Last updated: September 2026
Last updated: September 2026. This app is anonymous by design. There are no accounts and no sign-in. We do not ask for, collect, or store your name, email address, phone number, or any account details. Your questions, saved threads, and preferences live on your device. A few things do reach our backend, all tied to a random identifier rather than to your name: your question (and any image you attach) is sent to be answered, the anonymous session that authenticates it is recorded with the IP address and device type it connects from, and a small set of anonymous usage events tells us whether the app is working. Each is described in full below.
We do not collect your name, email, phone number, contacts, precise location, advertising identifiers, or any government or health-system identifiers. The app contains no third-party advertising and no ad-tracking SDKs, and we never sell or rent any data.
Your saved threads (questions and answers), your onboarding preferences (such as role, specialty, answer depth, region, and focus mode), your subscription status, and any images you attach are stored locally on your device. You can erase this at any time in the app: the Data & privacy screen — opened from Settings, and from the welcome screen when no subscription is active — lets you clear saved threads or delete all app data. Deleting the app also removes this local data.
To generate an answer, the text of your question — together with your non-identifying answer preferences (role, specialty, depth, region, format, and focus mode) — is sent over an encrypted connection to our backend and to our AI answer provider, Perplexity, which searches medical literature and returns a cited answer. These requests are keyed to a random anonymous identifier, not to your name or email. Perplexity processes these requests under its API terms, which apply a zero-retention policy to this type of request: it does not store your question after answering it and does not use it to train its models. Please do not include patient names, dates of birth, record numbers, or other identifying details in your questions. If you use dictation, the audio is processed by your device’s operating system speech service (which may use Apple’s servers) solely to convert speech to text; the app never records or stores audio. To display source logos, the app fetches each cited publication’s icon from a third-party icon service (Google); this shares only the publication’s web address — never your question — with that service.
If you attach an image to a question (for example a lab report or scan), that image is sent — over the same encrypted connection as your question, keyed to your random anonymous identifier — to our backend and to our AI answer provider, Perplexity, so it can be analyzed as part of the answer. A copy is also kept on your device with the thread until you delete it. Attachments are never used to identify you and are never sold or shared for advertising. Always crop or black out patient-identifying information before attaching anything.
When live answers are enabled, the app creates a random anonymous session with our backend (hosted on Supabase). The identifier contains no personal information. It exists to authenticate requests, prevent abuse, apply your plan’s usage limits, and key the anonymous usage events described below. Like most online services, our backend’s sign-in system also records the IP address and device type (the browser “user agent”) each session connects from; these are used only for authentication, security and abuse prevention. We never use the identifier or this connection information to work out who you are. The same identifier is also shared with our subscription service (RevenueCat) so your plan can be verified when you subscribe and when you ask a question.
So we can tell whether the app is working — how many people finish setup, how many reach an answer, where people get stuck — the app records a small number of events on our backend: things like the app being opened, setup being completed or skipped, the subscription screen being shown, a purchase starting or finishing, an offer code being redeemed, the option to rate or share the app being used, a question being sent, an answer completing or being interrupted, a source list being opened, a calculator being used, an answer being rated, and the app hitting an error. Each event carries only its name, a timestamp, and a few short fixed values such as which plan was tapped or which of four fixed reasons was given for a low rating. It never carries your question, an answer, a source, an attached image, or anything you typed — the app strips anything else before sending. These events are keyed to the same random anonymous identifier described above, never to your name or email, and are never sold, shared for advertising, or used to build a profile of you. We keep them for up to twelve months and then delete them automatically.
Subscriptions are purchased through, and billed by, the app store on your device (the Apple App Store or Google Play). We never see or store your card number, billing address, or other payment details. Subscription status is managed for us by RevenueCat, a third-party subscription service. So that we and our backend can confirm your plan is active, RevenueCat receives the same random anonymous identifier described above, the app store’s purchase and receipt records, and basic device and store-region information. On iPhone, the app also passes Apple’s ad-attribution token (Apple AdServices) to RevenueCat: if you installed the app from one of our Apple Ads (Apple Search Ads) campaigns, Apple tells RevenueCat which campaign, ad group and keyword the install came from, so we can see which of our ads work. This is not an advertising identifier, and it is not used to track you across other companies’ apps or websites. RevenueCat never receives your name, email, card details, or your questions.
Data on your device stays there until you delete it. On our backend we keep three things tied to your random anonymous identifier, and never to your name: the anonymous session record described above (the identifier, and the IP address and device type it connects from), the usage events described above, and your question counter — the tally that applies your plan’s weekly allowance. If you subscribe, the same weekly tally is also kept a second way, against your subscription instead of your identifier, so that reinstalling the app and restoring your subscription cannot restart the week’s allowance. That record holds only a one-way hash (SHA-256) of the subscription’s app store, product and original purchase date, the week it counts, and how many questions and free retries of interrupted answers were counted; it does not contain your identifier, a receipt, or the purchase date itself. The usage events and both question counters are deleted automatically after twelve months. The session record is kept for as long as the identifier exists, because your subscription is attached to it; it is not deleted automatically, and we will delete it on request (see “Your choices”). Our subscription service, RevenueCat, keeps its own record for the same identifier — the purchase and receipt records, device and store-region information, and any Apple Ads attribution described above — until it is deleted; it does not expire automatically either, and we will have it deleted on request too. Our backend host also keeps routine operational logs, such as the time, IP address and outcome of each request, for a short period for reliability and security. Your questions, your answers and your saved threads are never stored on our backend.
All communication between the app and our servers is encrypted in transit (HTTPS/TLS). No system is perfectly secure, so we keep what we hold to a minimum: the app never asks for, and our backend never stores, your name, email address, account or payment details.
This app is intended for healthcare professionals, students, and adults. It is not directed at children, and we do not knowingly process information from anyone under 18.
Use Incognito mode to keep a conversation out of your saved history entirely. Clear saved threads or delete all app data at any time from the Data & privacy screen — opened from Settings, and from the welcome screen when no subscription is active. That erases everything held on your device. Some things on our backend are deliberately kept: your question counter and, if you subscribe, its copy kept against your subscription, so that clearing the app cannot reset your plan’s weekly allowance; the anonymous usage events described above; and the anonymous session record your subscription is attached to. The counters and the events are deleted automatically after twelve months. Clearing the app does not remove RevenueCat’s subscription record for your identifier either, including any Apple Ads attribution. If you would like any of these erased sooner, email us at muneebrafishakoor@gmail.com and we will delete them, RevenueCat’s record included. Please include your Support ID, the random identifier described above, which is how we find these records: Contact support adds it to the email for you, both on the Data & privacy screen and in Settings. We hold no name, email or account, so the Support ID is the only way we can tell which records are yours.
If we change how the app handles data — for example, if cloud sync launches — we will update this policy in the app and revise the date above before the change takes effect.
Questions about this policy? Email us at muneebrafishakoor@gmail.com, or use Contact support in the app — on the Data & privacy screen, or in Settings. If you email us, we receive your email address and whatever the email contains, and use them only to respond to what you raise. That includes Report this answer, which opens an email already filled in with the question and answer being reported; nothing reaches us unless you send it.