Website and app privacy
OC Medic LLC provides OCMedic.com and the OCMedic iOS app. This page covers both. App permissions are managed in iOS Settings.
Last updated: October 5, 2026.
Privacy details
How OC Medic LLC handles information for the website, iOS app and support email.
OC Medic LLC provides OCMedic.com and the OCMedic iOS app. This page covers both. App permissions are managed in iOS Settings.
Last updated: October 5, 2026.
Netlify hosts OCMedic.com and processes request information, including IP addresses, requested pages, timestamps and device or browser information, to deliver and protect the site. Netlify’s server-side analytics also provides aggregate traffic information. These hosting logs are separate from browser storage.
We block browser analytics requests on this website. The reviewed website has no advertising pixels, Google Analytics or advertising personalization scripts. You can read and search without a cookie-consent prompt.
When you email support@ocmedic.com, we receive your email address, message, attachments and any other information you include. Microsoft Outlook handles this email. We use it to respond to your request.
OC Medic deletes support email messages within one calendar year. Deleting a message does not necessarily remove copies immediately from Microsoft’s deleted-item recovery, backups or retention systems. Those depend on the email service and account settings.
Do not send patient information, protected health information, passwords or other sensitive information in support messages.
The app uses permissions separately from this website. You can manage notification and location permissions in iOS Settings. These permissions apply to the app.
When you enable notifications, the app registers its Apple push-notification token with OCMedic’s notification service. The registration includes the app version, build number, notification environment and whether notification permission is enabled. The service records when the registration was last updated. On later app activations, the app attempts to update permission status, including when notifications have been disabled.
We store notification send records and Apple delivery results, including technical identifiers and errors. The app also reports a notification identifier when it observes a notice in the foreground or when you tap to open one; the service records those event times. These reports are best effort and are not a complete record of every notification displayed.
We associate these records with the app installation through its push token or a derived identifier. We use them to operate notifications, diagnose delivery problems, and measure notification delivery and use. Ordinary notification registration does not ask for your name or email address, and notification events contain no location, patient information, or general in-app search history. If you request Door Codes access, your request can be associated with the registered notification address to send an approval notice, as described below. Apple provides push delivery and Netlify hosts our notification service. These notification records are not used for cross-app advertising tracking.
For hospital discovery, mapping, stored route estimates and Live Activities, see Location and hospital information below.
Our notification records include device identifiers, interaction events and technical delivery information. They are linked to the app installation. Ordinary notifications do not require an account; protected-access requests separately collect the professional details described below. The App Store privacy disclosure describes these practices. Read the current App Store disclosure. For questions about app records or deletion, contact us; disabling notifications alone is not a request to delete server records.
With your permission, OCMedic uses your device’s location to display nearby hospitals, calculate distances, and request ordinary driving-time estimates. Location permission and Precise Location are controlled in iOS Settings. If location is unavailable, features that depend on your current position are limited; a displayed reference location is not your actual position.
Mapping and route estimates. The app sends the route’s starting coordinates and hospital destination to Apple’s mapping service to request driving estimates. Opening directions passes the selected hospital destination to Apple Maps, which handles navigation under its own permissions and privacy practices. These estimates are for ordinary vehicles, not emergency-response routing or guaranteed arrival times. See Apple Maps and Privacy.
Storage on your device. The app stores a recent route-estimate cache on your device, including its starting coordinates, calculation times and hospital estimates, so it can reuse suitable recent results. Successful refreshes replace this cache. A limit on reuse of old estimates does not automatically delete the stored cache, and turning off location permission does not erase previously stored information.
Live Activities and background location. When you explicitly pin a hospital Live Activity, OCMedic can continue using location in the background to update the selected or closest listed hospital and its driving estimate. These updates require a sufficiently accurate location; route estimates also require internet access. End all pinned hospital Live Activities, or withdraw location permission in iOS Settings, to stop this background location use. Ending one activity does not stop updates for another that remains active.
Optional Door Codes location sharing. Separately, you may choose to send one approximate location with a Door Codes access request to OCMedic administrators. This helps them review the request; it does not request emergency assistance. You may decline location sharing and still submit for manual review. The Door Codes access requests section below explains the information retained and how to request correction or deletion.
Emergency-service limitations. OCMedic is a professional reference and hospital-information app, not an emergency dispatch or emergency-assistance service. It does not dispatch responders or transmit your location to emergency services to summon help. Hospital listings, proximity and travel estimates do not establish current availability, diversion status or suitability for a particular patient. To request emergency assistance, call 911 or use your agency’s established emergency communication procedures. Follow current official policies, medical direction and agency procedures when making patient-care or destination decisions.
Starting with OCMedic 2.3.1 build 20, Share app usage is enabled by default and can be turned off in the app’s Settings. The app sends daily counts of app opens and visits to its main sections (Hospitals, Assist, Guides, Base and Door Codes), together with app version and build. Opening Door Codes records a section visit, not whether a code was viewed or which hospital was selected. These are event totals, not unique-person counts.
Usage batches contain a random batch identifier to prevent duplicate counting. Our usage store does not include a persistent installation identifier, push token, name, professional number, employer, searches, location, patient information or door-code values, and we do not join these counters to access requests or notification records. Netlify still processes technical request information, including IP addresses, to host and protect the service.
Offline uploads are limited to the current and previous seven UTC calendar days. Expired local counters are discarded the next time the app runs. Turning off Share app usage stops future collection and clears unsent counters; it cannot recall an upload already in progress or remove counts already included in aggregate totals. A daily cleanup is configured to remove server-side daily totals and batch identifiers outside the most recent 30 UTC days, normally within 31 days of collection; outages may delay cleanup. Provider logs and backups follow the provider’s retention arrangements.
If you choose Request Access, we collect the name, EMT or paramedic number, and employer that you submit. New requests require you to certify that these details are accurate and belong to you. We retain the wording and version of that attestation and the date it is received. A random request identifier and a protected device credential connect the request to the requesting phone; the server stores a hash of the credential, not the credential itself. The app stores the credential, your request, and any approved offline copy of door codes securely in the device Keychain.
Starting with OCMedic 2.3.1 build 21, you may also include your current area with an access request. This is optional. When you submit, the app requests one foreground location fix, rounds latitude and longitude to two decimal places before sending them, and reports an accuracy estimate of at least 1,500 metres and the capture time. Authorized administrators can view this approximate location with your request to help review whether you are in or around Orange County, California. It is not proof of identity, professional eligibility or county residency. If you turn this option off, deny permission, cannot obtain a location or are outside the area, you can still submit for manual review; the record indicates the available location status. This request feature does not continuously track you or collect location in the background. It is separate from hospital routing and explicitly enabled Live Activities.
Authorized OCMedic administrators review the submitted details and can approve, decline or revoke access. If push notifications are enabled, we associate this request with the phone’s registered notification address and send an approval notice to that phone. The notice opens Door Codes; the app still checks approval and requires device authentication. Delivery and open events are recorded with the notification records described above. The administrator register records the request, current status, request and decision dates, administrator identity and decision reasons. Professional details are user-supplied and are not automatically verified against a licensing registry. We use these records to manage protected access, review requests, address support issues and maintain an access audit. They are linked to the person named in the request and are not used for advertising or joined to aggregate usage counters.
App Review demonstrations use a separate, expiring administrator-issued code. They show sample values only and never approve access to real facility codes. The service retains the code’s hash, creator, expiry, device limit and revocation status, plus random requesting-device identifiers and hashed credentials, to enforce those limits. Demonstration mode does not require professional details or an access-request location.
Approval allows device authentication (Face ID, Touch ID or the device passcode) to unlock Door Codes on that phone. OCMedic does not receive biometric data or the device passcode. The app checks status online and can retain an approval for up to seven days offline. Revocation is enforced when the phone next successfully checks status or its saved approval expires. The upcoming 2.3.1 update requires administrator approval and no longer accepts the shared OCMedic passcode. Door codes are retrieved from an approval-protected service rather than included in the new app download. Saved codes are usable for up to seven days and cleared when the app detects expiry, revocation or withdrawal. Previously distributed app versions and copies cannot be remotely erased by this change.
We retain request details, any submitted approximate location and its accuracy and capture time, location status, attestations and decision history after approval, decline, revocation or withdrawal, with no automatic deletion period, to maintain the access register. Withdrawing a request or removing access from a phone does not erase the administrator record. To request access to, correction of or deletion of these records, contact support@ocmedic.com. We may need information to locate your request and verify it is yours. We review deletion requests under applicable requirements and explain any records we must retain. Netlify hosts these records and its logs and recovery copies follow its retention arrangements.
OC Medic does not sell customer information or share it for advertising. We use the service providers described in this policy to operate the website, app and support email.
Sale, advertising sharing and browser analytics stay off for all visitors, including browsers using Global Privacy Control. The website does not set advertising cookies or save new consent preferences. Previously saved website consent choices are removed from this browser when a page loads.
We do not change website behavior in response to the older Do Not Track setting; browser analytics and advertising remain off for all visitors. Browser privacy settings do not block necessary hosting requests or information you choose to send by email.
Depending on the law that applies, you may have rights to access, correct or delete personal information, request information about its use, or opt out of sale or sharing. Email us to make a request, including through an authorized agent. We may need information to verify the request and authority to act. We do not discriminate against people for exercising applicable privacy rights.
Netlify provides website and notification-service hosting, Microsoft provides support email, and Apple provides app distribution, device permissions, mapping and route estimates, and push delivery. These providers may process technical information for service delivery, security and their own legal obligations. Their storage and recovery periods are managed by the providers.
Notification registrations, send records and receipt records do not currently have an automatic deletion period. Apple-rejected invalid tokens are removed from the active recipient list, but that does not automatically delete historical send or receipt records. Contact support@ocmedic.com to request deletion of notification records; we may need information to identify your installation and verify the request. Disabling notifications stops alerts according to iOS settings and is not a deletion request. Provider logs, recovery copies and backups are subject to the providers’ retention arrangements; we do not promise a fixed deletion period for those copies.
OCMedic is intended for EMS education and professional reference, not directed to children under 13. If you believe a child has sent us personal information, contact us so we can address it.
Email support@ocmedic.com for privacy questions, corrections or requests. We will update this page and its date when these practices change. Review it before sending sensitive information. OC Medic is independent of Orange County EMS and county service providers.