Cookies & Trackers
A short, plain-language description of what we store on your device and what we don't.
1. The mobile app
The HealthLens mobile app does not use HTTP cookies, advertising cookies, or third-party advertising SDKs. We do not embed Google AdMob, Meta SDK, AppsFlyer, Branch, Adjust, Mixpanel, Amplitude, or any equivalent SDK. We do not use the device advertising identifier (IDFA on iOS, GAID on Android).
The app stores the following on your device, all of which are technically necessary to make the features work:
| Storage | What it holds | Why |
|---|---|---|
iOS Keychain / Android EncryptedSharedPreferences (via flutter_secure_storage) |
Supabase session tokens, refresh tokens, the active-profile pointer | To keep you signed in across launches |
| Hive (encrypted at the box level, namespaced per signed-in user) | Cached reports, AI summaries, chat sessions, reminders, family profiles | To make the app fast and to enable offline reading of records you already loaded |
| GetStorage (key-value) | UI preferences (theme, language, "seen privacy notice" flag) | To remember your settings between launches |
| App sandbox files | Temporary copies of report images and PDFs while you are scanning or sharing them | OS-level temp storage; cleared when the OS reclaims it or when you delete the report |
All of the above are wiped when you sign out of the app, and again when you delete your account.
2. This website
This website (/privacy.html, /terms.html, etc.) is a static documentation site hosted on Firebase Hosting. It does not set any first-party tracking cookies, and it does not embed any third-party analytics, advertising, or social-media scripts. The browser may use its own cache for the HTML, CSS and image files, which is standard browser behaviour and is not under our control.
Server-side, Firebase Hosting and any CDN it uses will see your IP address and basic request metadata in order to serve the page. That is the minimum any HTTP server sees and is not used by us for tracking.
3. Tracking technologies we explicitly do not use
- Behavioural advertising / re-targeting cookies
- Cross-app or cross-site tracking via fingerprinting
- Marketing-attribution SDKs
- Third-party fonts or analytics that ping a server
- Web beacons or tracking pixels
4. Your choices
Because the only data we store on your device is technically necessary, we do not show a cookie banner. If you object to any of it, your options are:
- sign out of the app — this clears the local storage tied to your account;
- delete the app — this removes the entire app sandbox;
- delete your account — this in addition removes your records from our server;
- use the platform's "limit ad tracking" / "ask app not to track" setting if you want belt-and-braces protection — although, as noted, the app does not use the advertising identifier in the first place.
5. Contact
For questions about this page, email contact@fcappstudio.tech.