Public Service and Optional Account Privacy Notice
This readable page comes from the exact source-bound document. The raw document is available at /legal/public-free-account-v1/privacy.md.
Status: CONDITIONAL PUBLIC PRIVACY NOTICE — EFFECTIVE ONLY UNDER A MATCHING EXACT-HASH FINAL RELEASE SEAL Version: adh-public-free-account-privacy-v1.3-2026-09-03 Effective condition: these exact bytes are adopted by DMH and served from the canonical domain under the matching PUBLIC_FREE_ACCOUNT_V1 release seal Attorney reviewed: no
This notice covers only the anonymous bounded Ask feature, public E001 case rep, and optional free email-code account released under PUBLIC_FREE_ACCOUNT_V1.
1. Current data boundary
Ask and the public E001 rep do not require an account or email address. They process transient educational questions or browser-generated voice-typing transcripts and the bounded E001 commitment facts described below. If you separately choose the optional account flow, the release also processes an account email, provider-generated account identifier, authentication and security metadata, and a short-lived signed application session.
It does not activate payment, paid membership, marketing automation, advertising, product analytics, saved question history, member learning storage, live AI, stored audio recording, Maya Realtime voice output, or publication features.
2. Optional email-code account
Only if you choose the optional account flow and request a code, the application sends the normalized email address to Supabase Auth so Supabase can create or locate the free identity and deliver a one-time code. Supabase processes the email, account identifier, code and verification state, timestamps, and ordinary authentication, delivery, security, and abuse-prevention data under its service configuration and applicable provider terms.
When a valid code is verified, the application receives the verified account identifier and email. A provider access token is used only during server-side verification and is not stored by the Operation ADH application or placed in its browser cookie.
3. Public account session cookie
After verification, the site places a signed, HTTP-only, secure, same-site cookie named adh_public_session for up to 24 hours. It contains the account identifier, email, public-Ask audience, issue time, and expiration time. JavaScript cannot read the cookie. Its signature protects integrity; it is not described as encryption.
The cookie recognizes the signed-in browser for optional account functions. It is not required or read to authorize bounded Ask, and application code does not attach Ask question text to the account or email. Clearing site data removes the browser copy. Cookie removal signs out that browser but does not delete the provider account.
4. Ask questions, browser voice typing, and responses
Ask processes one educational question or synthetic, de-identified clinical vignette of up to 16,000 characters in request memory. Application code screens the input for identifying or patient-specific content, classifies the educational boundary, and lexically matches only the released E001 content.
The question is not written to an application database, saved as history, included in product analytics, intentionally logged by application code, linked by application code to an account or email, sent to an AI model, or echoed in the response. The deterministic response is generated from fixed application rules and exact-approved E001 teaching content. No live model runs in this route.
The Ask box and the E001 learning flow may offer optional browser voice typing. Microphone access starts only after you press the visible Speak control. The browser's SpeechRecognition feature may process microphone audio through the browser or operating-system vendor under that vendor's settings and terms. Operation ADH application code does not upload, receive, save, or replay the microphone audio. It receives only the transcript that the browser inserts into the visible text field. You can edit or delete the transcript, and it is not submitted to Operation ADH until you press Ask or the applicable case action.
After the E001 explanation is revealed, the page may label the bounded follow-up interface as “Maya.” In this release, that interface still uses only fixed, physician-reviewed E001 rules and content. It is not a live AI model, realtime voice conversation, or Maya audio-output session.
5. E001 commit cookie
The separate public E001 rep transiently processes a browser-generated session identifier, released case identifier, and selected answer. It does not collect or process a written rationale in this release.
After a valid commitment, the site may place a signed, HTTP-only, same-site cookie for up to 30 minutes. It contains the session identifier, case identifier, selected answer, timestamps, and a neutral attestation that the answer selection was committed. It contains no free-text rationale.
6. Hosting and security data
Hosting, delivery, email, and security infrastructure may process ordinary technical data such as IP address, request time, route, user agent, referrer, coarse network or region information, delivery status, and abuse signals. Those provider-controlled records may follow provider security, reliability, backup, and retention settings.
Operation ADH does not add a product-analytics event store, advertising pixel, marketing tracker, or cross-site behavioral profile to this release. It does not intentionally include question text in hosting or security logs.
7. Purposes and providers
The information is processed to provide the anonymous bounded educational features, enforce rate limits and safety rules, prevent abuse, and troubleshoot availability. If you separately request an optional free account, the applicable account information is also processed to create and authenticate it, deliver and verify one-time codes, maintain its signed-in session, and handle verified support or deletion requests.
Supabase provides hosted identity and email-code authentication. The website host and its infrastructure providers deliver and protect the application. If you use optional voice typing, your browser or operating-system vendor may process microphone audio to produce the visible transcript. No question or transcript is sent by Operation ADH to Stripe, Kit, an advertising provider, a product-analytics provider, or an AI-model provider in this release.
8. Sharing, sale, and marketing
Operation ADH shares technical data and, if applicable, optional account data with service providers only as needed for the functions above, or may disclose information when required by law or reasonably necessary to protect rights and security. It does not sell this information, use it for targeted advertising, or treat optional account creation as marketing consent in this release.
Authentication and security emails are transactional. Optional marketing requires a separate future choice and release.
9. Retention and deletion
If you create an optional account, its active email identity and provider authentication metadata remain while the account is active, and its application session cookie expires after at most 24 hours. The E001 commitment cookie expires after at most 30 minutes. Ask question text and browser-generated transcripts have no application-level persistence or history.
If you create an optional account, you may request its deletion by emailing info@doctormikehansen.com from the account email address. Operation ADH may verify control of that address before processing the request through its account provider. Do not send a password, one-time code, patient information, or access token.
Deletion removes the active free identity available to the account workflow. Provider-controlled delivery, security, abuse, backup, or legal records may remain for their applicable operational period and are not reused for product analytics, advertising, or marketing. Support is best effort, with no response-time promise.
10. Patient information and security
Do not submit information about a real patient, your own health, symptoms, treatment, identifiers, protected health information, or confidential clinical information. Screening reduces risk but cannot guarantee detection of every prohibited submission.
The design uses explicit microphone controls, same-origin request checks, rate limits, signed HTTP-only cookies for optional account and commitment state, bounded expiration, exact release bindings, and input minimization. No security measure guarantees that an incident cannot occur.
11. Contact, changes, and release condition
Privacy, support, and deletion requests may be sent to info@doctormikehansen.com. Do not include patient information, passwords, one-time codes, or access tokens.
Material changes require a new notice version and release seal. This Notice is not effective in a local candidate, preview, or environment-only configuration. It becomes effective only if its exact hash is adopted by DMH and served from operationadh.com under the matching final PUBLIC_FREE_ACCOUNT_V1 seal.