Public contact forms are not medical-record channels and must not contain diagnoses, medications, certificate numbers, or medical documents.
1. Scope
This notice applies to the Preflight Records website, account-access pages, pilot workspace, examiner workspace, records-return portal, and packet-sharing pages.
2. Information collected
Account and contact information
We collect the name, email address, role, selected use case, and optional non-medical message that a person submits through an account or contact form.
Account and workflow information
We may collect account credentials, pilot-provided profile information, plan status, uploaded records, records-request activity, sharing decisions, and audit events.
Technical information
We record limited operational and security information needed to run the service, diagnose failures, prevent abuse, and maintain an audit trail. Public website events are counted without advertising cookies or third-party behavioral trackers.
3. How information is used
- Create accounts and respond to account or organization inquiries.
- Provide and improve the pilot, AME, and records-return workflows.
- Protect accounts, investigate incidents, and maintain access records.
- Respond to privacy, security, support, and deletion requests.
- Meet legal obligations that apply to the service.
4. Sharing and subprocessors
Preflight Records does not sell personal or health information and does not use it for targeted advertising. Information is shared only with service providers needed to operate the service, with a pilot's selected recipient when the pilot directs a share or signed request, or when required by law.
Service providers that handle regulated health information are reviewed for security and retention terms, and required Business Associate Agreements must be in place.
5. HIPAA and other health-data laws
HIPAA applicability depends on the relationship among the individual, Preflight Records, and a covered health-care entity. Information placed into a direct-to-consumer health app is not automatically protected by HIPAA. Other federal and state privacy laws, including Federal Trade Commission health-breach requirements, may apply. Provider deployments subject to HIPAA require the appropriate agreements and account configuration.
6. Retention and deletion
Account and contact inquiries are retained for up to 24 months unless a continuing relationship or legal obligation requires longer retention. Account holders can delete workspace content from the product. Security logs and backups may persist for a limited retention period after operational deletion.
7. Your choices
You may request access to, correction of, or deletion of contact information associated with your email. Account holders can revoke future sharing access; revocation cannot retrieve a copy that another authorized recipient already downloaded or retained under its own obligations.
8. Contact
Submit privacy and data requests through the Preflight Records contact form. Do not place medical details in the request.