Privacy policy
Larrey uses data to route care, not for advertising or cross-app tracking.
Larrey helps you decide where to go for care now. We collect information used to sign you in, route nearby care, keep your route history available to you, and improve routing quality.
Information we collect
Account identity may include the phone number or email address you use for one-time passcode sign-in. Care routing may include the care need you type, severity answers, location or manual area, route search history, routing results, whether a recommendation was displayed or opened, whether you initiated a call or opened directions, check-in handoff records, feedback you choose to send, and an opaque campaign key reported after the app handles a recognized Larrey campaign link. A call or directions observation does not establish that a call connected, you traveled, you arrived, or you received care.
How we use it
We use this information for app functionality: account continuity, nearby care routing, freshness and confidence evidence, route handoff, safety escalation, support, security, product quality, and a bounded understanding of the care-intent funnel. We use only the first reported campaign key that matches Larrey's closed allowlist to understand which deliberate distribution channels are associated with Larrey use. This record does not verify where an install came from or prove that a campaign caused later care activity. Larrey does not diagnose you or guarantee a wait time, appointment, insurance coverage, or outcome.
Location
Location is used to rank nearby care options and show route context. You can deny location access and use a manual area when available in the app. We do not use location for advertising or cross-app tracking.
Sharing
Larrey uses service providers such as Supabase for account identity and hosted infrastructure for the Larrey API. We do not sell personal data, run third-party advertising, or track you across other companies' apps and websites. We do not use an advertising identifier, device fingerprint, or third-party attribution SDK for campaign links.
Retention and deletion
Larrey keeps account and routing records while your account is active so your care routes and check-in handoffs remain available to you. You can delete your Larrey account in the iOS app under Profile. Larrey immediately blocks the original account identity from creating or accessing another Larrey account, removes direct identity, profile and continuity data, the first-touch campaign record, and consumer observation events, then requests global session revocation and deletion of the separate Supabase Auth identity. If that external deletion cannot be confirmed immediately, the request remains pending and retryable while the app clears its local state and signs out; an already-issued token cannot recreate the Larrey account. If any provider-handoff consent record already exists, the current integrity branch may retain related routing and handoff history with direct account identity pseudonymized. Granted consent is revoked, newly created handoffs are revoked, other historical handoff states remain source-labelled, and provider access is blocked by consent. The retention policy and backup expiry for that branch still require owner approval.
Contact
For privacy, account, or deletion questions, contact team@larrey.com.