Privacy Policy
protoquiz.com). The standalone consumer iOS application is covered by a separate consumer privacy policy. This Policy is a disclosure of our practices; the contractual relationship between Customer and ProtoQuiz is governed by the MSA or B2B Terms of Service.
1. Information We Collect
Account & Authentication Information
The Platform supports two sign-in methods. When you sign in with an emailed one-time code, we store your email address and display name; sign-in codes are short-lived, stored only in salted-hashed form, and there is no password to store. When you sign in via Google OAuth, we receive: your email address, display name, profile photo URL, and a unique Google user identifier. We do not receive or store your Google password.
Organization & Role Information
For each user, we store the organization identifier (e.g., highland), assigned role (user, supervisor, training officer, admin, developer), certification level (e.g., EMT, Paramedic), and access status (pending, approved, rejected).
Usage & Performance Data
Quiz attempts, scenario responses, leaderboard scores, flashcard progress, page visits, and time spent in various parts of the Platform. This data is tagged with your organization identifier and user identifier to enable per-org leaderboards and analytics.
Technical Data
Browser type, device type, IP address (recorded transiently for security and abuse prevention; not used for tracking across sites), and crash/error reports. Page-view pings and error reports are sent to our observability backend (api.protoquiz.com) and may include a session identifier, the visited URL, browser user agent, and the organization identifier.
Customer-Provided Content
Protocol PDFs and other materials an Organization provides to us (or its administrators upload) for its tenant. We treat this content as the property of that Organization and use it only to provide the Platform to that Organization.
What We Do NOT Collect
- Patient information. ProtoQuiz is a training tool, not a clinical documentation system. Do not upload patient charts, protected health information (PHI), or any patient-identifying clinical data.
- Payment card data. Billing is handled by Stripe; we never see your card or bank account numbers.
- Location. We do not collect GPS or precise location data.
- Microphone, camera, or contacts. The Platform does not request these permissions.
2. How We Use Information
We use the information we collect to:
- provide, maintain, and improve the Platform;
- authenticate users and enforce organization-scoped access controls;
- generate per-user and per-organization analytics, leaderboards, and compliance reports;
- diagnose errors, prevent abuse, and ensure platform security;
- communicate with you about service updates, billing, and support;
- comply with legal obligations and respond to lawful requests.
We do not use your data to train external AI models, sell your data to third parties, or display third-party advertising in the Platform.
AI-assisted processing of protocol content. We use third-party large-language-model ("LLM") services — currently commercial API offerings from Anthropic (Claude) and Google — to help draft quiz questions, scenarios, and similar study content from the protocol documents an Organization provides to us. This drafting happens on our side during onboarding and content updates, and the resulting content is verified against the Organization's own document and reviewed before it is delivered; the agency's document remains the source of truth, and questions are designed to carry a citation to the source document. Protocol content is sent to an LLM provider only for this purpose, using commercial API offerings whose applicable terms provide that customer content is not used to train the provider's models. Generated content is stored under the Customer's Organization. ProtoQuiz does not intentionally transmit User account or profile information to LLM providers; Customer Content provided for protocol processing may be transmitted as described in this Policy.
4. Subprocessors
We rely on the following trusted subprocessors to deliver the Platform:
- Google Cloud / Firebase
- Authentication, database (Firestore), file hosting, web hosting, and backend API hosting (
api.protoquiz.com, Cloud Run). Region: United States. Purpose: storing user accounts, quiz attempts, organization data, and Customer Content; serving requests, processing billing webhooks, and routing observability telemetry. - Cloudflare, Inc.
- DNS, email routing for
*@protoquiz.comaddresses, and edge protection. Region: Global edge network. - Stripe, Inc.
- Payment processing, invoicing, and ACH bank-transfer collection. Region: United States. Purpose: handling fees from Organizations. Stripe is PCI-DSS Level 1 certified.
- Brevo (Sendinblue)
- Transactional email delivery (sign-in codes, invitations, assignment reminders, system notifications). Region: European Union with US data residency option.
- Discord, Inc.
- Internal operational alerts sent via webhook from our backend. Discord receives summarized event data (e.g., "new sign-up at south-metro"); user-identifying information is minimized.
- Anthropic, PBC (Claude)
- Large-language-model drafting of quiz questions, scenarios, and related study content from protocol documents provided by the Organization, verified against the document before delivery. Region: United States. Commercial API offering whose applicable terms provide that customer content is not used to train Anthropic's models.
- Google AI / Vertex AI (Gemini)
- Large-language-model drafting of study content from protocol documents provided by the Organization, with the same verification. Region: United States. Commercial API offering whose applicable terms provide that customer content is not used to train Google's models.
- Documenso, Inc.
- Contract e-signature workflow for Master Services Agreement and Order Form execution. Processes the signing party's name, email address, and applied signature image. Region: United States.
An up-to-date list of subprocessors is maintained at this URL. We will notify Customers of new subprocessors at least thirty (30) days before they begin processing Customer data, except in emergencies where a substitution is necessary to maintain service continuity.
5. Data Retention
We retain information by category:
- Account & profile data (email, display name, role, certification level): retained while the Organization's subscription is active; deleted on verified request or following termination, per the DPA.
- Customer Content (protocol documents and materials provided by the Organization): retained for up to ninety (90) days after the subscription ends to allow export, then deleted from production systems.
- Quiz & performance records (attempts, scores, leaderboard entries, compliance history): treated as part of Customer Content for export purposes and deleted on the same ninety (90) day post-termination schedule.
- Billing & financial records: retained as required by law (e.g., tax record-keeping).
- Backups: kept on a rolling window of up to thirty (30) days; deleted data is purged from backup storage as that window rolls over.
- Aggregated, de-identified analytics: may be retained.
You may request earlier deletion by emailing [email protected], subject to our legal obligations to retain certain records.
6. Security
We implement administrative, technical, and physical safeguards designed to protect user information, including:
- Encryption in transit (TLS 1.2+) for all connections to the Platform;
- Encryption at rest provided by Google Cloud for all stored data;
- Organization-scoped Firestore security rules that prevent cross-tenant data access;
- Role-based access controls within Organizations;
- Strict access controls on production systems for ProtoQuiz personnel;
- Automated error monitoring and security alerting.
No system is perfectly secure. If you discover a security vulnerability, please email [email protected] and we will respond promptly.
7. Your Rights & Choices
Depending on your jurisdiction, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you.
- Correction: Ask us to correct inaccurate information.
- Deletion: Ask us to delete your information, subject to legal retention requirements.
- Portability: Receive your data in a machine-readable format.
- Opt-out: Of marketing communications (transactional emails like invoices and security alerts cannot be opted out of without canceling the subscription).
To exercise these rights, contact [email protected]. We will respond within thirty (30) days. For Users associated with an Organization, requests may need to be coordinated with your Organization's administrator since they control access to the tenant.
8. HIPAA & Clinical Data
If you believe PHI has been inadvertently uploaded to the Platform, contact [email protected] immediately so we can assist with removal. We may also scan or sample uploaded content for indicators of PHI and may reject, quarantine, or remove such uploads and notify the uploading administrator.
9. Children's Privacy
The Platform is intended for use by licensed or aspiring emergency medical professionals and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected such information, we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be posted at protoquiz.com/b2b/privacy with an updated effective date and, for active Customers, notice will be sent to the billing contact email at least thirty (30) days before the changes take effect.
11. Contact
Privacy questions, data requests, and security disclosures should be directed to:
Teach Me to Live LLC, d/b/a ProtoQuiz
Attn: Privacy
1500 N Grant St #10764, Denver, CO 80203
Email: [email protected]
Legal: [email protected]