Artful Intelligence, LLC · North Carolina, United States
Privacy Policy
Protocol is local-first. Core records stay on your device unless you export them or send information with feedback; catalog selections, support, and existing-account service requests are handled as described below.
Scope and controller
This Privacy Policy explains how Artful Intelligence, LLC ("Artful Intelligence," "we," "us," or "our") handles information in connection with the Protocol iOS app, theprotocolapp.co, support, and existing-account service requests.
Protocol is designed to be local-first. Core records remain in the app's local container unless you choose to export them or send information with feedback. Catalog selections, support, and existing-account service requests can transmit the limited data described below.
Information and on-device processing
Protocol processes protocol, compound, schedule, concentration, dose, administration, injection-location, notification, inventory, vial, preparation, reconstitution, storage, free-text records, preferences, appearance settings, warning thresholds, and local workflow state on your device. It also processes files you create through JSON or CSV export and information you choose to include in feedback or a support request.
Core app records are stored locally using Apple's app-storage technologies with iOS data protection. Protocol does not enable CloudKit synchronization for these records. The app's local data directory is excluded from ordinary iOS device backup by the app. A local-data wipe removes the app's local records and settings; it does not delete an existing account or server-side data. Deleting the app normally removes its local app container, subject to iOS behavior. Exports are unencrypted after creation and are controlled by you and the destination you select.
Network and service data
The following features communicate with services we operate or providers working for us.
- Compound catalog: Protocol may retrieve a current compound-title catalog. When you select a catalog title, the service can receive that title, a persistent per-install token, app version and build, iOS version, device model, user agent, and network information used for security and rate limiting. The server stores a hashed form of the install token with title and request metadata. We treat this as pseudonymous usage and diagnostic data, not anonymous data.
- Feedback and support: if you submit feedback or a support request, the service receives the information you enter and may receive your email, app/build version, iOS version, device model, optional screenshot, and an optional diagnostic log. The diagnostic log is designed to exclude Protocol records and Keychain contents, but you should still review every attachment before sending it. The app uses a persistent client token stored in the iOS Keychain; the support page uses a separate client token stored in that browser's local storage. Each is transmitted with its request, and the service stores its hashed form to associate submissions, prevent abuse, and apply rate limits. If you choose a public request and an administrator approves it, the title, public description, type, status, and aggregate votes may be displayed to other users. Your email, private troubleshooting fields, diagnostic log, and attachments are not intended for public display. Public ideas are reviewed before display. When you report a public idea, we receive the reported idea, the reason you select, and a pseudonymous installation hash. Administrators can remove public content and block an installation hash from submitting additional content; this does not create a broad ban on a person.
- Website access requests: if you submit the website access-request form, we receive your email address, acknowledgement, invite code or source path, browser user agent, and request timestamps. We use network information for security and rate limiting. The site stores your selected appearance preference in your browser's local storage.
- Existing-account service requests: if you use account-management or deletion controls for an existing authenticated account, our service receives the account identifier and the information necessary to process that request.
Use, providers, and disclosures
We use information only as reasonably necessary to provide, secure, maintain, troubleshoot, and improve Protocol; respond to website access and support requests; administer existing-account service requests; enforce our terms; prevent abuse; comply with law; and protect users, Artful Intelligence, and others. We do not use health or routine records for targeted advertising. We do not sell personal information, and Protocol does not include third-party advertising or cross-app tracking SDKs.
We may disclose the minimum information reasonably necessary to service providers that host infrastructure, provide authentication, deliver transactional email, process support or security events, or otherwise act for us under appropriate restrictions. Current categories include Supabase-hosted infrastructure, Apple platform and authentication services, and Resend for email delivery where configured. We may also disclose information as reasonably necessary for law, valid process, fraud, abuse, security, rights and safety, corporate transactions with safeguards, or with your direction or consent. Apple and other platforms, and your export destination, email provider, Files provider, or recipients, independently process information under their own terms.
Retention and requests
Local records remain until you delete them, wipe local data, or uninstall Protocol, subject to iOS behavior. User-created exports remain wherever you place them until you delete them there. Deleting an existing account is designed to delete its authentication user record and previously stored account files and metadata. The deletion cannot be undone once processed. Keep any export you need before requesting deletion.
Website access-request, support, catalog, security, diagnostic, and usage records are retained only for as long as reasonably necessary for the purposes described above, legal compliance, dispute resolution, and abuse prevention. System caches and logs may take additional time to expire. We have not independently verified a configured automatic deletion period for pseudonymous install-hash feedback, votes, catalog-selection, or related security records. Account deletion does not automatically remove feedback, votes, catalog-selection, or related records keyed to a pseudonymous installation hash.
You can review or edit local records; delete individual records; wipe local data; use account-management and deletion controls if you already have an authenticated account; and control permissions through iOS where available. Privacy laws may give you rights to access, correct, delete, or obtain a copy of personal information we hold, or appeal a request decision. Submit a request through the private Support & Privacy Request form at theprotocolapp.co/support or email support@theprotocolapp.co. We may need to verify your identity and may retain information where permitted or required by law.
Security, changes, and contact
We use technical and organizational safeguards intended to protect information, including on-device data protection, encrypted transport, and access controls. No storage, network, device, or service is completely secure or continuously available. You are responsible for device security and safe export handling. If we determine that a security incident triggers a legal notification duty, we will provide notice as required by applicable law.
Protocol is not designed to solicit personal information from children, and we do not knowingly collect personal information from a child through the service. Artful Intelligence operates from the United States; transmitted information may be processed there or other locations used by providers. We may update this policy as Protocol or law changes and will provide additional notice or request renewed consent when legally appropriate. Use Settings > Help & Feedback, the private Support & Privacy Request form, or support@theprotocolapp.co for support, privacy, and account-deletion requests. Do not send medical emergencies, full medical records, or passwords through support.