GlottaVue Privacy Policy
Last updated: September 22, 2026
This policy applies to GlottaVue Anesthesia, including TestFlight versions. Features may appear first in testing builds and may not be available in every installed version. GlottaVue is a professional clinical reference and planning tool, not a patient-record system. Do not enter patient names, birth dates, medical record numbers, contact details or other identifiers.
Offline tools and local storage
The bundled clinical library, pre-set dosing workflow and local planning tools operate on your device. Unsaved measurements and working drafts stay in memory unless you save, export, request AI synthesis or choose optional sync. The main dosing workflow reads precomputed reference tables; other named calculators use their stated inputs.
Saved dosing cases retain the entered age, weight, optional height, sex, non-identifying label and medication/equipment selections. Saved offline care plans retain the entered measurements, assessment/history, reference and medication selections, planning notes and label. Numeric care-plan doses and concentrations are not saved; catalogue doses are recalculated when reopened and manual values may need to be entered again. Measurements do not update automatically.
My workspace stores favorites, preference cards, case logs, study cards and review dates. Training logs may include dates, minutes, experience counts, site/supervisor notes, self-review status and the selected training cohort. The app does not send these records to a school, accreditor or certification body. Handoff drafts, bay tracking and the timer remain in screen memory. Notes, custom profiles, preferences, AI consent choices and an app-generated random rate-limit identifier may also be stored locally.
Operating-system backups may include local storage. Uninstalling ordinarily removes local app data but does not erase backups, exports or a synced server copy. PDF, Word, CSV, Excel and other exports are handled by the destination you choose. Workspace JSON backup covers its favorites, preference cards, logs and study cards; it excludes dosing cases, care plans, Notes, credentials and handoff drafts.
Optional Account & Sync
Sign in with Apple is optional on supported Apple devices. Signing in alone does not upload your workspace. When you choose Sync now, the app sends workspace favorites, preference cards, case logs, study cards, Notes, saved care plans and saved dosing cases to GlottaVue's Cloudflare-hosted backend. This includes saved age, weight, height, sex, assessment/history, free-text notes and medication selections where present. Free text is not automatically de-identified. Do not include patient identifiers.
Synced records are linked to your Apple account through a one-way hash of Apple's app-specific user identifier and retained for later manual sync. The app keeps the Apple user identifier and any name/email Apple shares locally for account display. The backend verifies Apple identity tokens. Sync contents, identity tokens and authorization codes are not sent to an AI provider. Optional sync is not represented as end-to-end encryption or a patient-record service. Signing out alone does not delete the cloud copy.
Versions with Account & sync → Delete account and saved data request deletion of the cloud document and the corresponding workspace, Notes, saved plans and cases on the requesting device, and revoke Sign in with Apple authorization. Confirmation is required because unsynced local entries in these collections are also removed. If your installed version does not include this control, request account and cloud-data deletion at conorearly@gmail.com; do not send patient information. After deletion, only a hashed account key and deletion time are retained for up to two days to reject replay of earlier tokens. A later explicit sign-in and sync can create a new account copy.
Other devices' local copies, previous exports, recipients' copies and operating-system backups are not erased by account deletion. Manage those separately. Any store subscription from an earlier version must be cancelled in the store's subscription settings; deleting the account does not cancel it.
Online AI features
Ask a Clinical Question and AI care-plan synthesis are optional, require an internet connection and have separate consent disclosures. Ask sends your question and relevant prior conversation turns to our Cloudflare-hosted backend, which forwards the content to the DeepSeek API. Care-plan synthesis sends the entered case details and assembled offline draft through the same backend to DeepSeek. The app-generated random device identifier is used by our backend for limits and is not included in the model prompt.
For source-enabled questions and care plans, the backend retrieves public reference material through PubMed and DailyMed. Care-plan lookup uses non-identifying topic queries; source-enabled questions use the submitted question to look for relevant material. Do not submit identifying or confidential information. Retrieved references and generated output require independent professional review.
The application does not write AI question, answer, case or plan text to its rate-limit database. AI requests use provider APIs; care-plan requests set store:false. Provider processing and retention may still apply. GlottaVue cannot guarantee that DeepSeek deletes submitted content immediately or excludes it from model training. Do not submit patient identifiers or other sensitive personal information. Cloudflare and DeepSeek may receive ordinary connection information, timestamps and headers under their own practices. Provider terms can change: see DeepSeek's API terms, DeepSeek's privacy policy and Cloudflare's privacy policy. AI output is not a secure clinical message, patient chart or patient-specific consultation.
Limits, operational counts and update checks
The random device identifier is generated by the app and contains no name, email, advertising identifier or hardware identifier. The backend hashes it for temporary rate-limit counters. Daily question counters expire after approximately 25 hours; calendar-month care-plan counters expire after up to 45 days. Only successful care-plan generations consume the monthly allowance.
To monitor reliability and cost, the backend retains daily aggregate counts of AI attempts, successes, errors, limit responses, modes, platforms and estimated usage cost for up to 400 days. These aggregates do not contain question or answer text, IP addresses, account identifiers or persistent device identifiers. They do not identify who first downloaded or opened the app.
The app occasionally fetches a public release list from our Cloudflare backend and compares it with the installed version on the device. The request does not include patient inputs, questions, notes, the installed version or the app-generated device identifier. Cloudflare receives ordinary connection information. The release list, last check and dismissed announcement are stored locally. Failed checks do not prevent offline use.
Purchases, analytics and external links
The current public build does not offer or require a GlottaVue subscription. Historical purchases, where applicable, are processed by Apple or Google under their policies. Any future paid offer will disclose its terms before purchase. See Apple's privacy policy and Google's privacy policy.
The app does not include a GlottaVue advertising or third-party analytics SDK. Apple and Google may provide installation, purchase, performance or diagnostic reports according to device settings and their policies. External links open services with their own privacy practices. This website is hosted separately and has its own ordinary web/cookie behavior; visiting it is not an app telemetry event.
Security and your choices
Online requests use HTTPS. Rate-limit and sync account keys are hashed as described above. No system can guarantee complete security. Use offline references without AI or sync, decline online consent, and delete local entries using the relevant controls. Free text is user-entered and must not contain patient identifiers. GlottaVue is intended for healthcare professionals and trainees, not children; we do not knowingly solicit children's personal information.
Changes and contact
We may update this policy when features, providers or data practices change. The date above identifies the current revision. Questions and deletion requests: conorearly@gmail.com. Please do not include patient information in support messages.