Last updated: July 11, 2026

This Privacy Policy explains how Todopocus Inc. (“TodoPocus,” “we,” “us,” or “our”) handles information when you use https://todopocus.com/ (the “Website”) and the TodoPocus Handheld Ultrasound mobile application (the “App”). It also explains how information is retained, how it can be deleted, and how to contact us about privacy requests.

1. Scope and Key App Privacy Summary

The Website and the App handle information differently. The Website supports product information, purchases, customer service, and related business functions. The App is a utility for compatible TodoPocus wireless ultrasound devices.

  • No App account is required.
  • No automatic TodoPocus cloud upload. The current Android release does not automatically upload patient information, ultrasound images, cine loops, measurements, annotations, notes, or DICOM files to TodoPocus servers.
  • Local processing and storage. App records are processed and stored on the user’s device unless the user intentionally exports them or sends them to a DICOM destination configured by the user.
  • No App advertising or sale of App data. The current Android release does not use patient or scan data for advertising, cross-app tracking, or sale.

2. Information the Website May Collect

Depending on how you use the Website, we may collect:

  • Contact and account information: name, email address, telephone number, billing and shipping address, organization, and account details if you create an account.
  • Order and transaction information: products ordered, order number, payment status, shipping information, returns, warranty, and customer-service records. Payment card information is processed by payment providers; we do not intentionally store complete payment card numbers on the Website.
  • Communications: information you provide through email, forms, chat, reviews, warranty requests, or other support channels.
  • Technical and usage information: IP address, browser and device type, operating system, pages viewed, referring URL, approximate location derived from IP address, cookie identifiers, and security or access logs.

Please do not submit patient medical records or other sensitive health information through general Website contact, chat, order, or review fields.

3. How We Use Website Information

  • Provide and maintain the Website, accounts, purchases, shipping, returns, warranties, and customer support.
  • Respond to inquiries and communicate about orders, products, software, and services.
  • Detect fraud, abuse, security incidents, and technical problems.
  • Analyze Website performance and improve our products, content, and customer experience.
  • Send marketing communications where permitted. You may unsubscribe at any time.
  • Comply with legal, tax, accounting, regulatory, and dispute-resolution obligations.

4. App Data, Device Permissions, and Local Storage

The App may process information that the user enters or creates, including patient or case identifiers, ultrasound images, cine loops, measurements, annotations, notes, presets, and device settings. This information is processed to provide the App functions requested by the user.

Depending on the device and operating-system version, the App may request access to functions such as local network or Wi-Fi connectivity and files, photos, media, or device storage. These permissions are used to connect to compatible hardware, display live device output, save records, open records, and export files. Denying a permission may prevent the related feature from working.

App records remain under the control of the user and the healthcare organization using the device. Users are responsible for securing their device, controlling access, applying appropriate patient identifiers, and following the privacy and recordkeeping rules that apply to their work.

5. DICOM, File Exports, and User-Directed Transfers

The App may allow a user to export files or send records to a DICOM server or other destination selected and configured by the user. TodoPocus does not choose or operate that destination. A transfer occurs only when the user configures the destination and initiates the transfer or uses the device’s sharing functions.

Once information is exported or transmitted, the receiving hospital, clinic, DICOM administrator, cloud provider, email provider, file-storage provider, or other recipient controls its use, security, retention, and deletion. Users should review the recipient’s privacy and security practices before sending patient information.

6. Cookies and Website Service Providers

The Website may use essential, preference, analytics, and advertising cookies or similar technologies. Essential cookies support functions such as security, account access, shopping carts, and checkout. Subject to consent requirements and browser settings, analytics or advertising technologies may help us understand Website use and measure campaigns. You can manage cookies through the Website consent controls and your browser settings.

We may disclose Website information to service providers that perform hosting, security, payment processing, fraud prevention, shipping, email delivery, customer support or chat, analytics, advertising, and professional services for us. We may also disclose information when required by law, to protect rights or safety, or as part of a merger, financing, acquisition, or sale of business assets. We do not sell personal information for money. Where applicable law treats certain analytics or advertising disclosures as a “sale” or “sharing,” you may opt out through available cookie controls or by contacting us.

7. Data Retention

We retain information only for the period needed for the purpose described below, unless a longer period is required or permitted by law:

  • App records stored locally: until the user deletes the record, clears the App’s storage, resets the device, or uninstalls the App. Copies in device or operating-system backups remain subject to the user’s backup settings and the backup provider’s retention rules.
  • DICOM and exported files: according to the retention rules of the user-selected recipient or destination. TodoPocus cannot delete copies controlled by that destination.
  • Website accounts: while the account is active and generally for up to 24 months after closure for non-transactional support and security purposes, unless deletion is requested earlier or a longer period is legally required.
  • Orders, invoices, tax, warranty, and transaction records: for the period required by applicable tax, accounting, warranty, fraud-prevention, and consumer-protection laws, generally up to 7 years where applicable.
  • Support requests and general communications: generally up to 24 months after the last interaction, unless needed longer for an active warranty, dispute, safety issue, or legal obligation.
  • Marketing information: until you unsubscribe or withdraw consent. We may keep a limited suppression record so that we can honor your opt-out.
  • Website cookies, analytics, and security logs: according to the relevant cookie setting or provider configuration, generally no longer than 26 months, unless a longer period is needed to investigate fraud, abuse, a security incident, or a legal claim.

When a retention period ends, we delete, anonymize, or aggregate the information unless continued retention is required by law, a court order, an unresolved transaction, a security investigation, or the establishment, exercise, or defense of legal claims.

8. How to Delete Data

Delete App Data Stored on Your Device

  1. Delete individual records using the available delete controls in the App.
  2. To remove all locally stored App data on Android, open Settings > Apps > TodoPocus Handheld Ultrasound > Storage and choose Clear storage or Clear data. Menu names may vary by device.
  3. Uninstalling the App removes App data stored in the App’s local storage, subject to any copies retained in device backups, exported folders, photo libraries, DICOM systems, or other destinations.

You do not need to contact TodoPocus to delete App data that exists only on your device.

Delete DICOM or Exported Copies

Contact the hospital, clinic, DICOM administrator, file-storage provider, email recipient, or other destination that received the exported record. TodoPocus cannot delete data controlled by a user-selected third party.

Request Deletion of Data Held by Todopocus Inc.

  1. Email support@todopocus.com with the subject line Data Deletion Request.
  2. Include your full name, the email address used with us, and enough information to locate the relevant Website account, order, support request, or communication. If relevant, include an order number. Do not send passwords or medical records.
  3. State whether you want specific records deleted or all personal information that Todopocus Inc. is permitted to delete.
  4. We may request reasonable information to verify your identity and protect against unauthorized deletion.

We will respond within the period required by applicable law and generally within 30 days after verifying the request. We will confirm completion or explain why certain information must be retained, such as transaction records required for tax, accounting, fraud prevention, safety, warranty, dispute, or legal purposes.

9. Your Privacy Choices and Rights

Depending on where you live, you may have the right to request access, correction, deletion, restriction, portability, or an explanation of personal information we control; to object to certain processing; to withdraw consent; or to appeal a decision. You may also unsubscribe from marketing emails using the link in the message. To exercise a right, contact us using the details below. We may verify your identity before completing a request.

10. Data Security

We use administrative, technical, and organizational safeguards designed to protect information we control. App users should use device passcodes, operating-system updates, access controls, secure networks, and appropriate DICOM security settings. No method of storage or transmission is completely secure, so absolute security cannot be guaranteed.

11. Children’s Privacy

The Website and App are intended for adults and professional use and are not directed to children under 13. We do not knowingly collect personal information directly from children under 13. If you believe a child has provided personal information to us, contact us so that we can review and delete it where appropriate.

12. International Processing

Todopocus Inc. is based in the United States. Website information may be processed in the United States and other countries where our service providers operate. Where required, we use appropriate safeguards for international transfers. App data that remains only on the user’s device is stored where the user keeps that device, subject to the user’s own backups and exports.

13. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in the App, Website, services, law, or business practices. The “Last updated” date will identify the current version. If a change materially affects how we handle information, we will provide additional notice where required.

14. Contact Todopocus Inc.

Todopocus Inc.
5th Ave Second Floor
Brooklyn, NY 11215
United States

Email: support@todopocus.com
Telephone: +1 747 777 6278

Use the subject line Privacy Request for general privacy questions or Data Deletion Request for deletion requests.