Operation Outbreak

Privacy Policy

Operation Outbreak Mobile App Privacy Policy

Last Updated: August 17, 2026

About this policy

Operation Outbreak is an educational app built around an experiential outbreak simulation. You take part in a simulated disease outbreak using Bluetooth on your phone or tablet. This policy covers the Operation Outbreak mobile app and our web-based outbreak tools, including Outbreak Creator, Outbreak Visualizer, and Outbreak Lookout. When this policy says “the app,” that includes these tools unless we say otherwise. This policy explains what data the app collects, why we collect it, who can see it, and the choices and rights you have. We have written it in plain language so students, parents, teachers, and other user groups can understand it. Please read it with care.

The short version for students

We never learn your name. The app gives your device a random ID and tracks your virtual infection through that ID, not through you. We use the data to run the simulation and to study how outbreaks spread. Surveys are always optional. We never show you ads and we never sell your data. You can ask us to delete your data anytime at welcome@operationoutbreak.org.

Who can use the app

Operation Outbreak is designed for users aged 13 and older. Do not use the app if you are under 13.

If you are in India, the app is intended for users aged 18 and older; younger users may take part only with verifiable consent from a parent or guardian, as required by applicable law. 

If we learn that a child under 13 has provided personal data through the app, we will delete that data promptly. If you believe this has happened, contact us at welcome@operationoutbreak.org.

Who we are

The organization responsible for your data (the “data controller”) is Operation Outbreak, Inc., a nonprofit corporation based in Boston, Massachusetts, United States. You can reach us at welcome@operationoutbreak.org or 361 Newbury St, 5th Floor, Boston, MA 02115.

Our representative in the European Union under Article 27 of the GDPR is VeraSafe Czech Republic s.r.o., Rohanské nábřeží 678/23, Prague 8, 18600, Czech Republic; privacy_notice@verasafe.com

Our privacy contact and Data Protection Officer, who also serves as our encarregado for Brazil under the LGPD, is Kian Sani, privacy@operationoutbreak.org.

A note on “anonymous” and “pseudonymous”

We designed the app to avoid collecting names, email addresses, and other direct identifiers from players. But most data in the app is linked to a random ID we assign to your device (see “UUID” below). Under laws like the GDPR, data linked to such an ID still counts as personal data, because in theory it could be connected back to a person. So we call that data “pseudonymous,” not “anonymous.” We only use the word “anonymous” for data that has been combined or stripped down so that no single person can be picked out. This honest wording matters, and it shapes the protections we apply.

What data we collect

The app collects the following, all linked to your random UUID unless stated otherwise:

  • Proximity data. Bluetooth records of close-contact events and how long they lasted between players.
  • UUID. A random 128-bit identifier assigned to your device. It is not your name, and we do not link it to your real identity. It is still treated as personal data.
  • Simulation data. Events in the game, such as your avatar’s health state and virtual pathogen spread.
  • Behavioral choice data. Time-stamped records of in-game decisions, such as spending virtual points on protective equipment.
  • Attitudinal survey data. Answers to short multiple-choice surveys about views on disease and prevention.  
  • App usage data. Counts such as sessions, duration, and use of features like help menus.
  • Environmental data. Non-identifying sensor readings, such as ambient light or temperature, used to study context.
  • System analytics. Diagnostic data such as crash reports and app-retention metrics, provided to us in aggregate by Apple and Google. Apple and Google collect this under their own privacy policies.
  • Organizer data. If you create or run simulations as an organizer, through the app or through tools like Outbreak Creator, we collect the account details you provide, such as your name, email address, organization, and the simulation settings you build. This data is linked to your organizer account, not to a player UUID.
  • Outbreak Lookout.  We offer an enhanced service with a free-text response section where users can enter notes about the events that occur in the simulation.   

We do not collect location data. On modern devices the app uses the Bluetooth permission for close-contact sensing. It does not need your location, and we do not store location.

Why we collect it and our legal basis

We rely on different legal bases for different purposes. Here is the plain-language version.

  • To run the simulation (proximity sensing, simulation state, gameplay, basic usage metrics): our legal basis is our legitimate interests in providing a working educational tool (GDPR Article 6(1)(f)). We have weighed this against your rights and use only the data the game needs.
  • To improve the app and fix problems (crash reports, retention metrics): our legitimate interests in maintaining a safe, reliable app (Article 6(1)(f)).
  • To confirm you are old enough to use the app: our legitimate interests in keeping the app age-appropriate, and compliance with the laws that require it.
  • To provide organizer accounts, run the simulations organizers set up, and offer support: performance of our agreement with the organizer (Article 6(1)(b)) and our legitimate interests in operating the program (Article 6(1)(f)).
  • For optional research and for attitudinal surveys: your consent (Article 6(1)(a)). You can take part or not, and you can withdraw at any time without losing access to the core game. Where we process data for research, we also apply the GDPR’s scientific-research safeguards (Article 89), including data minimisation and pseudonymisation.
  • Where the law requires us to act (for example, a valid legal order): compliance with a legal obligation (Article 6(1)(c)).

We do not use your data for advertising. We do not profile you to make automated decisions that have legal or similarly significant effects.

Artificial Intelligence

We use third-party large language model (LLM) services, accessed via the provider’s standard commercial API infrastructure, to help analyze simulation output data. Current providers include Anthropic (Claude API) and Google (Gemini API/Vertex AI). Only anonymized, aggregated results are submitted to these services––no raw simulation metadata, identifiers, or data capable of identifying an individual is ever transmitted. Under each provider’s standard commercial API terms, submitted data is not used to train their models.

Surveys and sensitive data

Our surveys are built to avoid special category data, such as data about your own health, under GDPR Article 9. If we ever needed to collect such data, we would first ask for your explicit consent and explain why.

How we collect it

  • Bluetooth sensing records the strength and duration of nearby signals.
  • Simulation logging captures in-game events through a secured connection.
  • In-app surveys record your multiple-choice answers and free-response responses.
  • Platform diagnostics come from Apple and Google in aggregate.

Children and schools

The app is for users aged 13 and older, and we do not knowingly collect personal data from anyone under 13. When schools run Operation Outbreak sessions, we work with high schools and other settings where participants are 13 or older, and we ask the school to confirm this before a session begins.

Users aged 13 to 17 get extra care. We collect only what the simulation needs. We do not use their data for advertising or profiling. For users in the United Kingdom, we follow the principles of the Age Appropriate Design Code, including high privacy by default.

Our optional surveys and research need consent. In some places, young people cannot give that consent themselves. For the EU, the age is 13 in Belgium, Denmark, Estonia, Finland, Latvia, Malta, Portugal, Sweden, 14 in Austria, Bulgaria, Cyprus, Italy, Lithuania, Spain. 15 in Greece, Czech Republic, and France and 16 in the Poland, Croatia, Germany, Hungary, Ireland, Luxembourg, Netherlands, Romania, Slovakia, Slovenia, 14 in Quebec and South Korea, and 18 in India. Where a user is below the local age, a parent or guardian must consent before the user takes part in surveys or research. 

If you believe a child under 13 has used the app and provided personal data, contact us at welcome@operationoutbreak.org and we will delete it promptly.

What we do with the data

The app is first an educational tool. It may also support research. We use pseudonymous data to summarize simulation events, analyze interaction and decision patterns, create visualizations such as outbreak graphs, and improve models of how outbreaks spread. We use survey answers to understand how knowledge and beliefs relate to behavior. We publish or share research findings in aggregate form that does not identify individuals. We do not sell or rent your data.

Who has access to the data

We share data only with trusted partners who help us run the app and the research, under contracts that require them to protect it:

  • The Broad Institute, Inc.: the originating institution of the Operation Outbreak project and publisher of the Operation Outbreak app.
  • NJI Media LLC: current developer partner of the app and website.
  • Amazon Web Services (AWS): encrypted cloud storage and hosting, acting as our processor.
  • Ben Fry, LLC (d/b/a Fathom Information Design): hosts outbreak-creation and visualization tools.
  • HubSpot, Inc.: Survey provider
  • Google, Inc’s Workspace:  Survey provider 

We store data in AWS using server-side encryption (SSE-S3 or AWS KMS) in Google Workspace using Google-managed encryption at rest, and anonymous in-app survey data in HubSpot using AES-256 encryption at rest. We may disclose data if the law validly requires it, and we will limit any such disclosure to what is required.

Where your data is stored and international transfers

Our servers and infrastructure are in the United States. If you use the app from outside the United States, your data is transferred to and stored in the US.

 

For users in the European Economic Area, Switzerland and the United Kingdom, we protect these transfers using Standard Contractual Clauses approved by the European Commission, together with the UK and Swiss Addendum. We have assessed the transfer and applied safeguards such as encryption and access controls. You can ask us for a copy of the relevant safeguards using the contact details above.

For users in other countries with transfer rules, such as Brazil, South Korea, Japan, China, India, South Africa and Canada (including Quebec), we apply the transfer protections required by local law. 

How long we keep data

We keep pseudonymous data only as long as we need it for the educational and research purposes described here, or as the law requires. Raw proximity and gameplay logs are deleted or de-identified within five (5) years of a simulation, and aggregated research outputs may be kept indefinitely. When we no longer need data in identifiable form, we securely delete it or turn it into truly anonymized data.

Your rights

Depending on where you live, you have some or all of these rights:

  • Access the data we hold about you.
  • Correct data that is wrong.
  • Delete your data.
  • Restrict or object to how we use it.
  • Receive your data in a portable format.
  • Withdraw consent at any time, where we rely on consent, without affecting past processing.
  • Lodge a complaint with your data protection authority. In the EU this is your national supervisory authority. In the UK it is the Information Commissioner’s Office. In Brazil it is the ANPD.

Because most player data is keyed only to a random UUID, we may need your avatar name, which links to that ID, so we can find your records. You can see your avatar name in the app by tapping the Info tab. Some research rights may be limited where the law allows, for example where honoring a request would seriously impair a research project, as permitted under GDPR Article 89. To exercise any right, contact us at welcome@operationoutbreak.org. 

We aim to respond within one month.

Do you have to provide data?

The simulation needs proximity and gameplay data to work. If you do not want that data collected, you can choose not to use the app. Research participation and surveys are always optional.

How we protect your data

We use random UUIDs instead of names, encrypt data in transit and at rest, store data on access-controlled servers, and collect only what we need. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority and, where required by law, affected individuals without undue delay, consistent with Articles 33 and 34 of the GDPR.

Changes to this policy

We may update this policy. If we make a significant change, we will update the “Last updated” date at the top and, where appropriate, provide a clearer notice in the app. We will not rely on your silence or continued use as consent where the law requires us to obtain fresh consent.

Contact us

Email privacy@operationoutbreak.org
361 Newbury St
5th Floor
Boston, MA 02115
USA