1. Who We Are
PathLight is a free service provided by Beej Care Foundation (EIN: 41-4834284), a 501(c)(3) nonprofit organization based in Coppell, Texas, USA. Our mission is to make pediatric health research accessible to every family, regardless of geography or income.
PathLight is not a medical service. It is a research intelligence tool that helps families understand published scientific literature about their child's condition in plain language. PathLight does not diagnose, prescribe, or replace the advice of a healthcare provider.
2. What We Collect — Complete Summary
The table below is a complete and accurate description of every piece of data PathLight collects or processes:
| Data | Collected? | Stored by BCF? | Notes |
|---|---|---|---|
| Your name | No | No | Never requested or stored |
| Your email address | No | No | Google handles sign-in; BCF never sees your email |
| Your questions / queries | No | No | Sent to AI for processing; not stored by BCF |
| Your child's diagnosis | No | No | Disease category you select is not stored |
| Medical records / PHI | No | No | PathLight is PHI-free by design |
| Location / GPS | No | No | Never requested or accessed |
| Contacts / camera / microphone | No | No | No device permissions requested |
| Anonymous identifier (UUID) | Yes | Yes | A one-way hash of your Google ID. Cannot be reversed to identify you. Used only for rate limiting. |
| Daily query count | Yes | Yes | Number of queries used today. Resets daily. Used to enforce the 50-query free limit. |
| Feedback (thumbs up/down) | Yes | Yes | Optional. Stored as anonymous vote. Used to improve response quality. |
3. How Authentication Works
PathLight uses Google Sign-In via Firebase Authentication (a Google service). When you sign in:
- Google authenticates your identity and issues a secure token to the PathLight app.
- PathLight receives this token and converts your Google ID into a one-way cryptographic hash (anonymous UUID). This hash cannot be reversed to identify you — not even by BCF engineers.
- BCF never receives, sees, or stores your name or email address.
- Google's own privacy policy governs the sign-in process: policies.google.com/privacy
4. How Your Questions Are Processed
When you submit a question to PathLight:
- Your question is sent securely (HTTPS) to BCF's server.
- The server searches BCF's research database for relevant papers.
- Your question and the relevant research are sent to Anthropic's Claude AI to generate a plain-language response.
- The response is returned to you.
- Your question is not stored by BCF. It is processed in memory and discarded after the response is generated.
Anthropic's privacy policy governs how queries are handled by Claude: anthropic.com/privacy
5. How We Use the Data We Do Collect
- Anonymous UUID: Used only to enforce the daily query limit. Never used for identification, profiling, or tracking.
- Daily query count: Used only to enforce the 50-query daily limit. Resets automatically at midnight UTC.
- Feedback votes: Used only to improve response quality. Not linked to any personally identifiable information.
We do not use any collected data for advertising, marketing, profiling, or any commercial purpose.
6. Data Sharing
BCF does not sell, rent, or share your data with third parties for commercial purposes. Data is shared only in these limited, necessary circumstances:
- Google / Firebase: Handles sign-in authentication. BCF does not receive your Google account details beyond what is described in Section 3.
- Anthropic: Your questions are processed by Claude AI to generate responses. Anthropic's privacy policy applies to this processing.
- Amazon Web Services (AWS): BCF's servers are hosted on AWS in the United States. AWS infrastructure processes all data in transit.
- Legal requirements: We may disclose data if required by applicable law, court order, or to protect the safety of our users.
7. Data Security
BCF implements industry-standard security measures to protect the minimal data we store:
- All data transmitted between the PathLight app and BCF servers is encrypted using HTTPS/TLS.
- BCF servers are hosted on Amazon Web Services (AWS) with standard security controls.
- Anonymous UUIDs are generated using SHA-256 cryptographic hashing with a secret salt — they cannot be reversed to identify any user.
- No sensitive health data is stored, which eliminates the most significant category of data security risk.
8. Data Retention
- Daily query counts: Reset automatically each day. Old query counts are not retained.
- Anonymous UUIDs: Retained as long as you actively use PathLight. If you have not used PathLight in 12 months, your record is eligible for deletion.
- Feedback votes: Retained indefinitely in aggregate anonymous form to improve the service.
9. Children's Privacy
PathLight is designed to be used by parents and caregivers on behalf of their children — not directly by children. PathLight does not knowingly collect personal information from children under 13.
If you believe a child under 13 has created a PathLight account, please contact us at [email protected] and we will promptly delete the account and any associated data.
10. Your Rights
You have the right to:
- Know: Request information about what data BCF holds associated with your anonymous identifier.
- Delete: Request deletion of your account and all associated data. See Section 10a below for step-by-step instructions.
- Opt out: Stop using PathLight at any time. No data is collected when you are not using the service.
To exercise these rights, contact us at [email protected]. We will respond within 30 days.
10a. How to Delete Your Account
You can delete your PathLight account and all associated data at any time. Deletion permanently removes your anonymous identifier, query history, and usage profile from BCF servers. This action cannot be undone.
What gets deleted:
- Your anonymous UUID (randomly generated identifier)
- Your daily query count and usage history
- Your usage profile (disease preferences, language settings)
- Your analytics events
- Your Firebase authentication account
How to delete — by platform:
- Web app (pathlight.beejcare.org): Sign in → click Settings → scroll to "Delete My Account" → confirm deletion.
- iOS app: Sign in → tap Settings tab → tap "Delete Account" → confirm deletion.
- Android app (current version): Account deletion is available via the web app at pathlight.beejcare.org/settings.html. The next Android app update will include in-app account deletion.
If you experience any difficulty deleting your account, contact us at [email protected] and we will manually delete your account within 30 days.
11. Cookies and Tracking
The PathLight web app uses Firebase Authentication, which sets cookies necessary for session management (keeping you signed in). These are functional cookies — not advertising or tracking cookies.
PathLight does not use third-party advertising cookies, tracking pixels, or cross-site tracking technologies of any kind.
The PathLight mobile app does not use cookies.
12. Changes to This Policy
We may update this Privacy Policy as PathLight evolves. When we make material changes, we will update the "Last Updated" date at the top of this page. For significant changes, we will provide notice within the PathLight app.
Continued use of PathLight after changes constitutes acceptance of the updated policy.
13. Contact Us
For privacy questions, data requests, or concerns, contact us:
Beej Care Foundation
EIN: 41-4834284
Coppell, Texas, United States
Email: [email protected]
Website: beejcare.org
Response time: within 30 days