Legal
Privacy Policy
Effective September 13, 2026 · Version 1.0
1. Who we are
The Promotional Standard LLC operates The EMS Standard. This policy explains what we collect, why, and who we share it with.
2. What we collect
Instructor accounts: email address, password (hashed by our authentication provider), plan and billing status, and the sessions, scenarios, agencies, and protocols you create or upload.
Students and devices: students join by session code without an account. We do not collect names or contact details from students. Device joins are associated with the session code only.
Session data: vital-sign and rhythm state, therapy actions, event logs, 12-lead acquisitions, and the text of patient conversations, stored to run the session and generate replays and debriefs.
Voice: when a student uses hold-to-talk, the audio clip is sent to a speech-to-text provider and the resulting text is sent to an AI model to generate the patient's reply, which is then synthesized to speech. We do not retain audio recordings. Transcript text is kept with the session for the session's retention period.
Technical: IP address, browser type, device type, timestamps, and error diagnostics. Error reports (Sentry) contain route names, status codes, and stack traces; they never contain transcripts, protocol text, or audio.
Payments: handled by Stripe. We receive a customer identifier, subscription status, and period dates. We never see or store card numbers.
3. How we use it
To operate sessions in real time across devices; to generate scenarios, patient dialogue, and debriefs; to enforce plan limits; to bill subscriptions; to detect abuse and keep the Service reliable; and to respond to support requests. We do not sell personal information and do not use your content to train AI models.
4. Who we share it with
Service providers who process data on our behalf: Supabase (database, authentication, realtime), Lovable (hosting and AI gateway), OpenAI and ElevenLabs (speech, language, and voice models, via the gateway), Stripe (payments), and Sentry (error monitoring). Each is bound by its own terms and processes data only to provide its service. We may also disclose data where required by law.
5. Retention
Live (unconcluded) sessions are deleted 48 hours after last activity. Concluded sessions, including transcripts and debriefs, are deleted 90 days after they conclude. Session-count records used for plan limits are kept without session content. Account, agency, scenario, and protocol data is kept until you delete it or close your account. Error diagnostics are retained by Sentry for 90 days.
6. Protected health information
The Service is for fictional training cases. Do not enter real patient information. If you believe PHI has been entered, contact us and we will delete the affected session.
7. Your choices
You can update your email or password in the Service, cancel a subscription through the billing portal, and request deletion of your account and data by emailing support@theemsstandard.com. We will confirm identity and complete deletion within 30 days, except for records we must keep for billing, legal, or fraud-prevention purposes.
8. Security
Data is encrypted in transit; access is enforced with row-level security and server-side authorization; anonymous endpoints are rate-limited. No system is perfectly secure; report concerns to support@theemsstandard.com.
9. Children
The Service is for adult EMS and fire-service professionals and students. We do not knowingly collect data from anyone under 18.
10. Changes
We may update this policy; material changes will be announced in the Service or by email.
11. Contact
support@theemsstandard.com
TermsPrivacysupport@theemsstandard.com© 2026 The Promotional Standard LLC