Skip to content
Pocket Genes

Privacy and rights

Privacy Policy

Explains what personal information Pocket Genes processes, why we need it, how it is protected, when it may be shared, and the choices available to users.

Purpose and scope

This Privacy Policy explains how Pocket Genes processes personal information in the mobile application, public Pocket Genes pages, Trust Center, account flows, report-access integrations, discovery features, trusted-organization features, and RareFriends by Pocket Genes community features.

Pocket Genes processes limited account and contact information, authentication information, integration information, platform decision records, technical information, support information, and community information depending on the features a person uses. It does not publish a broad claim that Pocket Genes never processes sensitive data, because community participation, RareFriends matching fields, report-access references, and user-provided context may reveal health or genetic information.

Genetic reports remain associated with the participating provider that created or delivered them. Pocket Genes helps authorized users reach and navigate the provider-connected mobile experience. Any provider URL, access token, report reference, or identifier handled by Pocket Genes is treated as confidential access information even when it is not the report itself.

Who this page applies to

  • People who create or use a Pocket Genes account.
  • People invited to a Pocket Genes workflow by an integrator, provider, clinic, laboratory, organization, or support program.
  • Parents, guardians, caregivers, or representatives who manage an account or workflow for another person where permitted.
  • People who participate in RareFriends, follow organizations, post, comment, send messages, or use matching features.
  • Trusted Organizations, integrators, and report providers that provide contact data, publish content, or operate report-access workflows connected to Pocket Genes.

Who controls the information

FieldCurrent public value
Operator/controllerGolden Crow Venture Studio
CountryArgentina
Product namePocket Genes
Privacy, security, and accessibility contactsupport@goldencrowvs.com
Data-protection representative or DPONot separately appointed in this Trust Center. Requests are routed through the same contact channel.

Definitions

Personal information

Information relating to an identified or identifiable person, including account, contact, technical, integration, platform decision, support, and community information.

Account information

Name, surname, email address, optional phone number, account identifier, profile settings, language, and other information used to create, maintain, secure, or support a Pocket Genes account.

Integration information

Limited information provided by a participating organization or generated by Pocket Genes to connect the intended person with a report-access path, service invitation, informed-consent workflow, or organization workflow.

Platform decision record

A record that identifies a platform action such as Terms acceptance, Privacy Policy acknowledgement, report-access activation, optional communication preference, informed-consent upload status, or report-access workflow status.

Community information

Profile fields, posts, comments, follows, groups, messages, interests, tags, role, country, language, journey stage, and other information a user voluntarily adds to RareFriends or community features.

Technical information

Device, browser, app, authentication, logging, diagnostic, security, and operational information needed to operate and protect the service.

Report provider

A laboratory, clinic, hospital, genetic testing company, rare disease organization, or other participating entity that creates, delivers, controls, or remains responsible for a genetic report or provider-controlled report resource.

Trusted Organization

An organization reviewed by Pocket Genes for a curated publishing or community presence. Trusted status is not a blanket endorsement of every service, claim, event, or resource from that organization.

Service provider

A vendor that processes information for Pocket Genes, such as cloud infrastructure, authentication, database, hosting, diagnostics, support, scheduling, or communication providers.

Processing table

CategoryExamplesSourcePurposeShared withRetention
Account dataName, surname, email, optional phone, language, profile settings, account id.User, caregiver, authorized representative, or integrator when an invitation starts.Create account, communicate, provide support, route report access, preserve account security.Infrastructure providers and authorized support personnel with need-to-know access.While the account is active, then deleted or de-identified through the account-deletion workflow subject to legal, safety, backup, and fraud-prevention limits.
AuthenticationFirebase user id, login records, session information, password-reset activity, security events.User, device, Firebase Authentication, and Pocket Genes backend.Sign-in, account recovery, session protection, abuse prevention, and access control.Google Firebase and Pocket Genes systems that verify identity and sessions.For the account and security period needed to operate authentication, investigate misuse, and comply with provider security logs.
Integration dataProvider or organization, invitation state, access reference, report code, provider reference, contact fields needed to reach the intended user.Integrator, report provider, Pocket Genes, or the user during onboarding.Connect the intended user with the relevant Pocket Genes experience, provider report path, informed-consent workflow, or organization workflow.Relevant backend, database, authentication, and infrastructure providers; the originating integrator only as needed for the integration.Current system behavior is tied to workflow completion, rejection, revocation, account deletion, or manual cleanup. No public automatic expiration is stated unless a specific integration publishes one.
Platform decision recordsPurpose, screen or policy version, status, timestamp, workflow, account, provider or organization reference where applicable.User action, caregiver or authorized representative action, and Pocket Genes workflow records.Terms acceptance, Privacy Policy acknowledgement, feature settings, report-access activation, optional communication preferences, and workflow accountability.Infrastructure providers and internal reviewers who need the record for the relevant workflow.May outlive temporary contact information where needed to prove the decision, resolve disputes, or satisfy legal obligations.
Community dataRareFriends profile, nickname, role, country, language, gene or condition tags, symptom tags, journey stage, posts, comments, follows, groups, messages, reports, blocks.User, community interactions, and moderation actions.Community participation, matching, moderation, safety, reporting, user controls, and support.Other users according to visibility settings; infrastructure providers; moderators where needed.Until the user deletes content or account, moderation removes it, the workflow is closed, or records are retained for safety/legal reasons.
Technical dataDevice type, browser, app version, logs, errors, security events, IP-derived operational data, diagnostic traces.Device, browser, app, infrastructure, and backend services.Reliability, security, troubleshooting, abuse prevention, and incident response.AWS, Firebase, diagnostic or hosting providers when used, and authorized operators.For provider log cycles, security investigation windows, incident records, or de-identified operational analysis.

Information received to start an integration

A laboratory, clinic, professional, or other participating organization may provide Pocket Genes with basic information such as name, surname, email address, and, where applicable, phone number.

Pocket Genes uses this information to send service-related communications, identify the intended recipient, and facilitate the corresponding workflow.

The organization that provides the information is responsible for having the necessary authority or legal basis to do so. When Pocket Genes contacts the person, it explains who provided the information, why Pocket Genes received it, and how the person can request information, object, or request deletion where applicable.

Informed consent for a genetic study

In some integrations, the professional or provider responsible for a genetic study may use Pocket Genes to ask the patient to upload the required informed-consent file.

Informed consent refers to the patient decision to accept or reject the study after receiving clear information from the responsible professional about the purpose, procedure, benefits, risks, alternatives, and relevant consequences.

The provider or professional responsible for the study is accountable for the required explanations and the decision about whether the uploaded informed consent allows the study to proceed.

Pocket Genes acts as a technical channel for the upload request, access instructions, file upload, and consent status. Processing and temporary retention of any related record is limited to what is necessary to complete that process and is governed by the Data-Retention and Deletion Policy.

Informed consent for the study is independent from the Pocket Genes Privacy Policy, Terms of Service, and optional Pocket Genes preferences.

Terms, privacy, and optional preferences

The Privacy Policy explains how Pocket Genes handles the personal data needed to operate the platform. The Terms of Service set the conditions for using Pocket Genes.

Preferences related to RareFriends, profile visibility, notifications, newsletters, and other optional communications are managed separately.

These choices are platform settings, not study approvals or clinical decisions.

Report access and confidential references

The participating provider remains responsible for the report, the findings, the scientific or clinical interpretation, and the provider-controlled delivery path. Pocket Genes is responsible for the account, integration, access, and user-experience functions it operates.

Depending on the integration, Pocket Genes may receive or create a report code, provider reference, URL, token, access state, or similar identifier. These items are handled as confidential access information and are kept out of community spaces, public profiles, analytics, screenshots, and logs except where narrowly needed for support or security investigation.

When a link or reference expires or can be revoked, that status is handled through the relevant user workflow or provider arrangement. Provider resources may become unavailable independently of Pocket Genes if the provider changes, removes, or disables the underlying report or service.

Community privacy

RareFriends participation is voluntary and separate from private report access. Creating an account, viewing a report, following an organization, or joining RareFriends does not automatically publish a private report.

Community information a user chooses to add may reveal health or genetic context. Matching may use user-provided gene, condition, symptom, country, language, role, interest, or journey-stage fields where those features are active. Visibility depends on the feature, user settings, group rules, and moderation actions.

Service providers, transfers, cookies, and tracking

Pocket Genes uses established service providers, including Amazon Web Services and Google Firebase, to operate different technical components. The Subprocessor List identifies public providers and the categories of information they may process.

Some providers may process information outside the user country. Pocket Genes remains responsible for selecting, configuring, and operating its own application safely even when the underlying cloud provider supplies infrastructure security.

Pocket Genes does not publish a sale of personal information or advertising-use model for Pocket Genes user data in this Trust Center. Any material expansion of cookies, website analytics, crash reporting, product analytics, push notifications, attribution, or marketing communications is handled through a relevant notice that identifies purpose, choice, and retention path.

Rights and request process

Users can contact support@goldencrowvs.com to request access, correction, deletion, a change to platform preferences where available, account closure, or information about a specific integration source.

Pocket Genes reviews the request, verifies identity when needed, checks whether the information is controlled by Pocket Genes or by a provider, and explains the expected action or limitation. A request may be limited when another person privacy is affected, a provider remains responsible for the underlying report, a legal or safety hold applies, a security investigation is active, or the information is needed to enforce terms or resolve a dispute.

Where Argentine personal-data law applies, people may have rights to access, rectify, update, or delete personal information and may contact the Agencia de Acceso a la Informacion Publica if a request is not resolved as required by applicable law. Where GDPR or another privacy law applies, additional rights or complaint paths may be available.

Children, caregivers, optional communications, and matching

  • Children and minors should use Pocket Genes only through a parent, guardian, caregiver, provider, or other authorized arrangement where required by law and product configuration.
  • Caregiver-managed accounts must respect the authority and privacy boundaries that apply to the person whose information is being managed.
  • Service communications are limited to account, support, invitation, report-access, security, accessibility, incident, and operational needs.
  • Optional newsletters, event notices, organization updates, or marketing communications should have a clear opt-in or opt-out path.
  • Automated matching or recommendations in RareFriends should rely on user-provided or permitted fields and should not be presented as diagnosis, treatment, clinical prioritization, or an endorsement.
  • Changes to this policy are published through the Trust Center. Material changes should be communicated through an appropriate product or account notice when required.

Pocket Genes responsibilities

  • Process only the information needed for the feature, integration, support, security, or community purpose.
  • Keep private report access separate from public or community participation.
  • Protect access references, tokens, report codes, and provider identifiers as confidential access information.
  • Configure service providers, authentication, access control, logging, moderation, and support workflows with appropriate safeguards.
  • Maintain request, deletion, incident, accessibility, and moderation channels.

User, integrator, and organization responsibilities

  • Users should keep credentials secure, avoid sharing report links or codes publicly, choose community disclosures carefully, and use request channels when they need changes.
  • Integrators must have authority to provide contact or identifying information to Pocket Genes and must provide accurate source, purpose, legal basis, and informed-consent or report-access context.
  • Trusted Organizations must label promotional material, avoid medical pressure, respect privacy boundaries, and avoid using community access to infer or collect private report information.

Exceptions and limitations

  • Pocket Genes cannot delete a provider report or provider-controlled medical record that remains with the provider.
  • Deleted information may briefly remain in backups or logs until rotation or restoration handling is complete.
  • Moderation, incident, fraud-prevention, legal, or security records may be retained where narrowly necessary.
  • Third-party provider reports, app stores, external websites, booking tools, or embedded resources may have their own privacy practices.

How to make a request or report a problem

Privacy, account, deletion, accessibility, safety, trusted-organization, and security requests can be sent to support@goldencrowvs.com. Use a subject line that identifies the issue, the affected Pocket Genes account or workflow, and whether the request is urgent.

Pocket Genes may need to verify the requester before changing or disclosing account information. Verification is handled proportionally to the request, the sensitivity of the information, and the risk of giving account access or private information to the wrong person.

Effective date, version, and review history

ItemValue
Effective dateAugust 14, 2026
Version1.1
Last reviewedAugust 2026
Material changesExpanded Trust Center format, operator identity, data-map boundaries, request paths, and responsibility sections.
Previous versionJuly 2026 Trust Center overview copy.

Related pages

Related pages