Status: Effective July 22, 2026 (counsel-reviewed 2026-07-06, no notes; declared effective by founder decision 2026-07-22). See PACKET.md.
Last updated 2026-07-22
End User License Agreement
Status: Effective July 22, 2026 (counsel-reviewed 2026-07-06, no notes; declared effective by founder decision 2026-07-22). See PACKET.md. Effective Date: July 22, 2026
1. Agreement and Scope
1.1 The Agreement
This End User License Agreement (this "EULA") is a legal agreement between you ("Licensee," "you," or "your") and Pattern Engine LLC, a Kansas limited liability company, doing business as Pidgeon Health ("Pidgeon Health," "we," "us," or "our"), governing your use of the Licensed Software described in Section 1.2. By installing, copying, activating a License Key for, or using the Licensed Software, you agree to the terms of this EULA. If you are accepting on behalf of an organization, you represent that you have authority to bind that organization, and "Licensee" refers to that organization.
1.2 What This EULA Covers
"Licensed Software" means the proprietary Pidgeon Health desktop software, in object-code form, together with its associated documentation:
- the Post, Flock, Loft, and Migrate desktop applications (the "Desktop Apps"), including the Conform module of Post;
- the Pidgeon launcher application; and
- the Pidgeon.Bridge local sidecar service (the "Bridge") bundled with and installed by the Desktop Apps.
The Licensed Software runs on your devices against a local engine. Healthcare message processing — generation, validation, de-identification, monitoring — happens on-device. Account, billing, and team management are provided through the separate web surface at account.pidgeon.health (the "Account Services"), which is governed by the Terms of Service, not this EULA.
1.3 What This EULA Does Not Cover
This EULA does not apply to the Pidgeon command-line interface (the "CLI") or to the Pidgeon.Core engine as distributed with the CLI. The CLI and Pidgeon.Core are open-source software licensed separately under the Mozilla Public License 2.0 ("MPL-2.0"); their use, modification, and distribution are governed exclusively by MPL-2.0. See Open Source Licenses for the licensing split.
Telemetry participation for the CLI is not governed by this EULA. It is governed by the Telemetry & VIN Consent Notice and, for holders of a Pidgeon Health account, by the Terms of Service. Section 7 of this EULA governs Telemetry for the Desktop Apps only. As of the date of this EULA, all Telemetry is off by default in the free CLI in both telemetry pipelines.
1.4 Related Agreements
Your use of the Licensed Software is also subject to the Acceptable Use Policy ("AUP"), which is incorporated by reference. The Privacy Policy describes how we handle personal information. Account creation, subscriptions, billing, trials, and cancellation are governed by the Terms of Service. Subscription fees are as set forth in the pricing schedule published at pidgeon.health/pricing (the "Pricing Schedule") or in an applicable Order Form.
2. License Grants
2.1 Nature of Each Grant
Each license granted in this Section 2 is a limited, non-exclusive, non-transferable, non-sublicensable, revocable license to install and use the identified Licensed Software, in object-code form only, for Licensee's internal business purposes — healthcare integration testing, development, quality assurance, staging, monitoring, and migration work within Licensee's organization. No license is granted to provide the Licensed Software to third parties as a service bureau, hosted offering, or managed service, except that consultants and contractors performing work for Licensee may use seats assigned to them for that work.
Each paid grant below is conditioned on (a) payment of the applicable subscription fees under the Pricing Schedule or an Order Form, (b) activation of a valid License Key where Section 3 requires one, and (c) compliance with this EULA.
2.2 Post Pro (including Conform)
Subject to Section 2.1, Pidgeon Health grants you a license to install and use the Post desktop application at the Pro tier, including the Conform module, to: generate, validate, and analyze healthcare test messages on your devices; run conformance testing against FHIR endpoints; create and manage workflow scenarios; manage vendor profiles; and generate reports and export data.
2.3 Flock
Subject to Section 2.1, Pidgeon Health grants you a license to install and use the Flock desktop application to: generate synthetic patient populations; export generated data in supported formats (SQL, CSV, HL7, FHIR); and use generated data for testing and development purposes.
2.4 Loft
Subject to Section 2.1, Pidgeon Health grants you a license to install and use the Loft desktop application to: monitor healthcare interface traffic in your environments; configure alerting rules and notification channels; and access analytics dashboards and reporting. Message content processed by Loft is processed locally on your infrastructure; you are responsible for the configuration of any alert destinations you connect (Section 8.4).
2.5 Migrate
Subject to Section 2.1 and to any engagement-specific agreement (statement of work or Order Form) governing a migration project, Pidgeon Health grants you a license to install and use the Migrate desktop application to: configure and execute data migrations between systems within your (or your client's, where your engagement terms permit) network environment; and generate migration mappings, dry-run reports, and audit artifacts.
2.6 Pidgeon Launcher
Pidgeon Health grants you a license to install and use the Pidgeon launcher application at no charge to install, update, launch, and manage the Desktop Apps for which you hold a license.
2.7 Console Free Tier
Pidgeon Health grants you a license to install and use the Desktop Apps at the Console Free tier at no charge, which includes: message viewing and inspection; basic message validation; scenario browsing and execution; and limited message generation.
The Console Free tier is designed to be provided in exchange for participation in the Pidgeon Vendor Intelligence Network, as described in Section 7 and in the Telemetry & VIN Consent Notice. Console Free features may be adjusted or restricted if you disable all Telemetry collection. No Telemetry is collected under this exchange unless and until the collection described in Section 7 is in effect for your tier and jurisdiction as stated in the Consent Notice.
2.8 Seats and Devices
Paid licenses are granted per seat: one named individual user per seat, in the quantity stated in your subscription or Order Form. A seat holder may install the Licensed Software on the devices that individual personally uses. Seats may be reassigned to a different named user permanently (for example, on personnel change), not rotated among concurrent users. You may not share login credentials, License Keys, or API keys to circumvent seat counts.
2.9 License Term
Each paid license runs for the subscription term stated in your subscription or Order Form and, where the license is delivered as a License Key, no later than the expiry date embedded in that License Key. The Console Free and launcher licenses run until terminated under Section 9.
3. License Keys and Activation
3.1 Offline Activation
Paid entitlements in the Licensed Software activate by means of a digitally signed license file (a "License Key") that the Licensed Software validates locally against an embedded public key. Activation is offline by design: validation involves no license server, no network call, and no phone-home. A License Key that is tampered with, unsigned, or expired will not activate. Free-tier and Console Free licenses are unsigned by design and confer no paid entitlements.
3.2 License Key Scope and Transferability
Each License Key is issued to a specific Licensee — identified by email address and, where applicable, organization — with a stated tier and expiry date. License Keys are non-transferable: they may be used only by the Licensee to whom they are issued and only within that Licensee's organization, and only for the tier entitlements they state. You may not sell, lend, publish, or otherwise provide a License Key to any person outside the licensed organization.
3.3 Expiry and Lapse
When a License Key expires, or a subscription lapses without renewal, the Licensed Software reverts to Free-tier functionality. Reversion to Free tier does not delete your local data. Renewal is effected by activating a replacement License Key or renewing the subscription through the Account Services.
3.4 Signing-Key Rotation
Pidgeon Health may rotate the cryptographic keys used to sign License Keys, including in response to a suspected key compromise. If a rotation invalidates outstanding License Keys, Pidgeon Health will reissue replacement License Keys, at no additional charge, to all Licensees holding valid, unexpired licenses at the time of rotation.
3.5 Fail-Closed Behavior
In deployments configured for on-premises or egress-restricted operation, the Licensed Software fails closed: if signature validation is unavailable — including where no trusted production public key is configured — paid tiers resolve to Free-tier functionality rather than honoring an unverifiable license. This behavior is a deliberate protection of the offline licensing model and is not a defect.
3.6 License Key Restrictions
As a condition of every license granted under this EULA, you must not:
- forge, alter, or fabricate a License Key, or modify the contents of a License Key;
- circumvent, disable, or interfere with the signature-validation mechanism, the embedded public key, or the fail-closed behavior described in Section 3.5, or induce the Licensed Software to honor an untrusted or invalid License Key;
- misrepresent your tier entitlements, including by using a License Key issued for a lower tier, a different licensee, or a development or testing purpose to obtain paid functionality;
- share License Keys outside the licensed organization or use another party's License Key.
Any breach of this Section 3.6 automatically terminates every license granted to you under this EULA.
4. License Restrictions
You may not:
- Copy, modify, or distribute the Licensed Software
- Reverse-engineer, decompile, or disassemble the Licensed Software, except to the extent that applicable law expressly permits such activity notwithstanding this restriction
- Sublicense, rent, lease, or lend the Licensed Software
- Remove or alter any proprietary notices or labels
- Use the Licensed Software to build a competing product
- Share login credentials or API keys with unauthorized users
- Exceed the usage limits of your subscription tier
- Circumvent, or attempt to circumvent, any technical protection or entitlement-enforcement measure in the Licensed Software, including the License Key mechanics in Section 3
- Use the Licensed Software for production clinical operations — it is a testing, development, and monitoring tool, not a medical device (see Section 10)
- Use the Licensed Software in violation of the Acceptable Use Policy
These restrictions do not limit any rights you hold in the separately licensed MPL-2.0 CLI and Pidgeon.Core engine under MPL-2.0 (Section 1.3).
5. CPT Data Usage Restrictions
5.1 CPT License
The Licensed Software may include Current Procedural Terminology (CPT) codes licensed from the American Medical Association (AMA). CPT codes are subject to additional restrictions:
- CPT is copyright by the American Medical Association. All rights reserved.
- CPT codes are provided for internal testing and development purposes only
- You may not redistribute CPT codes outside your organization
- You may not use CPT codes to create derivative works for commercial distribution
- The AMA disclaims liability for any consequences arising from CPT use
- CPT data access requires the CPT add-on subscription ($30/user/year)
5.2 AMA Compliance
By accessing CPT data through the Licensed Software, you agree to:
- Use CPT codes solely for internal healthcare testing and development
- Not extract, download, or bulk-export CPT codes for use outside the Licensed Software
- Comply with the AMA's CPT License Agreement terms
- Acknowledge that CPT codes are the intellectual property of the AMA
5.3 Other Coded Data
Other coded datasets (ICD-10, SNOMED CT, LOINC, NDC, CVX, RxNorm, HCPCS) are used under their respective license terms. Most are freely available for use in the United States. Certain restricted standards content is not shipped with the Licensed Software and must be supplied by you under your own license through the license-acceptance install step; see Open Source Licenses and Standards Licensing.
6. Intellectual Property
The Licensed Software and all associated documentation, interfaces, and designs are the intellectual property of Pattern Engine LLC. This EULA does not transfer any ownership rights to you. All rights not expressly granted are reserved.
Your data (messages, configurations, generated outputs, workspace content) remains your property. Pidgeon Health claims no ownership over your data. Pidgeon Health's rights in Telemetry contributed under Section 7 are as stated in that section.
7. Telemetry and the Vendor Intelligence Network
This Section 7 governs Telemetry collection from the Desktop Apps only. The operative disclosure of what is collected, the per-tier defaults, and the controls available to you is the Telemetry & VIN Consent Notice; CLI telemetry participation is governed by that Consent Notice and, for account holders, the Terms of Service (Section 1.3), not by this EULA.
7.1 Consent to Telemetry Collection
By installing or using the Licensed Software with Telemetry enabled for your tier as described in the Consent Notice, you consent to the collection of Interface Structure Metadata and De-identified Message Templates ("Telemetry") as described in this section and in our Privacy Policy. Telemetry is used to improve vendor-specific validation profiles, message generation accuracy, and platform intelligence for all users.
7.2 What Telemetry Includes
Telemetry consists of:
(a) Usage Metadata: command and feature usage patterns, message types and standards targeted, execution performance metrics, environment information, and session patterns.
(b) Interface Structure Data: message segment types and ordering, field population indicators (boolean presence, not field values), field data type and length metadata, Z-segment catalogs, and vendor signature metadata (cryptographically hashed before transmission).
(c) Standardized Clinical Terminology Distributions: coding system identifiers per field, code category distributions at the chapter or class level (e.g., ICD-10 chapter, LOINC class), and HL7 table value usage. Standardized clinical codes (ICD-10, LOINC, SNOMED CT, CPT, NDC, CVX) are public classification systems and are not Protected Health Information.
(d) De-identified Message Templates: complete message structures processed by an on-device de-identification engine that removes the 18 HIPAA Safe Harbor identifier categories as they appear in standard HL7 v2, FHIR, and NCPDP message structures, with free-text edge-case scanning on the roadmap (see De-Identification & HIPAA Safe Harbor for the as-built coverage map). De-identification is performed entirely on your local device before any data is transmitted to Pidgeon Health.
(e) Validation Results: rule pass/fail outcomes by segment, field, and vendor profile.
7.3 What Telemetry Does NOT Include
Telemetry never includes:
- Patient names, medical record numbers, Social Security numbers, dates of birth, addresses, phone numbers, or other identifiers within the HIPAA Safe Harbor categories as they appear in standard HL7 v2, FHIR, and NCPDP message structures (see Section 7.2(d) and De-Identification & HIPAA Safe Harbor)
- The actual content of healthcare message fields
- Your organization's name or facility identifiers in readable form
- Free-text clinical notes in their original form
- Geographic data below the state level
7.4 De-Identification Architecture
All Telemetry containing healthcare message data is de-identified on your device before transmission, and passes through two independent layers:
- A Collection Guard (on-device): the de-identification engine removes the 18 HIPAA Safe Harbor identifier categories as they appear in standard HL7 v2, FHIR, and NCPDP message structures, with free-text edge-case scanning on the roadmap, applying synthetic replacement at the time of data capture. This is the primary control.
- A Transmission Guard (server-side backstop): the ingest endpoint performs an independent PHI detection scan on receipt.
This layered architecture ensures that even in the event of a software defect in one layer, the other provides independent protection against identifier disclosure. The de-identification requirement, the as-built coverage map, and known edge-case gaps are documented in De-Identification & HIPAA Safe Harbor; the egress path is documented in VIN Aggregation & Egress.
7.5 Telemetry Defaults by Tier
| Tier | Default Setting | Opt-Out |
|---|---|---|
| Post CLI (free) | All Telemetry OFF in both telemetry pipelines (VIN and product-usage analytics); governed by the Consent Notice, not this EULA | n/a — nothing to opt out of; opt-in controls described in the Consent Notice |
| Console Free | All Telemetry categories enabled (EU/UK: off, opt-in per GDPR Art. 6(1)(a)) | Available in Settings; disabling may restrict Console-specific features |
| Console Pro / Individual | All Telemetry categories enabled | Full opt-out without feature restriction |
| Teams | All Telemetry disabled | Opt-in per category with administrator approval |
| Enterprise | All Telemetry disabled | Opt-in per category with administrator approval; zero data collection contractually guaranteed by default |
7.6 Use of Telemetry Data
Pidgeon Health uses Telemetry to:
- Improve vendor-specific validation profiles distributed to all users
- Enhance the accuracy and realism of synthetic message generation
- Identify common validation failure patterns across the user network
- Develop and improve platform features based on aggregate usage patterns
- Build aggregated interface intelligence that may be licensed to third parties in anonymous, statistical form only
Pidgeon Health will NOT:
- Publish or distribute Telemetry in any form that could identify an individual user, patient, or organization
- Publish aggregated vendor patterns until at least 50 independent sessions have contributed data for a given pattern (preventing organizational fingerprinting)
- Retain raw Telemetry events beyond 12 months
- Collect any Telemetry from Teams or Enterprise installations without explicit administrator opt-in
7.7 Your Telemetry Rights
You may at any time:
- View what Telemetry is being collected:
pidgeon config telemetry --showor Settings → Privacy - Audit recent Telemetry transmissions:
pidgeon config telemetry --auditor Settings → Privacy → Audit Log - Adjust Telemetry level: metadata only, structure, full, or off
- Request deletion of your contributed Telemetry events by contacting privacy@pidgeon.health
7.8 Vendor Intelligence Network
Aggregated Telemetry from across the user network is compiled into the Pidgeon Vendor Intelligence Network ("VIN") — anonymous statistical profiles of vendor-specific interface behaviors, field patterns, and validation characteristics. These profiles are distributed to users as improved vendor validation baselines and may be made available to third parties exclusively in aggregated, anonymous, statistical form. No individual user's, patient's, or organization's data is identifiable within Vendor Intelligence Network outputs.
8. AI Features and Data Egress
8.1 On-Device Default
AI-assisted features of the Licensed Software (including triage, analysis, and advisory review features) default to on-device processing: inference runs on your local machine and message content is not sent to any non-local provider.
8.2 Deployment Modes
The Licensed Software supports four AI deployment modes, configurable through the AI egress settings:
- Bundled on-device (default) — content stays on the local machine; non-local providers are refused.
- Workstation Ollama — content stays within the customer-operated host.
- Customer-controlled endpoint — a customer-owned, in-network inference endpoint; real message content is permitted; every call is audit-logged.
- BYOK cloud — a bring-your-own-key public-cloud endpoint; real message content is refused unless you affirmatively enable the BAA opt-in setting; synthetic content is always allowed.
8.3 Organizational Hard Switch and Audit Logging
A RequireOnDeviceForAnyContent organizational hard switch, when enabled, causes the Licensed Software to refuse any non-local AI provider regardless of deployment mode or content attestation. Off-device calls carrying attested-synthetic content are recorded in an egress audit log. Contradictory configurations (for example, a BAA opt-in outside BYOK-cloud mode) are rejected.
8.4 Licensee Responsibility
If you configure an off-device mode (customer-controlled endpoint or BYOK cloud with the BAA opt-in), you are responsible for your own legal and regulatory obligations with respect to the content you route off-device, including your HIPAA obligations, any business associate agreement required between you and your inference provider, and the terms of your provider relationship. Pidgeon Health is not a party to, and receives no content through, your configured inference endpoints.
9. Term and Termination
9.1 Term
This EULA is effective from your first installation or use of the Licensed Software and continues until terminated. Paid licenses run for the term described in Section 2.9.
9.2 Termination by You
You may terminate this EULA at any time by canceling your subscription (per the Terms of Service), deactivating any License Keys, and ceasing use of and uninstalling the Licensed Software.
9.3 Termination by Pidgeon Health
Pidgeon Health may terminate this EULA, or the licenses granted under it, if you breach any of its terms, including the License Key restrictions in Section 3.6 and the restrictions in Sections 4 and 5. Upon termination, you must cease all use of the Licensed Software.
9.4 Effect of Termination
Upon termination:
- All licenses granted under this EULA end, and your access to paid functionality is revoked; where applicable the Licensed Software reverts to Free-tier functionality pending uninstallation
- Data stored locally on your devices remains on your devices; account data held in the Account Services is handled per the Terms of Service, including the 30-day post-termination export window, after which it is deleted
9.5 Survival
The following survive any termination or expiration of this EULA, by topic rather than by section number:
- Intellectual property: Pidgeon Health's ownership of the Licensed Software and reservation of rights, and your ownership of your data
- CPT and third-party data restrictions: the AMA CPT restrictions and other third-party data license obligations, with respect to any coded data you accessed under this EULA
- Telemetry rights in contributed aggregates: Pidgeon Health's rights to retain and use Telemetry already contributed to aggregated, anonymous, statistical VIN outputs, subject to the limits and deletion rights in Section 7
- Disclaimers: the warranty disclaimers, including the medical-device and clinical-use disclaimers
- Liability limits: the limitation of liability
- Governing law and venue
10. Disclaimer of Warranties
THE LICENSED SOFTWARE IS PROVIDED "AS IS" WITHOUT WARRANTIES OF ANY KIND. PIDGEON HEALTH DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT.
THE LICENSED SOFTWARE IS A TESTING AND DEVELOPMENT TOOL. IT IS NOT CERTIFIED AS A MEDICAL DEVICE AND MUST NOT BE USED FOR CLINICAL DECISION-MAKING.
11. Limitation of Liability
IN NO EVENT SHALL PIDGEON HEALTH BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES. PIDGEON HEALTH'S TOTAL LIABILITY UNDER THIS EULA SHALL NOT EXCEED THE FEES PAID BY YOU IN THE 12 MONTHS PRECEDING THE CLAIM.
12. Updates
Pidgeon Health may make updates to the Licensed Software available from time to time. Updates may add, modify, or remove features. Updates may be delivered through the in-app updater or through the Pidgeon Health downloads catalog. All updates are digitally signed, and the in-app updater verifies the signature of an update before installing it. You may defer installing an update; however, support and security fixes are provided for current releases, and continued use of the Licensed Software after installing an update constitutes acceptance of the updated version.
13. Governing Law and Venue
This EULA is governed by the laws of the State of Kansas, without regard to conflict of law principles. The state and federal courts located in the State of Kansas have exclusive jurisdiction over any dispute arising out of or relating to this EULA, and each party consents to personal jurisdiction and venue in those courts.
14. Contact
For questions about this EULA:
- Email: legal@pidgeon.health
- Postal notice address: Pattern Engine LLC d/b/a Pidgeon Health, 2812 SW Huntoon St, Topeka, KS 66604, United States
- Website: https://pidgeon.health