Privacy Notice
Version: LatiGen-Privacy-v1.1 · Last updated: July 2, 2026 · Effective date: July 2, 2026
1. Who we are and what this notice covers
Heart Origins, doing business as LatiGen (the “Company,” “we,” “us,” or “our”), provides the LatiGen BP Forecasting and Measurement Platform, including blood-pressure logging, blood-pressure forecasting, health-readiness planning, and Pilot AME Planner features (the “Services”). This notice explains how we collect, use, disclose, and protect personal information when you use the Services. The Services are planning tools. They do not replace professional medical advice, diagnosis, treatment, prescribing, or certification decisions, are not operated by the FAA, and do not decide whether a user passes or fails an aviation medical exam.
2. Personal information we collect
Depending on the features you use, we may collect: account and identity information (name, email, credentials, account timestamps and status; optional date of birth; and, for pilot features, medical certificate class, target exam date, and readiness/documentation status); blood-pressure readings and measurement information (systolic/diastolic, pulse, date/time, morning/evening session, sequence, body position, measurement location, context, and — when available — device brand/model, data source, source record ID, quality flags, and whether a reading is synthetic/demo or real; entered manually or via CSV upload of your own readings); health and readiness information (cardiovascular-risk inputs you provide such as age, sex, race/ethnicity, SBP, DBP, total/HDL/LDL cholesterol, A1c, BMI, smoking, diabetes, and BP treatment status; medication and lifestyle inputs such as antihypertensive medication names, fitness level, exercise history, diet, sodium/potassium estimates, alcohol intake, pulse-wave velocity, ZIP/postal code, and search radius; genetic-ancestry information is not offered in the current pilot); and device, security, communications, and feedback information (session/authentication data, request IDs, and security logs — standard hosting logs may include IP or browser/device information for security and operations; plus communications and feedback you send us). You can optionally connect a supported blood-pressure monitor (currently Withings) to import your readings: connecting requires your explicit authorization through the vendor, we import only your blood-pressure readings (systolic, diastolic, pulse, timestamp), and you can disconnect at any time (already-imported readings remain in your account unless you delete them).
3. Sensitive personal information
Blood-pressure readings, medical-condition and medication information, physiological measurements, and genetic-ancestry information may be considered sensitive personal information. We use it only to provide and improve the Services, maintain security, comply with law, or for other purposes you authorize. Do not submit information you do not want processed; optional fields may improve forecasts, but some features work with limited information.
4. How we use personal information
To provide, operate, maintain, and improve the Services; create and manage accounts; store and organize BP readings; generate forecasts, readiness summaries, trend views, and checklists; help you plan discussions with your own clinician or AME; personalize outputs from the information you provide; operate security, authentication, audit logging, and fraud-prevention controls; conduct product testing and validation; communicate about the Services; comply with legal obligations; and any other purpose described at collection or with your consent. BP forecasts are computed within the LatiGen system; your health data is not sent to an external service for the forecast computation.
5. Forecasts and health-related outputs
Forecasts, probabilities, ranges, summaries, trend views, and checklists are estimates with uncertainty — not guarantees. The Services do not provide medical advice, diagnosis, treatment, prescribing, medication changes, or FAA/AME/employment/safety-sensitive decisions. Consult your treating clinician, Aviation Medical Examiner, or other qualified professional before making medical, medication, certification, occupational, or safety-sensitive decisions.
6. How your information is stored and protected
Health and account data in the pilot flow is stored in an encrypted data store using AES-256-GCM application-level encryption before storage. We use TLS in transit and managed cloud infrastructure for hosting, database storage, and key management. Access controls, hashed passwords, secure session cookies, role-based middleware, rate limiting, audit logging, and separate key custody reduce unauthorized-access risk. Audit events record that a change occurred, who initiated it, timestamps, revision numbers, and approximate size — not the clinical values themselves. No security program can guarantee data will never be accessed, disclosed, altered, or destroyed without authorization.
7. How we disclose personal information
We do not sell personal health information. We do not use advertising pixels or third-party analytics SDKs, and we do not transmit health data to the FAA, an AME, a clinician, an employer, or an insurer unless you direct us to or use a feature that clearly enables that disclosure. Service providers: we may disclose information to vendors that help us operate the Services (cloud hosting, database, key management, authentication, security, support, email, payment, and professional-services providers); Google Cloud Platform is the hosting and infrastructure processor for the pilot stack under a signed Business Associate Agreement, and providers may process information only to serve us under contract. Weather/location: optional weather, travel, or location-search features may send a ZIP-derived coordinate or latitude/longitude and date to a weather or map service — never your name, email, or clinical values. At your direction: you decide whether to view, print, download, or share summaries. We may also disclose information to professional advisors; in a merger, acquisition, or similar transaction (with confidentiality protections); or to comply with law, enforce our agreements, protect rights and safety, or investigate security incidents.
8. Cookies and similar technologies
The Services use first-party essential session cookies (HttpOnly, SameSite=Strict, Secure) to keep you signed in and protect sessions. We did not identify advertising, tracking, or analytics cookies. If non-essential technologies are added later, we will update this notice and provide choices where required by law.
9. Your choices and control
You may decline optional fields (some features may be less complete) and view and update many account and clinical fields. In the pilot flow you can download all your data and delete your account (or individual BP readings) yourself from the account panel. You may also request access, correction, deletion, restriction, or a copy of your information by contacting us at info@latigen.com; we may verify your identity first, and we aim to respond within 30 days, subject to retention rules and applicable law.
10. Data retention
We retain tester account data, health data, BP readings, uploaded CSV files, consent records, and security/audit logs for one (1) year, after which they are deleted (or de-identified). When you close your account or the pilot ends, your data is deleted or de-identified within that window. De-identified or aggregated information (see §11) may be retained beyond this period.
11. De-identified and aggregated information
We do not currently run analytics or ad tracking. We may create and use de-identified or aggregated information derived from your data for product development, validation of forecasting methods, benchmarking, and evidence review. De-identified or aggregated information is not intended to identify you, and we will not attempt to re-identify it except as permitted by law (for example, to test our de-identification process).
12. Health privacy and breach notifications
For this alpha, LatiGen is a consumer health technology service. We are not currently acting as a HIPAA covered entity or as a business associate for a covered entity or health plan, so HIPAA does not govern this direct-to-user pilot. We nevertheless apply strong health-data safeguards — including encrypted storage, access controls, audit logging, and BAA-covered cloud services where available. As a consumer health service we are subject to the FTC Act and the FTC Health Breach Notification Rule, and to applicable state health-data laws. If LatiGen is later offered to clinicians, health systems, or payors under a business associate agreement, those workflows may be governed by HIPAA, and we will provide the applicable notices.
13. Children
The Services are not intended for children under 13, and we do not knowingly collect their personal information. If we learn we did so without appropriate consent, we will take reasonable steps to delete it.
14. International users
We are based in the United States. If you use the Services from elsewhere, your information may be transferred to, stored in, or processed in the United States or other jurisdictions with different data-protection laws.
15. Third-party links and services
The Services may link to third-party websites or tools. We are not responsible for their privacy practices; review their policies before providing information to them.
16. Changes to this Privacy Notice
We may update this notice from time to time. For material changes we will provide notice as required by law — e.g. by posting the updated notice, updating the effective date, or notifying you through the Services or by email. Continued use after an update becomes effective means you acknowledge it, subject to applicable law.
17. Contact us
Heart Origins (dba LatiGen), Attn: Privacy — Corey Washington. Email: info@latigen.com. Mail: 50 Newton St., Boston, MA 02135.