Privacy Policy
e-Zap Health
Updated: 24th September 2026
Privacy at a glance
The short version
Most health information and uploaded images stay on your device. E-Zap Health does not operate a central database of your health records. One verified Primary Account can hold a Primary profile and up to four additional local profiles. External processing occurs only where needed for verification, app security and stability, purchases or entitlement checks, support, legal compliance, or when the Primary-profile user actively asks Pulse AI to generate a written review or Body Map.
- Your email address is required for verification and secure access.
- Additional profiles are local record areas within the Primary Account. They are not separate accounts, do not have separate email verification or PINs, and do not prevent a person with access to the unlocked App from viewing another profile.
- Health records, profile, wellbeing and diet entries, appointments, calendars, insights and Image Hub files for the Primary profile and each additional profile are primarily stored locally on your device in separate profile areas.
- You may choose English, French, Spanish or Simplified Chinese for the App interface. The language preference and any related acknowledgement are stored locally on your device. Changing the display language does not translate, replace or transmit your saved free-text records.
- The full Privacy Policy and Terms of Use are provided in English during verification. French, Spanish and Simplified Chinese are optional interface settings for users who have had the opportunity to read and understand the English documents. Changing the interface language does not create, translate or modify a legal document.
- Appointment-preparation summaries are generated locally from records already stored on your device. English-only UK summaries may include the symptom-update period you select. Bilingual summaries use a narrower structured-data set and exclude translation-sensitive free text and unsupported optional details.
- The App does not send multilingual appointment-preparation information to OpenAI or an online translation provider. A report leaves the App's local controls only if you deliberately save, print, message, email or otherwise share it.
- Pulse AI is optional and is available only for the Primary profile. Additional-profile records are excluded from written Pulse reviews and Pulse Body Map requests. For an eligible Primary-profile request, Pulse processes app-prepared health information only after you read the notice, tick the acceptance box, and choose to continue.
- To demonstrate that choice, we keep a minimal remote consent record containing identifiers, timestamps, notice and App versions, and request status. It does not contain the Pulse health payload, free-text notes or AI response.
- Pulse sends text and structured record information, including free-text notes. It does not send or analyse the image or document files stored in Image Hub.
- Apple handles paid App Store downloads. On Google Play, the app is free to download and an applicable in-app purchase is required at verification for users who are not entitled to free access.
- An email or entitlement record may be retained so that a person who used the app while it was free can be recognised and is not charged later solely because they deleted local data or reinstalled.
- Wiping an additional profile erases that profile's local records and restores its default profile name without deleting the Primary Account or other profiles. The Primary Account's full 'delete all data' control erases local information for all profiles and resets local access, but it does not automatically erase authentication, entitlement, provider logs, store purchase records, or backups held elsewhere.
- You may ask us to erase remotely held information, including authentication information, Pulse usage metadata and Pulse consent evidence, by emailing support@ezaphealth.com. The right to erasure is not absolute. If limited information must be retained, we will explain what is retained, why and for how long. Erasing the record used to recognise grandfathered access may mean we can no longer restore that free entitlement later.
- We do not sell personal data, use health data for advertising, or use Pulse to make legal or similarly significant decisions about you.
1. About this policy
This Privacy Policy explains how E-Zap Health Ltd collects, uses, shares, stores, protects and deletes personal data in connection with the e-Zap Health mobile application (the App). It also explains your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
The App is a personal health record, tracking and organisational tool. It lets users record and connect symptoms, diagnoses, medications, surgeries, tests and scans, appointments, profile information, wellbeing information, diet-related entries, notes, and supporting images or documents. It also provides localised interfaces and locally generated English-only or bilingual appointment-preparation summaries, subject to the limitations explained below.
This policy covers the App and the external services used to provide it. It does not automatically cover a separate website, device operating system, healthcare provider, app store, or third-party service that has its own privacy notice. Where we link to another provider, you should also read that provider's notice.
We use 'we', 'us' and 'our' to mean E-Zap Health Ltd. 'You' means the person who verifies and controls the Primary Account and accepts the App's legal terms. 'Primary profile' means the main local record area linked to that account. 'Additional profile' means one of up to four separate local record areas that you create for another person under your lawful authority. A person whose information is recorded in a profile is the 'profile subject'.
1.1 Language of this policy and optional interface settings
This Privacy Policy and the Terms of Use are presented in English during verification, before the user can select an alternative App interface language. The French, Spanish and Simplified-Chinese interface settings are optional convenience features for users who have had the opportunity to read and understand the English legal documents. Selecting another interface language does not translate, replace, amend or reduce this policy, the Terms of Use, the user's legal rights or E-Zap Health's legal obligations. The English documents remain the versions supplied by E-Zap Health except where mandatory applicable law requires otherwise.
Confirming that this policy has been read and understood records that the privacy information was presented to the user. It is not blanket consent for every use of personal data and does not replace the separate, specific and per-request consent required before Pulse processes health information.
2. Who is responsible for your data
E-Zap Health Ltd is the controller for personal data processed to operate the App, including verification, security, billing entitlement, customer support, local App functions and Pulse AI. Other organisations, such as Apple and Google, may act as separate controllers for information they process under their own store or payment terms.
Controller: E-Zap Health Ltd
Company number: 17138117
Registered office: 128 City Road, London, EC1V 2NX, United Kingdom
Privacy, rights and erasure: support@ezaphealth.com
General enquiries: enquiries@ezaphealth.com
We have not appointed a Data Protection Officer. Privacy enquiries should be sent to the privacy address above.
3. Information we process
3.1 Verification and account information
- Email address and one-time verification codes.
- Supabase authentication user ID, session tokens, verification and login timestamps, and security or access status.
- Technical authentication data such as IP address, device or browser information, and login activity where generated by the authentication service.
- Limited records needed to recognise access eligibility, including whether an email/account qualifies for grandfathered free access.
- Optional display names entered for the Primary profile or an additional profile. A display name is not an authentication credential. You should avoid using a full real name where it is not needed.
3.2 Health and profile information stored locally
The records you choose to enter about yourself or a profile subject may be personal data and special category health data. Depending on the features you use, they may include:
- Symptoms, severity, dates, locations, frequency, duration, status and symptom update history.
- Free-text notes, including notes added to symptom updates.
- Diagnoses, medications, dose-related records, allergies, tests, scans, results, procedures and surgeries.
- Appointments, providers, concerns discussed, advice, outcomes and links to other records.
- Profile information such as age in years, biological sex, height, weight, body mass index, blood pressure history, smoking information, alcohol use and work type where recorded.
- Diet tracker and wellbeing tracker entries, which may include mood, anxiety, motivation, energy, sleep and user-created notes or events.
- Relationships or links between records and local identifiers used to maintain those links.
- Locally generated summaries, charts and appointment-preparation information.
Entering health information is optional. The usefulness of some App features depends on what you choose to record.
3.3 Family profiles and authority
The verified Primary Account can create and manage up to four additional profiles on the same device. Each profile has a separate local data namespace for its records, calendar, Image Hub, appointment preparation, insights, trackers and settings. An additional profile is not a separate E-Zap Health account, login or user licence.
The same account email, authenticated session and local PIN protect every profile. Selecting a profile changes which local records the App displays and updates; it is an organisational control, not a security boundary. Anyone who can unlock the device and App may be able to switch profiles and view, edit, export or erase information held in any profile.
You must have lawful authority to create and manage a profile for another person. Only an adult aged 18 or over with parental responsibility or another lawful basis should create a profile for a child. For another adult, you must have that person’s permission or another valid authority. The App does not verify identity, relationship, parental responsibility, capacity or authority.
Additional profiles do not require a full legal name or dedicated date-of-birth field. They are not necessarily anonymous: a display name, age, free-text note, image, document or linked record may identify the profile subject. Record only what is necessary, involve the profile subject where appropriate, and avoid unnecessary identifiers.
3.4 Image Hub files
You may manually choose images or documents through your device's system picker. These may include screenshots, letters, prescriptions, referral documents, test results or scans. A selected file may contain a name, address, NHS number, insurance identifier, date of birth or other highly sensitive information.
The current App does not scan your photo library in bulk, access images in the background, or use the device camera. Only files you actively select are made available to the App. Image Hub files and their links to other records are stored locally.
Reduce unnecessary identifiers
Before adding a document or screenshot, consider cropping, redacting or obscuring information that is not needed. You control what you choose to store and share.
3.5 Pulse AI information
When the Primary profile is selected and you choose to generate a written Pulse review or Pulse Body Map, the App prepares a structured text payload from relevant Primary-profile records. It may include symptoms and complete symptom update histories, diagnoses, medications, surgeries, tests and scans, dates, results, healthcare providers, record relationships and free-text notes. Pulse is not available from an additional profile, and additional-profile records are excluded from the Pulse payload.
The Pulse profile may also include age in years, biological sex, height, weight, calculated body mass index, blood pressure history, allergies, smoking information, alcohol use and work type where recorded.
The current Pulse payload does not include the actual uploaded image or document files. It may include a technical indicator or local identifier showing that a file is linked to a record. Current Pulse processing also does not include appointment records, detailed diet tracker entries or detailed wellbeing tracker entries.
The App does not intentionally add your email address, optional username, NHS number, insurance identifier, authentication credentials, raw PDF files, uploaded images or a dedicated date-of-birth field to the Pulse payload. However, any identifier or sensitive detail that you type into a free-text record or note may be included. Age is used rather than a dedicated date of birth, but a date of birth typed into a note could still be transmitted.
3.6 Language settings and appointment-preparation information
After the English Privacy Policy and Terms of Use are presented during verification, the App can display its interface in English, French, Spanish or Simplified Chinese. The selected language, and a local record that a language-specific feature notice has been acknowledged where applicable, are stored on the device so that the App can reopen in the chosen mode. These settings do not require E-Zap Health to create a remote language profile.
Free text entered with an English, French, Spanish, Simplified Chinese or other supported device keyboard is stored locally as entered. Changing the App language changes supported interface labels and catalogue displays; it does not automatically translate, rewrite or replace existing free-text records. Some structured catalogue values retain a canonical English value while the App displays a reviewed local-language label.
For an English-only UK appointment summary, the App can locally prepare selected symptoms and either the previous one month or three months of their update notes and severity changes, together with supported diagnoses, medications, surgeries, profile information and other appointment-preparation content under the feature's current rules.
The App can also generate bilingual appointment-preparation summaries. French-, Spanish- and Simplified-Chinese-interface users can prepare a summary in their App language alongside English for a UK healthcare discussion. English-interface users can prepare English alongside one selected travel language: Spanish, French, Portuguese, Simplified Chinese or Italian.
Bilingual summaries use fixed, reviewed in-App labels and structured mappings. They are generated locally and do not use OpenAI, another AI model or an online translation service. Creating or previewing one does not send the underlying health records to E-Zap Health, OpenAI or a translation provider and does not alter the saved records.
To reduce translation ambiguity, bilingual summaries use a narrower data set than the English-only UK summary. They exclude free-text symptom-update notes, medication notes, provider names, custom comments, tests, scans, uploaded images and documents, and other unsupported or translation-sensitive details. A supported catalogue value may be shown in both languages. An unsupported core clinical term may remain in English and be identified as not translated; an unsupported optional or custom detail may be omitted. Language-specific report rules may also exclude a custom or mixed-language entry rather than guess a translation.
Medication names are not machine-translated into a presumed equivalent. Depending on the report route, a medication name is kept exactly as entered in English or excluded when a suitable English name has not been supplied. Users are prompted to compare medication information with the packaging or prescription and may separately choose to keep photographs in Image Hub. Image Hub files are not embedded in the appointment-preparation PDF and are not processed by the report generator.
The language and report controls process health information only to perform the user's local instructions. The generated summary is patient-prepared information, not a verified clinical record or certified translation. Its contents may be incomplete because of the user's selections, missing records, the chosen time period or the stated exclusion rules.
3.7 Technical, diagnostic and support information
- Crash reports, error logs, stack traces, app and operating-system version, device model or class, timestamps, performance information, and Firebase/Crashlytics installation identifiers.
- Verification email delivery status and message metadata.
- Pulse request identifiers, timestamps, response status, payload size, model/usage measurements and limited logs used for reliability, security and fair-use limits.
- Pulse consent evidence, including Supabase user ID, server acceptance time, consent-notice version and cryptographic hash, App version and build, platform, one-time receipt and request identifiers, and whether the request was submitted or completed. This record does not contain the Pulse health payload, free-text notes or AI response.
- Information you send when requesting support, exercising privacy rights or making a complaint.
We do not intentionally include the content of your local health records in crash reports. Diagnostic systems can nevertheless record technical state associated with an error, so we minimise diagnostics and restrict their use to security and reliability.
3.8 Purchase and entitlement information
Depending on your platform and when you first obtained the App, we may receive limited purchase or entitlement information from Apple or Google. This can include a product identifier, transaction or order reference, purchase token, purchase status, timestamp, store environment and eligibility status. We do not receive or store your full payment card or bank account details.
4. Where information comes from
- Directly from you when you create or select a profile; enter records about yourself or a profile subject; choose an App or report language; select records or files; generate a local appointment-preparation summary; verify your email; use Pulse from the Primary profile; contact us; or exercise a right. Information may also originate from a profile subject or a person lawfully acting for them when you enter it under your authority.
- Automatically from your device and the App when necessary for authentication, security, stability and request operation.
- From Apple or Google when confirming a download, purchase, eligibility or entitlement.
- From Supabase, Resend, Firebase Crashlytics and OpenAI when they provide the limited services described in this policy.
5. How and why we use information
UK data protection law requires a lawful basis for using personal data and, where health data is processed, a separate condition for special category data. The principal bases we rely on are set out below.
Provide and secure access
What we do: Verify email, maintain sessions, prevent unauthorised access and deliver core App functions.
Lawful basis: Article 6(1)(b), performance of a contract; and Article 6(1)(f), our legitimate interests in security and fraud prevention.
Local record functions
What we do: Enable you to create, organise, link, display, export and delete records under your control on your device, including records held in separate Primary and additional profiles.
Lawful basis: Article 6(1)(b), performance of our contract with you, applies to Primary Account and Primary-profile functions. Where you lawfully manage another person’s information in an additional profile, Article 6(1)(f), the legitimate interests of you and the profile subject in personal health organisation, may apply after considering necessity, impact and safeguards. Where our software processes health data to perform your instructions, Article 9(2)(a), explicit consent given or authorised by a person legally able to do so, applies where required. If you do not have a valid lawful basis and special-category condition, do not create or use the profile.
Language, localisation and appointment preparation
What we do: Remember the language you select; display reviewed interface and catalogue wording; preserve free text as entered; and locally select, structure, display and export appointment-preparation information according to the report route you choose.
Lawful basis: Article 6(1)(b), performance of a contract. Where our software processes health data on the device to perform your instructions, Article 9(2)(a), your explicit consent, applies where required. The bilingual report function does not itself disclose the information to E-Zap Health, OpenAI or an online translation provider.
Pulse AI
What we do: For the Primary profile only, transmit the app-prepared health payload, return the requested written review or structured Body Map output and create a minimal record of the per-request consent action. Additional-profile records are not used for Pulse.
Lawful basis: Article 6(1)(a), consent, and Article 9(2)(a), explicit consent.
Consent evidence and accountability
What we do: Keep a data-minimised record showing who consented, when, which notice version was accepted and whether that receipt was submitted for a Pulse action.
Lawful basis: Article 6(1)(c), compliance with data-protection accountability obligations; and Article 6(1)(f), our legitimate interests in demonstrating compliance, investigating disputes and protecting the integrity of the service.
Purchases and entitlement
What we do: Confirm payment or eligibility, provide paid access, preserve grandfathered free access and prevent duplicate charges or abuse.
Lawful basis: Article 6(1)(b), performance of a contract; Article 6(1)(f), legitimate interests in fair charging, fraud prevention and entitlement continuity; and Article 6(1)(c) where records are legally required.
Reliability and fair use
What we do: Diagnose crashes, secure backend services, enforce Pulse request limits, investigate abuse and improve operational reliability.
Lawful basis: Article 6(1)(f), our legitimate interests in operating a safe, reliable and sustainable service.
Email delivery
What we do: Send one-time verification codes and service messages required to operate access.
Lawful basis: Article 6(1)(b), performance of a contract, and Article 6(1)(f), service security.
Support, rights and complaints
What we do: Respond to requests, verify identity, investigate complaints and demonstrate compliance.
Lawful basis: Article 6(1)(c), legal obligation, and/or Article 6(1)(f), legitimate interests in resolving issues and defending legal claims.
Where we rely on legitimate interests, we consider the necessity of the processing, its expected benefit, its impact on you and the safeguards available. You may object to processing based on legitimate interests; see section 14.
6. Local storage and your control
Health records, profile data, appointments, calendars, diet and wellbeing entries, insights and Image Hub files are primarily stored in the App's private local storage on your device. Each profile uses a separate local data namespace. E-Zap Health does not operate a central database containing those local health records and does not routinely retrieve or view them.
Local storage and separate profile areas do not mean the information is risk-free or inaccessible to anyone in all circumstances. A person who can unlock your device, access an unlocked App session, compromise the device, or restore a device backup may be able to access data across profiles. All profiles share the Primary Account's local PIN and authenticated session. Profile selection is not a security boundary. The PIN is an additional access control; it is not a substitute for device encryption, a strong device passcode, operating-system updates and secure backups.
Locally generated appointment-preparation PDFs, Pulse Body Map PDFs or images, and other exports are created on the device. We do not centrally store them. Once you save, screenshot, print, message or otherwise share a report or image, its security and further use depend on you and the receiving service or person.
The App language preference and any completed language-feature acknowledgement are local settings. They remain until you change them, use the full local deletion/reset function, remove the App and its data, or the device or operating system removes them.
Appointment-preparation previews are assembled on the device from the records available at that time. The App does not automatically add the preview or PDF back into the health-record database. If you deliberately create or share a PDF, the copy may then be stored by the device file system, print service, messaging or email provider, recipient, or a cloud-backup service under settings and terms outside E-Zap Health's local controls.
7. Pulse AI
7.1 Your choice and consent
Pulse is optional, is available only while the Primary profile is selected, and is not required to use the App's core local record functions. Additional profiles retain their local record, appointment-preparation and insights functions but cannot start a written Pulse review or Pulse Body Map, and their records are excluded from Primary-profile Pulse requests. Before each eligible Primary-profile request, the App presents information about the processing. You must tick the acceptance control and select 'Accept and continue' before the relevant generate control is enabled. If you cancel or do not accept, the request is not sent.
Pulse's written AI review and Body Map are currently available only while the Primary profile is selected in English App mode. The appointment-preparation tool available to additional profiles or in French, Spanish or Simplified Chinese mode, and the bilingual travel-report option available to English-mode users, are separate local functions. They do not call Pulse, Supabase Edge Functions, OpenAI or a translation service, do not use the Pulse consent receipt and do not count towards the Pulse usage limit.
By completing that per-request action, you explicitly consent to the Primary-profile health information described in section 3.5 being processed for that written Pulse review or Body Map request. Consent applies to that request only. A new acceptance is required for every later Pulse action.
When you select 'Accept and continue', Supabase creates a short-lived, one-time consent receipt linked to your authenticated user ID and the exact version of the notice. The Generate control is unlocked only after that receipt is issued. The receipt contains the limited evidence described in section 3.7, not your health payload or AI response. If a receipt cannot be issued or verified, no Pulse health payload is sent to OpenAI.
You may withdraw before the request is submitted by cancelling. Once a request has been submitted and the processing has occurred, withdrawing consent cannot undo processing already completed lawfully, but you can decline every future request.
Withdrawing consent for future Pulse processing, deleting local App data or uninstalling the App does not automatically erase the minimal consent evidence already recorded. You may separately request erasure of that evidence as explained in section 12. We will assess the request under applicable data-protection law and will not retain the evidence for longer than is justified under section 11.
7.2 The processing route
- Supabase records the per-review consent evidence and issues a short-lived, one-time receipt.
- After you select Generate, the App prepares a structured text payload on your device.
- Supabase validates the secure session and one-time consent receipt, applies operational checks and routes an eligible request through an Edge Function that protects the OpenAI API credential.
- OpenAI processes the submitted text and produces a structured written-review response or Body Map data response.
- The response is returned to the App for temporary display. A Body Map is not automatically added to the user’s health records; any PDF, image or screenshot copy is created only when the user chooses to do so.
The Edge Function is not designed to write the Pulse health payload or output into a Supabase health-record database. Technical logs and usage metadata may nevertheless be created as described in this policy.
7.3 OpenAI data use and retention
OpenAI states that data submitted through its API is not used to train its models by default unless the API customer chooses to opt in. E-Zap Health does not authorise Pulse data to be used for advertising.
The production written-Pulse and Pulse Body Map services instruct OpenAI not to keep the response as a retrievable Responses record. A controlled fictional request completed on 10 August 2026 without creating a new retrievable dashboard record. OpenAI may still retain limited API content in separate security and abuse-monitoring logs, generally for up to 30 days, and may retain limited information for longer where required by law, to address security or abuse, or where another lawful exception applies. We do not claim that Pulse operates under a zero-data-retention arrangement.
7.4 Identifiability, restricted access and response-storage controls
The information intentionally sent to OpenAI does not include the verification email address, username, Supabase authentication UUID or authentication credentials as dedicated fields. Free text may nevertheless contain identifying information entered by the user.
Pulse information is pseudonymous, not anonymous. A Pulse request reference can be associated, under restricted administrative access, with separately held consent evidence and an authenticated user ID; that user ID may in turn relate to the account email. E-Zap Health prohibits routine correlation or viewing. Access is permitted only where necessary for a documented rights request, security incident, complaint or authorised synthetic test.
E-Zap Health treats the production non-retention instruction as a mandatory technical control. Any proposal to enable retrievable response storage requires prior DPIA reassessment, necessity and lawful-basis review, retention/deletion and access design, updated transparency and consent where required, and signed approval. The control is checked on every relevant release, quarterly and annually.
7.5 Limits and safeguards
- Pulse is designed for organisation, chronology, pattern review and healthcare discussion preparation. The optional Body Map presents user-recorded diagnosis, surgery, symptom and medication information in a visual organisational format; it does not diagnose, confirm a body location or provide clinical interpretation.
- Pulse is not a medical device, doctor, diagnostic system, emergency service, triage tool or treatment recommendation service.
- Outputs can be incomplete, inaccurate, inconsistent or omit an important issue. They must not replace professional medical advice or clinical judgement.
- Pulse does not make decisions producing legal or similarly significant effects about you, and we do not use it for advertising profiles.
- If you may need urgent medical help, use the appropriate emergency or urgent-care service and do not wait for Pulse.
Written Pulse reviews and Pulse Body Map requests share a combined limit of four completed Pulse actions in a rolling seven-day period. Limited user ID and timestamp records are processed to apply that limit. If the prepared payload is too large, the App will not complete the request and will ask you to reduce information you no longer need. Your local records remain unchanged unless you choose to edit or delete them.
8. Downloads, in-app purchases and grandfathered access
8.1 Apple App Store
On Apple devices, the App is offered as a paid App Store download. Apple processes the payment, store account and payment method under its own terms. We may receive limited transaction, sales and entitlement information needed to provide access, handle disputes and meet accounting obligations. We do not receive your full card or bank details.
8.2 Google Play
On Google Play, the App is free to download. Users who do not qualify for grandfathered free access must complete the applicable Google Play in-app purchase during the verification stage before full access is provided. Google processes the payment and payment method under its own terms. We receive only the purchase or entitlement information needed to validate and maintain access.
8.3 Grandfathered free access
People who installed and used the App while access was free may continue to qualify for free access. We may retain or match the verified email address, authentication user ID and an eligibility or entitlement status so that deleting local App data, reinstalling the App or returning to verification does not by itself cause that user to be charged.
Important consequence of remote erasure
You may request deletion of the remote email and authentication record used for recognition. If that record is erased, we may no longer be able to prove or restore grandfathered free access. A future verification or reinstall could then be treated as a new access request and the applicable Google Play purchase may be required. We will explain this consequence before completing a verified erasure request where it applies.
Store purchase history and transaction records held by Apple or Google are controlled by those providers and are not erased by the App's local deletion function or by an erasure request sent only to E-Zap Health.
9. Who receives information
We disclose personal data only where necessary for the purposes described in this policy, where you direct us to do so, or where disclosure is required or permitted by law.
Supabase
Information and purpose: Authentication, secure sessions, email/user identifiers, technical login data, Pulse request routing, fair-use metadata and access/entitlement support.
Role: Service provider/processor for our configured services.
Resend
Information and purpose: Recipient email address, verification message content, delivery status and delivery metadata.
Role: Transactional email service provider/processor.
OpenAI
Information and purpose: Pulse text payload, structured health information and generated written-review or Body Map output when you consent to a request.
Role: AI service provider/processor or sub-processor for Pulse.
Google/Firebase Crashlytics
Information and purpose: Crash and diagnostic information, technical device/app data and installation identifiers.
Role: App stability and diagnostics provider.
Apple App Store
Information and purpose: Store account, paid download, transaction and entitlement data processed under Apple's terms; limited confirmation shared with us.
Role: Independent controller for store/payment data and service provider for relevant developer data.
Google Play
Information and purpose: Store account, in-app purchase, transaction and entitlement data processed under Google's terms; limited confirmation shared with us.
Role: Independent controller for store/payment data and service provider for relevant developer data.
Professional advisers and authorities
Information and purpose: Only information reasonably necessary for legal advice, accounting, insurance, security, claims, regulatory cooperation or legal obligations.
Role: Recipients acting under legal or professional duties.
We do not sell personal data. We do not disclose health information for targeted advertising, data-broker activity or unrelated commercial profiling.
If E-Zap Health Ltd is involved in a merger, financing, restructuring or sale, relevant business data may be disclosed under confidentiality and data-protection safeguards. We will provide notice where the law requires it.
No external recipient receives health information merely because you change the App language or generate a local appointment-preparation preview. A healthcare professional, interpreter or other person receives a report only if you choose to show, print or share it. That user-directed disclosure is distinct from E-Zap Health appointing a processor to generate the report.
10. International transfers
Some providers may process personal data in the United States, European Economic Area or other countries outside the United Kingdom. These countries may have different privacy laws.
Where UK law requires a transfer safeguard, we use an applicable UK adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful mechanism. Where appropriate, we also assess the transfer and apply supplementary technical, contractual or organisational measures.
You may ask for information about the relevant safeguards by contacting support@ezaphealth.com. We may provide a summary or a redacted copy where necessary to protect commercial or security information.
The local multilingual interface and appointment-preparation functions do not introduce an additional international transfer by E-Zap Health because they do not send the report content to an external translation or AI provider. A transfer may occur under another party's service only if you subsequently choose to save, back up or share the exported report using that service.
11. How long information is kept
We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, including security, dispute, legal, tax and accounting needs. The periods below are the principal rules; a legal hold, active complaint or security investigation may require longer retention.
Local records and profile data
Retention approach: Until you delete an item, wipe the relevant additional profile, use the Primary Account's full local deletion function, or remove the App and its data, subject to device backups or operating-system behaviour.
Image Hub files
Retention approach: Until you delete the file, use full local deletion, or remove the App and its data, subject to copies and backups outside the App.
Language preference and local acknowledgements
Retention approach: Stored locally until you select another language, reset or fully delete local App data, uninstall the App with its data, or the device or operating system removes the setting. E-Zap Health does not maintain a central language-profile database for this function.
Appointment-preparation previews and exported reports
Retention approach: The preview is generated for local display and is not automatically retained by E-Zap Health or added to the App's health records. A PDF or other copy exists only when you deliberately create, save, print or share it, after which you and any receiving device or service control its retention and deletion.
Authentication email and user ID
Retention approach: While needed to provide or restore access, maintain security or recognise entitlement; then until a verified erasure request is completed, unless a lawful exception requires limited retention.
Grandfathered entitlement record
Retention approach: While needed to recognise continuing free eligibility and prevent a repeat charge. Erasure may permanently remove our ability to recognise the entitlement.
Pulse written-review and Body Map input and output at OpenAI
Retention approach: Pulse instructs OpenAI not to keep written Review or Body Map responses as retrievable response records. OpenAI may separately retain limited API content in security and abuse-monitoring logs, generally for up to 30 days, with limited longer retention where legally required or permitted.
Pulse usage metadata
Retention approach: For as long as necessary to enforce the rolling seven-day limit and, where relevant, investigate abuse, security incidents, service failures or disputes; then deleted or anonymised when no longer required.
Pulse consent evidence
Retention approach: Normally for up to six years after the consent event where reasonably necessary to demonstrate consent, meet accountability obligations, investigate a complaint or establish, exercise or defend legal claims. It may be erased sooner where retention is no longer necessary or an erasure request must be honoured. A legal hold or active dispute may require longer retention.
We will periodically review whether identifiable Pulse consent evidence is still necessary. At the end of the applicable period, it will be securely erased or irreversibly anonymised unless a documented legal hold, active dispute or other lawful exception requires limited further retention. Any further retention will be limited to the information and period reasonably necessary for that purpose.
Verification email data at Resend
Retention approach: Generally up to 30 days under the provider's standard service operation, subject to residual security or legally required records.
Crashlytics data
Retention approach: Firebase Crashlytics generally retains crash information for 90 days before removal begins, subject to the provider's documented process.
Purchase/accounting records
Retention approach: For the period needed to maintain entitlement and meet tax, accounting, fraud and dispute obligations, normally up to six years after the relevant accounting period where UK law requires.
Support, rights and complaints
Retention approach: For the time needed to resolve and document the matter. Records may be kept for up to six years after closure where reasonably necessary to establish, exercise or defend legal claims.
Deletion from an active system does not always remove every copy instantly. Encrypted backups and provider recovery systems may retain residual copies for a limited cycle. Such copies remain protected and are not restored for ordinary use after deletion.
12. Deleting local App data and requesting remote erasure
12.1 Additional-profile wipe and Primary Account deletion
When an additional profile is selected, its wipe control is designed to remove only that profile's local records, including its health records, profile fields, appointments, calendar, diet and wellbeing entries, insights, Image Hub records and files, relationship data and profile-specific settings. It restores the profile's default name, keeps the Primary Account and other profiles, and returns to that profile's Home page. It does not sign out, change the shared PIN or erase remote account information. The Primary Account's full local deletion function is designed to remove local App information for every profile, including the same record categories, local visibility and language settings, language-feature acknowledgements, the shared local PIN/onboarding state and the local Supabase session. The App then returns to the email-verification stage.
12.2 What it does not do
- It does not automatically delete the Supabase authentication user, verified email, remote entitlement, Pulse usage metadata or Pulse consent evidence.
- It does not delete Apple or Google store accounts, purchase history, receipts or transaction records.
- It does not delete OpenAI, Resend, Crashlytics or Supabase logs that remain within their stated retention periods.
- It does not delete copies you exported, printed, messaged, emailed, saved elsewhere, or placed in a device or cloud backup.
- It does not delete data held by healthcare providers or any other third party.
12.3 How to request erasure from us
Email support@ezaphealth.com from the relevant address, or identify the address clearly. You may write 'Email removal' in the subject line, although no particular wording is required. We may ask for proportionate evidence that you control the address before acting.
Your request may include remotely held authentication information, entitlement information, Pulse usage metadata and Pulse consent evidence. You do not need to use a particular form of words, but identifying the categories you want erased will help us locate and assess them.
We will assess Pulse consent evidence specifically. Where the right to erasure applies, we will erase it or instruct the relevant processor to do so. We may retain only the minimum evidence reasonably necessary where continued retention is required by law or justified for data-protection accountability, an active complaint, or the establishment, exercise or defence of legal claims. Retained evidence will not be used to authorise another Pulse review.
We will explain any important consequence, including the possible loss of grandfathered free access, before completing the request. If we erase only part of the requested information or refuse erasure, we will explain what has been retained, the reason, the expected retention period where possible, and your right to complain to the Information Commissioner's Office or seek a judicial remedy. We will erase or instruct our processors to erase information where required, subject to legal exceptions and information that another organisation controls independently.
13. Security
We use a combination of technical and organisational measures intended to protect personal data. These include data minimisation, local-first record storage, separate local profile namespaces, transport encryption for network requests, authenticated backend access, protected API credentials, access controls, provider due diligence, limited diagnostics, deletion controls and incident response. Separate profile namespaces reduce accidental record mixing but do not provide separate authentication between people who can access the unlocked App.
No system is completely secure. You should use a strong device passcode, enable device encryption where available, keep the operating system and App updated, protect access to your email account, avoid sharing verification codes or the App PIN, supervise access where profiles contain another person’s information, and review the sensitivity of notes and images before recording them.
If we become aware of a personal data breach, we will investigate, mitigate it and notify the Information Commissioner's Office and affected individuals where UK law requires.
14. Your data protection rights
Depending on the circumstances, you may have the following rights:
- Access: ask whether we process your personal data and receive a copy.
- Rectification: ask us to correct inaccurate or incomplete personal data.
- Erasure: ask us to delete personal data where the legal conditions apply.
- Restriction: ask us to limit processing in specified circumstances.
- Data portability: receive certain data you provided in a structured, commonly used and machine-readable format where the right applies.
- Withdraw consent: withdraw consent at any time for future processing based on consent, without affecting processing already carried out lawfully.
- Object: object to processing based on our legitimate interests. We will stop unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims.
- Complain: raise the matter with us and lodge a complaint with the Information Commissioner's Office.
Most health records, including additional-profile records, are stored only on your device, so we cannot search for, correct or export data we do not possess. You can exercise control over those records in the App. A profile subject or person acting for them may contact us about remotely held information, but we may need proportionate evidence of identity and authority. We can act on remotely held authentication, entitlement, support, usage and Pulse consent-evidence information.
To exercise a right, email support@ezaphealth.com. Rights are not absolute, and exemptions may apply. We may verify your identity and ask for information needed to locate the relevant record. We normally respond within one month, although the period may be extended by up to two further months for a complex request; if so, we will explain why.
Your right to object
You have the right to object to processing based on our legitimate interests. Contact support@ezaphealth.com and tell us what processing concerns you and why.
15. Children
The person who creates and controls the Primary Account must be at least 16. A person aged 16 or 17 may use their Primary profile for themselves but must not create or manage a profile for another person. An adult aged 18 or over may create an additional profile for a child only where the adult has parental responsibility or another lawful authority and satisfies any consent, capacity, confidentiality and best-interests requirements that apply. The App does not verify age, identity, relationship or authority. Child profiles use the same local fields and shared access controls as other profiles, but Pulse is unavailable and their records are excluded from Pulse. Use the minimum information needed, avoid unnecessary identifiers, involve the child where appropriate to their age and understanding, and protect the device and shared PIN. If you believe a child has provided remote personal data or a child profile is being managed without authority, contact support@ezaphealth.com so that we can investigate information under our control.
16. Complaints
Please send a privacy complaint to support@ezaphealth.com. Explain what happened, the information or feature involved and the outcome you seek. We will acknowledge the complaint, investigate it without undue delay, keep you informed where appropriate and provide an outcome. We aim to acknowledge and begin handling complaints within 30 days.
You may complain to the UK Information Commissioner's Office at any time. We would welcome the opportunity to address the issue first, but you do not have to contact us before contacting the ICO.
ICO website: Information Commissioner's Office complaints service
ICO telephone: 0303 123 1113
ICO address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom
17. Device permissions
The App uses internet access for verification, secure service calls, billing or entitlement checks and Pulse. Changing the App language and generating a local English-only or bilingual appointment-preparation summary do not themselves require an AI or online translation connection. The current Image Hub uses the device's system picker so that you can select individual files. The App does not currently require background photo-library scanning or camera capture.
You can review permissions in your device settings. Disabling a permission or network access may prevent the related function from working.
18. Changes to this policy
We may update this policy when the App, providers, legal requirements or processing activities change. We will publish the current version with its effective date. Where a change is material, we will provide an appropriate in-App or website notice and, where required, seek fresh consent.
A new policy version does not retrospectively expand a consent already given for a Pulse request. Pulse requires a fresh in-App acceptance for each review.
Version 2.7 preserves and consolidates every still-relevant disclosure carried forward through Version 2.6. It adds the implemented Primary Account and additional-profile model, separate local profile namespaces, the shared email, session and PIN boundary, authority requirements for another adult or child, profile-specific wipe behaviour, Primary Account full deletion, and the exclusion of additional-profile records from written Pulse reviews and Pulse Body Maps. It does not remove the existing disclosures on Pulse consent, billing, entitlement, providers, retention, erasure, rights, security, multilingual interfaces, appointment preparation, local generation or user-controlled exports.
19. Contact us
E-Zap Health Ltd: Company number 17138117
Registered office: 128 City Road, London, EC1V 2NX, United Kingdom
Privacy, rights, complaints and erasure: support@ezaphealth.com
General enquiries: enquiries@ezaphealth.com
When contacting us about an account, do not send health records, medical images, verification codes or more personal information than is necessary for us to handle your request.
