Last updated: July 18, 2026
PilotFlow Health LLC ("we", "our", or "us"), a Florida limited liability company, provides automated patient-communication software for healthcare providers. This Privacy Policy explains what data we access, how we use it, who we share it with, how we protect it, and how it is retained and deleted.
When a healthcare provider authorizes PilotFlow, we request a single Google permission:
gmail.send) — used only to send patient-communication emails from the provider's own account.We do not read, download, or store the contents of the provider's mailbox. The gmail.send permission is send-only; PilotFlow cannot access received mail, drafts, labels, contacts, or any other mailbox data. We store only the token needed to send on the provider's behalf and the sender email address.
PilotFlow's use of information received from Google APIs is limited to sending appointment, welcome, and follow-up communications on behalf of the authorized provider, to that provider's patients and inquirers.
We do not use Google user data to serve advertisements, build user profiles, or for any purpose other than the email service described above.
We do not sell Google user data, and we do not share it with advertisers or data brokers. We share data only with the infrastructure subprocessors required to operate the service, under contract and, where Protected Health Information is involved, under a Business Associate Agreement: Google Workspace (email delivery and hosting) and Amazon Web Services, including AWS Bedrock (application hosting and AI email generation).
PilotFlow uses an AI service (Anthropic Claude via AWS Bedrock) to draft email content from provider-supplied information. AWS Bedrock does not retain inputs or use them to train models. PilotFlow does not use Google user data to develop, improve, or train AI/ML models, and does not transfer Google user data to any third party for that purpose.
PilotFlow's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
OAuth tokens are stored as protected secrets and used solely to send email on the authorized provider's behalf. Patient-communication information (names, email addresses, appointment dates, and notes) provided by the provider is stored in Google Workspace and processed on Amazon Web Services. Data is transmitted over encrypted connections (TLS), access is limited and protected by two-factor authentication, and Protected Health Information is handled under signed HIPAA Business Associate Agreements.
We retain provider and patient-communication data for as long as the provider is an active PilotFlow customer. Operational sending logs are automatically pruned after 7 days. Upon an offboarding or deletion request (email jordan@pilotflow.org), we delete the data within 30 days, except where retention is required by law. Providers may revoke PilotFlow's access at any time at myaccount.google.com/permissions; revoking access immediately stops PilotFlow from sending on their behalf.
Healthcare providers using PilotFlow are responsible for ensuring that patient communications comply with applicable laws, including HIPAA. PilotFlow sends communications only to contacts explicitly provided by the healthcare provider, who have an existing or inquiring relationship with that provider.
PilotFlow is a business-to-business service for healthcare providers. Where a provider serves pediatric patients, that information is provided and controlled by the provider as the covered entity.
We may update this Privacy Policy from time to time. Material changes will be reflected by the "Last updated" date above.
PilotFlow Health LLC
Questions about this Privacy Policy or how we handle data:
jordan@pilotflow.org