Privacy Policy
Version 1.1 · Effective 2 August 2026Anamoris holds medical documents, which is about as sensitive as personal data gets. This policy sets out exactly what is collected, what leaves your device, who else processes it, how long it is kept, and how to have it erased.
1. Who is responsible
FINGERS YODA SP. Z O.O., Ostrobramska 101a/301, 04-041 Warszawa, Poland (“Anamoris”, “we”) is the controller of the personal data described in this policy.
Contact for any privacy matter, including the rights in section 10: support@anamoris.com.
We are established in Poland, so no Article 27 representative is required. Privacy questions go to the address above.
2. What we collect
Anamoris does not ask for your name, email address, date of birth, phone number or any government identifier. There is no sign-up form. The categories below are everything.
| Category | Examples | Where it lives |
|---|---|---|
| Documents you add | Scans, photographs and PDFs of laboratory reports, visit notes, referrals, discharge summaries and prescriptions | Your device only, in protected app storage. A temporary copy is sent for reading — see section 4. |
| Health information you or the app records | Document titles and types, sample and visit dates, laboratory marker names, values, units, reference ranges, your corrections, notes and reminders | Your device, and mirrored to our backend so it survives losing the device |
| Account identifier | A randomly generated anonymous user ID issued by Firebase Authentication | Our backend |
| Subscription status | Whether an entitlement is active, in trial, in grace period or expired, and the store it came from. Not your payment card, which we never see. | RevenueCat and our backend |
| Device and diagnostic data | App version, build number, device language, push notification token, crash reports and technical error codes | Our backend and our diagnostics provider |
| Product analytics | That an event occurred and a fixed set of technical properties — document type code, page count, result count, paywall placement, error category, entitlement state | Our analytics provider |
| Attribution data | Install source, campaign identifiers and device identifiers, including the Apple advertising identifier only if you permit tracking | AppsFlyer |
3. Why, and on what legal basis
Where the UK GDPR or EU GDPR applies, our legal bases are as follows.
| Purpose | Data | Legal basis |
|---|---|---|
| Storing your archive and making it available across a reinstall | Health information, account identifier | Contract (Art. 6(1)(b)) and your explicit consent for health data (Art. 9(2)(a)) |
| Reading a document with AI when you ask | Document pages | Contract (Art. 6(1)(b)) and your explicit consent (Art. 9(2)(a)) |
| Providing and enforcing subscriptions | Account identifier, subscription status | Contract (Art. 6(1)(b)) |
| Keeping the app working and secure | Device and diagnostic data | Legitimate interests (Art. 6(1)(f)) — running a reliable, secure service |
| Understanding how the app is used | Product analytics | Legitimate interests (Art. 6(1)(f)). No health data is included. |
| Measuring which campaigns bring installs | Attribution data | Consent (Art. 6(1)(a)) where tracking permission is granted; otherwise legitimate interests limited to non-tracking measurement |
You may withdraw consent at any time by deleting your account, which erases the data described in section 8. Withdrawal does not affect processing carried out beforehand.
4. Health data
Where your documents are stored
Every file you scan or import is copied into protected storage on your device and read from there. The app functions offline. Original files are not uploaded to our backend as part of ordinary use and are not part of the archive backup.
What happens when you ask for a document to be read
When — and only when — you tap to analyse a document:
- A temporary copy of that document's pages is uploaded to a private, per-user location in Google Cloud Storage that no other user can access.
- Our backend passes the pages to OpenAI, which extracts the printed values.
- The temporary copy is deleted as soon as the reading finishes, whether it succeeded or failed.
- The extracted values are shown to you as a draft. Nothing enters your archive until you review and confirm it.
Your documents are not used to train any AI model, by us or by our provider. Extraction is performed under a zero-retention arrangement with the provider.
Accuracy
Automated extraction can be wrong. This is why every reading is presented to you for review before it is saved, and why the original document is always kept and viewable. Anamoris is a record-keeping tool, not a diagnostic one.
5. What we never do
No filename, document text, extracted text, summary, marker name, marker value, comment, prescription or diagnosis ever reaches our analytics, our crash reports, or any advertising or attribution service.
This is enforced in the software, not only in this policy. Analytics events can carry only a fixed, allow-listed set of technical properties, and anything else is discarded before sending. Crash reports are stripped of file paths, query strings and free text. Both rules are covered by automated tests that run on every change.
We do not sell personal information. We do not share it for cross-context behavioural advertising. We do not use health data for advertising, marketing, or data mining, and we do not disclose it to data brokers or to any third party for their own purposes.
6. Who else processes it
We use the following processors. Each acts on our instructions under a data processing agreement.
| Processor | Purpose | Data received | Location |
|---|---|---|---|
| Google (Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions) | Anonymous sign-in, archive backup, temporary document handling, backend processing | Anonymous account ID, health information, temporary document copies | European Union and United States |
| OpenAI | Reading documents you submit for analysis | The pages of that document | United States |
| RevenueCat | Subscription management and entitlement verification | Anonymous account ID, purchase and subscription status | United States |
| AppsFlyer | Install attribution and campaign measurement | Device and campaign identifiers. No health data. | European Union and United States |
| Expo | Delivering push notifications | A device push token and generic notification text | United States |
| Apple | App distribution and payment processing | Purchase records. Apple is an independent controller for payment data. | Global |
We may also disclose data where legally required, to establish or defend legal claims, or in connection with a merger or acquisition — in which case this policy continues to apply until you are told otherwise.
7. International transfers
Some processors are located outside the UK and European Economic Area, as shown above. Where data is transferred there, we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with the supplementary measures described in section 9. A copy of the relevant safeguards is available on request from support@anamoris.com.
8. How long it is kept
| Data | Retention |
|---|---|
| Documents on your device | Until you delete them or delete the app |
| Health information in the archive backup | Until you delete the document or your account |
| Temporary document copies during a reading | Deleted immediately after the reading completes or fails |
| Extraction drafts you never confirmed | Up to 30 days |
| Anonymous account and subscription records | Until account deletion; subscription records may be retained where required for tax and accounting purposes |
| Push notification tokens | Until deregistered, invalidated by the provider, or account deletion |
| Crash reports and technical logs | Up to 30 days |
| Product analytics | Up to 30 days |
9. Security
- Documents are held in the app's protected storage area on your device, covered by iOS file protection and your device passcode.
- All traffic between the app and our backend uses TLS.
- Backend records are access-controlled per user: security rules make one account's data unreadable to any other, and those rules are covered by automated tests.
- Provider credentials exist only on our servers and are never present in the app.
- Temporary upload locations are scoped to a single user and a single request, and are emptied when that request ends.
- Entitlement state is written only by our backend from a verified provider notification; the app cannot grant itself a subscription.
No system is perfectly secure. If a breach affects your data and is likely to result in a risk to you, we will notify you and the relevant supervisory authority as the law requires.
10. Your rights
Subject to local law, you may:
- Access the data we hold about you.
- Correct it — every extracted value is editable in the app.
- Erase it — see deleting your account. Deletion is immediate and self-service; you do not need to ask us.
- Export it — you can share or export any document from the app at any time.
- Restrict or object to processing based on legitimate interests.
- Withdraw consent at any time.
- Complain to your data protection authority. In the UK that is the ICO (ico.org.uk); in the EU it is the authority for your country.
Because accounts are anonymous, we may be unable to identify which records are yours from an email alone. Requests made from within the app, which carries your account identifier, can always be honoured.
11. Tracking and advertising
On first launch, iOS asks whether Anamoris may track you across other companies' apps and websites. We ask once and record your answer.
- If you allow it, AppsFlyer may use the Apple advertising identifier to attribute your install to a campaign.
- If you decline, no advertising identifier is used and installs are measured without one. Every feature of the app continues to work identically.
No health data is included in attribution or analytics under either choice.
12. Children
Anamoris is intended for people aged 16 and over. We do not knowingly collect data from children below that age. If you believe a child has provided us data, contact support@anamoris.com and we will delete it.
13. Regional disclosures
California
In the last 12 months we collected the categories in section 2, including medical information and identifiers, for the purposes in section 3. We have not sold personal information and have not shared it for cross-context behavioural advertising. California residents may request access, deletion, correction and portability, and may not be discriminated against for exercising those rights.
Health-specific United States laws
Anamoris is a consumer product. We are not a covered entity or business associate under HIPAA, and this policy — not HIPAA — governs your data. Where state consumer health privacy laws apply, such as the Washington My Health My Data Act, we collect and process consumer health data only with your consent and for the purposes described here, and you may withdraw that consent by deleting your account.
Automated decision-making
Extraction reads printed values from a document. It does not evaluate you, make decisions about you, or produce legal or similarly significant effects, and no result is saved without your review.
14. Changes and contact
If this policy changes in a way that affects how your information is handled, we will notify you in the app before the change takes effect. The version and date at the top of this page always reflect the current text.
Contact: support@anamoris.com