Privacy Policy

Privacy Policy

Last updated: July 9, 2026

This Privacy Policy explains how we collect, use, store, and protect personal data when you use the Pneumotox and Cardiotox websites and mobile applications (together, the 'Services'). It is designed to meet the transparency requirements of Google Play, the Apple App Store, and applicable data protection laws, including the EU General Data Protection Regulation (GDPR).

By creating an account, using our mobile apps, or submitting information through our contact form, you acknowledge that you have read this Privacy Policy. If you do not agree, please do not use the Services.

1. Data controller

The data controller responsible for your personal data is:

  1. Philippe Camus, M.D.
  2. 13, rue de Turgot, 21000 Dijon, France
  3. Publication Director: Philippe Camus
  4. Design and production: AKYOS Communication

For privacy-related requests, please use our contact form and include 'Privacy request' in your message.

2. Scope of this policy

This policy applies to:

  1. The Pneumotox website and mobile app (Android and iOS)
  2. The Cardiotox website and mobile app (Android and iOS)
  3. Any account, bookmark, notification, or support feature connected to these Services

The Services are medical reference tools intended for healthcare professionals. They are not directed at children under 16, and we do not knowingly collect personal data from children.

3. Personal data we collect

We collect only the data necessary to operate the Services.

3.1 Account and profile data (mobile apps)

If you create an account in the Pneumotox or Cardiotox mobile app, we collect:

  1. Email address
  2. First name and last name
  3. Password (stored only in hashed form on our servers; never in plain text)
  4. Notification preferences (email and push notifications)
  5. Date of acceptance of our Terms of Use

Account creation is optional. You may browse most medical content without an account. An account is required only for features such as bookmarks, profile management, and notifications.

3.2 Bookmarks and app activity

If you are signed in, we store the drugs, patterns, or publications you save as favorites so that you can access them across sessions and devices linked to your account.

3.3 Push notification device tokens (optional)

If you enable push notifications, we store a device token provided by your mobile platform (Expo push token) so that we can send notifications to your device. Push notifications are optional and can be disabled at any time in Account settings.

3.4 Contact form data (website)

If you contact us through the website contact form, we collect the information you provide, such as your name, email address, and message content.

3.5 Data stored locally on your device

The mobile apps store a limited amount of data on your device using secure local storage, including:

  1. Your authentication token (to keep you signed in)
  2. Local app preferences (for example, whether you chose to skip the welcome screen)

This data remains on your device and is removed when you sign out, delete the app, or delete your account.

3.6 Technical data

When you use the Services, standard technical information may be processed automatically by our hosting infrastructure to deliver the Services securely, including connection logs and request metadata. We do not use this data to build advertising profiles.

3.7 Data we do not collect

We do not collect:

  1. Precise or approximate location
  2. Health records or clinical patient data
  3. Payment or financial information
  4. Photos, videos, contacts, calendar data, or SMS content
  5. Advertising identifiers for ad targeting
  6. Analytics or crash-reporting data through third-party tracking SDKs

Our mobile apps do not contain ads.

4. How we use your data

We use personal data only for the following purposes:

  1. Creating and managing your user account
  2. Authenticating you and securing access to account features
  3. Storing and syncing your bookmarks
  4. Sending service-related email or push notifications, if you have opted in
  5. Responding to contact and support requests
  6. Operating, maintaining, and securing the Services
  7. Complying with legal obligations

We do not sell your personal data.

5. Legal basis for processing (GDPR)

Where GDPR applies, we rely on the following legal bases:

  1. Contract: to provide account, bookmark, and notification features you request
  2. Consent: for optional email and push notifications, and when you submit the contact form
  3. Legitimate interests: to keep the Services secure, prevent abuse, and respond to user requests
  4. Legal obligation: where we must retain or disclose data under applicable law

6. Data sharing and service providers

We do not share your personal data with third parties for their own marketing purposes.

We may share data with trusted service providers who process it on our behalf and only according to our instructions, such as:

  1. Our hosting provider (ONLINE SAS, 8 rue de la Ville-l'Évêque, 75008 Paris, France)
  2. Expo / EAS infrastructure used to deliver mobile app updates
  3. Apple and Google platform services required to operate push notifications on your device

These providers may only use your data to deliver the contracted service and must protect it appropriately.

7. International transfers

Our servers are located in the European Union. If data is transferred outside the European Economic Area, we ensure appropriate safeguards are in place in accordance with applicable law.

8. Data retention

We retain personal data only for as long as necessary:

  1. Account data: kept while your account is active
  2. Bookmarks and notification preferences: kept while your account is active
  3. Push device tokens: removed when you disable push notifications or delete your account
  4. Contact form messages: kept for the time needed to handle your request, then deleted or archived as required by law

When you delete your account, your account data, bookmarks, notification preferences, and push tokens are deleted permanently and without undue delay.

9. Security

We implement appropriate technical and organizational measures to protect your data, including:

  1. Encryption in transit (HTTPS/TLS) for communications between your device and our servers
  2. Password hashing on our servers
  3. Secure local storage for authentication tokens on mobile devices
  4. Access controls limiting personal data to authorized personnel and systems

No method of transmission or storage is completely secure. If you believe your account has been compromised, please contact us immediately through our contact form.

10. Your rights and choices

Depending on your location, you may have the right to:

  1. Access the personal data we hold about you
  2. Correct inaccurate or incomplete data
  3. Delete your data
  4. Restrict or object to certain processing
  5. Withdraw consent for optional notifications at any time
  6. Request data portability, where applicable
  7. Lodge a complaint with your local data protection authority

You can exercise many of these rights directly in the mobile app:

  1. Update your profile and notification preferences in Account settings
  2. Remove bookmarks from the Favorites tab
  3. Delete your account from Account settings

For additional requests, visit our data deletion page or account deletion page, or contact us through the contact form. We respond to verified requests within 30 days.

11. Account and data deletion

You may permanently delete your account and associated personal data at any time from the mobile app or by following the instructions on our account deletion page.

Upon account deletion, we delete:

  1. Account credentials (email address and password)
  2. Profile information (first name, last name)
  3. Notification preferences
  4. Saved bookmarks
  5. Push notification device tokens

Deletion is immediate and permanent. This action cannot be undone.

12. Permissions used by the mobile apps

The Pneumotox and Cardiotox mobile apps request only the permissions needed to operate:

  1. Internet access: to load medical content and communicate with our servers
  2. Vibration (Android): for optional haptic feedback

The apps do not request access to your location, camera, microphone, contacts, calendar, or SMS.

13. Third-party links

The Services may contain links to external websites or scientific references. We are not responsible for the privacy practices of those third-party sites. We encourage you to review their privacy policies before providing personal data.

14. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or Service features. When we make material changes, we will update the 'Last updated' date at the top of this page. We encourage you to review this page periodically.

15. Contact us

If you have questions about this Privacy Policy or how we handle your personal data, please contact us through our contact form.

For postal correspondence:

Philippe Camus, M.D.

13, rue de Turgot

21000 Dijon

France