Privacy Policy
Working draft. This policy describes how the app is built today. It is waiting for review by a lawyer before the app is released in the app stores, and the wording may change after that review. When it changes, the app shows its agreement screen again.
Lines marked Aside are light remarks about how the app is built. They are not part of this policy and change nothing it says.
The short version
- Your health records, meals, symptoms, medicines, notes and everything else you enter stay on your device.
- If you turn on backup or sync, an encrypted copy goes to a cloud folder you choose, in your account (for example your OneDrive). We never see that folder or hold the password that opens it.
- There is no Inside Story account, no company server holding your health records, no advertising, no tracking and no selling or sharing of your data with anyone.
- A few lookups go out to public services, and each sends only what it needs: a barcode, a medicine name or code, a postal code, or a web address you pasted. They are listed below.
We built it so we could not look at your records even if we wanted to. We don't want to. Now we can't, which is better.
Who is responsible
Inside Story is made by an independent developer based in Mexico. Contact details for privacy questions and requests will be added here before the app is released in the stores.
What stays on your device
Everything you record lives in a database on the phone or computer you are using: food and meal logs, symptoms and flares, medicines and supplements, lab results, conditions you choose, notes, garden records, finances, routines, photos you attach, and your settings. Readings you allow from Android Health Connect (steps, sleep, weight and similar) are copied into that same database on the device. None of it is sent to us.
Deleting the app deletes this database. Because nothing is kept anywhere else unless you set up a backup, a lost device with no backup means lost records.
Backup and syncing between your devices
If you turn it on, the app saves an encrypted copy of your database to a folder you pick in your cloud storage. On a phone this goes through Microsoft's OneDrive service, signed in with your Microsoft account; on a computer it is the OneDrive folder on the disk. The copy is encrypted on your device with a password only you know, before it leaves. We cannot open it and cannot reset the password, which is why there is no "forgot password" option.
Beside the encrypted copy, a small plain file records which of your devices saved last and when. It holds no health information.
Nobody can reset your password, us included. Write it down somewhere other than the app it unlocks.
Your cloud provider's privacy terms apply to what is stored in your account.
Sharing with other people
You can connect with another person who uses the app, such as a partner, by sending an invitation they accept. Only what the connection is set up to share travels between you, and it is sealed on the sending device so that only the other person's device can open it. It can travel four ways:
- as a file you send yourself, through any app you choose;
- through a shared cloud folder;
- directly between two phones on the same Wi-Fi;
- through our relay at lifestead.ghostead.com, described next.
The relay. The relay is a mailbox that holds a sealed message until the other person's device collects it. It cannot open what it holds. It stores the sealed message, two anonymous key fingerprints (who it is for and who sent it), its size and when it arrived. A message is deleted when it is collected or after 30 days, whichever comes first. The relay runs on Cloudflare, which, like any web host, handles the network address your device connects from in order to deliver the request.
Think of a mail carrier who cannot read postcards, by design rather than by good manners.
What the app sends to other services
These happen only when you use the feature. None of them carries your name or an account identifier, and none carries your health records except the words you speak into voice input, as described in its row.
| When | Sent to | What is sent |
|---|---|---|
| Scanning or typing a barcode | Open Food Facts (and its sister databases for other products); USDA FoodData Central if it is not found | The barcode number |
| Looking up a medicine label | openFDA, run by the US Food and Drug Administration | The code, name or document number you entered |
| Finding your growing zone, and local weather, sunrise and air quality on Home | phzmapi.org (US ZIP codes), OpenStreetMap's Nominatim (other postal codes), Open-Meteo | The postal code you entered, or the approximate coordinates of its area |
| Importing a recipe from a link | The website at that link | An ordinary request for that page |
| Speaking instead of typing | Your phone's speech recognition service (Google on Android, Apple on iPhone), only when the phone has no speech pack to turn speech into text on the device. On Android the app offers to download the pack first, so nothing needs to leave the phone. | The recording of what you say, while the microphone button is on |
| Reading a weather station on your home network | The station itself, inside your home network | A request for its current readings |
| Checking for app updates | Expo, which delivers updates to the app | The app's version, the device platform and a random installation number used to deliver the right update |
Each of these services receives your device's network address as part of any internet request, and their privacy terms apply.
What we do not do
- No analytics, crash reporting or advertising tools are built into the app.
- No data is sold, rented or shared for marketing.
- No data is used to train artificial intelligence models.
- No health information is shared with employers, insurers or data brokers, because we never hold it.
No "anonymized" usage file either. There is nothing to anonymize, because nothing is kept.
Children
The app is not directed at children under 13. Where a parent keeps records about their child, those records are the parent's, kept on the parent's device under this same policy.
Your rights
Because your records are on your device, you can see, correct, export and delete them yourself at any time, from inside the app or by deleting it. For anything that reaches us, which is limited to sealed relay messages we cannot read, you can ask us for access, correction or deletion using the contact details above.
Laws this policy is written to meet
This section summarises, in outline, the laws the app is designed around. It is not legal advice.
- Mexico. Under the Federal Law on the Protection of Personal Data Held by Private Parties, health information is sensitive personal data and needs express consent. You have the rights of access, rectification, cancellation and opposition (the ARCO rights). The app asks for your agreement before first use, and the records it keeps are held by you, on your device.
- European Union and United Kingdom. Under the General Data Protection Regulation, health data is a special category. The app keeps it on your device and does not send it to us, so we do not process it. The little we could handle (relay messages we cannot open, and the network address that comes with any request) is kept to what delivery needs and deleted within 30 days.
- United States. The Federal Trade Commission's Health Breach Notification Rule applies to apps that hold personal health records. If health information we were responsible for were ever disclosed without your permission, we would tell you, the Federal Trade Commission and, where required, the media, within the time the rule sets. The app's design means we hold none, and some states (for example Washington and California) also have consumer health privacy laws, which the same design is meant to meet.
Changes to this policy
A changed policy gets a new version number and date here. When the change matters to how the app handles your information, the app asks you to read and agree again before going on.