Privacy Policy
Effective Date: January 2, 2026
Last Updated: July 18, 2026
Jones Technical Enterprises, LLC (“we,” “us,” or “our”) operates the OIT Tracker mobile application (the “App”). This Privacy Policy explains what information we collect, why we use it, when we disclose it, how long we keep it, and the choices available to you.
For disclosures and rights specifically concerning consumer health data, see our separate Consumer Health Data Privacy Policy.
1. Information We Collect
1.1 Information You Provide
Depending on the features you use, you may provide:
- Account information: An authentication identifier, optional email address, optional display name, and a device-generated identifier used for offline synchronization. We do not receive your account password from the authentication provider.
- Age-eligibility information: The App uses your date of birth on your device to determine whether you are an adult or an authorized minor age 13 or older, then discards the date. We store only the resulting eligibility class and the date of the check. If the user is under 13, the App does not create an account or collect usage data from that user.
- Child and treatment information: A child’s first name or nickname, optional date of birth, allergens, treatment details, dose history, reactions, sickness-mode periods, notes, care instructions, and derived treatment-progress information.
- Clinician and emergency information: Optional clinician or clinic contact details, emergency contacts, medications, treatment instructions, and information saved from an emergency action plan.
- Photos and documents: Child photos and action-plan page images are stored on your device. Child photos are never uploaded. An action-plan image leaves your device only if you choose and consent to AI-assisted entry, as described below.
- Caregiver information: A caregiver’s email address, requested permission level, and sharing status when you invite someone to access a child’s records.
- Support communications: Information you choose to include when contacting us.
Free-text fields and documents may contain additional information you choose to provide. Avoid including information that is not needed to use the App.
1.2 Information Collected Automatically
We may collect:
- Device and technical information: Device type, operating-system version, App version, and limited information needed to operate and configure the App.
- Product telemetry: Usage events, timestamps, App and device information, subscription tier, a randomly generated analytics identifier, and limited structured information about feature use. Some events may describe treatment activity, such as logging a dose or entering sickness mode, so we treat them as consumer health data when applicable. Telemetry does not include child names, email addresses, photos, precise location, or free-text notes in its event content, but transmitted telemetry may be linkable to an account or App installation.
Telemetry is buffered while offline and sent when the App has network access. It is optional and may be turned off as described in Section 6.
1.3 Website Waitlist
If you join the waitlist at oittracker.com, we collect your email address and use an email service provider to manage the list and send launch communications. The waitlist does not collect child or health information. You may unsubscribe through any waitlist email.
1.4 Information We Do Not Require
We do not require Social Security numbers, government identifiers, financial-account information, or precise geolocation. App Store purchases are handled by the app-store provider; we receive subscription status, not your payment-card details.
2. How We Use Information
We use information to:
- Provide the App’s tracking, record-organization, and family-sharing features
- Store information locally and synchronize selected records across your devices
- Make records available to people you authorize
- Authenticate accounts and manage subscriptions
- Calculate and display treatment-progress information from dose records
- Respond to support requests
- Understand feature use, diagnose problems, secure the service, and improve the App
- Comply with applicable law
Optional AI-Assisted Action-Plan Entry
If you choose and consent to AI-assisted entry, an action-plan page image is sent to a cloud AI processor to extract information for your review. Our backend does not store the submitted image or extraction response. The processor does not use the information to train models and does not retain it after processing, except for limited security-related processing. Only the information you review and save becomes part of the synchronized health record.
AI-assisted entry organizes information; it does not make treatment or dosing decisions. Always compare extracted information with the original clinician-issued document.
We do not use health data for targeted advertising, sell it, or use it to make treatment decisions about you or your child.
3. How We Disclose Information
We disclose only the information needed for the following purposes:
| Recipient Category | Information Disclosed | Purpose |
|---|---|---|
| Cloud hosting and operations providers | Account information, synchronized health records, derived metrics, technical information, and product telemetry | Host, secure, process, and synchronize the App |
| Optional AI document processor | An action-plan image and the extraction response, only when you request AI-assisted entry | Extract information for your review |
| Authentication and app-store providers | Authentication identifier, optional email address, and subscription or purchase status | Sign-in, identity, payment, and subscription management |
| Communications providers | Waitlist email addresses; or a caregiver recipient’s email address and invitation code | Send requested waitlist or caregiver-invitation emails |
| People you authorize | The child and health records allowed by the permission you select | Provide family sharing |
| Legal or regulatory recipients | Information legally required in the circumstances | Comply with valid legal process or applicable law |
We require service providers to protect information and process it only for the services they provide to us, subject to their independent legal and security obligations.
3.1 Family Sharing
Family sharing is optional. No health record is shared with another person until an invitation is accepted.
You choose which children to share and whether the recipient may view or edit records. A view-only recipient may have limited access to some record types, but safety information—including treated allergens, current sickness status, saved emergency-action information, and clinician contacts—remains visible. Editors and co-owners can access all records within the scope of their role. A co-owner can access and manage records for every child in the family, including children added later; only the primary owner may delete a child profile.
Child photos and action-plan page images are not shared through family sharing. We use a communications provider to deliver the invitation email; it receives the recipient’s email address and invitation code, not the child’s name or health records.
The primary owner may change permissions or revoke access. Revocation prevents future access through our systems but cannot recall information the recipient already viewed, downloaded, printed, or otherwise retained. If the primary owner deletes the account, family records follow the account-deletion process in Section 5; a co-owner does not automatically inherit them.
3.2 No Sale or Targeted Advertising
We do not sell, rent, or trade personal information or consumer health data. We do not disclose consumer health data for targeted advertising.
4. Storage and Security
The App is offline-first. Records are stored locally on your device so core features work without a network connection. Account and health records selected for synchronization are also stored on servers in the United States.
Child photos stay on the device where they were added. Action-plan images also stay on-device unless you request AI-assisted entry; in that case, the image is processed transiently as described in Section 2 and is not stored by our backend.
We use administrative, technical, and physical safeguards designed to protect information, including encryption in transit and at rest, restricted server access, access logging, and secure authentication. No system can be guaranteed completely secure.
Breach Notification
If we discover a breach involving identifiable health information, we will investigate, contain, and remediate it and notify affected users without undue delay and no later than 60 calendar days after discovery. We will also notify regulators or others when required by the FTC Health Breach Notification Rule or other applicable law. A notice will describe what happened, the information involved, our response, and steps users can take, to the extent known at the time.
5. Retention and Deletion
- Active and inactive accounts: We retain account and health data while the account is active. If an account remains inactive for an extended period, we may delete the account data after attempting to notify you using available contact information and giving you an opportunity to keep the account active by signing in.
- Account deletion: After you delete an account, we retain account-linked data for a 90-day recovery period and then permanently delete it. Synchronized health records, derived treatment-progress information, and family-sharing records follow this lifecycle.
- Product telemetry: Individual telemetry events are retained for no more than 18 months and then deleted or aggregated. Telemetry already transmitted is not removed by the in-App account-deletion flow. While telemetry remains linkable, contact support before deleting the account if you want us to authenticate and process a deletion request for those records.
- AI processing: Our backend does not retain the submitted action-plan image or extraction response. Limited security-related processing by the AI processor may occur as described in Section 2.
Deleting or revoking access cannot remove information independently retained by an authorized recipient or erase copies stored outside our systems.
6. Your Choices and Rights
Depending on applicable law, you may have the right to access, obtain, correct, or delete information; withdraw consent; receive information about disclosures; or appeal a refusal to act on a request. Parents and legal guardians may exercise applicable rights for their children.
You can:
- Review and correct most records directly in the App
- Delete your account through Settings → Account → Delete Account
- Change or revoke family-sharing access from the Account screen
- Stop future product telemetry through Settings → Privacy & Data by switching off Share Anonymous Analytics; this also discards unsent events still queued on the device
- Request access, portability, correction, or deletion by emailing support@oittracker.com
Despite the current analytics-setting label, transmitted telemetry may be linkable as described in Sections 1.2 and 5. For consumer-health-data rights and request procedures, see our Consumer Health Data Privacy Policy.
We may take reasonable steps to verify your identity and authority before completing a request. We will not unlawfully discriminate against you for exercising a privacy right.
7. Children’s Privacy and Age Requirements
The App is designed for parents and guardians to track a child’s oral immunotherapy treatment. A parent or authorized caregiver may enter information about a child of any age.
A child under 13 may not create an account, sign in, accept an invitation, operate the App, or enter information. An authorized minor age 13 or older may use the App only through an invitation initiated by a parent or legal guardian. We do not knowingly collect information directly from children under 13. If we learn that a child under 13 used the App or submitted information directly, we will disable access and take appropriate steps, which may include notifying the parent or guardian and deleting information collected directly from the child.
Parents may review a child’s information in the App, delete eligible child or account records, and contact us at support@oittracker.com. If you believe a child under 13 has used the App directly, contact us.
8. California Residents
California residents may have rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act. Some obligations apply only to businesses that meet statutory thresholds; we extend the following rights as a matter of practice:
- Know and access personal information
- Delete personal information
- Correct inaccurate personal information
- Limit use of sensitive personal information outside permitted purposes
- Opt out of sale or sharing as defined by California law
- Exercise rights without unlawful discrimination
We use sensitive health information only to provide and improve the App, not to infer unrelated characteristics or for advertising. We do not sell or share personal information as those terms are defined by the CCPA/CPRA.
To submit a request, email support@oittracker.com. We may verify the request and will respond within applicable legal timeframes. An authorized agent may submit a request on your behalf.
9. Third-Party Links
The App may link to third-party resources. We are not responsible for their privacy practices, and we encourage you to review their policies.
10. Changes to This Policy
We may update this policy by changing the “Last Updated” date. We will provide an in-App notice of material changes and request affirmative consent when required before materially expanding how previously collected personal or health information is used or disclosed.
11. Contact Us
Jones Technical Enterprises, LLC
Email: support@oittracker.com
For privacy inquiries, include Privacy in the subject line.
12. Users Outside the United States
OIT Tracker is intended for use in the United States and does not target users in the European Economic Area, United Kingdom, or other regions. If you access the App from outside the United States, you are responsible for applicable local requirements, and your information will be processed in the United States as described here. We will update this policy before intentionally expanding availability to regions requiring additional disclosures or safeguards.
This Privacy Policy is governed by the laws of the State of Illinois, United States.