Privacy Policy
1. Information We Do Not Collect
Unlike traditional web services, our mobile applications and platforms are engineered to minimize cloud-stored data:
- No Personally Identifiable Information (PII): We do not collect or store your legal name, passport numbers, email addresses, or government identification documents on our central servers.
- No Appointment Modification Tokens: Rescheduling tokens and reservation links extracted from emails or screenshots are saved strictly in your device’s native Secure Keychain (iOS) or EncryptedSharedPreferences (Android).
- No Financial Account Credentials: Payment transactions for subscriptions are handled directly by Apple StoreKit or Google Play Billing. We never receive or process your credit card numbers.
2. Information We Process
To operate our decentralized discovery mesh and high-priority alert system, our systems process minimal anonymous technical telemetry:
- Anonymous Device GUID: A randomly generated pseudonymous identifier used to manage push notification delivery preferences and device registration.
- Device Push Notification Token: Apple Push Notification service (APNs) device token or Firebase Cloud Messaging (FCM) token required to deliver real-time slot alerts to your device.
- Public Slot Telemetry: Public appointment availability timestamps observed and reported by mesh nodes to coordinate slot matrices across the network.
- Subscription Entitlements: Cryptographic receipt tokens issued by Apple or Google confirming active subscription tier (Free vs. Premium).
3. How We Use Anonymous Telemetry
The minimal anonymous data collected is used solely to:
- Coordinate non-overlapping background polling schedules across participating client mesh nodes.
- Arbitrate and dispatch sub-second push notifications when new appointment slots are detected.
- Verify client attestation and prevent malicious spam abuse using Apple DeviceCheck and Google Play Integrity.
4. Data Storage and Security
We maintain rigorous digital and physical safeguards to protect all telemetry:
- All network communications between your device and our coordinator API require mandatory TLS 1.3 encryption.
- Backend databases utilize hardware-level encryption at rest (AES-256) with strict role-based access isolation.
- Local application data is secured using the operating system’s hardware-backed Secure Enclave / Keystore with
kSecAttrAccessibleAfterFirstUnlockThisDeviceOnlyprotection.
5. California Privacy Rights (CCPA / CPRA)
Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), California residents have specific statutory rights:
- Right to Know & Access: You may request disclosure of any telemetry data categories collected. Because we do not store personal names or emails, telemetry is associated solely with your device GUID.
- Right to Deletion: You may delete all device registration records and subscriptions instantly by uninstalling the application or tapping "Delete Account & Data" in app settings.
- Do Not Sell or Share My Personal Information: We do not sell or share your personal information under any circumstance.
6. Children’s Privacy
Our applications and services are not directed to individuals under the age of 13. We do not knowingly collect personal information from children.
7. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect system updates or legal compliance. When updates occur, the effective date will be revised at the top of this document.
8. Contact & Data Inquiries
If you have questions, feedback, or legal inquiries regarding this Privacy Policy, please contact our legal operations desk:
Attn: Privacy Compliance Officer
30 N Gould St, Ste N
Cheyenne, WY 82001, United States
Email: privacy@cymbidiumlabs.com / support@cymbidiumlabs.com
Phone: +1 (307) 317-9170