Privacy Policy
Last Updated: February 25, 2026 | Effective Date: November 12, 2025
Introduction
Welcome to Polly. We are committed to protecting your privacy and ensuring the security of your personal and health information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application.
By using Polly, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use Polly.
1. Information We Collect
1.1 Account Information
When you create an account, we collect:
- Email address (used for authentication and account recovery)
- Password (encrypted and stored securely by Firebase Authentication)
- Email verification status
1.2 Profile Information
To personalize your experience, we collect:
- First name and last name
- Birthday (for age-appropriate features)
- Location information: City, State, and Country
- Location preferences (whether to use your current location)
1.3 Health Information
Polly is designed to help you track your asthma symptoms and medications. We collect:
- Symptom logs: Including symptom types, severity levels (None, Mild, Moderate, Severe), timestamps, and any notes you add
- Custom symptoms: Any additional symptoms you define beyond the default options
- Medication information: Medication names, dosages, schedules, and logs of when medications were taken
- Medication adherence data: Records of when you take your medications
1.4 Location Data
To provide weather and air quality information relevant to your area, we collect:
- Current location (when you grant permission): GPS coordinates (latitude and longitude)
- Location coordinates are sent to third-party weather services to fetch current conditions
- Location search history: Cities and locations you search for in Polly
1.5 Usage Data
We may automatically collect certain information about your device and usage:
- Device information: Device type, operating system version
- Polly usage patterns: Features you use, screens you visit
- Error logs: Technical information to help us fix bugs and improve Polly
2. How We Use Your Information
We use the information we collect for the following purposes:
2.1 Core Polly Functionality
- Authentication: To create and manage your account, verify your email, and secure your data
- Symptom Tracking: To store and display your symptom logs, allowing you to track patterns over time
- Medication Management: To help you manage your medication schedule and track adherence
- Insights and Analytics: To generate personalized insights about your asthma patterns, correlations between symptoms and environmental factors, and medication effectiveness
2.2 Location-Based Services
- Weather Information: To provide current weather conditions, air quality data, and pollen estimates for your location
- Environmental Alerts: To help you understand how weather and air quality may affect your asthma
2.3 Polly Improvement
- Bug Fixes: To identify and resolve technical issues
- Feature Development: To understand how users interact with Polly and improve features
- Performance Optimization: To ensure Polly runs smoothly
2.4 Communication
- Account Notifications: To send you important updates about your account (e.g., email verification, password resets)
- Service Updates: To inform you about new features or important changes to Polly
3. Third-Party Services
We use the following third-party services that may collect or process your information:
3.1 Firebase (Google)
We use Firebase services provided by Google LLC for:
- Authentication: Secure user authentication and account management
- Cloud Firestore Database: Secure storage of your profile, symptom logs, and medication data
- Data Storage: All data is stored on Google Cloud Platform servers
Firebase Privacy: Your data stored in Firebase is subject to Google's Privacy Policy. Firebase uses industry-standard security measures including encryption at rest and in transit. For more information, visit: https://firebase.google.com/support/privacy
3.2 OpenWeatherMap API
We use OpenWeatherMap to provide weather and air quality data:
- Location Data: We send your location coordinates (latitude/longitude) to OpenWeatherMap to fetch weather, air quality, and location information
- No Personal Information: We only send location coordinates, not your name, email, or any other personal identifiers
- OpenWeatherMap Privacy: OpenWeatherMap's privacy policy applies to data they collect. Visit: https://openweathermap.org/privacy-policy
Note: We do not share your health information, symptom logs, or medication data with OpenWeatherMap or any other third-party service.
4. Data Security
We take the security of your information seriously and implement appropriate technical and organizational measures:
4.1 Encryption
- In Transit: All data transmitted between your device and our servers uses TLS 1.2+ encryption (HTTPS)
- At Rest: All data stored in Firebase Firestore is encrypted using AES-256 encryption
- Authentication: Passwords are hashed and encrypted by Firebase Authentication
4.2 Access Controls
- User Isolation: Your data is isolated by user ID - you can only access your own data
- Authentication Required: All data access requires valid authentication
- Secure Storage: Data is stored on secure servers managed by Google Cloud Platform
4.3 Security Measures
- Regular security audits and updates
- Secure authentication protocols
- Protection against unauthorized access, alteration, disclosure, or destruction
However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.
5. Data Retention
We retain your information for as long as necessary to provide our services:
- Active Accounts: We retain all data while your account is active
- Deleted Accounts: When you delete your account, we will delete all associated data within 30 days
- Cached Data: Some cached insights and analytics data may be retained for up to 1 hour for performance purposes
- Legal Requirements: We may retain certain information as required by law or for legitimate business purposes
You can delete your account and all associated data at any time through Polly settings or by contacting us.
6. Your Rights and Choices
You have the following rights regarding your personal information:
6.1 Access
- View Your Data: You can view all your symptom logs, medication information, and profile data within Polly
- Export Data: You can request an export of your data in a portable format
6.2 Correction
- Update Information: You can update your profile information, symptoms, and medications at any time through Polly
6.3 Deletion
- Delete Account: You can delete your account and all associated data at any time
- Delete Individual Records: You can delete individual symptom logs or medication entries
- Right to be Forgotten: Upon account deletion, we will remove all your personal and health information
6.4 Location Permissions
- Grant or Revoke: You can grant or revoke location permissions through your device settings
- Manual Location: You can manually enter your location instead of using GPS
6.5 Opt-Out
- Analytics: You can disable certain analytics features in Polly settings (if available)
- Notifications: You can manage notification preferences in your device settings
7. Children's Privacy
Polly is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately. If we become aware that we have collected personal information from a child under 13, we will take steps to delete such information.
8. Health Information and HIPAA
Important Notice: Polly is not a medical device and is not intended to diagnose, treat, cure, or prevent any disease. The information provided is for informational purposes only and should not be used as a substitute for professional medical advice.
While we implement security measures to protect your health information, Polly may not be fully compliant with the Health Insurance Portability and Accountability Act (HIPAA). If you are concerned about HIPAA compliance, please consult with a healthcare provider or legal advisor before using Polly.
We strongly recommend:
- Do not use Polly as your sole method of managing your asthma
- Consult with healthcare professionals for medical advice
- Use Polly as a tool to supplement, not replace, professional medical care
9. International Users
If you are using Polly from outside the United States, please be aware that:
- Your information may be transferred to, stored, and processed in the United States
- Data protection laws in your country may differ from those in the United States
- By using Polly, you consent to the transfer of your information to the United States
10. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by:
- Posting the new Privacy Policy in Polly
- Updating the "Last Updated" date at the top of this policy
- Sending you an email notification (for significant changes)
You are advised to review this Privacy Policy periodically for any changes. Changes are effective when posted.
11. California Privacy Rights
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to Know: You can request information about what personal information we collect, use, and disclose
- Right to Delete: You can request deletion of your personal information
- Right to Opt-Out: You can opt-out of the sale of personal information (we do not sell your personal information)
- Non-Discrimination: We will not discriminate against you for exercising your privacy rights
To exercise these rights, please contact us using the information provided below.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
For data deletion requests or privacy-related inquiries, please include:
- Your account email address
- A clear description of your request
- Verification of your identity (for security purposes)
13. Consent
By using Polly, you consent to:
- The collection and use of information as described in this Privacy Policy
- The transfer of your information to the United States and processing by our service providers
- The use of third-party services (Firebase and OpenWeatherMap) as described
If you do not agree with any part of this Privacy Policy, please do not use Polly.
Summary
What we collect:
- Account information (email, password)
- Profile information (name, birthday, location)
- Health information (symptoms, medications)
- Location data (for weather services)
How we use it:
- To provide Polly functionality (tracking, insights)
- To provide weather and air quality information
- To improve Polly
Who we share with:
- Firebase (Google) - for authentication and data storage
- OpenWeatherMap - for weather data (location coordinates only)
- We do NOT sell your data to third parties
- We do NOT share your health information with advertisers
Your rights:
- Access your data
- Correct your data
- Delete your data
- Export your data
Security:
- Encryption in transit and at rest
- Secure authentication
- User data isolation
This Privacy Policy is effective as of the date listed above and applies to all users of Polly.
© 2025 MedIQ. All rights reserved.