IFPP Clinical Intelligence Extension — Privacy Policy
Last updated: March 17, 2026
1. Overview
The IFPP Clinical Intelligence extension ("Extension") is
developed and maintained by Shokat Wellness Academy LLC for use
by authorized staff at clinics operating the Integrated
Functional Pain Program (IFPP) platform.
2. Data Collection and Use
The Extension collects and processes the following data:
a) Text selections: When a user highlights text on any web page
and invokes the Extension via right-click or keyboard shortcut,
the selected text (up to 2,000 characters) is sent to the IFPP
server for processing. This text may include patient names,
diagnosis codes, procedure codes, medication names, or clinical
documentation.
b) Authentication credentials: The user's email address is
stored locally in the browser (chrome.storage.local) after
successful authentication. Passwords are not stored — they are
sent directly to Amazon Cognito for verification and are not
retained by the Extension.
c) User preferences: Demo mode preference is stored locally in
the browser (chrome.storage.local).
3. Data Transmission
All data transmitted by the Extension is sent exclusively to:
- IFPP API server (AWS API Gateway + Lambda) via HTTPS/TLS
- Amazon Cognito authentication service via HTTPS/TLS
No data is transmitted to any other third party, advertising
network, analytics service, or external server.
4. Data Storage
The Extension stores only the following data locally in the
browser using chrome.storage.local:
- User email address (for session management)
- Admin status flag (boolean)
- Demo mode preference (boolean)
No patient data, clinical information, query results, or
conversation history is stored locally by the Extension. All
query results are displayed in the side panel and discarded
when the panel is closed or cleared.
5. Server-Side Data Handling
Query data sent to the IFPP server is processed in real time
and is not logged or stored beyond what is necessary for the
immediate query response. The IFPP server infrastructure is
hosted on HIPAA-compliant AWS services (API Gateway, Lambda,
RDS) within an encrypted, access-controlled environment.
6. HIPAA Compliance
The Extension functions as a client interface to the existing
IFPP platform infrastructure, which operates under a Business
Associate Agreement (BAA) with AWS. The Extension does not
independently store, process, or transmit Protected Health
Information (PHI) beyond what is described in this policy.
All PHI handling is governed by the IFPP platform's existing
HIPAA compliance framework.
7. Permissions Justification
The Extension requests the following Chrome permissions:
- contextMenus: To add right-click menu options for clinical
intelligence actions.
- activeTab: To read highlighted text on the current tab when
the user invokes the Extension.
- sidePanel: To display query results in a persistent side
panel.
- storage: To store authentication state and user preferences
locally in the browser.
- host_permissions (IFPP API + Cognito): To send queries to
the IFPP server and authenticate users.
8. Data Sharing
We do not sell, rent, share, or transfer any user data or
query data to third parties for any purpose.
9. User Control
Users can:
- Sign out at any time via the Extension popup or options page,
which clears all locally stored data.
- Clear all Extension data via the options page.
- Uninstall the Extension at any time, which removes all
locally stored data.
10. Access Restriction
The Extension is distributed as an unlisted Chrome Web Store
extension and is intended only for authorized staff at clinics
using the IFPP platform. Access to the IFPP server requires
valid authentication credentials issued by the clinic
administrator.
11. Changes to This Policy
We may update this privacy policy from time to time. Changes
will be communicated through the Extension update notes or
direct notification to clinic administrators.
12. Contact
For questions about this privacy policy or the Extension's
data practices, contact:
Shokat Wellness Academy LLC
615 S. Hansell St
Thomasville, GA 31792
Email: admin@shokatwellness.com
Website: www.shokatwellness.com