Privacy Policy for Momentum
Last Updated: July 19, 2026
Introduction
Momentum ("we," "our," or "us") is a private, internal sales intelligence platform built for Hyland's healthcare sales and pre-sales teams, available as a web application and a companion iOS app. This Privacy Policy explains how Momentum collects, uses, discloses, and safeguards information when you use it.
Momentum is not a public consumer product. It is not available for public sign-up or download by the general public — access is provisioned by an administrator to authorised personnel only.
Our Core Privacy Principles:
- No Patient Data: Momentum does not collect, process, or store individual patient health records or any other Protected Health Information (PHI). It processes organisational/business data about healthcare facilities — never data about individual patients.
- Administrator-Provisioned Access: There is no public registration. Accounts are created and removed by an administrator; we do not operate a separate "account system" beyond Firebase's built-in authentication service.
- Google Firebase Infrastructure: All backend data storage, authentication, and file storage is managed entirely through Google Firebase — we do not run separate servers or databases of our own.
- AI-Assisted, Not Autonomous: Momentum uses Google's Gemini AI to summarise documents and generate analysis. AI output is clearly labelled and must be validated by the user before being relied upon.
- Transparency: We clearly disclose what data is collected, where it goes, and why.
Information We Collect
1. Account Information
Momentum accounts are not self-registered. An administrator creates your account using:
- Your work email address
- A role designation (e.g. sales, admin, super-admin), used only to control which features and data you can access
2. Content You Create or Upload
As part of using Momentum, the following business content is stored in our Firebase backend:
- Uploaded documents: hospital/facility annual report PDFs, legislation and policy document PDFs, and structured customer datasets (Excel/CSV).
- AI analysis output: Intelligence Prism session results (structured disruption-signal analyses), chat conversations with uploaded documents.
- ROI Calculator scenarios: financial modelling inputs and outputs you save, associated with your account.
- Deal notes (iOS app only): free-text notes you log against an account, visible to other authorised reps working the same account.
- Push notification token (iOS app only): a device token used solely to deliver in-app notifications.
3. Locally Cached Data (Your Device)
To make the iOS app usable with a poor or no connection, a copy of the Firestore data you've already viewed is cached on your device. This cached data:
- Stays on your device — it is never sent anywhere beyond the normal sync back to our Firebase backend.
- Is removed automatically if you delete the app.
4. What We Do NOT Collect
- Any individual patient's health information (PHI).
- Payment card numbers or financial information.
- Location or GPS data.
- Camera, photo library, or microphone access.
- Contacts.
- Advertising identifiers.
- Biometric data (Face ID data stays on your device and is not received by Momentum).
How We Use Your Information
Information described above is used to:
- Authenticate and Authorise You.
- Provide Sales Intelligence (facility data, legislation, disruption signals).
- Power the ROI Calculator.
- Enable Team Collaboration.
- Send Relevant Notifications (iOS).
We do NOT sell or rent any information, use your data for advertising, or track you across other apps or websites.
Data Storage Locations
Google Firebase (Primary Backend)
What: Authentication, Firestore, Firebase Storage, and Cloud Functions.
Location: Google Cloud infrastructure.
Access Control: Firestore security rules restrict most collections to authenticated users only.
Your Device (iOS App Only)
Cached copies of data you've already viewed, for offline use.
Third-Party Services
AI Processing — Google Gemini
What Gets Sent: Document text (PDF extraction), Account/organisation names, and Chat messages.
What Does NOT Get Sent: PHI, account credentials, other users' deal notes, or data from accounts you don't have permission to view.
Important: AI Output May Be Inaccurate. Always validate information before using it to make business, clinical, or financial decisions.
iOS App Specifics
Face ID / Touch ID App Lock
Handled entirely by Apple's on-device LocalAuthentication framework — Momentum never receives or stores your biometric data.
Push Notifications
Uses Apple Push Notification service (APNs). You can disable notifications at any time in iOS Settings.
Data Retention
While Active: Business content remains as long as your account exists for team continuity.
Upon Removal: Personal credentials are removed; shared business intelligence contributions generally remain for the team.
Your Privacy Rights
Rights are exercised through your organisation's administrator or by contacting office@keepingupwithtechnology.com. We aim to respond within 30 days.
Contact Us
Email: office@keepingupwithtechnology.com
Company: Keeping up with technology Pty Ltd
Summary: Quick Reference
What We Collect
- Work email & role
- Uploaded PDFs & Datasets
- AI analyses & ROI scenarios
- Deal notes (iOS only)
We NEVER Collect
- Patient Health Info (PHI)
- Personal payment/financial data
- Real-time GPS location
- Biometric data (Face ID)