Local-first architecture
Almost everything this app does happens on your phone or in this browser tab. There is no PACT patient file and no cloud profile of who you are. Optional encrypted sync may use Apple or Google sign-in.
No personal identifiers (PII)
The consumer app does not collect your name, phone, government ID or date of birth. Quick Quiz, AI Chat, Connect and Care do not need an account. Clinic-staff accounts use work email. Optional device sync may use Apple or Google sign-in.
Chat history is not stored in the cloud
The AI helper does not save your conversation on this device or upload a chat log to PACT Safe servers. Clearing the chat wipes this screen immediately. Identifiers are stripped before a message is sent to generate a reply.
GPS is processed only in this browser
Optional “clinics near me” sorting reads your location once inside this browser, uses it to order the on-device clinic list, then discards it. Coordinates are never stored, never uploaded, and never linked to your anonymous token.
Camera and photos
The camera is used on this phone to scan clinic or 18+ partner QR codes, and optionally to photograph a lab sheet. Images are processed on the device. A lab photo is sent only if you ask the helper to read it, after identifiers are stripped.
Reminders on this phone
Optional medication and care-window reminders use this device’s notification permission. They are not used to push partner notices to the lock screen.
Quick Quiz stays on-device
Symptom answers are scored in this browser only. They are not written to the cloud and are not attached to an identity.
Referral codes stay on this phone — and you can delete them
A PACT code is a walk-in coupon you can show at a desk, not a patient file and not a contract. Unused codes are removed from this device after 30 days. Cancel if you tapped the wrong clinic, or delete right after your visit.
Partner notices are fetched, not pushed to the lock screen
After an 18+ QR handshake, a result saved on one phone can be dropped in the other phone’s anonymous inbox. The server stores only a token-hash, a sealed blob, and an expiry. No name, phone, GPS, or infection name. The other person sees it when they open Notices in this app — not as a lock-screen push. HIV cannot be sent from a self-report.
What the publisher counts
The app sends aggregate counters so the publisher can see whether Care, Connect, clinic listings and notices are used — by UTC day, a coarse country code from the device timezone (or the clinic listing’s country), and the event name. Optional dim is a public catalogue id such as a clinic listing. No name, phone, email, GPS, IP log, anonymous token, or infection name is stored in that table. These are event counts, not unique people, and not infections prevented.
When the internet is used
A connection is used for optional encrypted device sync, clinic map links you tap, clinic booking pages you open, generating an AI reply after identifiers are stripped, the partner-notice inbox (token-hash + sealed blob + TTL only), and aggregate usage counters (day + country code + event). None of those steps create a named health record.
Erase and delete account
Erase on this phone wipes local data. If you turned on optional Apple or Google sync, Erase also deletes the encrypted backup and the Auth account used only for that backup. You can also delete the backup or the account from Sync. Clinic-staff email accounts are separate — ask hello@pactsafeapp.com to remove a work mailbox from the partner list.
Who to contact
PACT Safe is published independently. Email hello@pactsafeapp.com for app problems, partner requests, report of a notice, or questions about data. We do not hold a named patient file. If you used optional sync, use Erase or Delete account so the backup and Auth user are removed.
Saved on this phone