Version 2 · Effective 31 August 2026 · Previous version: 30 August 2026
This policy explains what fieldBB (“Field Business Book”, the “Service”), at fieldbb.com, does with information — yours and that of the people you record in it. It is written to be read, not to be survived.
The short version. fieldBB is offline-first: your work is stored on your own device. Nothing is sold, nothing feeds advertising, and no one at fieldBB reads your notes. Where fieldBB talks to Google — sign-in, calendar, key backup — it uses only your own account, only for the feature you switched on, and only while you keep it connected. Clinical text is removed before anything reaches a calendar.
fieldBB is operated by César Luis Valladares (“the operator”, “we”), an individual developer, who is the data controller for the information described in section 3 as account and service data.
Contact for anything in this policy, including requests about your rights: drcesarluisvalladares@gmail.com.
fieldBB holds two different kinds of information and our role differs for each. This distinction matters legally and is not decoration:
| Information | Our role | What it means |
|---|---|---|
| Your account, your username, your settings, your feedback, diagnostics | Controller | We decide why and how it is handled, and this policy governs it. |
| The contacts, visits, notes, schedules and inventory you record — including information about healthcare professionals | Processor (on your behalf) | You — or the company you work for — decide what to record and why, and are the controller of it. We only provide the tool that stores it, and act on your instructions. Section 12 sets out what that makes you responsible for. |
Most of fieldBB runs entirely in your browser. Contacts, visits, meals, schedules, inventory, expenses, routes and notes are written to your device’s local storage and remain readable offline. We cannot see them.
fieldBB has no passwords. Your account is a cryptographic key pair created on
your device (a Nostr key). The public half — an npub — identifies
you to teammates and is stored on our infrastructure when you use a shared
feature. The private half never leaves your device except into a backup you
explicitly choose to make.
| Data | Why it leaves the device |
|---|---|
| Username claim (your handle ↔ your npub) | So teammates can find you by name. |
| Team membership, shared contacts, shared calendar events, notifications | So the people you share with, and your other devices, can see them. |
| Direct messages | Relayed end-to-end encrypted. We cannot read them. |
| Feedback and crash reports you send | So they can be read and fixed. A crash report carries the error, a short technical stack, the app version, a device description (e.g. “iPhone 18 · Safari”), the screen you were on and your npub. It does not carry your contacts or notes. |
| Approximate technical logs at the hosting layer (IP address, timestamp, request) | Ordinary server operation and abuse prevention. Kept short-term by the hosting providers. |
No advertising identifiers, no cross-site tracking, no analytics profiling, no location history sent to us (route features run on your device and use the map provider you choose), no reading of your Google Drive files or email.
Where the EU/UK GDPR applies, these are the legal bases:
| Purpose | Basis |
|---|---|
| Providing the app, syncing your own data across your devices, team features you use | Contract — Art. 6(1)(b): you cannot have the service without them. |
| Connecting Google Calendar, Google Drive backup or Google sign-in | Consent — Art. 6(1)(a): each is off until you turn it on, and can be withdrawn at any time. |
| Keeping the service secure, preventing abuse, fixing crashes | Legitimate interests — Art. 6(1)(f): running a service that works and is not abused, balanced against the minimal data used. |
| Meeting legal obligations when they arise | Legal obligation — Art. 6(1)(c). |
Withdrawing consent does not affect what was lawful before you withdrew it.
Every Google feature is optional and off until you enable it. fieldBB requests the narrowest permission that makes each one work.
| Feature | Permission requested | What it is used for |
|---|---|---|
| Sign in with Google | openid, email, profile |
To show who is signed in, suggest a username and show your picture. Displayed on your device. |
| Account-key backup | drive.appdata |
To store an encrypted backup of your account key in a private folder of your own Drive that only fieldBB can see. fieldBB cannot see, list or open any other file in your Drive. |
| Calendar sync | calendar.events,calendar.calendarlist.readonly |
To create and update, in the calendar you choose, the activities you schedule in fieldBB, and to bring your changes back. The calendar list is read only so you can pick one. |
What is written to your calendar: the contact’s name, the activity type, the account or facility, the address, the territory when there is one, and an operational note. Notes that read as clinical are removed before sending — patient information, diagnoses, prescribing, dosages, adverse reactions, sample counts, formulary status and laboratory results, in English or Spanish — and stay in fieldBB.
Tokens. Google access tokens are held in your browser’s memory for the duration of your session. They are never written to disk, never synced, and never sent to any fieldBB server. fieldBB stores no long-lived Google credential — there is no refresh token, by design.
Limited Use. fieldBB’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: Google user data is used only to provide or improve the user-facing features described above; it is not transferred to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition with notice to users; it is never used for advertising; it is never sold; and no human reads it except with your explicit consent, for security purposes, to comply with applicable law, or where the data is aggregated and anonymised for internal operations.
fieldBB does not use Google user data to train generalised machine-learning or artificial-intelligence models.
fieldBB sets no advertising or tracking cookies. It uses your
browser’s localStorage and IndexedDB to hold your work
and your settings on your own device, and a session token so the server knows a
request is yours. These are strictly necessary for the app to function and are
not shared with anyone. Clearing your browser’s site data erases them — and, if
you have no backup, erases your work with them.
Information is disclosed only where a feature requires it:
We do not sell personal information, and we do not share it for cross-context behavioural advertising — as those terms are defined by the California Consumer Privacy Act — and we have not done so in the preceding twelve months.
The providers above may process data outside your country, including in the United States. Where the GDPR applies, such transfers rely on the European Commission’s Standard Contractual Clauses or an adequacy decision. You may ask us which apply to a given provider.
| Data | Retention |
|---|---|
| Everything on your device | Until you delete it, erase the device from the account menu, or clear your browser. |
| Username claim, teams, shared records | Until you delete the item, leave the team, or ask us to delete your account. |
| Feedback and crash reports | Up to 24 months, or until the issue they describe is resolved and released. |
| Hosting logs | Short-term, per the hosting providers’ own retention. |
| Records we must keep by law | For the period the law requires. |
Traffic is encrypted in transit (TLS). Messages between users are end-to-end encrypted, so we cannot read them. The key backup in your Drive can be protected with a passphrase that fieldBB never transmits. Access to the hosted database is restricted per user by row-level security policies, so one user cannot read another’s rows. Administrative actions are logged.
No system is perfectly secure, and we do not claim otherwise. If a breach occurs that is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours where the GDPR requires it, and notify affected users without undue delay.
If you find a vulnerability, please write to drcesarluisvalladares@gmail.com before disclosing it publicly. Good-faith research reported this way will not be pursued.
Wherever you are, you can do most of this yourself, immediately:
Where the GDPR or UK GDPR applies you also have the right to access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interests, and to withdraw consent. Where the CCPA applies you have the right to know, delete, correct, and to opt out of sale or sharing — which is moot here, because we do neither.
To exercise any right that you cannot exercise in the app, write to drcesarluisvalladares@gmail.com. We answer within 30 days (45 for CCPA requests, extendable once with notice). We may need to verify that the request is yours — usually by asking you to send it from the address linked to your account or to prove control of your npub. We will not discriminate against you for exercising a right.
One limit we cannot get around, and will not pretend otherwise. Data that lives only on your device is not something we can access, produce or delete for you — we have no copy. Requests about that data can only be answered by you, on your device. Equally, records already shared into a team, or published to a public Nostr relay, may persist with the people or relays that received them.
When you record a healthcare professional, a colleague or any other person in fieldBB, you are processing their personal data and you — or your employer — are the controller of it. You are responsible for having a lawful basis to do so, for telling them when the law requires it, and for honouring their rights. fieldBB never contacts the people in your contact list, never markets to them, and never uses their data for anything except showing it back to you and to the teammates you shared it with.
If one of them contacts us directly, we will refer them to you and assist you in responding, as a processor should.
fieldBB is not designed, offered or certified to hold protected health information, and no Business Associate Agreement is available. It is a tool for organising commercial field work — who you visited, when, where and what it cost. Do not record patient-identifiable information in it. The calendar integration actively strips clinical language before anything is sent, but that is a safety net, not a licence.
fieldBB is a professional tool, is not directed at children, and is not knowingly provided to anyone under 16 (or under 13 where that is the applicable threshold). If we learn that a child has created an account, we will delete it.
fieldBB makes no automated decision that produces legal effects concerning you or similarly significantly affects you. Its suggestions — route order, who to visit next — are proposals you accept or ignore.
If this policy changes materially, the version and date at the top change, the app’s release notes say so, and — for changes that require it — we ask for consent again. Continuing to use fieldBB after a change means accepting the updated policy.
drcesarluisvalladares@gmail.com
If you are in the EEA or the UK and believe your data has been mishandled, you may also complain to your national data-protection supervisory authority. We would rather you told us first, so we can fix it.
Versión 2 · En vigor desde el 31 de agosto de 2026 · Versión anterior: 30 de agosto de 2026
Esta política explica qué hace fieldBB («Field Business Book», el «Servicio»), en fieldbb.com, con la información: la tuya y la de las personas que registras en él. Está escrita para leerse, no para sobrevivirla.
En resumen. fieldBB funciona primero sin conexión: tu trabajo se guarda en tu propio dispositivo. No se vende nada, nada alimenta publicidad y nadie de fieldBB lee tus notas. Donde fieldBB habla con Google —inicio de sesión, calendario, copia de la clave— usa solo tu propia cuenta, solo para la función que hayas activado y solo mientras la mantengas conectada. El texto clínico se elimina antes de que nada llegue a un calendario.
fieldBB lo opera César Luis Valladares («el operador»), desarrollador individual, que es el responsable del tratamiento de la información descrita en el punto 3 como datos de cuenta y de servicio. Contacto para cualquier asunto de esta política, incluidos los derechos: drcesarluisvalladares@gmail.com.
fieldBB guarda dos clases de información y nuestro papel es distinto en cada una. La distinción es jurídica, no decorativa:
En tu dispositivo, no en nuestros servidores: contactos, visitas, comidas, agenda, inventario, gastos, rutas y notas se escriben en el almacenamiento local y siguen disponibles sin conexión. No podemos verlos.
Identidad: fieldBB no usa contraseñas. Tu cuenta es un par de
claves criptográficas creado en tu dispositivo. La parte pública —el
npub— te identifica ante tus compañeros y se guarda en nuestra
infraestructura cuando usas una función compartida. La privada no sale de tu
dispositivo salvo hacia una copia que decidas hacer tú.
Lo que sí sale del dispositivo: el nombre de usuario (para que te encuentren), la pertenencia a equipos y lo que compartes, los mensajes (cifrados de extremo a extremo, ilegibles para nosotros), los comentarios e informes de fallo que envías —un informe de fallo lleva el error, una traza técnica corta, la versión, una descripción del dispositivo, la pantalla en la que estabas y tu npub; no lleva tus contactos ni tus notas— y los registros técnicos normales del alojamiento (IP, fecha, petición).
Lo que no se recoge: identificadores publicitarios, rastreo entre sitios, perfiles analíticos, historial de ubicación enviado a nosotros, ni lectura de tus archivos de Drive o tu correo.
Retirar el consentimiento no afecta a lo que fue lícito antes de retirarlo.
Toda función de Google es opcional y está apagada hasta que la actives. Se pide el permiso más pequeño que la hace funcionar:
openid,
email, profile): tu correo, tu nombre y tu foto,
para mostrar quién ha entrado y sugerirte un nombre de usuario.drive.appdata): una carpeta
privada de tu Drive que solo fieldBB puede ver. No podemos ver, listar ni
abrir ningún otro archivo tuyo.calendar.events,
calendar.calendarlist.readonly): crear y actualizar en el
calendario que elijas las actividades que programas, y traer de vuelta tus
cambios. La lista de calendarios se lee solo para que elijas uno.Lo que se escribe en tu calendario: nombre del contacto, tipo de actividad, centro, dirección, territorio cuando lo hay y una nota operativa. Las notas que suenan clínicas se eliminan antes de enviar —información de pacientes, diagnósticos, prescripción, dosis, reacciones adversas, conteo de muestras, formularios terapéuticos, resultados de laboratorio— y se quedan en fieldBB.
Tokens: viven en la memoria del navegador durante la sesión. No se escriben en disco, no se sincronizan y no llegan a ningún servidor de fieldBB. No existe ningún token de larga duración, por diseño.
Uso Limitado. El uso y la transferencia por parte de fieldBB de la información recibida de las API de Google hacia cualquier otra aplicación se ajustarán a la Política de Datos de Usuario de los Servicios de API de Google, incluidos los requisitos de Uso Limitado. En concreto: los datos se usan solo para prestar o mejorar las funciones descritas; no se transfieren a terceros salvo lo necesario para prestarlas, por obligación legal o en una fusión o adquisición con aviso a los usuarios; nunca se usan para publicidad; nunca se venden; y ninguna persona los lee salvo con tu consentimiento expreso, por seguridad, por obligación legal o de forma agregada y anonimizada. Tampoco se usan para entrenar modelos generales de inteligencia artificial.
fieldBB no pone cookies de publicidad ni de rastreo. Usa
localStorage e IndexedDB para guardar tu trabajo y tus
ajustes en tu dispositivo, y un token de sesión para que el servidor sepa que la
petición es tuya. Son estrictamente necesarios y no se comparten. Borrar los datos
del sitio los elimina —y, si no tienes copia, elimina tu trabajo con ellos.
Solo donde una función lo exige: tus compañeros, respecto de lo que compartes; los encargados que actúan siguiendo nuestras instrucciones (Hostinger como alojamiento, Supabase como base de datos, relés Nostr públicos para mensajes cifrados y registros compartidos, y —solo si lo activas— el proveedor del asistente de notas para el texto que le envías); Google, para lo del punto 5 y dentro de tu propia cuenta; cuando la ley lo exija o para defender acciones legales; y un eventual sucesor si el Servicio se transfiere, con aviso y sin rebajar estas protecciones.
No vendemos información personal ni la compartimos para publicidad conductual entre contextos, en el sentido de la CCPA de California, y no lo hemos hecho en los últimos doce meses.
Los proveedores anteriores pueden tratar datos fuera de tu país, incluido Estados Unidos. Cuando aplica el RGPD, esas transferencias se amparan en las Cláusulas Contractuales Tipo de la Comisión Europea o en una decisión de adecuación. Puedes preguntarnos cuál corresponde a cada proveedor.
Lo de tu dispositivo, hasta que lo borres tú. El nombre de usuario, los equipos y lo compartido, hasta que borres el elemento, salgas del equipo o pidas la supresión de la cuenta. Los comentarios e informes de fallo, hasta 24 meses o hasta que se resuelva lo que reportan. Los registros de alojamiento, el plazo corto de cada proveedor. Y lo que la ley obligue a conservar, mientras obligue.
El tráfico va cifrado (TLS). Los mensajes entre usuarios son cifrados de extremo a extremo. La copia de la clave en tu Drive puede protegerse con una frase de paso que fieldBB nunca transmite. El acceso a la base de datos está restringido por usuario mediante políticas a nivel de fila. Las acciones administrativas quedan registradas.
Ningún sistema es perfecto y no pretendemos lo contrario. Si ocurre una brecha que probablemente entrañe un riesgo para tus derechos, lo notificaremos a la autoridad de control competente en 72 horas cuando el RGPD lo exija, y a los usuarios afectados sin dilación indebida.
Si encuentras una vulnerabilidad, escribe a drcesarluisvalladares@gmail.com antes de publicarla. La investigación de buena fe comunicada así no será perseguida.
Casi todo lo puedes hacer tú mismo, ahora: desconectar Google en Ajustes › Integraciones; revocar el acceso en myaccount.google.com/permissions; exportar todo desde Ajustes › Datos y sincronización —que es tu derecho de portabilidad, sin pedirle permiso a nadie—; y borrar este dispositivo desde el menú de cuenta.
Cuando aplica el RGPD tienes además derecho de acceso, rectificación, supresión, limitación, portabilidad, oposición al tratamiento basado en interés legítimo y a retirar el consentimiento. Cuando aplica la CCPA, derecho a saber, suprimir, corregir y a oponerte a la venta o cesión —que aquí es irrelevante, porque no hacemos ninguna de las dos.
Para ejercer lo que no puedas hacer en la app, escribe a drcesarluisvalladares@gmail.com. Respondemos en 30 días (45 para solicitudes CCPA, prorrogables una vez con aviso). Puede que necesitemos verificar que la solicitud es tuya. No te trataremos peor por ejercer un derecho.
Un límite que no podemos sortear, y no vamos a fingir que sí. Los datos que viven solo en tu dispositivo no podemos consultarlos, entregarlos ni borrarlos: no tenemos copia. Esas solicitudes solo puedes atenderlas tú, en tu dispositivo. Igualmente, lo ya compartido con un equipo o publicado en un relé Nostr público puede permanecer en poder de quien lo recibió.
Cuando registras a un profesional sanitario, a un colega o a cualquier otra persona en fieldBB, estás tratando sus datos personales y tú —o tu empresa— sois el responsable. Te corresponde tener una base legal para hacerlo, informarles cuando la ley lo exija y atender sus derechos. fieldBB nunca contacta a las personas de tu lista, nunca les hace marketing y nunca usa sus datos para nada que no sea mostrártelos a ti y a quien tú compartas. Si alguna nos escribe directamente, la remitiremos a ti y te ayudaremos a responder, como corresponde a un encargado.
fieldBB no está diseñado, ofrecido ni certificado para contener información de salud protegida, y no hay Business Associate Agreement disponible. Es una herramienta para organizar trabajo comercial de campo: a quién visitaste, cuándo, dónde y cuánto costó. No registres en ella información identificable de pacientes. La integración de calendario elimina activamente el lenguaje clínico, pero eso es una red de seguridad, no un permiso.
fieldBB es una herramienta profesional, no está dirigida a menores y no se presta a sabiendas a menores de 16 años (o de 13 donde ese sea el umbral aplicable). Si sabemos que un menor ha creado una cuenta, la borraremos.
fieldBB no toma decisiones automatizadas que produzcan efectos jurídicos sobre ti o te afecten significativamente. Sus sugerencias —orden de ruta, a quién visitar— son propuestas que aceptas o ignoras.
Si esta política cambia de forma sustancial, cambian la versión y la fecha de arriba, las notas de versión lo dicen y, cuando corresponda, se vuelve a pedir el consentimiento.
drcesarluisvalladares@gmail.com
Si estás en el EEE o el Reino Unido y crees que se han tratado mal tus datos, puedes reclamar ante tu autoridad de control nacional. Preferimos que nos lo digas antes, para poder arreglarlo.