Skip to content
Pocket Genes

Security

Data-Flow Diagram

Separates informed-consent handling before a study, genetic-report access after a study, and optional education or community features.

Purpose and scope

This page separates three different Pocket Genes data paths: informed-consent handling before a study, private genetic-report access after a study, and optional education or community features. It is not a server topology diagram and does not expose implementation secrets.

The goal is to show what information enters each path, who is responsible, what Pocket Genes does, whether information is retained, and what the user controls.

Who this page applies to

  • Users and caregivers trying to understand report-access and community boundaries.
  • Providers and integrators that initiate invitations or report-access workflows.
  • Trusted Organizations and community publishers.
  • Privacy, security, and support reviewers handling requests.

Definitions

Provider

The organization that created, delivered, or controls the genetic report or provider resource.

Integrator

A provider, clinic, laboratory, organization, or support program that connects a person to a Pocket Genes workflow.

Access reference

A URL, code, token, identifier, provider reference, or similar value used to connect an authorized user to a report-access path.

Community participation

Optional RareFriends actions such as profile creation, matching, follows, groups, posts, comments, and messages.

Informed consent before the study

Consent request and upload before a genetic study.

Request created

The provider starts the flow with the minimum patient details.

Access email sent

The patient receives the portal instructions and access key.

Consent file uploaded

The patient uploads the required informed-consent file.

Consent confirmed

The responsible doctor, clinic, laboratory, or provider confirms and validates that the informed-consent file was uploaded.

Genetic report access after the study

Secure access to an uploaded genetic report.

Report uploaded

The provider uploads the report so it can be viewed by the authorized doctor and patient.

Access limited

Pocket Genes keeps access limited to the authorized accounts.

Sign-in

The doctor or patient signs in securely with enabled credentials or with the security key provided by the system.

Report available

The report can be viewed, saved in the app, or downloaded.

Optional Pocket Genes features

Optional features, separate from private report access.

Education and discovery

General resources and organizations without exposing private report information.

RareFriends and community

Optional participation with profiles, posts, groups, and user controls.

Explicit boundaries

  • The provider remains responsible for the underlying report and findings.
  • The responsible provider remains responsible for the study, the informed-consent requirement, and whether the study can proceed.
  • Pocket Genes is a secure transit and access tool for the uploaded genetic report.
  • Authorized doctors and patients may keep downloaded report files outside Pocket Genes.
  • Pocket Genes is responsible for the account, access, integration, education, discovery, and community processes it operates.
  • Accessing a report does not publish it.
  • Joining RareFriends does not disclose a report to other users.
  • Using education or community features is optional and is not part of a provider study decision.
  • Trusted Organizations do not receive unrestricted account access.
  • An integrator does not automatically receive the user subsequent community activity.
  • Report information is not used for advertising under the Trust Center data criteria.

User device and local state

The user device may hold app state, cached screens, notifications, downloaded files, screenshots, browser history, or operating-system records depending on device settings and app behavior. Downloaded or locally saved copies remain on the doctor or patient device for as long as that person keeps them; the provider has neither the right nor the technical ability to delete a report that has already been delivered.

Provider links, report codes, and private report content are kept out of public profiles, community posts, analytics, and support screenshots unless narrowly needed for support or security.

Infrastructure

Pocket Genes uses service providers including Amazon Web Services and Google Firebase for technical functions such as authentication, communications, application operation, and workflow management. These providers support the processes described above but do not change the responsibility of the professional or provider for the study or report.

Data-handling model

  • Each step is limited to the information needed for that workflow.
  • Source responsibility stays separated between providers, Pocket Genes, organizations, and users.
  • Access references and private account data are treated as protected information.
  • Access, request, deletion, and incident paths are recorded where required for operation and support.

External boundaries

  • Invitations, community choices, and private report access remain separate user experiences.
  • Integrator-provided information is limited to authorized and necessary workflow data.
  • Community follows, comments, and membership do not expose private account or report data to organizations.

Exceptions and limitations

  • Specific integrations may have additional provider terms, retention rules, or support paths.
  • External provider resources may become unavailable outside Pocket Genes control.
  • Backups, logs, and legal holds may affect deletion timing.

How to make a request or report a problem

Privacy, account, deletion, accessibility, safety, trusted-organization, and security requests can be sent to support@goldencrowvs.com. Use a subject line that identifies the issue, the affected Pocket Genes account or workflow, and whether the request is urgent.

Pocket Genes may need to verify the requester before changing or disclosing account information. Verification is handled proportionally to the request, the sensitivity of the information, and the risk of giving account access or private information to the wrong person.

Effective date, version, and review history

ItemValue
Effective dateAugust 14, 2026
Version1.1
Last reviewedAugust 2026
Material changesExpanded Trust Center format, operator identity, data-map boundaries, request paths, and responsibility sections.
Previous versionJuly 2026 Trust Center overview copy.

Related pages

Related pages