POTS Check Privacy Policy

How we protect your health data

Effective Date: November 20, 2025
Version: 1.4
Last Updated: November 29, 2025

đź”’ Your Privacy is Our Priority

POTS Check is designed with privacy-first principles. Your health data belongs to you, and you have complete control over how it's stored, used, and shared.

1. Introduction

This Privacy Policy describes how POTS Check ("the App," "we," "us," or "our"), developed by Cascade Agentic Labs LLC, collects, uses, stores, and protects your personal information and health data.

Key Points:

2. Information We Collect

2.1 Health Data

POTS Check collects the following health information to provide wellness tracking functionality:

Data Type Source Purpose Storage
Heart Rate Apple Watch via HealthKit (READ access) Measure orthostatic heart rate response during test Local device, encrypted
Blood Pressure Manual entry by user Track blood pressure changes during standing Local device, encrypted
Age (Month/Year) User input Apply age-appropriate POTS screening thresholds Local device, encrypted
Symptom Notes Optional user input Track symptoms during test (max 100 characters) Local device, encrypted
Posture Data iPhone Core Motion sensors Validate standing posture during test Local device, not persisted
Workout Session HealthKit WRITE access Enable continuous heart rate monitoring during test HealthKit (Apple manages)
Health Profile Optional Apple Health import (Secure Account only) Baseline vitals context: BP history, HRV, resting/walking HR, respiratory rate for POTS test interpretation Local device, encrypted

Important Notes:

2.2 Technical Data

We collect minimal technical data necessary for app functionality:

We do NOT collect:

2.3 Anonymous Usage Analytics

Effective: Current version and later

To improve app experience and identify issues, we collect anonymous usage analytics via TelemetryDeck, a privacy-first analytics service:

What We Collect:

What We Do NOT Collect:

How Analytics Work:

Anonymous usage analytics are disabled by default. During onboarding, you will be asked if you want to share anonymous usage data to help improve the app. You can:

How to Change Analytics Setting:

  1. Open Settings in POTS Check
  2. Navigate to Data & Privacy section
  3. Toggle "Share Anonymous Usage Data" on or off

When disabled, no analytics events will be sent to TelemetryDeck. This does NOT affect app functionality.

Note for Existing Users: If you installed POTS Check before November 20, 2025, your current analytics setting is preserved.

Data Processor:

Purpose: Analytics help us identify onboarding drop-off points, test completion rates, watch connectivity issues, and feature adoption—allowing us to improve the app for all users.

3. How We Use Your Information

3.1 Primary Uses

Your health data is used exclusively for the following purposes:

3.2 Prohibited Uses

We will NEVER use your health data for:

4. Data Storage and Security

4.1 Two-Tier Architecture

POTS Check offers two modes with different storage approaches:

Guest Mode (Free)

Secure Account Mode (Free)

Note: Secure Account is free to create and use. Subscription barriers have been removed to improve accessibility.

4.2 Encryption Details

Encryption Algorithm: ChaCha20-Poly1305 (AEAD)

Key Storage: iOS Keychain

File Protection: iOS Data Protection

4.3 Data Residency

In the current version of POTS Check:

Future Cloud Sync: If you choose to enable cloud synchronization in future versions:

5. Data Sharing and Third Parties

5.1 No Sale of Health Data

We will NEVER sell your health data to third parties for monetary compensation. Your health information is not a commodity.

5.2 User-Initiated Sharing Only

The ONLY way your health data leaves your device is if YOU explicitly choose to:

Sharing requires affirmative action—pre-checked boxes or default sharing are NOT used.

5.3 Service Providers

We may use third-party service providers for:

Service providers:

5.4 Legal Compliance

We may disclose your information if required by law, such as:

We will notify you of such requests unless prohibited by law.

6. Your Privacy Rights

You Have the Right To:

  • Access Your Data: View all test results and health data stored by the app
  • Export Your Data: Download your complete test history as PDF or TTL files
  • Delete Your Data: Remove individual tests or delete all data at once
  • Revoke HealthKit Access: Disable heart rate monitoring via iOS Settings
  • Opt Out of Usage Analytics: Disable anonymous usage tracking via in-app Settings
  • Opt Out of Crash Reporting: Disable analytics via iOS Settings → Privacy
  • Request Data Portability: Export data in interoperable formats (RDF/Turtle)
  • Object to Processing: Stop using the app at any time without penalty

6.1 How to Exercise Your Rights

6.2 Data Retention

Guest Mode: Data deleted immediately when app closes or new test starts

Secure Account: Data retained until you manually delete it—no automatic deletion

Backup Policy: If you delete data, it is permanently removed and cannot be recovered

7. Children's Privacy (COPPA Compliance)

7.1 Age Requirements

7.2 Parental Controls

If you are a parent or guardian consenting to a minor's use (ages 13-17):

7.3 No Collection from Children Under 13

We do not knowingly collect health information from children under 13. If we discover we have inadvertently collected such data, we will delete it immediately.

8. International Users and Data Transfers

8.1 Data Residency

All data remains on your local device. No international data transfers occur.

8.2 Future Cloud Sync

If you enable cloud synchronization in future versions:

8.3 GDPR Rights (EU Users)

European Union users have additional rights under GDPR:

8.4 CCPA Rights (California Users)

California residents have rights under CCPA:

9. Security Breaches and Incident Response

9.1 Security Measures

We implement industry-standard security practices:

9.2 Breach Notification

In the unlikely event of a security breach affecting your health data, we will:

Note: All data is local-only, significantly reducing breach risk.

10. HealthKit Data Policy

10.1 Apple HealthKit Requirements

In compliance with Apple's HealthKit policies:

10.2 HealthKit Permissions

Required Permissions (All Users)

These permissions are required for test functionality:

Optional Permissions (Secure Account Only - Health Profile)

If you choose to import your Health Profile, you may grant access to:

Important Notes:

You can revoke any of these permissions at any time in:

iOS Settings → Privacy & Security → Health → POTS Check

10.3 Health Profile Blood Pressure Import (Optional)

During Tests: All blood pressure readings are entered manually during tests. The app does not measure BP automatically.

Health Profile Import (Optional): If you have a Secure Account and choose to import your Health Profile, you can grant optional access to historical blood pressure data from third-party HealthKit-compatible devices (e.g., Omron, Withings BP cuffs that sync to Apple Health).

Purpose of BP Import:

What is NOT Collected:

11. Changes to This Privacy Policy

11.1 Updates

We may update this Privacy Policy to reflect:

11.2 Notification

We will notify you of significant changes by:

11.3 Version History

Previous versions of this Privacy Policy are available upon request.

12. Contact Information

Questions About Privacy?

For privacy-related inquiries, data access requests, or concerns, contact us at:

Privacy Officer
Cascade Agentic Labs LLC
Email: privacy@cascadeagenticlabs.com
Website: https://cascadeagenticlabs.com

Response Time: We will respond to privacy requests within 30 days.

13. Additional Resources