Alpha Privacy Notice
This notice explains the data practices implemented in the current closed-alpha build. It is not a certification that Debrief is approved for real health information.
Use fictional information only. Do not provide real medical records, health information, Social Security numbers, VA file numbers, or another person’s information during alpha testing.
Information Debrief handles
- Google sign-in data: name, email address, profile image, and Google account identifier used for authentication.
- Workspace data: questionnaire answers, statement drafts, timelines, evidence statuses, progress, and condition labels you enter.
- Test documents: fictional PDF, JPEG, or PNG files you intentionally upload, plus filename, type, size, checksum, storage location, and upload date.
- Security records: database sessions and limited audit events for workspace creation and test-document upload, download, and deletion. Audit metadata excludes document names and contents.
How the information is used
Data is used only to authenticate testers, provide private saved workspaces, generate requested drafts or preparation PDFs, maintain document ownership controls, diagnose errors, and protect the alpha service. Debrief does not sell personal information or use Google sign-in data for advertising or generalized AI training.
Service providers and transfers
The application relies on Google for sign-in and on the configured hosting, PostgreSQL database, and private object-storage providers to operate the service. If AI drafting is later enabled, questionnaire answers are sent to OpenAI only after an explicit in-product acknowledgement; the optional display name is excluded and API storage is disabled in the request. The non-AI guided narrative does not send answers to OpenAI.
Cookies and browser storage
Debrief uses essential authentication cookies. Signed-out drafts may be stored in the browser’s local storage. The alpha does not include advertising cookies or cross-site analytics.
Retention and deletion
Account data remains until the tester deletes individual workspaces or uses Account and data → Delete account and data. Account deletion removes database records and stored test documents from active application storage. Hosting and infrastructure providers may retain encrypted backups or security logs under their own configured retention schedules. The alpha administrator must document those vendor schedules before real-data use.
Security and health-data status
Debrief uses account-scoped access checks, database sessions, private test-file storage, file-signature checks, random storage keys, request limits, and security headers. The alpha does not have malware scanning, a completed production threat assessment, or a determination that its controls meet requirements for real health data. Debrief does not claim to be HIPAA compliant.
Your choices
You can use public educational pages without signing in, remove individual claims and test documents, delete the entire account, or stop participating in the alpha. For a privacy or deletion problem, debrief_admin@pm.me.
Google user data
Information received through Google sign-in is limited to authentication and account identification. Debrief’s use and transfer of that information follows the Google API Services User Data Policy, including applicable Limited Use requirements.
Important legal scope
Depending on the product’s future data sources and relationships, laws beyond HIPAA may apply, including the FTC Act and the FTC Health Breach Notification Rule. This notice must be reviewed by qualified counsel before accepting real claimant information or opening access beyond a controlled fictional-data alpha.