Anamoris

Privacy Policy

Version 1.1 · Effective 2 August 2026

Anamoris holds medical documents, which is about as sensitive as personal data gets. This policy sets out exactly what is collected, what leaves your device, who else processes it, how long it is kept, and how to have it erased.

1. Who is responsible

FINGERS YODA SP. Z O.O., Ostrobramska 101a/301, 04-041 Warszawa, Poland (“Anamoris”, “we”) is the controller of the personal data described in this policy.

Contact for any privacy matter, including the rights in section 10: support@anamoris.com.

We are established in Poland, so no Article 27 representative is required. Privacy questions go to the address above.

2. What we collect

Anamoris does not ask for your name, email address, date of birth, phone number or any government identifier. There is no sign-up form. The categories below are everything.

CategoryExamplesWhere it lives
Documents you add Scans, photographs and PDFs of laboratory reports, visit notes, referrals, discharge summaries and prescriptions Your device only, in protected app storage. A temporary copy is sent for reading — see section 4.
Health information you or the app records Document titles and types, sample and visit dates, laboratory marker names, values, units, reference ranges, your corrections, notes and reminders Your device, and mirrored to our backend so it survives losing the device
Account identifier A randomly generated anonymous user ID issued by Firebase Authentication Our backend
Subscription status Whether an entitlement is active, in trial, in grace period or expired, and the store it came from. Not your payment card, which we never see. RevenueCat and our backend
Device and diagnostic data App version, build number, device language, push notification token, crash reports and technical error codes Our backend and our diagnostics provider
Product analytics That an event occurred and a fixed set of technical properties — document type code, page count, result count, paywall placement, error category, entitlement state Our analytics provider
Attribution data Install source, campaign identifiers and device identifiers, including the Apple advertising identifier only if you permit tracking AppsFlyer

3. Why, and on what legal basis

Where the UK GDPR or EU GDPR applies, our legal bases are as follows.

PurposeDataLegal basis
Storing your archive and making it available across a reinstall Health information, account identifier Contract (Art. 6(1)(b)) and your explicit consent for health data (Art. 9(2)(a))
Reading a document with AI when you ask Document pages Contract (Art. 6(1)(b)) and your explicit consent (Art. 9(2)(a))
Providing and enforcing subscriptions Account identifier, subscription status Contract (Art. 6(1)(b))
Keeping the app working and secure Device and diagnostic data Legitimate interests (Art. 6(1)(f)) — running a reliable, secure service
Understanding how the app is used Product analytics Legitimate interests (Art. 6(1)(f)). No health data is included.
Measuring which campaigns bring installs Attribution data Consent (Art. 6(1)(a)) where tracking permission is granted; otherwise legitimate interests limited to non-tracking measurement

You may withdraw consent at any time by deleting your account, which erases the data described in section 8. Withdrawal does not affect processing carried out beforehand.

4. Health data

Where your documents are stored

Every file you scan or import is copied into protected storage on your device and read from there. The app functions offline. Original files are not uploaded to our backend as part of ordinary use and are not part of the archive backup.

What happens when you ask for a document to be read

When — and only when — you tap to analyse a document:

  1. A temporary copy of that document's pages is uploaded to a private, per-user location in Google Cloud Storage that no other user can access.
  2. Our backend passes the pages to OpenAI, which extracts the printed values.
  3. The temporary copy is deleted as soon as the reading finishes, whether it succeeded or failed.
  4. The extracted values are shown to you as a draft. Nothing enters your archive until you review and confirm it.

Your documents are not used to train any AI model, by us or by our provider. Extraction is performed under a zero-retention arrangement with the provider.

Accuracy

Automated extraction can be wrong. This is why every reading is presented to you for review before it is saved, and why the original document is always kept and viewable. Anamoris is a record-keeping tool, not a diagnostic one.

5. What we never do

No filename, document text, extracted text, summary, marker name, marker value, comment, prescription or diagnosis ever reaches our analytics, our crash reports, or any advertising or attribution service.

This is enforced in the software, not only in this policy. Analytics events can carry only a fixed, allow-listed set of technical properties, and anything else is discarded before sending. Crash reports are stripped of file paths, query strings and free text. Both rules are covered by automated tests that run on every change.

We do not sell personal information. We do not share it for cross-context behavioural advertising. We do not use health data for advertising, marketing, or data mining, and we do not disclose it to data brokers or to any third party for their own purposes.

6. Who else processes it

We use the following processors. Each acts on our instructions under a data processing agreement.

ProcessorPurposeData receivedLocation
Google (Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions) Anonymous sign-in, archive backup, temporary document handling, backend processing Anonymous account ID, health information, temporary document copies European Union and United States
OpenAI Reading documents you submit for analysis The pages of that document United States
RevenueCat Subscription management and entitlement verification Anonymous account ID, purchase and subscription status United States
AppsFlyer Install attribution and campaign measurement Device and campaign identifiers. No health data. European Union and United States
Expo Delivering push notifications A device push token and generic notification text United States
Apple App distribution and payment processing Purchase records. Apple is an independent controller for payment data. Global

We may also disclose data where legally required, to establish or defend legal claims, or in connection with a merger or acquisition — in which case this policy continues to apply until you are told otherwise.

7. International transfers

Some processors are located outside the UK and European Economic Area, as shown above. Where data is transferred there, we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with the supplementary measures described in section 9. A copy of the relevant safeguards is available on request from support@anamoris.com.

8. How long it is kept

DataRetention
Documents on your deviceUntil you delete them or delete the app
Health information in the archive backupUntil you delete the document or your account
Temporary document copies during a readingDeleted immediately after the reading completes or fails
Extraction drafts you never confirmedUp to 30 days
Anonymous account and subscription recordsUntil account deletion; subscription records may be retained where required for tax and accounting purposes
Push notification tokensUntil deregistered, invalidated by the provider, or account deletion
Crash reports and technical logsUp to 30 days
Product analyticsUp to 30 days

9. Security

No system is perfectly secure. If a breach affects your data and is likely to result in a risk to you, we will notify you and the relevant supervisory authority as the law requires.

10. Your rights

Subject to local law, you may:

Because accounts are anonymous, we may be unable to identify which records are yours from an email alone. Requests made from within the app, which carries your account identifier, can always be honoured.

11. Tracking and advertising

On first launch, iOS asks whether Anamoris may track you across other companies' apps and websites. We ask once and record your answer.

No health data is included in attribution or analytics under either choice.

12. Children

Anamoris is intended for people aged 16 and over. We do not knowingly collect data from children below that age. If you believe a child has provided us data, contact support@anamoris.com and we will delete it.

13. Regional disclosures

California

In the last 12 months we collected the categories in section 2, including medical information and identifiers, for the purposes in section 3. We have not sold personal information and have not shared it for cross-context behavioural advertising. California residents may request access, deletion, correction and portability, and may not be discriminated against for exercising those rights.

Health-specific United States laws

Anamoris is a consumer product. We are not a covered entity or business associate under HIPAA, and this policy — not HIPAA — governs your data. Where state consumer health privacy laws apply, such as the Washington My Health My Data Act, we collect and process consumer health data only with your consent and for the purposes described here, and you may withdraw that consent by deleting your account.

Automated decision-making

Extraction reads printed values from a document. It does not evaluate you, make decisions about you, or produce legal or similarly significant effects, and no result is saved without your review.

14. Changes and contact

If this policy changes in a way that affects how your information is handled, we will notify you in the app before the change takes effect. The version and date at the top of this page always reflect the current text.

Contact: support@anamoris.com