Privacy Policy
ReportWise (the "app") is a private vault for medical-report images. This policy explains what data the app handles, where it lives, what is shared with OpenAI when you ask the AI to analyze reports, and how to control or delete it.
1. Data that stays on your device
- Report images you import are written to the app's local, sandboxed storage. They do not leave the device automatically.
- Profiles, dates, and labels you assign to reports are stored locally in a SQLite database.
- Encrypted exports (
.rwarchivefiles) are produced only when you tap "Export" and saved wherever you choose.
2. Data that leaves your device — only when you ask
Before the app sends report data to OpenAI for the first time, it asks for your explicit permission. If you decline, no report image or prompt is uploaded and no analysis credit is charged. When you give permission and tap Analyze in the app, the following data is uploaded over HTTPS to the ReportWise proxy at api.reportwise.codeblog.net:
- the report images in the date range you selected, after any redactions you applied (up to 20 images),
- the per-image report dates,
- the free-text prompt or question you wrote, and
- the model identifier you picked.
The ReportWise proxy forwards that data to OpenAI to generate the explanation you requested, then returns OpenAI's response to your phone.
3. What the ReportWise server keeps
- Images and prompts are not persisted on our server. They are passed through to OpenAI and discarded after the response is returned.
- AI results may be stored temporarily in encrypted form so your device can retrieve the response. They expire automatically and are not kept long-term.
- An AI task record is stored: anonymous account id, requested model, timestamps, status, and credits charged or refunded. We use this to enforce quota, refund failed calls, and diagnose outages. It does not contain image content or your prompt.
- An entitlement record tracks your remaining analysis credits, free-credit state, platform purchase identifier if you made a purchase, and OpenAI data-sharing consent status.
4. OpenAI
ReportWise currently uses OpenAI as the third-party AI provider. OpenAI receives the selected report images after any redactions you applied, report dates, your prompt, and the model name only after your explicit in-app permission and only when you run an analysis. OpenAI's handling of that data is governed by OpenAI's own privacy terms. You can choose not to share data with OpenAI by declining permission or by not running an analysis.
5. Accounts and identifiers
- The app generates an anonymous device id at first launch.
- You can optionally bind a Google account to restore entitlement on a new device. Binding shares the Google account identifier with our server; it does not share contacts, mail, or other Google data.
- We do not collect names, addresses, phone numbers, contacts, or location.
6. In-app purchases
On iOS, analysis credit packs are sold only through Apple In-App Purchase using StoreKit. On Android, purchases go through Google Play Billing. The platform tells our server the transaction identifier and product information so we can verify the purchase and credit your account. We do not see or store payment card details.
7. Your rights
- Export: produce an encrypted
.rwarchivefrom inside the app. - Delete locally: delete a report and its files are removed from the device.
- Delete your account in the app: go to Me → Privacy & Account → Delete Account. This deletes the server-side anonymous account, device identity, linked account identifiers, entitlement and credit records, purchase-grant records, AI task records, and consent records tied to that account. It also clears local ReportWise data from that device.
- Ask for help: if you cannot use the in-app deletion flow, email reportwise.support@codeblog.net from a Google-bound account or include your anonymous account id.
- If you are in the EEA, UK, or California, you have additional rights to access and rectify the personal data we hold; the same email reaches us.
8. Children
ReportWise is not directed at children under 13. Family profiles for minors are intended to be created and managed by a parent or guardian.
9. Security
Transport is HTTPS only. Local exports are encrypted with a passphrase you choose. We do not transmit unredacted images on your behalf; redaction is performed and burned into the image on the device before upload.
10. Not medical advice
ReportWise is not a medical device. AI output is educational, may be wrong, and is not a substitute for advice from a licensed clinician. The app shows source or citation sections with AI explanations where available so you can review the basis for the information.
11. Changes
If we change this policy, we will update the "Last updated" date above and, for material changes, surface a notice in the app the next time you open it.
12. Contact
For privacy questions or data requests: reportwise.support@codeblog.net. Typical reply within 48 hours.