Skip to document
Protocol Home

Legal documents

Health & Safety Privacy Policy Terms of Use Support & Data

Artful Intelligence, LLC · North Carolina, United States

Privacy Policy

Protocol is local-first. Health and routine records stay on your device unless you deliberately export them, send them with feedback, or use optional encrypted account backup.

Effective
August 29, 2026
Revision
2026-08-29.1

Scope and controller

This Privacy Policy explains how Artful Intelligence, LLC ("Artful Intelligence," "we," "us," or "our") handles information in connection with the Protocol iOS app, theprotocolapp.co, beta access, support, and optional account and backup services.

Protocol is designed to be local-first. Many categories of sensitive data can be used without creating an account and are processed only inside the app's local container unless you choose a feature that transmits them.

Information you provide and create

Depending on the features you use, Protocol may process the following information on your device.

  • Protocol, compound, schedule, concentration, dose, administration, injection-location, notification, inventory, vial, preparation, reconstitution, storage, and free-text records.
  • Bloodwork values, laboratory names, reference ranges, units, dates, notes, and source documents or images that you import or scan.
  • App preferences, appearance settings, warning thresholds, and local workflow state.
  • Files you create through JSON or CSV export and any information you choose to include in feedback.
  • If you use an optional account: your email address or Apple-provided account identifiers, authentication state, backup metadata, and encrypted backup objects.
  • If you request beta access or support: your email address, request text, consent state, source path or invite code, and any optional attachment or diagnostic log you elect to send.

On-device processing

Core app records are stored locally using Apple's app storage technologies with iOS data protection. Protocol does not enable CloudKit synchronization for these records. The app's local data directory is excluded from ordinary device backup by the app.

When you scan or import bloodwork, supported text extraction uses Apple's on-device Vision framework. The source document and extracted values remain local unless you deliberately export them, attach them to feedback, or include them in an optional encrypted account backup.

Deleting the app normally removes its local app container. A local-data wipe removes the app's local records and settings but does not automatically delete separately stored encrypted account backups. Account backups must be deleted through the account controls described below.

Network and service data

Some optional or live features communicate with services we operate or providers working for us.

  • Compound catalog: Protocol may retrieve a current compound-title catalog. When you select a catalog title, the service can receive that title, a persistent per-install token, app version and build, iOS version, device model, user agent, and network information used for security and rate limiting. The server stores a hashed form of the install token with title and request metadata. We treat this as pseudonymous usage and diagnostic data, not anonymous data.
  • Feedback and support: if you submit feedback or a support request, the service receives the information you enter and may receive your email, app/build version, iOS version, device model, optional screenshot, and an optional diagnostic log. The diagnostic log is designed to exclude protocol, health, backup, and Keychain contents, but you should still review any attachment before sending it. If you deliberately choose Public Request in the app, and an administrator approves it, the title, public description, type, status, and aggregate votes may be displayed to other users. Your email, private troubleshooting fields, diagnostic log, and attachments are not intended for public display.
  • Accounts and authentication: if you create an account, our authentication provider processes your email address or Sign in with Apple identifiers, authentication events, and session information. Authentication credentials are stored using the iOS Keychain where applicable.
  • Encrypted account backup: if enabled, Protocol encrypts a backup of supported local records and source documents on your device using AES-GCM before upload to private object storage. The recovery key is designed not to be sent to us. We receive encrypted objects and operational metadata such as account identifier, object identifier, size, hash, version, and timestamps.
  • Website and beta access: the website can receive email address, consent state, invite or source path, browser and device information, user agent, IP-derived security information, and request timestamps. Theme preference may be stored in your browser's local storage.

How we use information

We use information only as reasonably necessary to provide, secure, maintain, troubleshoot, and improve Protocol; authenticate accounts; deliver encrypted backups; respond to requests; administer beta access; enforce our terms; prevent abuse; comply with law; and protect users, Artful Intelligence, and others.

We do not use health or routine records for targeted advertising. We do not sell personal information, and Protocol does not include third-party advertising or cross-app tracking SDKs. We will update this policy before materially changing those practices.

Service providers and disclosures

We may disclose the minimum information reasonably necessary to service providers that host infrastructure, provide authentication and private storage, deliver transactional email, process support or security events, or otherwise act for us under appropriate restrictions. Current categories include Supabase-hosted infrastructure, Apple platform and authentication services, and Resend for website or account email delivery where configured.

We may also disclose information when reasonably necessary to comply with law or valid legal process; investigate fraud, abuse, security incidents, or violations; protect rights and safety; complete a merger, financing, acquisition, reorganization, or sale subject to appropriate safeguards; or with your direction or consent.

Apple and other platforms may independently process information under their own terms and privacy policies. Your export destination, email provider, Files provider, and any person with whom you share an export act independently of us.

Retention

Local records remain until you delete them, wipe local data, or uninstall Protocol, subject to iOS behavior. User-created exports remain wherever you place them until you delete them there.

Optional encrypted backups are retained according to the backup policy shown in the app. The current automated policy is designed to keep the newest three backups, daily recovery points for the current day and prior six days, and weekly recovery points for the prior four weeks, although operational failures or future product changes may affect availability. Deleting your Protocol account is designed to delete its backup objects, backup metadata, and authentication user record.

Support, beta, catalog, security, and diagnostic records are retained only for as long as reasonably necessary for the purposes described above, legal compliance, dispute resolution, and abuse prevention. Backups, caches, and logs may take additional time to expire.

Your choices and requests

You can use core local features without an account; decline optional backup; review or edit local records; delete individual records; wipe local data; delete your account and associated encrypted backups through account settings; and control notification, camera, network, and other permissions through iOS where available.

Privacy laws may give you rights to access, correct, delete, or obtain a copy of personal information we hold, or to appeal a request decision. Submit a request through the current support channel listed in the app or at theprotocolapp.co/support. We may need to verify your identity and may retain information where permitted or required by law.

Security and breach notice

We use technical and organizational safeguards intended to protect information, including on-device data protection, encrypted transport, private object storage, and client-side encryption for optional account backups. No storage, encryption, network, device, or service is completely secure or continuously available. You are responsible for device security, safe export handling, and preserving any recovery key shown to you.

If we determine that a security incident triggers a legal notification duty, we will provide notice as required by applicable law.

Children, geography, and changes

Protocol is intended only for adults with legal capacity to accept its terms. It is not directed to children, and we do not knowingly collect personal information from a child through the service. Contact us if you believe a child has provided information.

Artful Intelligence operates from the United States. If you use Protocol elsewhere, information transmitted to our services may be processed in the United States or other locations used by our providers, where law may differ from your jurisdiction.

We may update this policy as Protocol or applicable law changes. The app and public policy identify the effective date and revision. If a change materially affects the promises made to you, we will provide additional notice or request renewed consent when legally appropriate.

Contact

Use Settings > Feedback & Support inside Protocol or the private Support & Privacy Request form at theprotocolapp.co/support for support, privacy, and account-deletion requests. Do not send medical emergencies, full medical records, passwords, or recovery keys through support.

© 2026 Artful Intelligence, LLC. Protocol is a personal organizational and arithmetic tool, not medical advice.

Health & Safety · Privacy Policy · Terms of Use · Support & Data