Privacy Policy
Effective 26 August 2026
This policy explains what data the ECG Lab iOS app (“ECG Lab”, “the app”, “we”, “us”) accesses, what happens to it, and the choices you have. We have written it to be read, not skimmed: the short version is that your ECG data is analyzed and stored on your iPhone, there is no account, and we do not sell, rent or advertise with your health data — ever.
1. Summary
- No account. You never sign up, and we never learn your name or email address from the app.
- On-device analysis. Beat detection, rhythm classification, QT/QTc, HRV and signal quality are computed on your iPhone and stored in the app’s local database.
- Three things leave the device, only when you use them: (a) derived measurements sent to our AI service when you tap “Ask AI to Explain”; (b) anonymous purchase records handled by Apple and RevenueCat when you buy Premium; (c) a PDF you choose to share.
- No advertising, no analytics on health data, no selling or sharing of health data with data brokers, insurers, employers or anyone else.
2. Data the app accesses
| Data | Source | Purpose |
|---|---|---|
| ECG recordings — voltage samples, sampling rate, Apple’s classification (e.g. Sinus Rhythm, AFib), average heart rate, recording date and device model | Apple Health (HealthKit), with your explicit permission | Displaying the strip and computing findings, measurements and trends |
| Derived measurements — detected beats, premature beats, QT/QTc, HRV (rMSSD/SDNN), signal quality, rhythm findings | Computed by the app on your iPhone | Findings, trends, baseline comparison, PDF reports, AI explanations |
| Symptoms and notes you log in the app | Entered by you | Shown alongside recordings and trends to help you spot correlations |
| App preferences (e.g. QTc formula, notification settings) | Entered by you | Making the app work the way you set it |
| Purchase status (whether Premium is active) and an anonymous app-user identifier | Apple App Store via RevenueCat | Unlocking Premium and restoring purchases |
ECG Lab requests read-only access to Electrocardiogram data in Apple Health. It does not read any other Health category and does not write to Apple Health. You can withdraw access at any time in the Health app under Sharing → Apps → ECG Lab; the app will then stop importing new recordings.
3. Where your data is processed and stored
All ECG analysis runs locally on your iPhone. Recordings, measurements, symptoms and settings are stored in the app’s private database on your device, protected by iOS data protection and your device passcode. This data is included in your encrypted iPhone backups according to your iCloud / iTunes backup settings; we do not operate a server that stores it.
4. What leaves your device, and why
4.1 AI explanations (only when you ask)
When you tap “Ask AI to Explain”, the app sends a short text summary of the recording’s derived measurements — for example rhythm class, heart rate, QTc value and formula, HRV values, premature-beat counts and signal quality — to our AI explanation service, which uses a large-language-model provider (currently OpenAI) to generate the explanation. We send this through our own server so that no provider credentials are stored in the app.
We do not send your name, Apple ID, contact details, device identifiers, precise location, the raw ECG waveform, or your Apple Health record. The request is not linked to an account because there is none. Explanations are generated on demand and are not used to train the provider’s models under the terms of our API agreement.
If you never tap the button, nothing is sent.
4.2 Purchases
Premium purchases are processed by Apple through the App Store. We use RevenueCat to validate receipts and keep your subscription status in sync. RevenueCat receives an anonymous app-user identifier generated on your device, your purchase and subscription events, and basic device information (such as iOS version and app version). It never receives health data. Apple’s handling of your payment details is governed by Apple’s Privacy Policy.
4.3 Sharing you initiate
When you export a PDF report or share a recording, the file goes wherever you send it (Mail, Messages, AirDrop, Files, a doctor’s portal…). That sharing is under your control and outside the app.
4.4 What we deliberately don’t do
- No advertising networks or ad identifiers.
- No third-party analytics or tracking SDKs that see your health data.
- No selling, renting or licensing of personal or health data to anyone.
- No use of health data for marketing, and no sharing with insurers, employers or data brokers.
5. Our HealthKit commitments
In line with Apple’s HealthKit requirements, we commit that data obtained through HealthKit is used only to provide the app’s health features to you; is never used for advertising, marketing or similar purposes; is never sold to advertising platforms, data brokers or information resellers; and is never disclosed to third parties except as you direct (for example, sharing a report) or as strictly necessary to provide a feature you have requested (the AI explanation described above, which receives derived measurements only).
6. Retention and deletion
- On your device: data is kept until you delete it. You can delete individual recordings and symptoms inside the app, or remove everything by deleting the app. Deleting the app does not delete the original ECG recordings from Apple Health — those remain under your control in the Health app.
- AI service: the measurement summaries sent for explanations are processed transiently to generate a response. Our server does not keep a database of requests; provider-side retention (if any) is limited to short-term abuse monitoring as described by the provider.
- RevenueCat: anonymous purchase records are retained as needed to honour your subscription and Apple’s refund and restore rules.
7. Your rights
Because your health data lives on your device and is not tied to an account, you exercise most rights directly: view it in the app, export it as a PDF, delete it in the app or by deleting the app, and revoke HealthKit access in the Health app. Depending on where you live (for example under the EU/UK GDPR or the California CCPA/CPRA), you may also have rights to access, correct, delete or port personal data we hold, to object to or restrict processing, and to lodge a complaint with a supervisory authority. To exercise any of these, email us at support@ecglab.app. We do not discriminate against you for exercising your rights, and we do not “sell” or “share” personal information as those terms are defined in the CCPA.
8. Children
ECG Lab is intended for adults and is not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has used the app in a way that involved sending us data, contact us and we will delete it.
9. Security
Data on your device is protected by iOS data protection and your passcode or biometrics. Connections to our AI service and to RevenueCat use TLS encryption. No method of storage or transmission is perfectly secure, but we design the app so that the most sensitive data — your raw recordings — never needs to be transmitted at all.
10. Changes to this policy
If we change how the app handles data, we will update this page, change the effective date above, and — for material changes — tell you in the app before the change takes effect.
11. Contact
Questions, requests or concerns: support@ecglab.app.