Status: Effective July 22, 2026 (counsel-reviewed 2026-07-06, no notes; declared effective by founder decision 2026-07-22). See PACKET.md.
Last updated 2026-07-22
Telemetry & Vendor Intelligence Network Consent Notice
Pattern Engine LLC d/b/a Pidgeon Health Status: Effective July 22, 2026 (counsel-reviewed 2026-07-06, no notes; declared effective by founder decision 2026-07-22). See PACKET.md. Effective Date: July 22, 2026
This notice is the operative disclosure for the two telemetry pipelines in Pidgeon Health products. It contains the full notice (§ 1–7) and, in § 8, the exact short-form texts the products display at first run and in settings. The Privacy Policy § 2.3–2.5 describes the same collection in the context of all data we process; if this notice and the Privacy Policy ever diverge, the more protective description controls.
1. The two pipelines, in one view
Pidgeon Health products can send two — and only two — kinds of telemetry. They are separate pipelines with separate payloads, destinations, and controls. Nothing else leaves your machine from the products' telemetry systems.
| Vendor Intelligence Network ("VIN") Telemetry | Product Usage Analytics | |
|---|---|---|
| What it is | De-identified interface structure: segment ordering, field-population patterns (presence, not values), Z-segment catalogs, hashed vendor signatures, validation pass/fail patterns, and de-identified message templates | Product usage events: feature and screen usage, counts, durations, tier — from a fixed allowlist of event types |
| What it can never contain | Message field contents; patient or provider identifiers; readable organization or facility names; geography below state level; free-text notes in original form | Message content of any kind; events not on the typed allowlist cannot be sent |
| Where it goes | Pidgeon Health's telemetry ingest service, where an independent server-side scan re-checks for identifier patterns before storage | An analytics service (PostHog), for product improvement |
| Why we collect it | To build aggregated, anonymized vendor interface profiles that improve validation and generation for all users — published only after at least 50 independent sessions have contributed for a vendor and message type | To understand which features are used and how the products perform |
| How it is protected | De-identified on your device before transmission (§ 3); hashed vendor signatures; aggregation floor; 12-month raw retention | Typed event allowlist; bounded property values; anonymized device data; country-level geography only |
2. Defaults by tier
Consent state is evaluated against your subscription tier, which is resolved server-side — a client cannot raise its own collection level by misreporting its tier.
| Tier | VIN Telemetry | Usage Analytics | Notes |
|---|---|---|---|
| CLI (free, open source) | Off | Off | The free CLI transmits nothing; there is no first-run consent flow to establish a value exchange |
| Console Free | On by default | On by default | The disclosed value exchange for free access (§ 4); reducible or fully disableable in Settings |
| Console Free — EU/UK | Off — explicit opt-in required | Off — explicit opt-in required | Consent under GDPR Art. 6(1)(a); the full product is provided either way |
| Pro / Individual | On by default | On by default | Full opt-out, no feature restriction |
| Teams / Enterprise | Off | Off | Administrator opt-in required; the off default is a contractual commitment |
| On-premises / air-gapped | Off (hard) | Off (hard) | No egress endpoint is configured; there is nothing to send to |
3. How de-identification protects VIN Telemetry
Before any VIN Telemetry leaves your machine, our de-identification engine — the same engine we ship as a product feature — removes the 18 HIPAA Safe Harbor identifier categories (45 CFR § 164.514(b)(2)) as they appear in standard HL7 v2, FHIR, and NCPDP message structures, with free-text edge-case scanning on the roadmap. The as-built coverage map, including its known edge-case gaps, is published in De-Identification & HIPAA Safe Harbor.
Two layers enforce this:
- Collection layer (your device): identifiers are removed and replaced with synthetic values before anything enters the transmission buffer. This is the primary control.
- Transmission layer (our servers): an independent pattern scan runs on receipt and replaces any residual identifier patterns before storage. This is defense-in-depth, not a substitute for the on-device layer.
Facility and vendor identifiers are cryptographically hashed on your device before transmission, and no aggregated pattern is published until at least 50 independent sessions have contributed data for that vendor and message type.
4. The Console Free value exchange
Console Free provides the full desktop experience at no charge. In exchange, Console Free installations contribute VIN Telemetry and Usage Analytics by default (outside the EU/UK), as disclosed at first run using the § 8 text. You can reduce collection to structure-only or metadata-only, or disable it entirely; disabling all telemetry may adjust access to Console-Free-specific features that are funded by the exchange. Your access to the core product does not depend on contributing de-identified message templates.
5. Your controls
| Action | CLI | Desktop Apps |
|---|---|---|
| Disable everything | pidgeon config telemetry --off |
Settings → Privacy → Disable all telemetry |
| Reduce to metadata only | pidgeon config telemetry --level metadata |
Settings → Privacy → Level |
| Reduce to structure only (no templates) | pidgeon config telemetry --level structure |
Settings → Privacy → Level |
| See what is collected, with examples | pidgeon config telemetry --show |
Settings → Privacy → View Data |
| Audit recent transmissions | pidgeon config telemetry --audit |
Settings → Privacy → Audit Log |
Changes take effect immediately and apply going forward. Disabling telemetry does not remove data already contributed; raw events are deleted on the 12-month schedule in the Privacy Policy § 5, and previously published aggregates (which contain no individual-level data) are retained.
6. Withdrawing consent
Where collection is based on your consent (all EU/UK collection; any opt-in you granted), you may withdraw it at any time using the § 5 controls or by contacting privacy@pidgeon.health. Withdrawal stops collection going forward and does not affect the lawfulness of processing before withdrawal.
7. Changes
If we materially expand what either pipeline collects, we will present a new consent request before the expanded collection begins — an existing "on" setting does not carry over to new categories of data.
8. Product surface texts
The texts below are the operative short-form disclosures. Product surfaces must present them as written once this notice is in effect; the long-form sections above are one click away from each.
8.1 First-run consent dialog — Console Free (non-EU/UK)
Help improve healthcare interfaces — anonymously.
Console Free is free because installations like yours contribute de-identified interface structure to the Vendor Intelligence Network: segment patterns, field usage, and validation outcomes — never message contents, never patient data, never your organization's name. Identifiers are removed on this machine before anything is sent, and product usage analytics (feature usage counts, never message content) help us improve the product.
You can see exactly what leaves this machine (Settings → Privacy → Audit Log), reduce what is shared, or turn it all off.
[Keep contributing — recommended] [Choose what to share] [Turn everything off]
Details: Telemetry & VIN Consent Notice · Privacy Policy
8.2 First-run consent dialog — EU/UK
Telemetry is off.
Pidgeon can contribute de-identified interface structure (never message contents, never patient data) to improve vendor profiles for everyone, and can share anonymous product usage analytics. In your region this requires your explicit opt-in, and everything works fully without it.
[Leave off] [Review and opt in]
Details: Telemetry & VIN Consent Notice · Privacy Policy
8.3 First-run notice — Pro / Individual
Telemetry is on (you can turn it off).
Pro installations share de-identified interface structure and anonymous usage analytics by default — never message contents, never patient data, identifiers removed on this machine before anything is sent. Turning it off restricts nothing.
[OK] [Open privacy settings]
8.4 Settings screen summary text
Pidgeon has two telemetry streams: Vendor Intelligence (de-identified interface structure that improves vendor profiles for all users) and Usage Analytics (anonymous feature-usage events). Neither ever contains message contents or patient data. Identifiers are removed on this device before transmission, and you can audit every transmission below.
8.5 Enterprise/Teams administrator surface
Telemetry is off for this organization and stays off unless an administrator enables it here. This default is part of your agreement with Pidgeon Health. Enabling telemetry applies the same de-identification and audit controls documented in the Telemetry & VIN Consent Notice.
8.6 CLI note (free tier)
The free CLI sends no telemetry. If you sign in with a paid or Console Free account, telemetry follows your account tier's settings — see
pidgeon config telemetry --show.
9. Contact
- Privacy questions: privacy@pidgeon.health
- Legal: legal@pidgeon.health
- Postal notice address: Pattern Engine LLC d/b/a Pidgeon Health, 2812 SW Huntoon St, Topeka, KS 66604, United States
- Website: https://pidgeon.health