Privacy Policy
- emsOS is software that EMS agencies use to run their operations. Your agency decides what goes into it and who can see it.
- We collect what's needed to run the service: your member profile, the things you do in emsOS, and basic technical data.
- We never sell your information, and we don't show ads.
- You can ask your agency or us to see, fix or delete your information at any time: info@emsos.app.
Contents
- Who we are
- Your agency's role
- Information we collect
- The emsOS app and your device
- How we use information
- AI-assisted features
- How information is shared
- How long we keep information
- Security
- Your choices and rights
- Deleting your account
- Children
- U.S. state privacy rights
- Changes to this policy
- Contact us
1. Who we are
emsOS is operated by Danny Ackerman, doing business as emsOS, in New Jersey, USA ("emsOS", "we", "us"). This policy explains how we handle information in:
- the emsOS web portal, including each agency's portal address (for example, youragency.emsos.app) and any public pages an agency publishes through it;
- the emsOS mobile app for iPhone and Android; and
- this website, emsos.app
Together we call these the "Services".
2. Your agency's role
emsOS is used by EMS organizations such as ambulance corps, rescue squads and EMS departments ("Agencies"). If you use emsOS as a member, officer or employee of an Agency, that Agency set up your account and controls the information about you in its emsOS workspace. It decides which features are turned on, who can see what, and how long records are kept. We process that information on the Agency's behalf and under its instructions.
That means some requests, such as correcting your membership record or removing you from the roster, are best handled by your Agency's administrators. You can always contact us too, and we'll help or route your request to your Agency.
Each Agency has its own policies for how it uses member information. This policy covers what emsOS does; your Agency's policies cover what your Agency does.
3. Information we collect
Information your Agency or you provide
- Profile and contact details: name, username, email address, phone numbers, mailing address, date of birth, gender, profile photo and emergency contacts.
- Membership records: member status, positions, driver status, member or line number, join and leave dates, issued equipment, permissions and group memberships.
- Certifications: certification types, numbers, issue and expiration dates, and images or PDFs of certification cards you or your officers upload.
- Agency activity: calendar events and sign-ups, meeting check-ins and votes, election ballots, documents and questions asked about them, incident reports, phone lists and similar records your Agency keeps in emsOS.
- Expense and financial records: expense reports, receipt images, vendors, amounts, account assignments and reimbursement status. If your Agency connects accounting or donation services, related transaction and donor records. We do not collect payment card numbers through the app.
- Patient-related records: some Agencies use emsOS features that handle information about the patients they serve, such as records requests and patient letters. This information belongs to the Agency and is handled only to provide those features for it.
- Messages to us: anything you send when you contact support.
Information collected automatically
- Sign-in and security data: login times, IP address, browser or device type, and a list of the devices signed in to your account, which you can review and sign out.
- Activity logs: an event log of changes made in emsOS (for example, "certification approved"), which Agencies use for accountability.
- Usage and diagnostics: which screens and features are used, performance, and error reports, so we can fix problems and improve emsOS. We do not use this for advertising.
- Cookies: the web portal uses cookies that are necessary to keep you signed in and to protect your account. This website (emsos.app) does not use advertising or tracking cookies.
Information from others
- Sign in with Google: if you choose it, Google shares your name, email address and Google account identifier with us so we can match you to your Agency account. We never receive your Google password.
- Text messages: if you use the "text us a receipt" feature, we receive the photos and phone number of the text you send while that screen is open. Texts that arrive when you're not waiting on that screen are ignored and not stored.
- Integrations your Agency connects, such as accounting or online-donation services, which send us the records needed for those features.
4. The emsOS app and your device
The mobile app only uses device features when you ask it to:
| Permission | What it's for |
|---|---|
| Camera | Taking a profile photo, photographing a receipt or certification card, and scanning a meeting check-in code. Scanned codes are read on the device; the camera image isn't saved. |
| Photo library | Choosing an existing photo you pick for your profile, a receipt or a card. The app sees only the photos you select. |
| Local network (iOS) | Used only in development builds to reach a test server. It isn't used in the App Store version. |
Location: the emsOS app does not collect your device's location. If a future feature needs it, we'll ask your permission first and update this policy before we do.
Stored on your phone: your sign-in token is kept in the device's secure storage. If your Agency turns on offline reference features (for example hospitals, phone numbers and protocols), copies are stored on your phone, encrypted, so they work without a signal. Signing out or deleting the app removes them.
Device details: the app sends your device model, operating system version and app version so you can see and manage your signed-in devices and so we can support older app versions.
Notifications and tracking: the app does not track you across other companies' apps or websites, and it contains no third-party advertising.
5. How we use information
- To provide the Services: showing your Agency's roster, calendar, documents, meetings and other features to the people allowed to see them.
- To sign you in, keep accounts secure and prevent misuse.
- To send messages the Services are designed to send, such as certification reminders, sign-in links, event notices and replies to your questions. Your Agency controls most of these settings.
- To process receipts and certification cards and fill in their details for you to review.
- To provide support, fix bugs and improve emsOS.
- To comply with the law, enforce our Terms of Service, and protect the rights and safety of our users and others.
We do not sell personal information, share it for cross-context behavioral advertising, or use it to build advertising profiles.
6. AI-assisted features
Some features use artificial-intelligence services from third-party providers (for example Anthropic and Google Cloud) to read the text on receipts and certification cards, and to answer questions using only your Agency's documents. When you use one of these features, we send the provider only what that request needs (such as the receipt image, or your question and the relevant documents) and use the result to fill in the form or show you an answer with its sources.
AI output can be wrong. That's why emsOS asks a person to review what it read before a record is saved, and shows the document a question was answered from. We don't use your information to train AI models, and we use these providers under terms that don't allow them to train their models on it.
7. How information is shared
Within your Agency. People in your Agency see information according to the permissions your Agency sets. For example, officers may see membership records and certifications, and members may see the directory. For a secret ballot, emsOS records only that you voted, not how. No one, including the Agency and emsOS, can link your choice to you.
Service providers. We use trusted companies to help run emsOS, and they may process information only to provide their services to us:
| Purpose | Examples |
|---|---|
| Hosting, databases, file storage and network security | DigitalOcean, Cloudflare |
| Email and text messages | Mailgun, Twilio |
| Sign-in | Google (Sign in with Google) |
| Reading receipts and cards; answering document questions | Google Cloud, Anthropic |
| Product analytics and error reporting | PostHog |
| Address verification | Smarty |
| Printing and mailing letters | Thanks.io |
Services your Agency connects. If your Agency links emsOS to another service, such as QuickBooks Online or an online-donation platform, we exchange the information needed for that connection. That service's own privacy policy applies to what it receives.
Legal reasons. We may disclose information if we believe in good faith it's required by law, subpoena or court order, or needed to protect someone's safety, prevent fraud, or protect our rights. Where the law allows, we'll tell the affected Agency first.
Business changes. If emsOS is sold, merged or reorganized, information may transfer to the new owner, who must continue to protect it as this policy describes.
8. How long we keep information
We keep Agency information for as long as the Agency uses emsOS, following the Agency's instructions. Some records, such as certification history and the event log, are kept on purpose because Agencies rely on them. Short-lived data is removed automatically. For example, receipt photos texted to emsOS are deleted with the waiting session they belong to.
When an Agency stops using emsOS, we delete or return its information within 90 days of its request or the end of its subscription, except where we must keep something longer to meet a legal obligation, resolve a dispute or enforce our agreements. Backups are overwritten on a regular cycle.
9. Security
We protect information with encryption in transit (HTTPS), access controls based on each person's role, re-authentication for confidential areas, audit logs, and separation of each Agency's data. No system is perfectly secure, so please use a strong password, keep your devices locked, and tell us right away at info@emsos.app if you suspect a problem. If a security incident affects your information, we'll notify your Agency, and you where required, as the law requires.
Agencies that are subject to HIPAA should contact us before storing protected health information in emsOS so we can discuss the appropriate agreements.
10. Your choices and rights
- See and update your information: much of your profile can be viewed and edited in the portal or app under My Profile. For other records, ask your Agency's administrators.
- Get a copy, correct or delete: email info@emsos.app. We'll verify your identity and handle the request ourselves or with your Agency, usually within 30 days.
- Email: your Agency controls operational emails like certification reminders. You can ask your Agency's officers to change them.
- Devices: you can sign out any device from My Profile → Signed-in devices.
11. Deleting your account
Because your Agency creates and manages your account, there are two ways to have it deleted:
- Ask your Agency's administrator to deactivate or delete your account; or
- Email info@emsos.app from the address on your account with the subject "Delete my emsOS account" and the name of your Agency.
We'll confirm the request with you and your Agency and delete your sign-in, profile and personal details within 30 days. Your Agency may keep a limited record it is required or entitled to keep, such as the fact that you were a member, certification history or financial records needed for its books. We'll tell you if anything is kept and why. More detail is on our support page.
12. Children
emsOS is built for EMS organizations and isn't directed to children under 13. We don't knowingly collect personal information from children under 13. If you believe a child under 13 has an account, contact us and we'll delete it. Some Agencies have youth or cadet members who are 13 or older; the Agency is responsible for any parental consent those programs require.
13. U.S. state privacy rights
Depending on where you live (for example California, Colorado, Connecticut, New Jersey, Virginia and other states with privacy laws), you may have the right to know what personal information we hold about you, to get a copy, to correct it, to delete it, and to opt out of its sale or use for targeted advertising. We don't sell personal information or use it for targeted advertising. To exercise any right, email info@emsos.app. You can use an authorized agent, and we won't treat you differently for exercising your rights. Where we process information on behalf of an Agency, we may refer your request to that Agency.
emsOS is operated in the United States and your information is stored in the United States.
14. Changes to this policy
We may update this policy as emsOS changes. We'll post the new version here with a new "Last updated" date, and if the changes are significant we'll notify Agencies (and, where appropriate, users in the app) before they take effect.
15. Contact us
Questions or requests about privacy:
emsOS (Danny Ackerman, d/b/a emsOS)
New Jersey, USA
info@emsos.app