Legal
Privacy Policy
Effective August 24, 2026 · Version 2026-v1
1. Scope and responsibility
This Privacy Policy explains how Acuity Medical Technologies, LLC (“Acuity,” “we,” “us”) handles information through this website, CCT Critical Care (the “App”), its supporting services, and related support. This Policy does not govern the independent practices of Apple, Google, RevenueCat, OpenAI, OpenStreetMap services, or external sites you visit.
2. Website information
This website does not use advertising trackers, behavioral advertising, account sign-in, or a marketing analytics platform in its initial release. The hosting provider may process routine technical information such as IP address, browser or device type, requested page, time, response status, and security events to deliver and protect the site. Contact links open your email provider; the website does not submit a contact form or store form entries.
3. Business and project inquiries
If you contact Acuity about software, product design, prototyping, parts, production, teaching materials, or another business matter, we process the contact information and project details you choose to send so we can evaluate and respond to the inquiry, prepare requested project communications, and maintain appropriate business records. Do not send patient information, credentials, export-controlled material, or confidential design files until an appropriate submission method and any needed agreement are in place.
4. App information we collect or process
- Subscription and entitlement data. The applicable app store processes payment. RevenueCat receives an app-generated customer identifier, transaction or receipt information, product and subscription status, and technical information needed to validate and restore access. The App server receives the app-generated identifier and entitlement or limit status to protect paid features and prevent abuse. These records are not used for advertising or cross-app tracking.
- Optional AI and import content. Before the first use of each optional cloud-AI feature, the App identifies the selected data, recipient, and purpose and requires affirmative consent. If you agree, the App transmits only the text, image, or file you select, including visible content, through Acuity’s processing service and to OpenAI, L.L.C. for the requested extraction or formatting. Do not submit patient identifiers, protected health information, credentials, or other confidential information.
- Optional precise location. With permission, precise coordinates are used on the device to sort nearby facilities and select a state directory cache. If you separately request an OpenStreetMap nearby-services search, coordinates are sent directly to OpenStreetMap Overpass for that request. Acuity does not request location for advertising or continuous background tracking.
- Data stored on the device. Preferences, accepted-notice version, reference selections, workflow notes, imported facility or equipment lists, matching overrides, caches, and similar content may be stored locally. On native devices, protected facility and scanner records use platform-backed encrypted storage. Lab results expire within 24 hours and ventilator results within 8 hours. Selected scanner images remain only in active memory during the current retry or review flow and clear when the app or page reloads.
- Typed correction reports. Typed, non-patient-specific correction reports may include the affected item, current value, proposed correction, and supporting context. Common identifier patterns are rejected. Time-limited submission text is deleted under the App’s documented correction-retention process; governance status may remain.
- Technical, security, and support data. Services may process request IP address, app-generated identifier, feature requested, timestamps, request size, entitlement or rate-limit status, error details, and similar diagnostic metadata. Support messages contain the information you choose to provide.
5. How information is used
We use information to provide requested features; extract and format selected content; identify nearby facilities; validate and restore subscriptions; enforce feature limits; secure and troubleshoot the App and website; respond to support; comply with law; and protect users, the public, and our rights. We do not sell submitted clinical content or use it for advertising.
6. Service providers and disclosures
Depending on the feature, information may be processed by the applicable app store, RevenueCat, hosting and infrastructure providers, OpenAI for optional AI processing, OpenStreetMap services for an explicitly requested nearby search, and professional advisers or authorities when legally required. These providers have independent roles and policies. We do not operate third-party advertising trackers.
7. Retention
- Submitted AI or import content is processed to produce a response and is not intentionally added to an App database or application log. Hosting infrastructure may handle it temporarily. OpenAI API inputs and outputs may be retained securely for up to 30 days for abuse monitoring unless a different approved control applies.
- Technical metadata is retained only as reasonably needed for security, rate limiting, troubleshooting, service continuity, and legal obligations, then deleted or de-identified when feasible.
- Subscription records are retained by the app store and RevenueCat as needed for entitlement restoration, fraud prevention, accounting, disputes, and legal obligations.
- Device data remains until you clear it, the applicable cache expires, or you uninstall, subject to the shorter scanner-result periods described above.
- Support and legal records are retained while needed to respond, document resolution, protect rights, and meet legal obligations.
8. Your choices and requests
- Deny or revoke location permission in device settings.
- Avoid optional scanners, AI imports, and parsers, or withdraw future cloud-AI permission in Settings → Privacy & AI Controls.
- Use available clear or reset controls, clear browser or app data, or uninstall to remove device-stored data.
- Manage subscriptions and transaction history through the applicable app-store account.
- Email us to request access, correction, or deletion of Acuity-controlled personal information. Verification may be required, and information required for security, transactions, disputes, or law may be retained.
Depending on where you live, law may provide additional privacy rights. We will honor verified requests when applicable and will not discriminate for exercising a protected right.
9. Security
Network requests use encrypted transport, and the App applies access controls, input limits, rate limits, and other safeguards. No method of storage or transmission is guaranteed secure. Users remain responsible for device security, screen privacy, authorized use of facility access information, and organizational policy.
10. Health-information notice
The App is not offered as a HIPAA-compliant chart or business-associate service. Do not use it to create, receive, maintain, or transmit protected health information on behalf of a covered entity or business associate unless the organization has approved the complete workflow and any required agreements are in place.
11. Children, transfers, and changes
The App is intended for credentialed healthcare professionals and is not directed to children. Service providers may process information in the United States or other countries where they operate, subject to applicable safeguards. Material Policy revisions will receive a new effective date and, when appropriate, an in-app notice.
12. Contact
For privacy questions or verified data requests, email privacy@acuitymedicaltechnologies.com. For a responsible security report, email security@acuitymedicaltechnologies.com. Include enough detail to identify the feature and request, but do not email patient information, passwords, access codes, or payment details.