Privacy Policy
Attuned Labs LLC
Effective Date: April 10, 2026 | Last Updated: August 23, 2026
Attuned Labs LLC ("Company," "we," "us," or "our") operates the Follie mobile application (the "App"). This Privacy Policy describes how we collect, use, and protect your information when you use the App. By using Follie, you consent to the practices described in this Privacy Policy.
This Privacy Policy should be read in conjunction with our Terms of Service and End User License Agreement.
Follie offers two modes of use: Guest mode (no account required, all data stored locally on your device) and Signed-in mode (optional account via Sign in with Apple or Sign in with Google, with cross-device sync). This Privacy Policy describes data practices for both modes.
1. Information We Collect
1.1 Guest Mode (No Account)
Follie does not require you to create an account. If you choose to use the App without signing in, we do not collect your name, email address, phone number, mailing address, or any other personal contact information. There is no login, registration, or sign-up process required. All clinical and study data you enter remains stored locally on your device and is not transmitted to our servers or to any third party. There are two exceptions, and each happens only when you choose it: feedback you submit (Section 1.6), and a score you post to a game leaderboard (Section 1.8). Nothing else leaves your device.
1.2 Signed-In Mode (Optional Account)
You may optionally create an account using Sign in with Apple or Sign in with Google. We do not offer email-and-password registration. Attuned Labs never collects, stores, or has access to your Apple or Google password.
When you sign in, we receive and store the following information from your authentication provider:
- Email address — provided by Apple or Google. If you use Apple's "Hide My Email" feature, we receive only the private relay address generated by Apple, not your real email address.
- Display name — if provided by your authentication provider (optional).
- Unique account identifier — a token used to associate your account with your synced data.
We do not receive or store your authentication provider password, payment information, contacts, or any other data from your Apple or Google account beyond what is listed above.
1.3 Clinical Data You Enter
Guest users: All clinical data you enter (patient parameters, generated plans, case logs, calculator inputs, drug references, quick handoff notes) is stored locally on your device. This data is never transmitted to our servers or to any third party.
Signed-in users: If you are signed in, certain data you create — including generated anesthetic plans, case logs, favorites, and the notes you write in the Notebook and Anes. Team sections of the Casebook — is synced to our cloud database (Supabase, hosted on Amazon Web Services) to enable cross-device access. You may continue to use the App’s clinical features without signing in, in which case all data remains local.
What that clinical data contains. The App does not ask for, and provides no field for, patient names, medical record numbers, dates of birth, or other direct patient identifiers, so none are transmitted or stored on our servers. A synced anesthetic plan does contain the case details you entered — age, sex, weight, comorbidities, medications and allergies — associated with your account. Notes you write are free text, and what they contain is up to you; the App asks you to keep patient information out of them.
Procedure names. The Notebook lets you write up a procedure your facility performs. If the procedure you name is not one the App recognizes, that name alone is sent to us so we can decide what to add to Follie’s library. Only the name is sent, only when it is unrecognized, and only once per device. It is not linked to your account, and nothing else from the note — no surgeon, no facility, no free text — is sent. Names pass through the same automatic filter described in Section 1.6 before leaving your device.
1.4 Information Collected Automatically
Device and App Information. The App may automatically collect limited technical information, including device type, operating system version, and app version. This information is used solely for ensuring compatibility, delivering over-the-air updates, and diagnosing technical issues.
Crash Reports. The App uses Sentry, a third-party error monitoring service, to collect anonymous crash reports when the App crashes or encounters an error. Crash reports contain technical diagnostic information such as stack traces, device model, and OS version. Crash reports do not contain any clinical data you have entered into the App, and do not contain personally identifiable information. Sentry's privacy practices are governed by Sentry's own privacy policy.
1.5 OCR Scanning
Photos taken or selected for the OCR scanner feature are processed entirely on your device using on-device optical character recognition. Images are never transmitted to our servers, any third-party service, or any external system. No images are stored or retained beyond the scanning session.
1.6 Feedback You Submit
The App includes a "Share feedback" option on most screens and a "Report an issue" option on Follie Academy questions. Submitting feedback is entirely voluntary. When you submit feedback, we receive the message you wrote, the screen or content you were viewing when you wrote it (for example, a study-guide name or a question identifier), your app version, and your device platform (iOS or Android). If you are signed in, your account identifier is attached so we can follow up; if you are using Guest Mode, the submission is anonymous and is not linked to any account.
Feedback is stored in our Supabase database and is readable only by administrators we have explicitly authorized. Before any feedback leaves your device it is passed through an automatic filter designed to remove text that resembles Protected Health Information, and the filtered text is shown to you for confirmation before sending. Please do not include patient information, names, dates of birth, medical record numbers, or any other identifying details in feedback.
1.7 Follie Academy and Study Progress
Follie Academy quiz answers, scores, streaks, weak-area profiles, spaced-repetition schedules and study history are generated and stored on your device. No account is required to use Follie Academy, and for guest users this study data never leaves the device.
Syncing study progress is optional and off by default. If you are signed in, you may turn on "Sync Academy progress" in Settings, after which your progress is available on your other devices and survives reinstalling the App. Signing in alone does not sync study data. Synced study data consists only of question identifiers, counts of attempts and correct answers, timestamps, and derived scores. It contains no clinical data you have entered, no free text, and no patient information of any kind. It is stored in our Supabase database, is readable only by you, and is deleted when you delete your account (see Section 4.3).
1.8 Games and Leaderboards (Downtime)
The App's Settings include a "Downtime" section containing simple games. Playing is entirely optional, requires no account, and is unrelated to the App's clinical and study features. What you do inside a game — your best score, how far you have progressed, and whether you have acknowledged the game's safety notice — is stored locally on your device.
A game may include a leaderboard. Where it does, the following is sent to our Supabase database at the end of a run: a three-letter code, the score, the level reached, your app version, and your device platform. The time the entry arrived is recorded. That leaderboard is visible inside the App to everyone who plays. Nothing else about the run, your device, or your use of the App is transmitted.
The three-letter code is assigned by the App, not chosen by you. It is generated at random on your device the first time you play, screened against a blocklist, and stored locally so that it stays the same across your runs. It is not your initials, it is not a username, and there is no way to type your own. Codes are short enough that different players are sometimes assigned the same one.
Leaderboard entries are not linked to any account. A score carries no user identifier whether you are signed in or not, and signing in does not change what is sent. We cannot tell who posted any given entry, and neither can anyone else. The only exception is an internal marker that flags scores posted by an authorised Attuned Labs administrator, so that our own entries are identifiable as ours.
Because an entry contains nothing that identifies you, we cannot find "your" scores in order to delete them on request, and uninstalling the App does not remove entries already posted. If you want a specific entry removed, contact us at follie@heyattuned.com with the code, the score and the approximate date. We may also remove any leaderboard entry, or reset a leaderboard, at our discretion.
This section applies to every game in the Downtime section, including games added in future releases. If a future game collects anything beyond what is described here, this Privacy Policy will be updated before that game ships.
1.9 Information We Do NOT Collect
- We do NOT ask for, want, or knowingly collect Protected Health Information (PHI) as defined under HIPAA. No feature requests it. Two things you write can reach us: feedback, which is passed through an automatic PHI filter and shown to you for confirmation before sending; and the name of a Notebook procedure the App does not recognize, which passes through the same filter and is sent without any account link (Section 1.3). Because that field accepts anything you type, please do not enter patient-identifying details; if you tell us you have, we will delete the submission
- We do NOT collect or store passwords — authentication is handled entirely by Apple and Google
- We do NOT collect precise or coarse geolocation data
- We do NOT collect contacts, calendar data, or other personal files from your device
- We do NOT collect biometric data (fingerprints, facial geometry, voiceprints)
- We do NOT use tracking technologies, advertising identifiers, or analytics SDKs for advertising purposes
- We do NOT collect browsing history, search history, or behavioural profiles, and we do not track what you look up in the App. The one exception is Follie Academy study progress, and only if you are signed in and have switched sync on: quiz results are then associated with your account so they reach your other devices (Section 1.7). A game leaderboard entry is not an exception to this: it records the result of a single run you chose to post, is linked neither to your account nor to anything you do elsewhere in the App, and builds no profile (Section 1.8)
- We do NOT transmit or store patient photographs or images
2. How We Use Your Information
On-Device Clinical Features. The App's clinical tools — including calculators, drug references, quick handoff, airway assessment, and other reference features — operate entirely on your device using deterministic, rule-based logic. No clinical data from these features is transmitted to any server, API, or third-party service.
Cross-Device Sync (Signed-In Users Only). If you sign in with an account, your generated plans, case logs, and favorites are synced to our cloud database to enable access across your devices. This synced data is stored securely on Supabase (hosted on Amazon Web Services) with Row Level Security, meaning your data is accessible only to your authenticated account. Guest users' data is never transmitted.
Account Authentication. Your email address and account identifier are used solely to authenticate your identity and associate your synced data with your account. We do not use your email address for marketing, advertising, or any purpose other than account management and essential service communications.
App Updates. We use Expo EAS to deliver over-the-air JavaScript bundle updates to the App. These updates download new application code to your device. No user data or clinical data is transmitted to Expo's servers during this process.
Crash Diagnostics. Anonymous crash report data collected by Sentry is used solely to identify and fix software defects and improve the App's stability. Crash reports do not contain clinical data or personally identifiable information.
Games and Leaderboards. A score you choose to post is used only to display and rank entries on that game's leaderboard inside the App, to show how a score compares with others, and to count how many runs have been recorded. It is not used to profile you, is not linked to your account, and is not used for any other purpose.
Legal Compliance. We may use or disclose information to the extent required by applicable law, regulation, or legal process.
3. Data Storage and Security
3.1 Local Storage (All Users)
Regardless of whether you use Guest mode or Signed-in mode, the App stores data locally on your device using the device's native storage mechanisms. In Guest mode, this is the only location where your data exists.
3.2 Cloud Storage (Signed-In Users Only)
If you sign in, your generated plans, case logs, and favorites are also stored on our cloud database, operated by Supabase and hosted on Amazon Web Services (AWS). Supabase is SOC 2 Type II compliant. All synced data is protected by Row Level Security (RLS), which ensures that each user can only access their own data through authenticated queries. Data is encrypted in transit (TLS) and at rest.
Game leaderboard entries (Section 1.8) are stored on the same infrastructure but sit outside this model, because they belong to no account. They are deliberately public to everyone who plays, and are protected by carrying nothing that identifies the player rather than by access control.
3.3 Device Security
The security of your locally stored data depends on the security of your device. We recommend that you protect your device with a passcode, biometric lock, or other access controls, and keep your device's operating system up to date. If your device is lost, stolen, or compromised, any data stored in the App may be accessible to unauthorized parties.
3.4 Authentication Security
Sign in with Apple and Sign in with Google use industry-standard OAuth 2.0 protocols. Attuned Labs never receives, processes, or stores your Apple or Google password. Authentication tokens are managed securely by Supabase Auth.
4. Data Retention and Deletion
4.1 Local Data
All data stored locally on your device persists until you delete it within the App or uninstall the App. You have full control over your local data at all times. Uninstalling the App from your device permanently removes all locally stored App data.
4.2 Synced Data (Signed-In Users)
If you have signed in, your synced data (plans, case logs, favorites) is stored on our cloud database for as long as your account is active. You may delete individual synced items at any time from within the App.
4.3 Account Deletion
You may delete your account and all associated synced data at any time from within the App's settings. When you delete your account:
- All synced plans, case logs, favorites, and account information are permanently deleted from our cloud database.
- Your authentication credentials are removed from our authentication system.
- This deletion is permanent and cannot be undone.
- Locally stored data on your device is not affected by account deletion — you may continue to use the App in Guest mode. To remove local data, delete it within the App or uninstall the App.
- Any game leaderboard entries you have posted are not affected, because they are not associated with your account and cannot be traced back to it (see Sections 1.8 and 4.5).
4.4 Crash Reports
Anonymous crash report data retained by Sentry is subject to Sentry's own data retention policies and does not contain clinical or personal information.
4.5 Leaderboard Entries
Game leaderboard entries (Section 1.8) are retained for as long as the leaderboard exists. They are not deleted by uninstalling the App or by deleting your account, because they are not connected to your device or your account in any way that would let us find them. An entry consists of an assigned three-letter code, a score, a level, an app version, a platform and a timestamp, and identifies no one. To have a specific entry removed, contact us with the details described in Section 1.8.
5. Third-Party Services
5.1 Apple App Store and Google Play Store
The App is distributed through the Apple App Store and Google Play Store. Your purchase of the App is processed entirely by Apple or Google, as applicable. We do not receive or store your payment card information, billing address, or other financial details. Your purchase is governed by the terms and privacy policies of the applicable app store.
5.2 Sign in with Apple and Sign in with Google
If you choose to create an account, authentication is handled by Apple or Google, as applicable. We receive only the limited information described in Section 1.2. We do not receive your password. Apple's "Hide My Email" feature is fully supported, allowing you to sign in without sharing your real email address. These authentication services are governed by Apple's and Google's respective privacy policies.
5.3 Supabase (Cloud Database and Authentication)
For signed-in users, account data and synced clinical data are stored on Supabase, a cloud database platform hosted on Amazon Web Services (AWS). Supabase is SOC 2 Type II compliant. All data is protected by Row Level Security and encrypted in transit and at rest. Supabase's privacy practices are governed by Supabase's own privacy policy. Guest users' clinical and study data is never transmitted to Supabase. Feedback voluntarily submitted by a guest is stored there without any account identifier (Section 1.6).
Feedback you submit through the App is also stored in Supabase, as described in Section 1.6, as are game leaderboard entries, as described in Section 1.8. Leaderboard entries carry no account identifier for any user, signed in or not.
5.4 Sentry (Crash Reporting)
The App uses Sentry for anonymous crash reporting and error monitoring. Sentry receives only technical diagnostic information (stack traces, device model, OS version, app version). Sentry does not receive clinical data, personal information, or account credentials. Sentry's privacy practices are governed by Sentry's own privacy policy.
5.5 Expo (Over-the-Air Updates)
The App uses Expo EAS to deliver over-the-air updates (JavaScript bundle downloads). When the App checks for or downloads an update, limited technical information (device type, OS version, app version) may be transmitted to Expo's servers. No clinical data or personal information is transmitted. Expo's privacy practices are governed by Expo's own privacy policy.
5.6 RevenueCat (In-App Purchases)
The App includes the RevenueCat SDK for managing in-app purchases. When in-app purchases are available, RevenueCat processes purchase verification and entitlement management through the Apple App Store or Google Play Store. RevenueCat does not receive clinical data, health information, or App content. RevenueCat's privacy practices are governed by RevenueCat's own privacy policy.
5.7 No Other Third-Party Data Sharing
We do not transmit your data to any AI service, analytics platform, advertising network, data broker, or other third party not listed in this section. We do NOT sell, rent, trade, or lease your information to any third party. We do NOT share your data with advertisers.
6. Your Rights
6.1 Guest Users
If you use the App without an account, all data is stored locally on your device and you have complete control over it. You can view, modify, or delete any data within the App at any time. Uninstalling the App permanently removes all App data from your device. We hold no server-side copy of guest user data, so in general there is no need to submit a data access, correction, or deletion request to us. The only things you can send us are feedback (Section 1.6) and a game leaderboard entry (Section 1.8); either can be removed on request, and the contact details and the information we need in order to find it are given in those sections.
6.2 Signed-In Users
If you have an account, you have the right to:
- Access your synced data at any time through the App.
- Delete individual synced plans, case logs, or favorites from within the App.
- Delete your account and all associated synced data permanently from within the App's settings (see Section 4.3).
- Request a copy of your data or ask questions about your stored data by contacting us at follie@heyattuned.com.
6.3 Data Portability
The App includes a Backup & Restore feature that exports your data to a JSON file you control. The export contains your saved anesthetic plans, case logs, favorited tools, streak record, and Follie Academy study progress. The file is created on your device and shared only where you choose to send it; we do not receive a copy.
If you wish to obtain a copy of your synced data instead, please contact us at follie@heyattuned.com with the subject line "Data Export Request."
7. Children's Privacy
The App is intended for licensed healthcare professionals and healthcare professional students who are at least 18 years of age. We do not knowingly collect personal information from individuals under 18 years of age. If you are under 18, you should not use the App.
8. HIPAA Considerations
Attuned Labs LLC is not a "Covered Entity" or "Business Associate" as defined under the Health Insurance Portability and Accountability Act of 1996, as amended ("HIPAA"). The App does not collect, transmit, or store Protected Health Information (PHI).
Guest users: All clinical data entered into the App remains on the user's local device and is never transmitted externally.
Signed-in users: The App de-identifies clinical data before syncing to our cloud database. No patient names, medical record numbers, dates of birth, Social Security numbers, or other direct patient identifiers are transmitted or stored on our servers. The synced data consists of de-identified clinical parameters (such as age, weight, medical history categories, and procedural details) that do not constitute PHI.
Users who are healthcare providers subject to HIPAA are solely responsible for ensuring that their use of the App complies with their own HIPAA obligations. Users should exercise appropriate judgment regarding what information they enter, particularly on shared or unsecured devices. The App's architecture — local-first storage with de-identified cloud sync — is designed to minimize PHI exposure.
9. Geographic Applicability
All clinical content, drug references, dosing guidelines, and clinical protocols provided in the App are based on United States medical standards, guidelines, and regulatory approvals. Drug names, approved indications, dosing ranges, and clinical protocols may differ in other countries. Users outside the United States should verify all information against their local medical standards, institutional protocols, and regulatory requirements.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will post the updated Privacy Policy on our website and update the "Last Updated" date. Material changes will also be noted in the App's release notes when applicable. Your continued use of the App after any changes indicates your acceptance of the updated Privacy Policy. We encourage you to review this Privacy Policy periodically.
11. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy, please contact us:
Attuned Labs LLC
Email: follie@heyattuned.com
Website: https://heyfollie.com
For privacy-specific inquiries, please use the subject line: "Follie Privacy Inquiry."
BY USING FOLLIE, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTOOD, AND AGREE TO THE PRACTICES DESCRIBED IN THIS PRIVACY POLICY.