Privacy Policy
Effective August 23, 2026
This policy covers the public Guardrail Health site and the current private Sabrina app. Sabrina is presently for authenticated Founder use; it is not a public clinical service.
Information we process
We process the information needed to operate the service: account and authentication information supplied through the configured sign-in provider, requests and bounded tool inputs, and the resulting governed operating records or proposals. Depending on a Founder-directed workflow, those records can concern Health, Rideshare, or Financial operations. The public site’s contact form processes the contact details and message that a visitor chooses to submit.
How Sabrina works
Sabrina uses a proposal-and-confirmation model. A request to capture or correct an event first creates a reviewable proposal; a canonical event is recorded only after an explicit confirmation. Read tools return bounded results for the active operation. Sabrina does not provide medical diagnosis, treatment, emergency guidance, or a substitute for professional care.
Authentication, credentials, and providers
The private app uses OAuth 2.1 for authentication. Credentials and tokens are handled at the service boundary and are not returned in tool results. Where a Founder chooses to use a third-party provider, that provider’s own terms and privacy practices apply to its service. Sabrina does not expose provider credentials as a tool result. Composio is not currently an operational provider in Sabrina.
Use and disclosure
We use information to authenticate the Founder, provide the requested governed workflow, maintain security and audit continuity, diagnose service problems, and respond to support or deletion requests. We do not sell personal information. We do not disclose information except to service providers needed to operate the chosen workflow, when directed by the authenticated Founder, or when required by law.
Security and limits
We use access controls, scoped authentication, and an append-only command/audit model for governed workflows. No system is perfectly secure. Please do not send passwords, API keys, payment-card data, or other secrets through a support message.
Your choices
You may ask about access, correction, or deletion by contacting contact@guardrailhealth.net. We will verify the request against the applicable account and explain any legal, security, or audit-retention limit before acting.
Changes
We may update this policy as the service changes. The effective date above identifies the current version.