted within the App and at this page, and the effective date will be updated. For substantive changes (new data collection, new vendor) the App will prompt for re-acknowledgment.
IPMN Compass Project
Email: TBD-SUPPORT-EMAIL
Interim contact — an institutional address will replace this once the project's institutional / fiscal-sponsor arrangements are finalized.