AirMD+
privacy policy
Last updated: September 4, 2026
Introduction
Hatching Point LLC ("Company", "we", "us", or "our") operates the AirMD+ mobile application. This Privacy Policy describes how we collect, use, and share information when you use our App and related services.
Information We Collect
Account Information:
- Email address and account creation date
- Password handled and securely hashed by our authentication provider; the App does not store your raw password
- Name and private-relay or account email if you authorize Sign in with Apple
- Google profile information (email, name, and profile picture) if you authorize Google Sign-In
Device and Sensor Data:
- Unique monitor identifier
- Temperature readings (supply air, return air)
- Calculated metrics (delta T and informational range comparisons)
- Timestamps and device firmware version
Equipment Information:
- Photos of HVAC labels you choose to submit for text extraction
- Equipment specifications, type, installation date, and notes you choose to save
Feedback and Support Data:
- Feedback category and message you choose to submit
- Optional reply email you provide with feedback
- Basic context sent with feedback, including App version, device model, iOS version, and locale
Other Data:
- Operational diagnostics such as uptime, sensor state, WiFi signal strength, reconnect state, queue depth, upload results, and recovery timestamps
- Bounded product-workflow analytics and app/release metadata
- Subscription status and purchase history (via Apple), including an account-linked purchase token used to associate purchases with your AirMD+ account
How We Use Your Information
- Provide and maintain App functionality
- Store and display temperature history and analytics
- Generate user-requested AI reading summaries
- Process equipment scans and extract specifications
- Send optional filter-change, daily check-in, inactivity, and subscription-trial reminders (if enabled)
- Improve the App and develop new features
- Provide customer support
Data Storage and Security
Your data is stored using Supabase (hosted on AWS) with encryption in transit and at rest. Client-facing row-level policies are designed to limit signed-in users to their own account data; privileged server functions and authenticated Device ingest process data as needed to operate the service. Some readings, preferences, and settings are cached locally, and authentication tokens are stored in iOS Keychain.
Information Sharing
We do not sell your personal information.
We share data with trusted service providers:
- Supabase: Database hosting for account data, readings, equipment information, and device state
- OpenAI: AI analysis of relevant temperature/equipment context and equipment-label photos you choose to submit
- Apple: Authentication, subscription status and purchase history, an account-linked purchase token, notifications, and other iOS platform services used by the App
- Google: Optional authentication
- PostHog: Anonymous, bounded product-workflow events and app/release metadata; not names, emails, HVAC content, photos, or monitor identifiers
- Convex: Feedback text, an optional reply email, and basic app/device context you choose to submit
We may disclose information if required by law or legal process.
AI Features and Data Processing
When you request an AI feature, relevant temperature or equipment context is sent through an authenticated AirMD+ server function to OpenAI. We do not intentionally include your account name or email, although submitted HVAC context may include equipment identifiers. Equipment-label photos are processed for the requested scan, are not saved to your AirMD+ account, and are not retained by our server function.
OpenAI states that API data is not used to train its models unless the API account explicitly opts in; AirMD+ does not intentionally submit AI-feature content for training. Under OpenAI's default API controls, customer content may be retained in abuse-monitoring logs for up to 30 days, subject to provider safety or legal exceptions.
Hardware Device Data
The AirMD+ hardware Device collects temperature readings and the operational health metrics described above. It uses a per-device credential to authenticate cloud uploads; the App never receives that credential.
During setup, your iPhone connects directly to the Device over its board-specific, password-protected setup network. WiFi credentials are transmitted directly to and stored only on the Device; they are not sent to AirMD+ servers. On compatible App and firmware versions, nearby setup first uses an encrypted Bluetooth connection and a physical BOOT-button confirmation to obtain temporary setup access, without requiring a printed QR label. Private QR/manual setup remains a recovery option for compatible provisioned Devices. The App uses setup credentials in memory to derive purpose-separated values. Pending registration may temporarily keep a derived cloud claim token, matching proof, and limited account-and-device-bound enrollment state in this-device Keychain; pending state is cleared after confirmation, cancellation, or sign-out.
The service stores a one-way hash of the claim token and protects the independent Device upload credential in server-side secret storage. Nearby DIY enrollment also exchanges a public key and short-lived, account-and-device-bound challenges and signed proofs with the service. The DIY Device supplies its upload credential directly to the service during authenticated enrollment over TLS; that credential is never returned to the iOS App. The service may retain enrollment and one-way challenge records needed to prevent replay. The setup root, local setup password, local authorization value, home WiFi password, and plaintext upload credential are not stored in the App's ordinary data or returned by the cloud service to the iOS App.
Your Rights and Choices
- Access: View your data within the App at any time
- Correction: Update account and equipment details in the App
- Deletion: Delete your account in the App's Settings or email support@hatchingpoint.com for help. Active subscriptions must be cancelled separately through the App Store. We may retain records required for legal, security, fraud-prevention, or operational-integrity purposes.
- Notifications: Manage in App settings
Data Retention
- Temperature readings and derived history: retained while needed to provide monitoring and history, subject to service retention and downsampling rules
- Equipment and device-health data: retained while the Device or account is active
- Account data: deleted when in-app deletion completes, except records we must retain for legal or security purposes
Children's Privacy
AirMD+ is not intended for children under 13. We do not knowingly collect personal information from children under 13.
California Privacy Rights
California residents have additional rights under CCPA: right to know what data is collected, right to delete, right to opt-out of sale (we don't sell data), and right to non-discrimination. Contact support@hatchingpoint.com to exercise these rights.
Changes to This Policy
We may update this Privacy Policy periodically. Continued use after changes constitutes acceptance.