Legal

Privacy Policy

Last updated: April 18, 2026

Who we are

Plan B for PANS is a free symptom-tracking tool and research project for families of children with PANS (Pediatric Acute-onset Neuropsychiatric Syndrome) and PANDAS. It is operated by Rachel Johnson as an independent research and tracking service. The tracker is available at app.planbforpans.com and as native apps for iOS and Android.

We are not a medical practice. We do not provide diagnosis, treatment, or medical advice. The tracker exists to help families see patterns in their child's symptoms over time. Parents remain responsible for working with licensed medical professionals for all care decisions.

What we collect

When you use Plan B, we collect the following information:

  • Child information: first name, age/date of birth, gender, caregiver name, contact info, onset history, current treatments, symptom ratings (0–10 scale)
  • Daily logs: medications taken, doses, new symptoms, free-text notes you enter
  • Weekly check-ins: symptom ratings over time, session modality, notes
  • Account info: for practitioner/admin access — password hash only, no other credentials stored
  • Device info: if you enable push notifications, we store the device token issued by Apple Push Notification service or Google Firebase Cloud Messaging so we can send reminders
  • Technical data: basic server logs (IP address, browser, timestamps) for security and debugging, retained for 30 days

What we do not collect

We do not collect: social security numbers, insurance information, payment information (the tracker is free), biometric data, location data beyond IP address, data from other apps or services on your phone.

How we use your data

  • Per-family tracker: your child's data is used to populate charts, heatmaps, and AI analyses visible only to you and the Plan B practitioner who invited you
  • Minta (AI synthesis): when you request an analysis, your child's symptom, medication, and note data is sent to our synthesis engine, which is powered by Anthropic's API to generate clinical interpretations. Anthropic does not train on API inputs by default; see their privacy policy. For panel and transcript analyses, we may also use OpenAI's Whisper transcription API; see OpenAI's privacy policy
  • Aggregate research: with your explicit consent (a future opt-in flag on each client record), de-identified data may be included in cross-patient pattern analysis. We would never publish individually identifying information without your written permission. Today no aggregate research is conducted without consent
  • Push notifications: if you opt in, we use your device token to send reminder notifications when a daily log is due

Who we share data with

  • Supabase: our database provider. Your data is stored encrypted at rest in Supabase's US data centers. See Supabase's privacy policy
  • Anthropic: our synthesis engine provider, used for Minta's analysis queries as described above
  • OpenAI (Whisper): for audio transcription of source content in the knowledge base, as described above
  • Vercel: our hosting provider. See Vercel's privacy policy
  • Apple & Google: when push notifications are enabled, device tokens pass through APNs (Apple) or FCM (Google) to deliver notifications

We do not sell your data. We do not share data with advertisers, data brokers, insurers, or any third party not listed above.

Children's privacy

Plan B is intended to be used by parents or legal guardians to track their children's symptoms. A child under 13 should not use the tracker directly. All account access is controlled by the parent/practitioner. Any child data we store has been provided by the parent.

We comply with the Children's Online Privacy Protection Act (COPPA) by collecting child data only through parent entry and never directly from a minor. Parents can request deletion of their child's data at any time by emailing info@planbforpans.com.

Your rights

You may request at any time:

  • A full export of all data Plan B holds about your child
  • Correction of any inaccurate data
  • Deletion of your child's entire record (we will comply within 30 days; aggregate/research usage is stopped immediately)
  • Opt-out of any future aggregate research usage
  • Revocation of push notification consent (via your phone settings or in-app)

Email info@planbforpans.com for any of these.

Data security

All data is transmitted over HTTPS. Database storage is encrypted at rest. Access to the admin and research interfaces is password-protected. API keys and secrets are stored in Vercel's environment variable system. We aim to retain only the data we need and for as long as you choose to use Plan B.

Plan B is a small-team research project and is not HIPAA-certified. Do not include protected health information that you would not be comfortable sharing through a non-HIPAA service. For clinical-grade compliance needs, work with your licensed medical provider.

Data retention

We retain your child's data for as long as your family uses the tracker. If you stop using Plan B and want your data deleted, email us and we will remove it within 30 days. After deletion, de-identified aggregate statistics (e.g., “N kids were tracked in 2026”) may persist but no identifying information.

Changes to this policy

As Plan B grows we will update this policy. Material changes will be flagged prominently in the app and at the top of this page. Continued use after changes constitutes acceptance; you can always delete your data if you disagree.

Contact

For any privacy question, request, or concern:

Rachel Johnson
info@planbforpans.com

← Back to Plan B