Legal

Lab Results with AI Insights — Privacy Policy

Lab Results with AI Insights — Privacy Policy

Last updated: 11 September 2026

Lab Results with AI Insights ("the app", "we", "our") is developed by ByteNine AS. There are no ads in this app, it does not use your device's advertising identifier or track you across other companies' apps and websites, and we never sell or share your data for marketing. From version 1.1, the app sends crash reports and basic usage statistics to Google Firebase — section 3f sets out exactly what, and what it never includes.

Your lab results live on your device. Some data does leave it, and this policy sets out exactly what, when, and to whom — most importantly, that reading a lab report sends an image of that report to an AI provider, so anything printed on it, including your name, is part of what is sent.

1. Introduction

This policy explains how the app handles your data. It covers the app itself and the ByteNine backend it talks to.

2. Data stored on your device

Stored locally, in iOS's SwiftData database, protected by your device's own security (Face ID, Touch ID, or passcode):

  • Lab report files you import (PDFs and images)
  • Extracted test names, values, and reference ranges
  • AI-generated explanations
  • Your health profile, if you choose to fill one in
  • Preferences, settings, and your AI credit balance

If you have iCloud enabled for the app, this data also syncs to your own private iCloud database, operated by Apple under Apple's privacy policy. We cannot read it.

3. Data that leaves your device

a. Reading a lab report (import)

When you import a PDF, photo, or screenshot, the app renders the pages as images and sends them to an AI provider to extract the test values.

The image is the document as it is. If your name, date of birth, patient number, or doctor's name is printed on the report, it is part of the image that is sent. We do not redact it, because reliably locating and removing identifiers from an arbitrary lab layout is not something we can guarantee — and silently getting it wrong would be worse than telling you plainly.

If you would rather not send identifiers, crop or cover them before importing, or type the results in manually.

b. Asking for an AI explanation

When you tap to get an explanation, the app sends only:

  • Test names, numeric values, units, and reference ranges
  • The trend across your previous measurements of that test
  • Other tests from the same report, so the explanation can relate them to each other
  • Your health profile summary, if you have filled one in (for example age band, risk factors, family history)

No name, date of birth, national identity number, email address, or account identifier is attached.

c. How AI requests travel

Requests go to the ByteNine AI gateway at ai.bytenine.com, which forwards them to the provider you have selected — Anthropic or OpenAI. The gateway exists so that provider keys never ship inside the app.

The gateway does not store the contents of your requests. It records one usage row per request for cost control and abuse detection, containing: the app, the provider and model, token counts, cost, a timestamp, and a one-way hashed installation identifier. That row cannot be linked back to your lab data or to you personally.

Provider privacy policies:

  • Anthropic: https://www.anthropic.com/privacy
  • OpenAI: https://openai.com/privacy

d. Sending feedback

If you use "Send Feedback" in Settings, we receive the report you write, plus the app version, iOS version, and device model. Supplying an email address is optional — it is used only to reply to you, and if you provide one, your report is stored against it so we can follow up. Leave it blank and the report is anonymous.

Feedback marked as public appears on the app's page at bytenine.com. Your email address is never shown publicly.

e. Purchases

Subscriptions and credit packs are handled entirely by Apple. We never see your payment details.

f. Crash reports and usage statistics (from version 1.1)

From version 1.1, the app includes two services from Google Firebase:

  • Firebase Crashlytics — if the app crashes, it sends a crash report: where in the code the crash happened, the app and iOS version, the device model and its technical state (such as available memory), a random identifier created for this installation, and short technical notes about which step of an import was running (for example "saving").
  • Firebase Analytics — the app records basic usage events: that it was opened, how long it was in use, that it was updated, and in-app purchases (which product, the price and the currency). Google estimates your country or region from your IP address; the app never asks for your location.

What these reports never contain: your lab results, test names or values, the contents of your documents, AI explanations, your health profile, your name, or your email address. Nothing is linked to your identity, and none of it is used for advertising or to build an advertising profile.

One exception in version 1.1: if the app crashes after you have imported a PDF, the crash report can include that file's name. If you name files after yourself, that name is part of the report. This is removed in the next update.

Firebase is operated by Google, which processes this data on our behalf. Google deletes crash reports after 90 days, and deletes usage events tied to an installation identifier after at most 14 months.

  • Firebase: https://firebase.google.com/support/privacy

4. How we use your data

  • To display your lab results and track them over time
  • To generate AI explanations, when you ask for one
  • To answer feedback and fix the problems you report
  • To monitor AI cost and detect abuse, using the usage rows described above
  • To find and fix crashes, and to see which parts of the app are used, using the crash reports and usage statistics described in 3f

We do not profile you, advertise to you, or share your data with anyone beyond the AI provider, Apple, and — for crash reports and usage statistics — Google, as described above.

5. Data security

  • On-device data sits in SwiftData, protected by your device's security
  • iCloud sync, when enabled, uses your private iCloud database
  • All communication with the gateway and with AI providers uses HTTPS
  • Provider API keys are never embedded in the app

6. Your rights

Under GDPR and other applicable law you may:

  • Access your data — everything the app holds is visible in the app itself
  • Delete your data — "Delete all data" in Settings removes it from the device; disabling iCloud sync and deleting the app removes the iCloud copy
  • Export your data — via PDF export
  • Restrict or object to processing
  • Have feedback erased — email privacy@bytenine.com and we will delete your reports and any email address attached to them

7. Children's privacy

The app is not intended for anyone under 16, and we do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has sent us information, contact us and we will delete it.

8. Legal basis for processing

  • Consent — you decide when to import a report or request an AI explanation, and whether to send feedback or give an email address
  • Legitimate interests — running and securing the service, including AI cost control and abuse detection, and — from version 1.1 — crash reports and usage statistics to keep the app working and improve it

You can withdraw consent at any time by deleting your data in Settings or removing the app.

9. Changes to this policy

We may update this policy. Changes are published here with a revised "Last updated" date. Please check back from time to time.

Contact

Questions or requests about this policy or your data:

ByteNine AS — privacy@bytenine.com — https://bytenine.com