Privacy

Privacy Policy

AI Health Records is designed to keep your confirmed health-record history on your phone unless you deliberately use an online feature.

Operator: NEXTB LTD · Draft updated 4 August 2026

1. Scope and who controls the data

This policy explains how NEXTB LTD handles information in AI Health Records on Android and iOS, the secure report viewer, support channels, and account-deletion service.

Questions about privacy can be sent to privacy@nextb.uk. The final registered address, launch jurisdictions, and any jurisdiction-specific rights notice will be added after legal review and before activation.

2. Data that stays on your device

3. Optional AI recognition

AI recognition is optional. Before the first request, the app names the active provider and asks for separate consent. Manual entry remains available.

The app crops the meter display, resizes and re-encodes it, and removes photo metadata before it sends the temporary image through a first-party Cloudflare Worker to the configured multimodal model. The request does not include your name, email, notes, full record history, Apple Health or Health Connect history, access codes, or account token.

The model returns a candidate only. Nothing becomes a formal record or health-platform entry until you review, edit if necessary, and explicitly save it. The first-party service does not write recognition images to D1, R2, Cache, or Queue. Final wording about Cloudflare platform logs, model abuse monitoring, processing regions, and retention remains subject to provider and legal review.

4. Accounts, device trust, and secure sharing

An account is needed only for cloud features such as creating and managing secure links or deleting cloud-account data. Authentication may use Apple, Google, or a separately invited account. We store provider-scoped irreversible identifiers and bounded session information, not your provider password.

Device-attestation information may be used to protect paid and online features from abuse. This can include an app installation identifier, app package or bundle version, integrity verdicts, and security counters. It is not used for advertising.

A secure link contains only the records and context you select. The snapshot is encrypted before storage. A recipient may keep a copy by screenshot, download, print, or another method; revoking the link prevents later service access but cannot erase copies already made by a recipient.

5. Purchases, analytics, and diagnostics

Apple or Google processes payment details. We receive the product, transaction or purchase-token identifiers, subscription state, and minimum information needed to validate and restore access. We do not receive your card number or bank details.

Product analytics is disabled unless the product clearly asks for separate consent and the service is enabled. If enabled, only allowlisted product-interaction events and short-lived random event identifiers may be accepted; health values, photos, notes, account IDs, device IDs, stable session IDs, and advertising identifiers are prohibited.

Security and operational logs may contain request timing, coarse result codes, model/configuration versions, and abuse-prevention information. They must not contain raw health images, readings, access codes, passwords, or bearer tokens.

6. Purposes and choices

We process information to provide the feature you request, protect accounts and services, validate subscriptions, operate secure sharing, respond to support requests, and meet legal obligations. Optional AI and optional analytics use separate controls and are not bundled with health-platform permission.

You can use manual entry, local history, trends, local reports, export, and local deletion without an online account. You can withdraw AI consent in the app; this stops future AI requests and does not delete local records.

7. Retention and deletion

Cloud-account deletion does not remove local records, health-platform entries, exported files, recipient copies, or an Apple/Google subscription. Those are controlled separately. See Delete cloud account.

8. Service providers and international processing

Cloudflare provides the first-party edge, D1/R2, service bindings, and—when activated—the selected Workers AI model. Apple and Google provide authentication, app distribution, purchases, and their health platforms as applicable. Providers process only the information needed for the relevant function under their own platform terms and our configuration.

Cloud services may process information in more than one country. We will not claim US-only or UK-only processing unless the exact production configuration and contract evidence prove it. Required transfer safeguards and regional disclosures will be finalized before public activation.

9. Security, children, and changes

We use transport encryption, bounded requests, encrypted secure-link payloads, session revocation, rate limits, device integrity checks, least-privilege service bindings, and redacted logs. No internet service can guarantee absolute security.

AI Health Records is not directed to children. The final minimum age and jurisdiction-specific child policy require legal confirmation before release.

Material policy changes will be dated here and, when appropriate, shown in the app before the changed processing begins.

Need help or want to exercise a privacy right?

Email privacy@nextb.uk. Do not include health readings, meter photos, passwords, access codes, or payment details in email.