TestFlight beta
Sunn TestFlight Privacy Policy
Effective date: August 12, 2026
This Privacy Policy describes how Sunn Health (“Sunn,” “we,” “us,” or “our”) handles information in the Sunn iPad beta application distributed through Apple TestFlight (the “Beta”).
This Policy applies exclusively to the Beta. It does not apply to a future public App Store release or to another Sunn product unless that product expressly adopts this Policy.
1. Purpose and permitted use
The Beta is provided solely for product evaluation and testing. It is not intended for diagnosis, treatment, clinical decision-making, or any other form of patient care.
Only fictional, synthetic, or properly de-identified test information may be entered into the Beta. Testers must not submit real patient information, protected health information, or information that identifies an actual patient.
The Beta is not offered under a Business Associate Agreement and must not be used to satisfy HIPAA obligations. Sunn may remove prohibited information, restrict access, or remove a tester from the Beta if the Beta is used contrary to these requirements.
2. Information we process
Account and professional information
We may process:
- information provided through Sign in with Apple and the supporting identity service, including an email address or private relay address when made available;
- unique account, authentication, and authorization identifiers;
- sign-in status and account-security information;
- the practice or business name entered by a tester;
- the legal name and acknowledgments submitted when accepting the Beta evaluation terms; and
- the app version, operating-system version, and device model associated with the evaluation record.
Sunn does not receive a tester’s Apple Account password.
Test purchase and access information
The Beta may process information associated with Apple TestFlight and the StoreKit sandbox, including:
- test product and transaction identifiers;
- account-linking identifiers;
- test visit balances and usage status;
- reservation, completion, refund, or revocation status; and
- related timestamps and duplicate-prevention records.
Apple processes payment credentials. Sunn does not receive full payment-card information.
Synthetic test encounter content
The Beta may process fictional, synthetic, or properly de-identified test content that a tester chooses to provide, including:
- test names and dates of birth;
- synthetic prior-note text;
- microphone audio and speech transcripts;
- typed responses;
- brief camera images or video frames;
- test symptoms, histories, medications, allergies, and other intake responses;
- corrections, confirmations, and refusals; and
- generated patient-facing and clinician-facing summaries.
The microphone and camera are accessed only after the tester grants the relevant iPadOS permission. Sunn does not receive Face ID or Touch ID templates. Device authentication is handled by iPadOS.
TestFlight, feedback, and technical information
Apple may provide Sunn with limited TestFlight information, including testing status, device and operating-system details, session and crash information, and feedback submitted through TestFlight.
Sunn may also process limited technical and security information needed to operate and protect the Beta, including request times, app version, service status, error categories, and security events.
Sunn does not use advertising identifiers or third-party behavioral-tracking tools in the Beta.
3. How we obtain information
We obtain information:
- directly from testers when they sign in, enter test data, use the microphone or camera, make a sandbox purchase, or contact us;
- from Apple through TestFlight, Sign in with Apple, StoreKit, and iPadOS services;
- from Microsoft identity and cloud services used to provide the Beta; and
- automatically when reasonably necessary to operate, secure, and troubleshoot the Beta.
4. How we use information
We use information to:
- authenticate testers and maintain Beta accounts;
- provide and evaluate Beta functionality;
- process synthetic voice, text, image, and summary requests;
- administer sandbox purchases and test visit access;
- maintain security, prevent fraud and duplicate transactions, and enforce the synthetic-data restriction;
- diagnose failures and improve reliability;
- respond to feedback, support requests, privacy requests, and security reports; and
- comply with applicable law and protect Sunn, testers, and others.
Sunn does not sell personal information.
Sunn does not use Beta information for advertising, cross-app tracking, or behavioral profiling.
Sunn does not use or authorize the use of Beta content to train general-purpose artificial-intelligence models.
5. Service providers and disclosures
Sunn may disclose information to the following categories of recipients only as needed for the purposes described in this Policy:
- Apple, for TestFlight distribution, Sign in with Apple, StoreKit sandbox transactions, device permissions, and related platform services;
- Microsoft, for identity, hosting, security, and cloud processing used to operate the Beta;
- professional advisers or service providers that assist with security, legal compliance, or support; and
- government authorities or other parties when disclosure is required by law or reasonably necessary to protect rights, safety, or the integrity of the Beta.
Service providers are required to process information only for authorized purposes and to protect it under applicable contractual and legal obligations. Apple and Microsoft also process information under their own terms and privacy statements.
Sunn does not disclose Beta information to data brokers, advertising networks, or social-media advertising platforms.
6. Retention and deletion
Synthetic encounter content
Sunn’s application-controlled encounter state is designed to retain synthetic encounter content only for the active test session and to clear that state when the session ends, the app terminates, or a privacy-protection event closes the session.
Cloud providers may process synthetic content for the time necessary to provide the requested service and may retain limited information for security, abuse prevention, service reliability, or legal compliance under their applicable terms. Testers must therefore use only fictional, synthetic, or properly de-identified information.
Account, evaluation, and transaction information
Sunn retains account, practice, evaluation, sandbox transaction, security, and access records for as long as reasonably necessary to operate the Beta, maintain account and transaction integrity, resolve disputes, prevent fraud, and comply with law.
When a tester initiates account deletion, Sunn will delete or de-identify account information that it is not required to retain. Deletion requests are ordinarily completed within 30 days.
Limited evaluation, transaction, fraud-prevention, security, or legal records may be retained when reasonably necessary for legal compliance, account integrity, dispute resolution, or security. Access to retained records is restricted to those purposes.
Apple independently controls information maintained in TestFlight, the App Store, and the tester’s Apple Account.
7. Privacy choices and account deletion
Testers may:
- deny or revoke microphone and camera permissions in iPadOS settings;
- stop using the Beta and remove it from the device;
- request access to or correction of account and practice information; and
- delete the Sunn Beta account from within the app.
To initiate account deletion:
- Select Continue on the opening introduction to reach the main patient configuration screen.
- Select Delete Account, located next to Sign Out.
- Review the deletion notice and confirm the request.
Sunn may require reauthentication or another reasonable verification step before completing deletion. Removing the app or selectingSign Out does not delete the account.
A tester who cannot access the account may contact[email protected]for assistance. Do not include test encounter content, real patient information, or protected health information in the message.
8. Security
Sunn uses reasonable administrative, technical, and organizational safeguards designed to protect information processed through the Beta. These safeguards include access controls, encrypted communications, limited data retention, restricted service-provider access, and measures intended to prevent unauthorized use or disclosure.
No system is completely secure. Testers are responsible for protecting their devices, Apple Accounts, passcodes, and access to the Beta.
Security concerns may be reported to[email protected]. Reports should not contain personal health information.
9. Children
The Beta is intended only for adult testers who are authorized to evaluate it. Sunn does not knowingly permit children to create Beta accounts or participate as testers.
10. Processing location
Information may be processed in the United States and in other locations where Apple, Microsoft, or their authorized service providers operate. Those providers apply their own legal and contractual safeguards to their processing.
11. Changes to this Policy
Sunn may update this Policy as the Beta changes. The revised Policy will be posted at the same public location with an updated effective date. Material changes will be communicated through TestFlight, the Beta, or another appropriate channel when required.
12. Contact
Questions, privacy requests, account-deletion assistance, and security reports may be sent to:
Sunn Health[email protected]