Privacy Policy
Last updated: June 26, 2026 · Version 3.3
Introduction
Drug Infusion (the "App") is an educational simulator that helps healthcare students, trainees, and professionals practice intravenous (IV) medication calculations. The App is published by iAnesthesia LLC ("we," "us," "our," or the "Developer"), a Washington State limited liability company located at 100 N Howard St, Ste R, Spokane, WA 99201-0508, United States.
We built Drug Infusion to be private by design. The App has no user accounts, runs no servers that collect your data, contains no third-party analytics or advertising SDKs, and performs no cross-app or cross-site tracking. Substantially all data you create stays on your device.
This Privacy Policy explains, in plain language, what limited data the App involves, how it is used, the narrow circumstances in which Apple (not us) processes data on your behalf, the limited processing connected to our website and support email, and the rights you have under U.S. state privacy laws (including California's CCPA as amended by the CPRA), the EU/UK GDPR, and other applicable laws.
This policy applies to the Drug Infusion application distributed through the Apple App Store and to our related website at druginfusion.com.
Privacy at a Glance
| Question | Answer |
|---|---|
| Do you have user accounts or require sign-in? | No. |
| Do you operate servers that collect or store my data? | No app-data servers. Our marketing/support website is hosted by Vercel, which keeps standard visitor logs (see §2.6). |
| Does my practice data leave my device? | No. Only your purchase/entitlement status syncs through your own Apple iCloud (Key-Value Store), which we cannot access. Calculations, scenarios, and progress stay on your device. |
| Do you use third-party analytics, ads, or trackers? | No (no Firebase, Sentry, Crashlytics, Mixpanel, ad networks, IDFA, etc.). |
| Do you sell or "share" my personal information? | No. Never. |
| Do you track me across other apps or websites? | No. |
| Do you collect patient data or health information? | No — and you must never enter real patient data. |
| Can I delete my data? | You can delete local App data in-app or by deleting the App. Apple purchase records, optional iCloud entitlement keys, website logs, and support emails follow the retention rules described below. |
| What does the App use the camera for? | Only to optically scan a colleague's verification QR code, processed on-device. |
1. Scope and Roles
Who controls what. Because the App is local-first and account-free:
- Data you create on your device (calculations, practice progress, scenarios, simulated infusions, the on-device Activity Log, settings) is stored on your device and under your control. We do not have access to it and do not receive copies of it.
- The limited personal data we actually process is essentially: (a) your purchase entitlement status, which Apple associates with your Apple ID and reports to us in pseudonymous form; (b) the contents of any support message you choose to send us; and (c) standard website-visitor data generated when you visit druginfusion.com (see §2.6). For that limited processing, iAnesthesia LLC is the data controller (GDPR) / business (CCPA/CPRA).
- Apple Inc. acts as the payment processor and (if you enable iCloud) as the sync/storage provider, processing certain data on your behalf under Apple's own privacy policy.
This policy covers (a), (b), and (c) and explains (for transparency) the on-device data and the Apple-mediated data, even where we are not the controller of it.
2. Information the App Involves
2.1 Data Stored Locally on Your Device
The following is stored only on your device and protected by iOS device security. It is not transmitted to us.
- Practice & learning data — drug calculations (generic drug names, concentrations, dose rates, volumes, results), quiz/practice progress and mastery levels, and custom practice scenarios you create.
- Educational infusion-monitoring data (simulation only) — simulated infusion name, rate, volume, start time, duration, rate-change history, and status. Optional free-text room/bed labels are for workflow organization and must not contain patient identifiers.
- App preferences & settings — display precision, warnings, theme, shift times.
- Local usage counters — e.g., the count of free two-person-verification initiations used (to enforce the free-tier allowance) and related entitlement counters.
2.2 On-Device Activity Log and Pseudonymous Device Identifier
To support the App's educational record-keeping (for example, the verifier's record of a two-person verification outcome), the App maintains a local, on-device Activity Log in a dedicated on-device store, separate from your other app data. Its entries may include practice details such as the generic drug name, the computed rate, and the verification outcome. The Activity Log contains no patient identifiers and is never uploaded by the App.
Each Activity Log entry is tagged with a locally stored pseudonymous device identifier used to distinguish this device in local audit entries. On iOS, this identifier is derived from Apple's vendor-scoped device identifier where available, with a locally generated fallback if the system value is unavailable. It is not your name, email, Apple ID, advertising identifier, or hardware serial number, is not linked by us to your real-world identity, and is not transmitted to us by the App.
Retention. Activity Log entries are deleted automatically once they are older than 90 days. This is a fixed storage-hygiene limit, not a user- or admin-configurable setting. The cleanup runs when you open the App and whenever a new entry is recorded, so an entry could persist beyond 90 days only if you do not reopen the App. Independent of this automatic 90-day cleanup, you can export (CSV) or clear the entire Activity Log at any time via Settings → Activity Log.
2.3 Data That May Sync Through Your Own Apple iCloud (Optional)
If you are signed into iCloud, certain data may sync through your personal Apple iCloud account, which resides in your Apple account and which we cannot access:
- Entitlement/"Pro" status and related counters (e.g., grandfathered/lifetime status, the date access was granted, and free two-person-verification initiation counts) via Apple's iCloud Key-Value Store, so your purchase status follows you across your devices.
- Your practice data itself (calculations, scenarios, progress) is not synced off-device; only the small set of entitlement keys above uses iCloud.
You can disable this in iOS Settings → [your name] → iCloud. Apple encrypts iCloud data in transit and at rest; see Apple's Privacy Policy.
2.4 Purchase Data Processed by Apple
When you buy "Pro" (a one-time purchase), Apple processes the transaction through the App Store and StoreKit. We receive entitlement/transaction information from Apple (e.g., a pseudonymous transaction identifier and whether the purchase is valid) and App Store sales and aggregate analytics reports that Apple provides to developers. We do not receive your payment card number, full billing address, or Apple ID password.
2.5 Product-Interaction Data (App Functionality)
The App processes product-interaction data on your device — e.g., feature usage needed to make the App function, such as the local counters above. This data is used only for App functionality, is not linked to your identity, and is not used to track you. It is disclosed as Product Interaction in our App Store privacy label (see §17).
2.6 Website (druginfusion.com)
Our marketing and support website is hosted by Vercel Inc. on our behalf. Like any web host, Vercel automatically processes standard server-log data when you visit the site — for example, your IP address, browser/user-agent, the pages requested, and timestamps — for security, reliability, and basic traffic measurement. We do not place advertising or cross-site tracking cookies, and we do not run third-party analytics SDKs on the site. If you contact us through the site or by email, your message is delivered through Google Workspace (Google LLC) and handled as described in §2 and §4. This website processing is separate from the App and does not involve any of your on-device practice data.
3. Information We Do NOT Collect
To be explicit, the App does not collect, store on our servers, or transmit to us:
- Patient data / PHI — no patient names, MRNs, identifiers, or any Protected Health Information. The App is a simulator; never enter real patient data.
- Identity data about you — no name, email (unless you email us), password, or account.
- Location — no precise or coarse location.
- Tracking identifiers — no IDFA/advertising identifier, no cross-app/cross-site tracking, no fingerprinting. NSPrivacyTracking is false; the tracking-domains list is empty.
- Contacts, photo library, microphone, health/fitness data (the camera is used only for live, on-device QR scanning — no images are saved or transmitted).
- Remote push notifications / device tokens — the App does not register for the Apple Push Notification service (APNs) and sends no remote push notifications, so it collects no push tokens. Any reminders (e.g., infusion-completion alerts) and Live Activities run locally on your device and are not driven by a remote server.
- Third-party analytics or crash SDKs — no Firebase, Google Analytics, Crashlytics, Sentry, Bugsnag, Mixpanel, Amplitude, Segment, ad networks, or similar. The App ships with no third-party runtime SDKs of this kind. For diagnostics the App uses Apple's own first-party, on-device MetricKit framework: crash/hang/performance payloads are processed and stored locally on your device and are not transmitted by us (see §5). Separately, Apple may provide us aggregate crash/energy reports via Xcode Organizer only if you opted in under iOS Settings → Privacy & Security → Analytics & Improvements.
4. How Information Is Used (and Legal Bases)
We (and, where applicable, Apple on your behalf) use the limited data described above to:
| Purpose | Data involved | GDPR legal basis |
|---|---|---|
| Provide App functionality (perform calculations, track progress, run simulations, store your scenarios, maintain the on-device Activity Log) | On-device data | Performance of a contract (Art. 6(1)(b)) / your consent for optional features |
| Manage your "Pro" entitlement and free-tier allowances | Purchase/entitlement status; local counters | Performance of a contract (Art. 6(1)(b)) |
| Sync your "Pro" entitlement & counters across your devices | iCloud Key-Value Store | Your consent — you control iCloud (Art. 6(1)(a)) |
| Operate and secure our website | Website server logs (e.g., IP, request metadata) | Legitimate interests (Art. 6(1)(f)) — security, reliability, basic measurement |
| Respond to support requests | Your message contents | Legitimate interests (Art. 6(1)(f)) — supporting users |
| Maintain security, prevent fraud/abuse, and enforce our Terms | Local counters; pseudonymous device id (on-device) | Legitimate interests (Art. 6(1)(f)) |
| Comply with law | As required | Legal obligation (Art. 6(1)(c)) |
We do not sell or "share" personal information, use it for advertising, build commercial profiles, or make legally/similarly significant decisions about you by solely automated means.
5. Apple Services and Other Providers
The App relies on Apple's native services. Apple's processing is governed by Apple's policies, not ours.
| Service | Purpose | Data involved | Our access |
|---|---|---|---|
| App Store / StoreKit 2 | Distribution; one-time "Pro" purchase; restore purchases | Purchase transaction (handled by Apple) | Entitlement/transaction status only — no payment card details |
| iCloud Key-Value Store | Sync entitlement status & free-tier counters across your devices | A small number of keys | The App reads/writes those keys through your iCloud on your device; we do not have server-side access to your iCloud account or practice data. |
| Apple MetricKit (on-device) | Capture crash, hang & performance diagnostics so we can fix bugs and improve reliability | Diagnostic payloads — device model, OS & app-build version, region format, and crash/hang call stacks | None over a network — processed and stored locally on your device; we read them only via Xcode on a device we physically control. Apple separately provides aggregate Organizer reports only if you opted into device analytics |
| Camera (VisionKit / AVFoundation) | Scan a colleague's verification QR code | Camera frames processed on-device | None — local only; no images stored or sent |
| Vercel Inc. (website hosting) | Host druginfusion.com | Standard server logs (IP, user-agent, request metadata) for site visitors | We access aggregate/operational logs only; no App practice data |
| Google LLC (Google Workspace) | Deliver and store support email you send us | Contents of your support correspondence | We read messages you send to support |
No other third parties. We do not integrate advertising networks, social logins, analytics vendors, data brokers, A/B-testing platforms, or third-party crash reporting.
Platform and service providers. Platform and service providers we use for the limited data we control include Apple, Vercel, and Google Workspace. None of them receives your on-device practice data.
6. Two-Person (QR) Verification
The two-person verification feature lets a colleague independently double-check a calculation. It is fully offline and one-way. There is no Bluetooth, NFC, Wi-Fi, local network, or internet connection involved, and no pairing.
6.1 How it works
- Show. The first device displays a QR code containing the proposed calculation parameters.
- Scan. The colleague optically scans that QR code with their device's camera (processed on-device via VisionKit).
- Check. The colleague independently enters a rate; the match/mismatch is computed and shown on their own (the verifier's) device.
6.2 What the QR code contains
Only calculation parameters, for example: generic drug name; concentration; weight (if the exercise is weight-based — an educational example, not a real patient); calculation mode; proposed result (e.g., flow rate); and integrity/version metadata (a tamper-/corruption-evidence code and compatibility fields).
6.3 What the QR code does NOT contain
No patient names or identifiers, no health information, no location, no persistent device identifier, no calculation history, and no information about you.
6.4 Privacy properties
- Offline & optical only — the only "transfer" is light from a screen to a camera.
- One-way — the outcome is recorded on the verifier's device; the sender's screen is not a verification record.
- Integrity, not surveillance — the integrity code lets a device reject a damaged or altered QR. It is tamper-evidence from a bundled app key, not sender authentication, and involves no tracking.
- On-device Activity Log only — the verifier's device logs the outcome locally (see §2.2); nothing is uploaded.
6.5 Permissions
The only permission this feature uses is Camera, requested when you start scanning. Bluetooth and Local Network are not used and not requested.
7. Storage, Security, and Breach Response
7.1 Architecture
| Data | Where it lives | Protection |
|---|---|---|
| Local app data (calculations, scenarios, simulated infusions, the Activity/Audit Log, preferences, and on-device diagnostics) | On your device | iOS device security (encrypted at rest when the device is locked) |
| Entitlement keys ("Pro" status & counters) | Your Apple iCloud | Apple encryption in transit & at rest |
| Website logs | Website host (Vercel) | Encrypted in transit & at rest |
| Support email | Email provider (Google Workspace) | Provider security controls |
7.2 Measures
- No App data-collection servers, which structurally removes server-side breach risk for your practice data.
- On-device encryption via iOS Data Protection; cryptographic receipt verification via StoreKit 2; offline two-person verification (no wireless attack surface).
- Data minimization — we store only what the App needs to function, and the Activity Log is held to a fixed 90-day maximum age.
- No security system is perfect; we cannot guarantee absolute security, but the local-first design materially limits exposure.
7.3 Breach response
Because we hold essentially no personal data on servers, the population of data we could "breach" is extremely limited. If a security incident affecting personal data we control occurs, we will investigate and notify affected users and regulators as required by applicable law and within applicable statutory timeframes (for example, GDPR's 72-hour authority-notification standard and applicable U.S. state breach-notification laws).
8. Data Retention
| Data | Retention | Method |
|---|---|---|
| Running/paused simulated infusions | Never auto-deleted while active | Manual |
| Completed simulated infusions | Hidden from the dashboard after ~7 days; auto-deleted after ~30 days | Automatic on launch |
| Calculations, quiz progress, scenarios | Until you delete them | Manual |
| On-device Activity Log | Deleted automatically once older than 90 days (a fixed age-based cap, not configurable); cleanup runs at App launch and when a new entry is recorded. You can also export or clear it at any time | Automatic/Manual |
| On-device diagnostics (MetricKit) | Capped local cache — oldest auto-deleted past ~30 files / ~5 MB | Automatic |
| Preferences | Until you delete the App | With App |
| Entitlement status (iCloud KVS) | Persists with your Apple account until cleared | Apple/Manual |
| Support correspondence (Google Workspace) | Until resolved plus a reasonable period, then deleted on a routine basis | Manual/Routine |
| Website server logs (Vercel) | Per host defaults (short-term operational retention) | Automatic |
| Apple purchase records | Per Apple's retention policies | Apple |
Deleting the App removes local data from that device. Entitlement keys in iCloud and your purchase history with Apple persist per Apple's policies until you/Apple remove them.
9. Your Choices and Controls
- Access your data anytime in-app (History, Learn, Scenarios; Activity Log via Settings).
- Export the Activity Log / calculation history as CSV (Settings → Activity Log).
- Correct/Edit entries directly in the App.
- Delete individual items, clear the entire Activity Log (Settings → Activity Log), Clear All Data (Settings → Data Management), or delete the App to remove all local data.
- Permissions — manage Camera and local Notifications in iOS Settings.
- iCloud sync — disable in iOS Settings → [your name] → iCloud → Drug Infusion.
- Purchases — view/restore "Pro" in the App's Settings; manage purchases via Apple ID.
- Crash diagnostics — controlled entirely by you in iOS Settings → Privacy & Security → Analytics & Improvements.
10. U.S. State Privacy Rights
This section addresses the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), and the comprehensive privacy laws of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon, Montana, and other states with comparable rights. We honor the rights below for residents of states that provide them, regardless of whether we meet a given law's applicability thresholds.
10.1 Notice at Collection (CPRA)
| CCPA/CPRA category | Do we collect? | Source | Purpose | Sold? | "Shared"? | Retention |
|---|---|---|---|---|---|---|
| Identifiers (name, email) | Only if you email support | You | Respond to you | No | No | Until resolved + reasonable period |
| Commercial information (purchase/entitlement status) | Yes (via Apple) | Apple/StoreKit | Provide "Pro"; restore purchases | No | No | While entitlement is active |
| Internet/electronic activity (product-interaction, on-device; website server logs) | Yes (on-device; website logs via Vercel) | Your device; your browser | App functionality; website security/operation | No | No | See §8 |
| Geolocation | No | — | — | No | No | — |
| Biometric / sensory | No | — | — | No | No | — |
| Sensitive personal information | No | — | — | No | No | — |
| Health information | No | — | — | No | No | — |
We do not sell or share personal information, and we do not use or disclose sensitive personal information for purposes that would trigger the CPRA "right to limit." We do not use personal information for cross-context behavioral advertising.
10.2 Your rights
Subject to applicable law, you may: know/access what we process; delete it; correct it; port it (obtain a portable copy); opt out of sale/share/targeted advertising (n/a — we do none); and not be discriminated/retaliated against for exercising rights. Most data is under your direct control in-app; for the limited data we control, contact us (below).
10.3 How to exercise rights / verification / agents
Email support@ianesthesia.org with subject "Privacy Request." We will verify your request reasonably (typically by confirming control of the email/device or purchase associated with the request) and respond within statutory timeframes (generally 45 days, extendable as permitted). Authorized agents may submit requests with proof of authorization. There is no fee for the first request in a 12-month period absent abuse.
10.4 Appeals (VA/CO/CT/etc.)
If we decline a request, you may appeal by replying to our decision email. If your appeal is denied, you may contact your state Attorney General.
10.5 California "Shine the Light" & minors
We do not disclose personal information to third parties for their direct marketing (Cal. Civ. Code § 1798.83). We do not knowingly collect or sell the personal information of minors; eligible California minors may request removal of content they posted (Cal. Bus. & Prof. Code § 22581) — though the App has no public posting feature.
10.6 No financial incentives
We offer no financial incentives or price/service differences in exchange for personal information.
11. European Economic Area, United Kingdom, and Switzerland (GDPR)
If you are in the EEA, UK, or Switzerland, the EU GDPR / UK GDPR / Swiss FADP apply.
Controller. For the limited personal data we control (entitlement status; support correspondence; website server logs), the controller is iAnesthesia LLC, 100 N Howard St, Ste R, Spokane, WA 99201-0508, United States, contact support@ianesthesia.org.
Legal bases. See the table in §4.
Your rights. Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent (without affecting prior processing). Most data is exercisable directly in-app; otherwise contact us.
EU/UK Representative. We have not appointed an EU or UK representative. You may contact us at support@ianesthesia.org. We will revisit this as our processing changes.
International transfers. See §14.
Automated decision-making. None producing legal or similarly significant effects.
Complaints. You may lodge a complaint with your supervisory authority (e.g., your national DPA; the UK ICO; the Swiss FDPIC). We ask that you contact us first.
12. Children's Privacy
Drug Infusion is intended for an adult, professional/educational audience. The minimum age to use the App is 17, consistent with the App Store's medical-category guidance. The App is not directed to children, and the only optional feature that relies on consent (iCloud sync) is controlled through your own Apple device settings rather than offered by us to children. We do not knowingly collect personal information from children under 13 (COPPA) or process the data of "known children" under applicable state laws, and because the App is age-gated to 17+ and not directed to children, the GDPR Article 8 "digital consent age" rules are not engaged. If you believe a child has provided personal information, contact support@ianesthesia.org and we will delete it.
13. Health Information / HIPAA Statement
Drug Infusion is an educational simulator. It is not intended to create, receive, maintain, or transmit Protected Health Information (PHI), and you must not enter real patient data. The Developer is not a HIPAA "covered entity" or "business associate" by virtue of the App, and the App is not offered as a HIPAA-compliant service. Any free-text field (e.g., a room label) is for your own workflow organization and must not contain identifiable patient information.
14. International Data Transfers
We do not operate App data-collection servers, so we do not ourselves transfer your practice data internationally.
Where Apple processes data on your behalf (App Store purchases; iCloud), Apple may process and store it in data centers in multiple countries under Apple's own transfer mechanisms (including, where applicable, the EU Standard Contractual Clauses and the UK Addendum).
For the limited personal data we control, processing takes place in the United States. Where we process personal data outside your country, we use appropriate safeguards where required, such as standard contractual clauses, the UK International Data Transfer Addendum, adequacy decisions, or other lawful transfer mechanisms.
15. Changes to This Policy
We may update this policy. We will revise the "Last Updated" date and, for material changes, we may provide additional notice through channels reasonably available to us — such as an in-app notice when you next open or update the App, App Store release notes, or a notice on our website. Because we do not maintain user accounts or collect email addresses, we do not notify users by email. Your continued use after the effective date of an update constitutes acceptance, except where additional consent is required by law.
Version history
We update this policy from time to time. The current version number and effective date appear at the top of this policy; earlier versions are available on request at support@ianesthesia.org.
16. Contact Us
iAnesthesia LLC
Privacy inquiries & rights requests: support@ianesthesia.org (subject: "Privacy Request")
Support: https://druginfusion.com/support
Mailing address: 100 N Howard St, Ste R, Spokane, WA 99201-0508, United States
Target response time: within 5 business days (statutory deadlines control where applicable).
17. Apple App Store Privacy Label (Nutrition Label) Mapping
Our App Store privacy label reflects the following (NSPrivacyTracking = false — we do not track you):
- Data used to track you: None.
- Data linked to you: None.
- Data not linked to you: Usage Data → Product Interaction (used only for App functionality; not linked to your identity; not used for tracking).
- Purchases: handled by Apple; Apple's own disclosures cover payment data.
This label describes the App. Standard server logs generated by visiting our website (druginfusion.com) are a website matter (see §2.6), separate from the App's App Store privacy label.
Drug Infusion is an educational simulator. It is NOT a medical device and NOT intended for clinical decision support, diagnosis, treatment, or patient care. All drug information and calculations are for educational practice only.