Privacy Policy
InjuryLog — injurylog.ai
Last updated: 11 July 2026
InjuryLog ("we", "our", "us") operates the InjuryLog mobile application (the "App"). This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our App.
By using InjuryLog, you agree to the collection and use of information in accordance with this policy.
1. What We Collect
1.1 Account Information
- Email address — used for authentication and account recovery
- Password — stored securely via Supabase Auth (hashed; we never store or see plaintext passwords). Only applies if you sign up with email.
- Name — if you sign in with Apple or Google, we receive the name and email associated with that account. With Sign in with Apple you may choose to hide your name or use a private relay email.
1.2 Health & Injury Data
- Injury records — body part, injury type, severity level, pain levels, date of injury, symptoms, and free-text notes
- Recovery updates — pain tracking over time, mood ratings, sleep quality assessments
- Medical visit records — healthcare provider name, visit type, visit cost
- Treatment records — treatment type, duration, and related notes
1.3 User-Uploaded Content
- Profile pictures — optional avatar image
- Documents and receipts — photos or files you upload related to injuries, medical visits, or treatments
1.4 Technical Data
- Usage timestamps — when records are created or modified.
- Push notification token — if you enable reminders, a device push token is stored solely so we can deliver the reminders you asked for.
We do not bundle any third-party analytics, advertising, or crash-reporting SDK, and we do not collect location data, contacts, browsing history, or any data beyond what is described above. (Apple and Google may collect their own crash/diagnostic data at the operating-system level; that collection is governed by their policies, not ours.)
2. How We Use Your Data
We use the information we collect to:
- Provide the service — store and display your injury logs, recovery progress, medical visits, and treatments
- Authenticate your account — verify your identity when you sign in
- Sync your data — keep your records available across devices linked to your account
- Improve the App — understand usage patterns in aggregate to fix bugs and improve features
- Communicate with you — send transactional emails (password resets, account confirmations) and, with your consent, product updates
We do not use your data for advertising. We do not sell, rent, or trade your personal data to any third party.
3. Data Storage & Security
3.1 Infrastructure
Your data is stored in a Supabase backend (PostgreSQL database and Supabase Storage for files), hosted on Amazon Web Services (AWS) infrastructure located in the European Union.
3.2 Access Controls
- All user data is protected by Row Level Security (RLS) at the database level. Each user can only access their own records.
- File uploads are stored in private, per-user storage buckets with access policies enforced server-side.
- All data transmitted between the App and our servers is encrypted in transit using TLS 1.2+.
- Passwords are hashed using industry-standard algorithms (bcrypt) via Supabase Auth.
3.3 Security Measures
We employ industry-standard security practices including encrypted connections, secure authentication tokens, and regular security reviews. While no system is 100% secure, we take reasonable and appropriate measures to protect your data.
4. Third Parties
4.1 Service Providers
We use the following third-party services to operate the App:
| Provider | Purpose | Data Shared |
|---|---|---|
| Supabase | Backend database, authentication, file storage | All user data (as our data processor) |
| Amazon Web Services | Cloud infrastructure hosting | All user data (as infrastructure provider) |
| Mistral AI SAS (France, via our secure gateway) | Generating your educational recovery assessments and summarising report text you provide | The specific injury details, notes, or document text you submit for an AI assessment (as a data processor) |
| Apple / Google | Sign in with Apple / Google authentication | Your name and email from that account (only if you choose social sign-in) |
| Apple App Store / Google Play | App distribution, subscription billing | Purchase and subscription data (managed by Apple/Google) |
| RevenueCat | Subscription management | User ID, subscription status, purchase tokens |
| Expo (push notifications) | Delivering recovery reminders | Device push token (only if you enable reminders) |
Each provider acts as our data processor under contract and processes your data only to deliver the service. We do not permit them to use your health data for their own purposes.
4.2 AI Processing
Some features send the injury details, notes, or report text you choose to submit to our AI provider, Mistral AI SAS (France), through our secure server-side gateway, which returns educational recovery support (never a medical diagnosis or treatment decision). We do not send your data to the AI provider for advertising, and per our agreement it is not used to train third-party models. AI features always carry a "not medical advice" disclaimer.
We do not send your name, email, or account identifiers to the AI provider — only the injury text you choose to submit.
Scans and images are never read by AI. Where we offer a plain-English summary of a medical report, it is generated only from report text you paste in yourself. We do not analyse or interpret the scan images stored in your Injury Vault.
4.2.1 EU Data Residency
Both our backend (Supabase, hosted in the EU — Ireland, eu-west-1) and our AI provider (Mistral AI SAS, France) process your data within the European Union. Your health data is not transferred outside the EU/EEA for AI processing.
4.3 No Analytics
We do not use any third-party analytics or tracking services, and no analytics SDK is bundled in the App. If this changes in the future, we will update this Privacy Policy and notify users.
4.4 No Advertising
We do not display ads and do not share data with advertising networks.
4.5 No Data Sales
We do not sell your personal data to any third party, under any circumstances.
5. Your Rights
5.1 All Users
You have the right to:
- Access your data at any time through the App
- Update or correct your data directly within the App
- Delete your account and all associated data instantly from within the App (Profile → Delete Account), or by contacting us at privacy@injurylog.ai
- Export your data upon request
5.2 European Economic Area (EEA) Users — GDPR Rights
If you are located in the EEA, you have additional rights under the General Data Protection Regulation (GDPR):
- Right of access (Article 15) — request a copy of all personal data we hold about you
- Right to rectification (Article 16) — request correction of inaccurate data
- Right to erasure (Article 17) — request deletion of your data ("right to be forgotten")
- Right to restrict processing (Article 18) — request that we limit how we use your data
- Right to data portability (Article 20) — receive your data in a structured, machine-readable format
- Right to object (Article 21) — object to certain types of processing
- Right to withdraw consent — where processing is based on consent, withdraw it at any time
Legal basis for processing: We process your data based on (a) contractual necessity (to provide the service you signed up for), (b) legitimate interest (to improve and secure our service), and (c) consent (where applicable).
Data Protection Officer: For GDPR-related inquiries, contact us at privacy@injurylog.ai.
Supervisory Authority: You have the right to lodge a complaint with your local data protection authority. In Ireland, this is the Data Protection Commission (www.dataprotection.ie).
6. Data Retention
- Active accounts: We retain your data for as long as your account is active.
- Deleted accounts: When you request account deletion, we permanently delete all associated data within 30 days. Backups containing your data are purged within 90 days.
- Subscription records: Billing and subscription records may be retained for up to 7 years as required by tax and financial regulations.
7. Children's Privacy
InjuryLog is not intended for use by children under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected data from a child under 16 without parental consent, we will take steps to delete that information promptly. If you believe a child under 16 has provided us with personal data, please contact us at privacy@injurylog.ai.
8. International Data Transfers
Your data is stored on servers located in the European Union. If you access the App from outside the EU, your data will be transferred to and processed in the EU. We ensure that all data transfers comply with applicable data protection laws, including GDPR.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the "Last updated" date at the top of this page
- Notify you via the App or email for significant changes
- Post the updated policy at https://injurylog.ai/privacy
Your continued use of the App after changes are posted constitutes acceptance of the updated policy.
10. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, contact us at:
- Email: privacy@injurylog.ai
- Website: https://injurylog.ai
- Data deletion requests: privacy@injurylog.ai (subject line: "Data Deletion Request")