Privacy Policy
At BP-AI, we are fully committed to protecting your health data privacy and ensuring complete transparency in how your information is handled. This Privacy Policy details the data collected by the BP-AI mobile application and how that data is processed, stored, and protected.
Important Disclosure: Your personal health records are stored directly inside your device's sandboxed local container. We do not host, access, see, or sell your blood pressure readings. Syncing with Apple Health (HealthKit) is optional and occurs only when you choose to enable it.
1. Data Collection & Processing
Our app processes data to help you scan, track, and log your blood pressure values. Here is how different categories of data are processed:
- Blood Pressure Readings: When you enter or scan readings, the numerical values (systolic, diastolic, and optional pulse) are stored directly inside Apple's local sandbox container on your device using SwiftData. We have no external backend database and cannot access these readings.
- Monitor Screen Photos (Camera/OCR): To use the camera scanner, you must grant Camera permissions. In order to extract your blood pressure values, you must explicitly consent to cloud OCR processing. With your consent, a cropped photo containing only your physical monitor display is transmitted securely over an encrypted HTTPS connection to BP-AI's Cloudflare Worker, which forwards it to Google Gemini (operated by Google LLC) strictly for OCR text recognition. No saved history, notes, or HealthKit data are ever sent. Images are processed ephemerally in memory and are immediately discarded; no photos are ever saved, stored, or logged on any servers. You can revoke your Cloud OCR consent at any time in Settings, or use Manual Entry to record values locally without sending any data.
- HealthKit Integration (Apple Health): If you choose to sync with Apple Health, the app will request write access through HealthKit to save systolic and diastolic blood pressure readings. Syncing only occurs upon your explicit consent. Your HealthKit data is never shared with third parties, data brokers, or advertising platforms.
- In-App Purchases (RevenueCat): We use RevenueCat to process subscription and lifetime entitlements. Your purchase details are validated via anonymous identifiers to check if you have unlocked Pro features.
2. Data Security & Storage
All data transmitted between the app and the AI processor is encrypted in transit using industry-standard Transport Layer Security (TLS/HTTPS). Personal records are stored in private directories on your device. Since we do not maintain accounts or server databases, your logs cannot be compromised in a server-side breach.
3. Data Deletion & Control
You have full ownership of your records. You can purge all records from the device sandboxed database instantly by using the "Delete Everything" button under the app settings menu. Deleting the application will also erase all local SwiftData logs.
4. Children's Privacy
Our services are not designed for or targeted at children under the age of 13. We do not knowingly collect personal details from children.
5. GDPR & CCPA Compliance
For users residing in the European Union (GDPR) and California (CCPA), your rights are fully respected:
- Right to Erasure: You can completely erase your data locally using the in-app deletion button.
- No Tracking: We do not track you across third-party websites or sell/share personal data.
- Ephemeral OCR Processing: Uploaded images are strictly used for real-time OCR extraction and are immediately discarded.
6. Contact Us
If you have any questions or feedback regarding this Privacy Policy or your data privacy, you can reach out directly to us at:
Support Email: bpaitracker@outlook.com