Privacy Policy

Last updated: July 18, 2026

PilotFlow Health LLC ("we", "our", or "us"), a Florida limited liability company, provides automated patient-communication software for healthcare providers. This Privacy Policy explains what data we access, how we use it, who we share it with, how we protect it, and how it is retained and deleted.

1. Google Data We Access

When a healthcare provider authorizes PilotFlow, we request a single Google permission:

We do not read, download, or store the contents of the provider's mailbox. The gmail.send permission is send-only; PilotFlow cannot access received mail, drafts, labels, contacts, or any other mailbox data. We store only the token needed to send on the provider's behalf and the sender email address.

2. How We Use Google User Data

PilotFlow's use of information received from Google APIs is limited to sending appointment, welcome, and follow-up communications on behalf of the authorized provider, to that provider's patients and inquirers.

We do not use Google user data to serve advertisements, build user profiles, or for any purpose other than the email service described above.

We do not sell Google user data, and we do not share it with advertisers or data brokers. We share data only with the infrastructure subprocessors required to operate the service, under contract and, where Protected Health Information is involved, under a Business Associate Agreement: Google Workspace (email delivery and hosting) and Amazon Web Services, including AWS Bedrock (application hosting and AI email generation).

3. AI Processing and Limited Use

PilotFlow uses an AI service (Anthropic Claude via AWS Bedrock) to draft email content from provider-supplied information. AWS Bedrock does not retain inputs or use them to train models. PilotFlow does not use Google user data to develop, improve, or train AI/ML models, and does not transfer Google user data to any third party for that purpose.

PilotFlow's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

4. Data Storage and Security

OAuth tokens are stored as protected secrets and used solely to send email on the authorized provider's behalf. Patient-communication information (names, email addresses, appointment dates, and notes) provided by the provider is stored in Google Workspace and processed on Amazon Web Services. Data is transmitted over encrypted connections (TLS), access is limited and protected by two-factor authentication, and Protected Health Information is handled under signed HIPAA Business Associate Agreements.

5. Data Retention and Deletion

We retain provider and patient-communication data for as long as the provider is an active PilotFlow customer. Operational sending logs are automatically pruned after 7 days. Upon an offboarding or deletion request (email jordan@pilotflow.org), we delete the data within 30 days, except where retention is required by law. Providers may revoke PilotFlow's access at any time at myaccount.google.com/permissions; revoking access immediately stops PilotFlow from sending on their behalf.

6. Healthcare Provider Responsibilities

Healthcare providers using PilotFlow are responsible for ensuring that patient communications comply with applicable laws, including HIPAA. PilotFlow sends communications only to contacts explicitly provided by the healthcare provider, who have an existing or inquiring relationship with that provider.

7. Children's Privacy

PilotFlow is a business-to-business service for healthcare providers. Where a provider serves pediatric patients, that information is provided and controlled by the provider as the covered entity.

8. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by the "Last updated" date above.

9. Contact

PilotFlow Health LLC
Questions about this Privacy Policy or how we handle data:
jordan@pilotflow.org