Privacy Policy

Effective Date: January 2, 2026

Last Updated: July 18, 2026

Jones Technical Enterprises, LLC (“we,” “us,” or “our”) operates the OIT Tracker mobile application (the “App”). This Privacy Policy explains what information we collect, why we use it, when we disclose it, how long we keep it, and the choices available to you.

For disclosures and rights specifically concerning consumer health data, see our separate Consumer Health Data Privacy Policy.


1. Information We Collect

1.1 Information You Provide

Depending on the features you use, you may provide:

Free-text fields and documents may contain additional information you choose to provide. Avoid including information that is not needed to use the App.

1.2 Information Collected Automatically

We may collect:

Telemetry is buffered while offline and sent when the App has network access. It is optional and may be turned off as described in Section 6.

1.3 Website Waitlist

If you join the waitlist at oittracker.com, we collect your email address and use an email service provider to manage the list and send launch communications. The waitlist does not collect child or health information. You may unsubscribe through any waitlist email.

1.4 Information We Do Not Require

We do not require Social Security numbers, government identifiers, financial-account information, or precise geolocation. App Store purchases are handled by the app-store provider; we receive subscription status, not your payment-card details.


2. How We Use Information

We use information to:

Optional AI-Assisted Action-Plan Entry

If you choose and consent to AI-assisted entry, an action-plan page image is sent to a cloud AI processor to extract information for your review. Our backend does not store the submitted image or extraction response. The processor does not use the information to train models and does not retain it after processing, except for limited security-related processing. Only the information you review and save becomes part of the synchronized health record.

AI-assisted entry organizes information; it does not make treatment or dosing decisions. Always compare extracted information with the original clinician-issued document.

We do not use health data for targeted advertising, sell it, or use it to make treatment decisions about you or your child.


3. How We Disclose Information

We disclose only the information needed for the following purposes:

Recipient Category Information Disclosed Purpose
Cloud hosting and operations providers Account information, synchronized health records, derived metrics, technical information, and product telemetry Host, secure, process, and synchronize the App
Optional AI document processor An action-plan image and the extraction response, only when you request AI-assisted entry Extract information for your review
Authentication and app-store providers Authentication identifier, optional email address, and subscription or purchase status Sign-in, identity, payment, and subscription management
Communications providers Waitlist email addresses; or a caregiver recipient’s email address and invitation code Send requested waitlist or caregiver-invitation emails
People you authorize The child and health records allowed by the permission you select Provide family sharing
Legal or regulatory recipients Information legally required in the circumstances Comply with valid legal process or applicable law

We require service providers to protect information and process it only for the services they provide to us, subject to their independent legal and security obligations.

3.1 Family Sharing

Family sharing is optional. No health record is shared with another person until an invitation is accepted.

You choose which children to share and whether the recipient may view or edit records. A view-only recipient may have limited access to some record types, but safety information—including treated allergens, current sickness status, saved emergency-action information, and clinician contacts—remains visible. Editors and co-owners can access all records within the scope of their role. A co-owner can access and manage records for every child in the family, including children added later; only the primary owner may delete a child profile.

Child photos and action-plan page images are not shared through family sharing. We use a communications provider to deliver the invitation email; it receives the recipient’s email address and invitation code, not the child’s name or health records.

The primary owner may change permissions or revoke access. Revocation prevents future access through our systems but cannot recall information the recipient already viewed, downloaded, printed, or otherwise retained. If the primary owner deletes the account, family records follow the account-deletion process in Section 5; a co-owner does not automatically inherit them.

3.2 No Sale or Targeted Advertising

We do not sell, rent, or trade personal information or consumer health data. We do not disclose consumer health data for targeted advertising.


4. Storage and Security

The App is offline-first. Records are stored locally on your device so core features work without a network connection. Account and health records selected for synchronization are also stored on servers in the United States.

Child photos stay on the device where they were added. Action-plan images also stay on-device unless you request AI-assisted entry; in that case, the image is processed transiently as described in Section 2 and is not stored by our backend.

We use administrative, technical, and physical safeguards designed to protect information, including encryption in transit and at rest, restricted server access, access logging, and secure authentication. No system can be guaranteed completely secure.

Breach Notification

If we discover a breach involving identifiable health information, we will investigate, contain, and remediate it and notify affected users without undue delay and no later than 60 calendar days after discovery. We will also notify regulators or others when required by the FTC Health Breach Notification Rule or other applicable law. A notice will describe what happened, the information involved, our response, and steps users can take, to the extent known at the time.


5. Retention and Deletion

Deleting or revoking access cannot remove information independently retained by an authorized recipient or erase copies stored outside our systems.


6. Your Choices and Rights

Depending on applicable law, you may have the right to access, obtain, correct, or delete information; withdraw consent; receive information about disclosures; or appeal a refusal to act on a request. Parents and legal guardians may exercise applicable rights for their children.

You can:

Despite the current analytics-setting label, transmitted telemetry may be linkable as described in Sections 1.2 and 5. For consumer-health-data rights and request procedures, see our Consumer Health Data Privacy Policy.

We may take reasonable steps to verify your identity and authority before completing a request. We will not unlawfully discriminate against you for exercising a privacy right.


7. Children’s Privacy and Age Requirements

The App is designed for parents and guardians to track a child’s oral immunotherapy treatment. A parent or authorized caregiver may enter information about a child of any age.

A child under 13 may not create an account, sign in, accept an invitation, operate the App, or enter information. An authorized minor age 13 or older may use the App only through an invitation initiated by a parent or legal guardian. We do not knowingly collect information directly from children under 13. If we learn that a child under 13 used the App or submitted information directly, we will disable access and take appropriate steps, which may include notifying the parent or guardian and deleting information collected directly from the child.

Parents may review a child’s information in the App, delete eligible child or account records, and contact us at support@oittracker.com. If you believe a child under 13 has used the App directly, contact us.


8. California Residents

California residents may have rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act. Some obligations apply only to businesses that meet statutory thresholds; we extend the following rights as a matter of practice:

We use sensitive health information only to provide and improve the App, not to infer unrelated characteristics or for advertising. We do not sell or share personal information as those terms are defined by the CCPA/CPRA.

To submit a request, email support@oittracker.com. We may verify the request and will respond within applicable legal timeframes. An authorized agent may submit a request on your behalf.


The App may link to third-party resources. We are not responsible for their privacy practices, and we encourage you to review their policies.


10. Changes to This Policy

We may update this policy by changing the “Last Updated” date. We will provide an in-App notice of material changes and request affirmative consent when required before materially expanding how previously collected personal or health information is used or disclosed.


11. Contact Us

Jones Technical Enterprises, LLC

Email: support@oittracker.com

For privacy inquiries, include Privacy in the subject line.


12. Users Outside the United States

OIT Tracker is intended for use in the United States and does not target users in the European Economic Area, United Kingdom, or other regions. If you access the App from outside the United States, you are responsible for applicable local requirements, and your information will be processed in the United States as described here. We will update this policy before intentionally expanding availability to regions requiring additional disclosures or safeguards.


This Privacy Policy is governed by the laws of the State of Illinois, United States.