Debrief home
Effective July 18, 2026

Alpha Privacy Notice

This notice explains the data practices implemented in the current closed-alpha build. It is not a certification that Debrief is approved for real health information.

Information Debrief handles

How the information is used

Data is used only to authenticate testers, provide private saved workspaces, generate requested drafts or preparation PDFs, maintain document ownership controls, diagnose errors, and protect the alpha service. Debrief does not sell personal information or use Google sign-in data for advertising or generalized AI training.

Service providers and transfers

The application relies on Google for sign-in and on the configured hosting, PostgreSQL database, and private object-storage providers to operate the service. If AI drafting is later enabled, questionnaire answers are sent to OpenAI only after an explicit in-product acknowledgement; the optional display name is excluded and API storage is disabled in the request. The non-AI guided narrative does not send answers to OpenAI.

Cookies and browser storage

Debrief uses essential authentication cookies. Signed-out drafts may be stored in the browser’s local storage. The alpha does not include advertising cookies or cross-site analytics.

Retention and deletion

Account data remains until the tester deletes individual workspaces or uses Account and data → Delete account and data. Account deletion removes database records and stored test documents from active application storage. Hosting and infrastructure providers may retain encrypted backups or security logs under their own configured retention schedules. The alpha administrator must document those vendor schedules before real-data use.

Security and health-data status

Debrief uses account-scoped access checks, database sessions, private test-file storage, file-signature checks, random storage keys, request limits, and security headers. The alpha does not have malware scanning, a completed production threat assessment, or a determination that its controls meet requirements for real health data. Debrief does not claim to be HIPAA compliant.

Your choices

You can use public educational pages without signing in, remove individual claims and test documents, delete the entire account, or stop participating in the alpha. For a privacy or deletion problem, debrief_admin@pm.me.

Google user data

Information received through Google sign-in is limited to authentication and account identification. Debrief’s use and transfer of that information follows the Google API Services User Data Policy, including applicable Limited Use requirements.

Important legal scope

Depending on the product’s future data sources and relationships, laws beyond HIPAA may apply, including the FTC Act and the FTC Health Breach Notification Rule. This notice must be reviewed by qualified counsel before accepting real claimant information or opening access beyond a controlled fictional-data alpha.