Privacy Policy - How e-Zap Health Protects Your Data

Privacy Policy

e-Zap Health
Updated: 10th August 2026

Privacy at a glance

The short version

Most health information and uploaded images stay on your device. E-Zap Health does not operate a central database of your health records. External processing occurs only where needed for verification, app security and stability, purchases or entitlement checks, support, legal compliance, or when you actively ask Pulse AI to generate a review.

 

  1. Your email address is required for verification and secure access.
  2. Your health records, profile, wellbeing and diet entries, appointments, and Image Hub files are primarily stored locally on your device.
  3. Pulse AI is optional. It processes app-prepared health information only after you read the notice, tick the acceptance box, and choose to continue for that review.
  4. Pulse sends text and structured record information, including free-text notes. It does not send or analyse the image or document files stored in Image Hub.
  5. Apple handles paid App Store downloads. On Google Play, the app is free to download and an applicable in-app purchase is required at verification for users who are not entitled to free access.
  6. An email or entitlement record may be retained so that a person who used the app while it was free can be recognised and is not charged later solely because they deleted local data or reinstalled.
  7. The in-app 'delete all data' control erases local app information and resets local access, but it does not automatically erase authentication, entitlement, provider logs, store purchase records, or backups held elsewhere.
  8. You may ask us to erase remote authentication information by emailing support@ezaphealth.com. Erasing the record used to recognise grandfathered access may mean we can no longer restore that free entitlement later.
  9. We do not sell personal data, use health data for advertising, or use Pulse to make legal or similarly significant decisions about you.

1. About this policy

This Privacy Policy explains how E-Zap Health Ltd collects, uses, shares, stores, protects and deletes personal data in connection with the e-Zap Health mobile application (the App). It also explains your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

The App is a personal health record, tracking and organisational tool. It lets users record and connect symptoms, diagnoses, medications, surgeries, tests and scans, appointments, profile information, wellbeing information, diet-related entries, notes, and supporting images or documents.

This policy covers the App and the external services used to provide it. It does not automatically cover a separate website, device operating system, healthcare provider, app store, or third-party service that has its own privacy notice. Where we link to another provider, you should also read that provider's notice.

We use 'we', 'us' and 'our' to mean E-Zap Health Ltd. 'You' means the person using the App.

2. Who is responsible for your data

E-Zap Health Ltd is the controller for personal data processed to operate the App, including verification, security, billing entitlement, customer support and Pulse AI. Other organisations, such as Apple and Google, may act as separate controllers for information they process under their own store or payment terms.

Controller: E-Zap Health Ltd

Company number: 17138117

Registered office: 128 City Road, London, EC1V 2NX, United Kingdom

Privacy, rights and erasure: support@ezaphealth.com

General enquiries: enquiries@ezaphealth.com

We have not appointed a Data Protection Officer. Privacy enquiries should be sent to the privacy address above.

3. Information we process

3.1 Verification and account information

  1. Email address and one-time verification codes.
  2. Supabase authentication user ID, session tokens, verification and login timestamps, and security or access status.
  3. Technical authentication data such as IP address, device or browser information, and login activity where generated by the authentication service.
  4. Limited records needed to recognise access eligibility, including whether an email/account qualifies for grandfathered free access.
  5. Optional username entered for local display. It is not an authentication credential and should not be your real name.

3.2 Health and profile information stored locally

The records you choose to enter may be personal data and special category health data. Depending on the features you use, they may include:

  1. Symptoms, severity, dates, locations, frequency, duration, status and symptom update history.
  2. Free-text notes, including notes added to symptom updates.
  3. Diagnoses, medications, dose-related records, allergies, tests, scans, results, procedures and surgeries.
  4. Appointments, providers, concerns discussed, advice, outcomes and links to other records.
  5. Profile information such as age in years, biological sex, height, weight, body mass index, blood pressure history, smoking information, alcohol use and work type where recorded.
  6. Diet tracker and wellbeing tracker entries, which may include mood, anxiety, motivation, energy, sleep and user-created notes or events.
  7. Relationships or links between records and local identifiers used to maintain those links.
  8. Locally generated summaries, charts and appointment-preparation information.

Entering health information is optional. The usefulness of some App features depends on what you choose to record.

3.3 Image Hub files

You may manually choose images or documents through your device's system picker. These may include screenshots, letters, prescriptions, referral documents, test results or scans. A selected file may contain a name, address, NHS number, insurance identifier, date of birth or other highly sensitive information.

The current App does not scan your photo library in bulk, access images in the background, or use the device camera. Only files you actively select are made available to the App. Image Hub files and their links to other records are stored locally.

Reduce unnecessary identifiers

Before adding a document or screenshot, consider cropping, redacting or obscuring information that is not needed. You control what you choose to store and share.

 

3.4 Pulse AI information

When you choose to generate a Pulse review, the App prepares a structured text payload from relevant records. It may include symptoms and complete symptom update histories, diagnoses, medications, surgeries, tests and scans, dates, results, healthcare providers, record relationships and free-text notes.

The Pulse profile may also include age in years, biological sex, height, weight, calculated body mass index, blood pressure history, allergies, smoking information, alcohol use and work type where recorded.

The current Pulse payload does not include the actual uploaded image or document files. It may include a technical indicator or local identifier showing that a file is linked to a record. Current Pulse processing also does not include appointment records, detailed diet tracker entries or detailed wellbeing tracker entries.

The App does not intentionally add your email address, optional username, NHS number, insurance identifier, authentication credentials, raw PDF files, uploaded images or a dedicated date-of-birth field to the Pulse payload. However, any identifier or sensitive detail that you type into a free-text record or note may be included. Age is used rather than a dedicated date of birth, but a date of birth typed into a note could still be transmitted.

3.5 Technical, diagnostic and support information

  1. Crash reports, error logs, stack traces, app and operating-system version, device model or class, timestamps, performance information, and Firebase/Crashlytics installation identifiers.
  2. Verification email delivery status and message metadata.
  3. Pulse request identifiers, timestamps, response status, payload size, model/usage measurements and limited logs used for reliability, security and fair-use limits.
  4. Information you send when requesting support, exercising privacy rights or making a complaint.

We do not intentionally include the content of your local health records in crash reports. Diagnostic systems can nevertheless record technical state associated with an error, so we minimise diagnostics and restrict their use to security and reliability.

3.6 Purchase and entitlement information

Depending on your platform and when you first obtained the App, we may receive limited purchase or entitlement information from Apple or Google. This can include a product identifier, transaction or order reference, purchase token, purchase status, timestamp, store environment and eligibility status. We do not receive or store your full payment card or bank account details.

4. Where information comes from

  1. Directly from you when you enter records, select files, verify your email, use Pulse, contact us, or exercise a right.
  2. Automatically from your device and the App when necessary for authentication, security, stability and request operation.
  3. From Apple or Google when confirming a download, purchase, eligibility or entitlement.
  4. From Supabase, Resend, Firebase Crashlytics and OpenAI when they provide the limited services described in this policy.

5. How and why we use information

UK data protection law requires a lawful basis for using personal data and, where health data is processed, a separate condition for special category data. The principal bases we rely on are set out below.

Provide and secure access

What we do: Verify email, maintain sessions, prevent unauthorised access and deliver core App functions.

Lawful basis: Article 6(1)(b), performance of a contract; and Article 6(1)(f), our legitimate interests in security and fraud prevention.

Local record functions

What we do: Enable you to create, organise, link, display, export and delete records under your control on your device.

Lawful basis: Article 6(1)(b), performance of a contract. Where our software processes health data to perform your instructions, Article 9(2)(a), your explicit consent, applies where required.

Pulse AI

What we do: Transmit the app-prepared health payload and return the requested review.

Lawful basis: Article 6(1)(a), consent, and Article 9(2)(a), explicit consent.

Purchases and entitlement

What we do: Confirm payment or eligibility, provide paid access, preserve grandfathered free access and prevent duplicate charges or abuse.

Lawful basis: Article 6(1)(b), performance of a contract; Article 6(1)(f), legitimate interests in fair charging, fraud prevention and entitlement continuity; and Article 6(1)(c) where records are legally required.

Reliability and fair use

What we do: Diagnose crashes, secure backend services, enforce Pulse request limits, investigate abuse and improve operational reliability.

Lawful basis: Article 6(1)(f), our legitimate interests in operating a safe, reliable and sustainable service.

Email delivery

What we do: Send one-time verification codes and service messages required to operate access.

Lawful basis: Article 6(1)(b), performance of a contract, and Article 6(1)(f), service security.

Support, rights and complaints

What we do: Respond to requests, verify identity, investigate complaints and demonstrate compliance.

Lawful basis: Article 6(1)(c), legal obligation, and/or Article 6(1)(f), legitimate interests in resolving issues and defending legal claims.

 

Where we rely on legitimate interests, we consider the necessity of the processing, its expected benefit, its impact on you and the safeguards available. You may object to processing based on legitimate interests; see section 14.

6. Local storage and your control

Health records, profile data, appointments, diet and wellbeing entries, and Image Hub files are primarily stored in the App's private local storage on your device. E-Zap Health does not operate a central database containing those local health records and does not routinely retrieve or view them.

Local storage does not mean the information is risk-free or inaccessible to anyone in all circumstances. A person who can unlock your device, access an unlocked App session, compromise the device, or restore a device backup may be able to access data. The App's local PIN is an additional access control; it is not a substitute for device encryption, a strong device passcode, operating-system updates and secure backups.

Locally generated appointment-preparation PDFs and other exports are created on the device. We do not centrally store them. Once you save, print, message or otherwise share a report, its security and further use depend on you and the receiving service or person.

7. Pulse AI

7.1 Your choice and consent

Pulse is optional and is not required to use the App's core local record functions. Before each Pulse review, the App presents information about the processing. You must tick the acceptance control and select 'Accept and continue' before the generate control is enabled. If you cancel or do not accept, the request is not sent.

By completing that per-review action, you explicitly consent to the health information described in section 3.4 being processed for that Pulse review. Consent applies to that request only. A new acceptance is required for every later review.

You may withdraw before the request is submitted by cancelling. Once a request has been submitted and the processing has occurred, withdrawing consent cannot undo processing already completed lawfully, but you can decline every future request.

7.2 The processing route

  1. The App prepares a structured text payload on your device.
  2. Supabase validates the secure session and routes the request through an Edge Function that protects the OpenAI API credential.
  3. OpenAI processes the submitted text and produces a structured response.
  4. The response is returned to the App for display.

The Edge Function is not designed to write the Pulse health payload or output into a Supabase health-record database. Technical logs and usage metadata may nevertheless be created as described in this policy.

7.3 OpenAI data use and retention

OpenAI states that data submitted through its API is not used to train its models by default unless the API customer chooses to opt in. E-Zap Health does not authorise Pulse data to be used for advertising.

The production Pulse service instructs OpenAI not to store the response as retrievable Responses application data. A controlled fictional request completed on 10 August 2026 without creating a new retrievable dashboard record. This does not mean zero processing or guaranteed zero retention: OpenAI may separately retain limited API content in abuse-monitoring or security logs, generally for up to 30 days, and may retain limited information for longer where required or permitted by law or needed to address security or abuse.

7.4 Limits and safeguards

  1. Pulse is designed for organisation, chronology, pattern review and healthcare discussion preparation.
  2. Pulse is not a medical device, doctor, diagnostic system, emergency service, triage tool or treatment recommendation service.
  3. Outputs can be incomplete, inaccurate, inconsistent or omit an important issue. They must not replace professional medical advice or clinical judgement.
  4. Pulse does not make decisions producing legal or similarly significant effects about you, and we do not use it for advertising profiles.
  5. If you may need urgent medical help, use the appropriate emergency or urgent-care service and do not wait for Pulse.

Pulse requests are subject to a rolling usage limit. Limited user ID and timestamp records are processed to apply that limit. If the prepared payload is too large, the App will not complete the review and will ask you to reduce information you no longer need. Your local records remain unchanged unless you choose to edit or delete them.

8. Downloads, in-app purchases and grandfathered access

8.1 Apple App Store

On Apple devices, the App is offered as a paid App Store download. Apple processes the payment, store account and payment method under its own terms. We may receive limited transaction, sales and entitlement information needed to provide access, handle disputes and meet accounting obligations. We do not receive your full card or bank details.

8.2 Google Play

On Google Play, the App is free to download. Users who do not qualify for grandfathered free access must complete the applicable Google Play in-app purchase during the verification stage before full access is provided. Google processes the payment and payment method under its own terms. We receive only the purchase or entitlement information needed to validate and maintain access.

8.3 Grandfathered free access

People who installed and used the App while access was free may continue to qualify for free access. We may retain or match the verified email address, authentication user ID and an eligibility or entitlement status so that deleting local App data, reinstalling the App or returning to verification does not by itself cause that user to be charged.

Important consequence of remote erasure

You may request deletion of the remote email and authentication record used for recognition. If that record is erased, we may no longer be able to prove or restore grandfathered free access. A future verification or reinstall could then be treated as a new access request and the applicable Google Play purchase may be required. We will explain this consequence before completing a verified erasure request where it applies.

 

Store purchase history and transaction records held by Apple or Google are controlled by those providers and are not erased by the App's local deletion function or by an erasure request sent only to E-Zap Health.

9. Who receives information

We disclose personal data only where necessary for the purposes described in this policy, where you direct us to do so, or where disclosure is required or permitted by law.

Supabase

Information and purpose: Authentication, secure sessions, email/user identifiers, technical login data, Pulse request routing, fair-use metadata and access/entitlement support.

Role: Service provider/processor for our configured services.

Resend

Information and purpose: Recipient email address, verification message content, delivery status and delivery metadata.

Role: Transactional email service provider/processor.

OpenAI

Information and purpose: Pulse text payload, structured health information and generated output when you consent to a request.

Role: AI service provider/processor or sub-processor for Pulse.

Google/Firebase Crashlytics

Information and purpose: Crash and diagnostic information, technical device/app data and installation identifiers.

Role: App stability and diagnostics provider.

Apple App Store

Information and purpose: Store account, paid download, transaction and entitlement data processed under Apple's terms; limited confirmation shared with us.

Role: Independent controller for store/payment data and service provider for relevant developer data.

Google Play

Information and purpose: Store account, in-app purchase, transaction and entitlement data processed under Google's terms; limited confirmation shared with us.

Role: Independent controller for store/payment data and service provider for relevant developer data.

Professional advisers and authorities

Information and purpose: Only information reasonably necessary for legal advice, accounting, insurance, security, claims, regulatory cooperation or legal obligations.

Role: Recipients acting under legal or professional duties.

 

We do not sell personal data. We do not disclose health information for targeted advertising, data-broker activity or unrelated commercial profiling.

If E-Zap Health Ltd is involved in a merger, financing, restructuring or sale, relevant business data may be disclosed under confidentiality and data-protection safeguards. We will provide notice where the law requires it.

10. International transfers

Some providers may process personal data in the United States, European Economic Area or other countries outside the United Kingdom. These countries may have different privacy laws.

Where UK law requires a transfer safeguard, we use an applicable UK adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful mechanism. Where appropriate, we also assess the transfer and apply supplementary technical, contractual or organisational measures.

You may ask for information about the relevant safeguards by contacting support@ezaphealth.com. We may provide a summary or a redacted copy where necessary to protect commercial or security information.

11. How long information is kept

We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, including security, dispute, legal, tax and accounting needs. The periods below are the principal rules; a legal hold, active complaint or security investigation may require longer retention.

Local records and profile data

Retention approach: Until you delete an item, use the App's full local deletion function, or remove the App and its data, subject to device backups or operating-system behaviour.

Image Hub files

Retention approach: Until you delete the file, use full local deletion, or remove the App and its data, subject to copies and backups outside the App.

Authentication email and user ID

Retention approach: While needed to provide or restore access, maintain security or recognise entitlement; then until a verified erasure request is completed, unless a lawful exception requires limited retention.

Grandfathered entitlement record

Retention approach: While needed to recognise continuing free eligibility and prevent a repeat charge. Erasure may permanently remove our ability to recognise the entitlement.

Pulse input and output at OpenAI

Retention approach: OpenAI may retain API inputs, outputs and abuse-monitoring data for up to 30 days, with limited longer retention where legally required or permitted.

Pulse usage metadata

Retention approach: For as long as necessary to enforce the rolling seven-day limit and, where relevant, investigate abuse, security incidents, service failures or disputes; then deleted or anonymised when no longer required.

Verification email data at Resend

Retention approach: Generally up to 30 days under the provider's standard service operation, subject to residual security or legally required records.

Crashlytics data

Retention approach: Firebase Crashlytics generally retains crash information for 90 days before removal begins, subject to the provider's documented process.

Purchase/accounting records

Retention approach: For the period needed to maintain entitlement and meet tax, accounting, fraud and dispute obligations, normally up to six years after the relevant accounting period where UK law requires.

Support, rights and complaints

Retention approach: For the time needed to resolve and document the matter. Records may be kept for up to six years after closure where reasonably necessary to establish, exercise or defend legal claims.

 

Deletion from an active system does not always remove every copy instantly. Encrypted backups and provider recovery systems may retain residual copies for a limited cycle. Such copies remain protected and are not restored for ordinary use after deletion.

12. Deleting local App data and requesting remote erasure

12.1 What 'delete all data' does

The full local deletion function is designed to remove App records stored on the device, including symptoms, diagnoses, medications, surgeries, tests and scans, profile data, appointments, diet and wellbeing entries, Image Hub records and files, relationship data, local visibility settings, local PIN/onboarding state and the local Supabase session. The App then returns to the email verification stage.

12.2 What it does not do

  1. It does not automatically delete the Supabase authentication user, verified email, remote entitlement or Pulse usage metadata.
  2. It does not delete Apple or Google store accounts, purchase history, receipts or transaction records.
  3. It does not delete OpenAI, Resend, Crashlytics or Supabase logs that remain within their stated retention periods.
  4. It does not delete copies you exported, printed, messaged, emailed, saved elsewhere, or placed in a device or cloud backup.
  5. It does not delete data held by healthcare providers or any other third party.

12.3 How to request erasure from us

Email support@ezaphealth.com from the relevant address, or identify the address clearly. You may write 'Email removal' in the subject line, although no particular wording is required. We may ask for proportionate evidence that you control the address before acting.

We will explain any important consequence, including the possible loss of grandfathered free access, before completing the request. We will erase or instruct our processors to erase information where required, subject to legal exceptions and information that another organisation controls independently.

13. Security

We use a combination of technical and organisational measures intended to protect personal data. These include data minimisation, local-first record storage, transport encryption for network requests, authenticated backend access, protected API credentials, access controls, provider due diligence, limited diagnostics, deletion controls and incident response.

No system is completely secure. You should use a strong device passcode, enable device encryption where available, keep the operating system and App updated, protect access to your email account, avoid sharing verification codes, and review the sensitivity of notes and images before recording them.

If we become aware of a personal data breach, we will investigate, mitigate it and notify the Information Commissioner's Office and affected individuals where UK law requires.

14. Your data protection rights

Depending on the circumstances, you may have the following rights:

  1. Access: ask whether we process your personal data and receive a copy.
  2. Rectification: ask us to correct inaccurate or incomplete personal data.
  3. Erasure: ask us to delete personal data where the legal conditions apply.
  4. Restriction: ask us to limit processing in specified circumstances.
  5. Data portability: receive certain data you provided in a structured, commonly used and machine-readable format where the right applies.
  6. Withdraw consent: withdraw consent at any time for future processing based on consent, without affecting processing already carried out lawfully.
  7. Object: object to processing based on our legitimate interests. We will stop unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims.
  8. Complain: raise the matter with us and lodge a complaint with the Information Commissioner's Office.

Most health records are stored only on your device, so we cannot search for, correct or export data we do not possess. You can exercise control over those records in the App. We can act on remotely held authentication, entitlement, support and usage information.

To exercise a right, email support@ezaphealth.com. Rights are not absolute, and exemptions may apply. We may verify your identity and ask for information needed to locate the relevant record. We normally respond within one month, although the period may be extended by up to two further months for a complex request; if so, we will explain why.

Your right to object

You have the right to object to processing based on our legitimate interests. Contact support@ezaphealth.com and tell us what processing concerns you and why.

 

15. Children

The App is intended for people aged 16 and over and is not knowingly directed to children under 16. If you believe a child under 16 has provided remote personal data, contact support@ezaphealth.com so that we can investigate and take appropriate action. A parent or guardian should not use the App to create a record for a child unless the intended use and applicable consent requirements have been appropriately assessed.

16. Complaints

Please send a privacy complaint to support@ezaphealth.com. Explain what happened, the information or feature involved and the outcome you seek. We will acknowledge the complaint, investigate it without undue delay, keep you informed where appropriate and provide an outcome. We aim to acknowledge and begin handling complaints within 30 days.

You may complain to the UK Information Commissioner's Office at any time. We would welcome the opportunity to address the issue first, but you do not have to contact us before contacting the ICO.

ICO website: Information Commissioner's Office complaints service

ICO telephone: 0303 123 1113

ICO address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom

17. Device permissions

The App uses internet access for verification, secure service calls, billing or entitlement checks and Pulse. The current Image Hub uses the device's system picker so that you can select individual files. The App does not currently require background photo-library scanning or camera capture.

You can review permissions in your device settings. Disabling a permission or network access may prevent the related function from working.

18. Changes to this policy

We may update this policy when the App, providers, legal requirements or processing activities change. We will publish the current version with its effective date. Where a change is material, we will provide an appropriate in-App or website notice and, where required, seek fresh consent.

A new policy version does not retrospectively expand a consent already given for a Pulse request. Pulse requires a fresh in-App acceptance for each review.

19. Contact us

E-Zap Health Ltd: Company number 17138117

Registered office: 128 City Road, London, EC1V 2NX, United Kingdom

Privacy, rights, complaints and erasure: support@ezaphealth.com

General enquiries: enquiries@ezaphealth.com

When contacting us about an account, do not send health records, medical images, verification codes or more personal information than is necessary for us to handle your request.

Controlled clarification — OpenAI storage, access and identifiability

The information intentionally sent to OpenAI does not include the verification email address, username, Supabase authentication UUID or authentication credentials as dedicated fields. Free text may nevertheless contain identifying information entered by the user.

Pulse information is pseudonymous, not anonymous. A Pulse request reference can be associated, under restricted administrative access, with separately held consent evidence and an authenticated user ID; that user ID may in turn relate to the account email. E-Zap Health prohibits routine correlation or viewing. Access is permitted only where necessary for a documented rights request, security incident, complaint or authorised synthetic test.

E-Zap Health treats the production non-retention instruction as a mandatory technical control. Any proposal to enable retrievable response storage requires prior DPIA reassessment, necessity and lawful-basis review, retention/deletion and access design, updated transparency and consent where required, and signed approval. The control is checked on every relevant release, quarterly and annually.

©Copyright. All rights reserved.

Information icon

We need your consent to load the translations

We use a third-party service to translate the website content that may collect data about your activity. Please review the details in the privacy policy and accept the service to view the translations.