Privacy
Privacy Policy
AI Health Records is designed to keep your confirmed health-record history on your phone unless you deliberately use an online feature.
1. Scope and who controls the data
NEXTB LTD (company number 15920637) is the operator and data controller for AI Health Records on Android and iOS, the secure report viewer, support channels, and account-deletion service. Its registered office is 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.
Questions about privacy can be sent to aihealthrecords@nextb.uk. This policy applies wherever AI Health Records is offered; storefront availability may differ by platform and region. Depending on where you live, applicable law may give you rights to access, correct, delete, restrict, or object to processing, or to complain to a data-protection authority.
2. Data that stays on your device
- Confirmed blood-pressure and blood-glucose records are stored locally as the primary record history.
- Full camera or library photos are not uploaded or kept by our servers. The app temporarily prepares only the meter-display area for optional AI recognition.
- Reports and exported files remain where you choose to save or share them.
- Apple Health or Health Connect data is written only after your confirmation and permission. AI Health Records does not read a cloud health-history mirror for AI processing.
3. Optional AI recognition
AI recognition is optional. When you choose Camera or Photo Library, the app prepares the image locally and shows a separate consent screen before any AI request. That screen identifies the data, recipient and purpose. Manual entry remains available if you do not consent.
The data sent is only a temporary, metadata-free crop of the external meter display. The app obtains it from the camera frame or library image you selected, then crops, resizes and re-encodes it on the device. Full photos, backgrounds, location metadata, your name, email, notes, full record history, Apple Health or Health Connect history, access codes and account tokens are not sent for AI recognition.
The recipient is Cloudflare Workers AI, reached through a first-party Cloudflare Worker operated by NEXTB LTD. Cloudflare Workers AI processes the crop using Meta Llama 4 Scout only to suggest the numbers visible on the display. The user must review and may edit every suggested value before saving.
The model returns a candidate only. Nothing becomes a formal record or health-platform entry until you review, edit if necessary, and explicitly save it. Cloudflare states that Workers AI customer content is not used to train models or improve Cloudflare or third-party services without explicit consent, and that customer content may be stored when the customer deliberately combines Workers AI with a storage service. This integration has no image-storage binding and does not write recognition images or model results to D1, R2, Cache, or Queue.
Built with Llama. The currently configured multimodal model is Meta Llama 4 Scout, provided through Cloudflare Workers AI. Its output is used only as an editable display-reading candidate and not as medical advice.
4. Accounts, device trust, and secure sharing
An account is needed only for cloud features such as creating and managing secure links or deleting cloud-account data. Authentication may use Apple, Google, or a separately invited account. We store provider-scoped irreversible identifiers and bounded session information, not your provider password.
Device-attestation information may be used to protect paid and online features from abuse. This can include an app installation identifier, app package or bundle version, integrity verdicts, and security counters. It is not used for advertising.
A secure link contains only the records and context you select. The snapshot is encrypted before storage. A recipient may keep a copy by screenshot, download, print, or another method; revoking the link prevents later service access but cannot erase copies already made by a recipient.
5. Purchases, analytics, and diagnostics
Apple or Google processes payment details. We receive the product, transaction or purchase-token identifiers, subscription state, and minimum information needed to validate and restore access. We do not receive your card number or bank details.
Product analytics is disabled unless the product clearly asks for separate consent and the service is enabled. If enabled, only allowlisted product-interaction events and short-lived random event identifiers may be accepted; health values, photos, notes, account IDs, device IDs, stable session IDs, and advertising identifiers are prohibited.
Security and operational logs may contain request timing, coarse result codes, model/configuration versions, and abuse-prevention information. They must not contain raw health images, readings, access codes, passwords, or bearer tokens.
6. Purposes and choices
We process information to provide the feature you request, protect accounts and services, validate subscriptions, operate secure sharing, respond to support requests, and meet legal obligations. Optional AI and optional analytics use separate controls and are not bundled with health-platform permission.
You can use manual entry, local history, trends, local reports, export, and local deletion without an online account. You can withdraw AI consent in the app; this stops future AI requests and does not delete local records.
7. Retention and deletion
- Temporary recognition images are released from first-party request memory after the request completes and are not intentionally persisted by NEXTB LTD.
- Anonymous installation, device-trust, quota, consent, and recognition-usage metadata is deleted after 12 months without activity, unless it is still needed for an active subscription, an unresolved security incident or dispute, or a legal hold.
- Encrypted Google Play purchase tokens, token hashes, and terminal real-time developer notification records are deleted 90 days after final expiry or revocation, after acknowledgement, reconciliation, replacement-token processing, and any dispute are complete.
- Sampled first-party Worker logs are retained by the platform for no more than seven days. They contain allowlisted technical fields, not readings, images, access codes, passwords, or bearer tokens.
- Secure links expire or can be revoked. Expired and revoked objects are removed through bounded retention jobs.
- An accepted cloud-account deletion immediately blocks the account and starts deletion of account-scoped cloud data and secure links. A minimal deidentified receipt may remain for up to 31 days so you can check completion.
A narrowly scoped retention hold may delay deletion only while needed for a security incident, dispute, or legal obligation. Separate accounting records may be kept for the period required by law; the operational purchase-token ledger does not contain card details, prices, invoices, health values, or images.
Cloud-account deletion does not remove local records, health-platform entries, exported files, recipient copies, or an Apple/Google subscription. Those are controlled separately. See Delete cloud account.
8. Service providers and international processing
Cloudflare provides the first-party edge, D1/R2, service bindings, and—when activated—the selected Workers AI model. Cloudflare describes Workers AI models as third-party services that may carry separate open-source or provider license terms. Apple and Google provide authentication, app distribution, purchases, and their health platforms as applicable. Providers process only the information needed for the relevant function under their own platform terms and our configuration.
NEXTB LTD requires every service provider that receives user data to provide the same or equivalent privacy and security protection stated in this policy and required by applicable law and platform rules. If that protection or a material provider practice changes, we will stop the affected processing or present updated information and obtain consent again before sending more data.
Cloud services may process information in more than one country. Where applicable law requires it, NEXTB LTD uses contractual and other appropriate safeguards for international processing. You can contact us for more information about the safeguards relevant to your data.
9. Security, children, and changes
We use transport encryption, bounded requests, encrypted secure-link payloads, session revocation, rate limits, device integrity checks, least-privilege service bindings, and redacted logs. No internet service can guarantee absolute security.
AI Health Records is intended for adults aged 18 and over and is not directed to children.
Material policy changes will be dated here and, when appropriate, shown in the app before the changed processing begins.
Need help or want to exercise a privacy right?
Email aihealthrecords@nextb.uk. Do not include health readings, meter photos, passwords, access codes, or payment details in email.