Legal

Privacy Policy

Effective August 4, 2026 · HealthPilot is operated by PilotSuite LLC.

This policy explains how PilotSuite LLC ("we," "us," or "our") handles information when you use the HealthPilot website, web app, mobile app, and related services (the "Service"). HealthPilot is designed to work locally, with account-based cloud sync and AI features available when you choose to use them.

1.The short version

  • Local first. You can use HealthPilot without an account. Records remain in the web browser or mobile app storage unless you sign in and use cloud features.
  • Your health information is not for advertising. We do not sell personal information or use health information for targeted advertising.
  • You choose when to use AI. Recent records are sent for AI processing only when you request an AI-powered feature.
  • Billing is handled by established providers. RevenueCat, Apple, Google Play, and their payment partners handle purchases and subscription status; we do not receive your full payment card number.

2.Information we handle

Account information. If you create an account, we handle information such as your name, email address, authentication provider, and a unique account identifier. Authentication is provided through Firebase Authentication and, when selected, Sign in with Apple.

Wellness records. HealthPilot may contain information you choose to enter, including symptoms, mood, energy, sleep, pain, stress, meals, habits, medications, goals, tags, pregnancy tracking, condition-pack entries, notes, and appointment-preparation content.

Subscription information. We receive purchase and entitlement information such as your plan, renewal status, product identifier, transaction identifier, and subscription-management link from RevenueCat, Apple, Google Play, and their payment partners.

Location and weather information. If you grant the mobile app foreground location permission and use local weather, the app rounds your latitude and longitude before sending the approximate coordinates to HealthPilot and OpenWeatherMap to return current weather. HealthPilot does not retain those coordinates or use location for advertising.

Apple Health information. If you choose to connect Apple Health, the mobile app may read the activity and wellness categories you authorize, such as steps, sleep, resting heart rate, active energy, and weight, and may write mindfulness sessions you choose to record. You can change Health permissions in iOS Settings.

AI and voice request information. When you request AI-generated insights, HealthPilot sends the recent records needed for that request to our server and OpenAI. If you use voice logging, your microphone recording is sent for transcription and the resulting text is processed to create the requested record. The app removes its temporary recording after processing. AI output can be inaccurate and is not a diagnosis or treatment recommendation.

Technical, installation, and support information. The mobile app creates an anonymous Firebase installation identity on first use so our server can authenticate app requests, enforce feature limits, and protect the Service even when you do not create a named account. Our hosting and security providers may also process standard technical information such as IP address, browser type, device type, request logs, and timestamps. We do not use the anonymous identity for advertising. If you contact us, we keep the message and contact details needed to respond.

3.Where information is stored

On your device. The web app stores local records in browser storage, and the mobile app stores local records within its app storage. These stores rely on the security of your browser, device, and operating system and are not separately end-to-end encrypted by HealthPilot. You can remove records with HealthPilot's data controls; web records can also be removed through browser storage controls.

In your cloud account. If you sign in and use cloud continuity, records may be stored in Google Firebase so they can be available across supported devices. Cloud records are associated with your authenticated account.

With service providers. Subscription, hosting, authentication, and AI providers process only the information needed to provide their part of the Service, subject to their own terms and privacy practices.

4.How we use information

  • Provide local tracking, account access, cloud continuity, and cross-device features.
  • Generate charts, summaries, reports, and AI-powered insights you request.
  • Process purchases, verify premium access, and support subscription management.
  • Operate, secure, troubleshoot, and improve the reliability of the Service.
  • Respond to support requests and comply with legal obligations.

5.Service providers and disclosures

We use providers that help operate the Service, including:

  • Google Firebase for authentication and optional cloud data storage.
  • RevenueCat for subscription entitlement and purchase coordination.
  • Apple and Google Play for app distribution, payment processing, and subscription management.
  • OpenWeatherMap for approximate location-based weather when you request that feature.
  • Vercel for website hosting, delivery, and operational logs.
  • OpenAI for AI-powered features you request. Requests are configured not to store generated responses in our API application history, although provider security and abuse-monitoring retention may still apply.

We may also disclose information when required by law, to protect users or the Service, or in connection with a business reorganization. We do not sell personal information or share health information for cross-context behavioral advertising.

6.Data retention

Local records remain in your browser or mobile app until you clear them, remove the relevant app data, or uninstall the app. Temporary mobile voice recordings are removed after processing. Cloud records remain until they are deleted or your account is closed, subject to backups and legal requirements. Subscription and transaction records may be kept as needed for accounting, fraud prevention, tax, dispute resolution, and legal compliance. Support messages are kept as long as reasonably needed to resolve the request.

7.Your choices and privacy rights

  • Use the core web app locally without creating an account.
  • Choose whether to sign in, use cloud continuity, enable notifications, or request AI features.
  • Clear records stored in the current browser from HealthPilot Settings.
  • Manage or cancel a subscription through the applicable billing provider.
  • Delete a signed-in mobile account from Settings → Account → Delete Account, or use our account deletion page.
  • Request access to, correction of, or deletion of account and cloud information by emailing flightcrew@pilotsuite.design.

Depending on where you live, you may have additional rights, including rights to know, correct, delete, or limit certain uses of personal information. We will not discriminate against you for making a valid privacy request.

8.Security

We use reasonable technical and organizational safeguards appropriate to the sensitivity of the information we handle. No internet transmission or storage system can be guaranteed completely secure. Keep your account credentials private and contact us if you believe your account or information may have been compromised.

9.Children

The Service is not directed to children under 13, and we do not knowingly collect personal information from a child under 13 without legally valid authorization. If you believe a child has provided information improperly, contact us so we can review and delete it where appropriate.

10.Changes and contact

We may update this policy as the Service or applicable requirements change. We will update the effective date above and provide additional notice when appropriate. For privacy questions or requests, email flightcrew@pilotsuite.design.