Legal & Privacy

Terms & Conditions

Policies governing MetroPCR and MetroRMS products and services from Saffire Software Inc.

iOS Policy

MetroRMS for iPad: Privacy Policy

Effective October 6, 2026 Saffire Software Inc.

MetroRMS for iPad ("the app") is used by emergency medical services and fire agency crews to document patient care reports and fire incident reports in the field. Saffire Software Inc. ("we," "us") provides the app to agencies that license the MetroRMS system. This policy explains what the app collects, why it collects it, and what happens to it.

Who is responsible for the data

The app works only with an account issued by an agency that licenses MetroRMS. Information a crew member enters in the app is collected on behalf of that agency, which controls who may access the records and how long they are kept. We host the agency's MetroRMS system and process the data on the agency's behalf under our agreement with it, including a business associate agreement that governs protected health information. For questions about a specific record, contact your agency.

What the app collects

DataWhy
Patient information entered by the crew: names, dates of birth, addresses, phone numbers, insurance details, medical history, assessments, vital signs, medications, procedures, signatures, and photos.To complete the agency's patient care and incident reports.
Crew member identity: name, email address, certification identifier, and the unit and shift selected at the start of a shift.To sign in and to record who provided care.
A device identifier generated by the app at registration.To register the iPad with the agency and keep it linked to the agency's server.
Location, only when a crew member uses a GPS field in a report and only while the app is in use.To record where an incident or transport occurred.
Camera, only when a crew member takes a report photo or scans a driver license or barcode. A license scan reads the barcode on the device and fills in the patient's name, address, and date of birth.To attach photos and to fill in patient details without typing.
Microphone, only when a crew member starts a Synapse dictation. Speech is converted to text on the iPad, and the audio never leaves the device.To fill in the report from dictation.
Bluetooth, only when a crew member connects a VitalStream monitor.To import vital signs from the monitor into the report.

The app does not collect data for advertising or tracking, contains no analytics or advertising software, and does not link data to you across other companies' apps or websites.

Where the data goes

Your agency's MetroRMS server. Reports, photos, signatures, and crew identity are sent over an encrypted (TLS) connection to your agency's MetroRMS server, which we host and operate on the agency's behalf. This server is the only destination for report data sent from the app. Each agency's data is kept separate from other agencies' data.

Services your agency has connected. Your agency may connect its MetroRMS server to computer-aided dispatch, medical device feeds, medication references, and an AI service that converts Synapse dictation transcripts into report entries. When Synapse is used, the transcript text is processed by the AI service your agency has configured. Ask your agency which services it has enabled.

We do not sell data. We do not share it with anyone other than your agency, the services it has chosen, and the infrastructure providers we use to host the MetroRMS system, except where required by law.

Data on the iPad

Reports remain on the iPad only until they have been sent to the agency's server and the server has confirmed receipt, after which they are removed from the device. All data the app stores is protected by iOS data protection (encrypted at rest). Patient information and other personal information stored by the app are excluded from iPad backups, as is the on-device speech model, which is downloaded again when needed. Deleting the app removes all of its data from the iPad.

Security

Connections to the agency's server use TLS. Passwords are never stored in plain text. A device must be registered with an agency-issued key before it can be used to sign in. Access to records on the server is controlled by your agency, and our staff access agency data only as needed to provide and support the service.

Your choices and rights

The app asks for permission the first time it needs location, camera, microphone, or Bluetooth access. You can turn any of these off in Settings → MetroRMS, and the related features will be unavailable until access is turned back on.

Accounts are created and removed by your agency's administrators. To access, correct, or delete records, or to close your account, contact your agency. Patients seeking access to their records should contact the agency that provided their care.

You may also contact us using the information below. We will refer requests about specific records to the responsible agency.

Children

The app is a professional tool for agency personnel and is not directed to children.

Changes

If this policy changes, the updated version will be posted on this page with a new effective date.

Contact

Saffire Software Inc.

Email: