Skip to content
Anamnesis
  • Privacy
  • Terms
  • Support
Get the app

Legal

Privacy Policy

Effective date September 19, 2026

On this page

  1. 1. Information We Collect and How We Use It
  2. 2. Third-Party Service Providers and Sub-Processors
  3. 3. Legal Basis for Processing and International Data Transfers
  4. 4. Data Retention and Deletion
  5. 5. Your Privacy Rights (GDPR)
  6. 6. Children's Privacy
  7. 7. App Permissions
  8. 8. Changes to This Privacy Policy
  9. 9. Contact Us

Brishtan Filipp ("we," "us," or "our") operates the Anamnesis mobile application (the "App"). This Privacy Policy explains how we collect, use, and protect your information when you use our App.

By using the App, you agree to the collection and use of information in accordance with this Privacy Policy.

1. Information We Collect and How We Use It

We strictly separate your personal medical documents from technical app data, and we treat any health-related information in your documents as sensitive data.

A. Local Medical Documents (Strictly On-Device)

  • Collection: You can scan, photograph, or import medical documents into the App.
  • We Upload It, But We Do Not Store It: When you scan, photograph, or import a document, we upload it to our document-recognition backend (described in Section 2) in order to automatically categorize it and extract structured data - patient name, date of birth, identifiers, test results, medications, and similar details, where present in your document. We do not persistently store this document, or any copy of it, on our backend, in any database, or in any cloud storage we control: it exists on our infrastructure only for the time needed to process your request and return the result to your device, after which no copy is retained on our side.
  • Local Storage of Your Catalog: The App does not require account registration. Once processing is complete, your finished medical catalog - documents, notes, categories, and extracted text - is stored exclusively on your device. We do not maintain any database or account system containing your medical catalog.
  • On-Device Text Recognition (OCR): The App also performs text recognition directly on your device using Apple's Vision framework. The recognition itself happens entirely on-device, without any network transmission, and is used to enable full-text search within your local catalog. However, the resulting recognized text is included in AI Chat requests as described in Section 1.C.

B. Technical and Analytics Data (Automatically Collected)

To keep the App stable, fix bugs, and understand how the App's non-medical features are used, we use the following Google Firebase products:

  • Firebase Crashlytics - collects crash logs, error traces, and basic device diagnostic information (e.g., device model, OS version, and an anonymous, non-resettable device identifier such as IDFV) strictly for crash reporting.
  • Firebase Remote Config - used only to check whether your installed App version meets our minimum supported version.
  • Firebase Analytics - collects aggregated, pseudonymous usage data such as session duration, screen views, and which non-medical features of the App you interact with (for example, which tab or menu you use), together with basic device/OS information and an anonymous device identifier. If you purchase an Anamnesis Plus subscription, we also receive transaction information from Apple via StoreKit - the product purchased, price, currency, and an anonymous transaction identifier - and an aggregated count of how many free document scans you have remaining. We do not receive or store your payment card or billing details; all payment is handled directly by Apple.
  • We use this data solely to understand overall App usage and improve the product.

Important: None of this technical or usage data includes the content of your medical documents, the text extracted from them, or any patient information contained in them, and it is never linked to your identity or to the medical documents stored on your device. We do not use this data for advertising, do not share it with data brokers, and do not combine it with data from other companies' apps or websites to track you across them.

C. AI Chat

The App includes an "AI Chat" tab where you can ask questions about your health records. Each time you send a message in AI Chat, we send your question together with the structured information already extracted from your entire local health record catalog (for example: categories, titles, dates, patient information, test results, medications, and other structured fields described in Section 1.A, the full text recognized on your device from your documents' attachments (Section 1.A, OCR), and any notes you have added to your records) - not only the records relevant to your specific question - to our document-recognition backend, which forwards it to Amazon Bedrock to generate an answer. Raw document images or file attachments themselves are not sent for AI Chat - only text: the structured data, the on-device recognized text, and your notes. This uses the same infrastructure and the same zero-retention configuration described in Section 2: your question and record data are not used to train AI models and are not persistently stored by our backend, DigitalOcean, or Amazon Web Services beyond the time needed to generate and return the answer to your device.

2. Third-Party Service Providers and Sub-Processors

We use the following service providers to operate the App:

  • Document Recognition Backend (our own infrastructure, hosted on DigitalOcean): When you scan or upload a document, the file is sent to our own backend service, which we operate on infrastructure hosted by DigitalOcean. DigitalOcean acts solely as our infrastructure/hosting provider and does not independently access or use your document content beyond what is necessary to host our service.
  • AI Text Structuring and AI Chat (Amazon Web Services - Amazon Bedrock): Our backend forwards the document to Amazon Bedrock to extract and structure the text (document type, language, patient information if present, test results, medications, tables, etc.). The structured result is returned to our backend and then to your device; it is not stored by our backend beyond the time required to complete this single request. We use the same Amazon Bedrock integration to power AI Chat: each time you send a message in AI Chat, your question, the structured information, the on-device recognized text, and your notes from your entire local health record catalog (Section 1.C) are sent to our backend and forwarded to Amazon Bedrock to generate an answer, under the same safeguards described below.
  • We have configured this integration so that data sent to Amazon Bedrock is not used to train AI models, and we have enabled Amazon Bedrock's zero-retention setting for the AI model we use: no copy of your document content or AI Chat data is written to durable storage by Amazon Web Services, and it is not shared with the underlying AI model's own provider - Amazon Bedrock's architecture keeps that provider from ever accessing customer data.
    Processing takes place in Amazon Web Services' Frankfurt, Germany (eu-central-1) region, within the European Economic Area.
  • Firebase Crashlytics / Remote Config / Analytics (Google): used as described in Section 1.B. You can review Google's Privacy Policy for details on how Google processes this technical data.
  • Apple Inc. (App Store / StoreKit): If you purchase an Anamnesis Plus subscription, your payment is processed entirely by Apple through the App Store. We never receive or store your credit card or other payment details. We only receive confirmation that a purchase was made, together with transaction metadata (product identifier, price, currency, and transaction ID) via Apple's StoreKit framework and, in aggregate form, via Firebase Analytics, as described in Section 1.B.

We do not sell your personal data or your health information to any third party, and we do not use your medical documents or any health information extracted from them for advertising, marketing, or any purpose other than providing the App's core functionality to you

3. Legal Basis for Processing and International Data Transfers

Where the General Data Protection Regulation ("GDPR") applies to you, our legal basis for processing the content of your medical documents and the health record data sent to AI Chat (including any special category health data they may contain, such as diagnoses, test results, or medication information) is your explicit consent (Article 9(2)(a) GDPR), which you provide during onboarding before any document is processed or before you first use AI Chat, and which you may withdraw at any time by discontinuing use of the App's scanning/recognition and AI Chat features (your existing local catalog is unaffected).

Our AI text-structuring sub-processor (Amazon Web Services - Amazon Bedrock) processes your document content within the European Economic Area (AWS region eu-central-1, Frankfurt, Germany). Where a sub-processor is a global company potentially subject to compelled disclosure under non-EU law, we also rely on that provider's Standard Contractual Clauses or equivalent GDPR safeguards as an additional layer of protection.

Where you purchase an Anamnesis Plus subscription, our legal basis for processing the related transaction data described in Section 1.B is the performance of a contract with you (Article 6(1)(b) GDPR) - namely, providing you with the subscription you purchased.

4. Data Retention and Deletion

  • Medical Data: Because your finished catalog is stored locally, you have full control over it. You can delete individual documents or records within the App, or delete the entire App at any time. Deleting the App will instantly and permanently erase all your stored medical data from your device. We cannot recover this data for you, as we do not hold a copy.
  • Recognition Processing Data: Document images and extracted text sent for recognition (Section 2) are not retained by our backend, DigitalOcean, or Amazon Web Services beyond the time needed to complete the recognition request.
  • Technical Data: Crash logs and diagnostic data collected via Firebase Crashlytics are retained according to Google's standard retention policies (typically up to 90 days) and are automatically deleted thereafter.
  • Usage and Purchase Analytics: Firebase Analytics data (including the purchase-related information described in Section 1.B) is retained according to Google's standard Firebase Analytics data-retention settings and is not linked to your medical documents or your identity.

5. Your Privacy Rights (GDPR)

Under the GDPR, and under similar laws that may apply to you depending on where you live (for example, UK GDPR, or U.S. state privacy laws such as the California Consumer Privacy Act), you may have rights to access, rectify, delete, or restrict the processing of your personal data, and to object to certain processing.

  • Since we do not hold your medical catalog or your identity on any server of ours, most of these rights (in particular, the right to erasure / "right to be forgotten") are fully and immediately exercised by deleting the relevant record in the App or by uninstalling the App from your device.
  • For any request relating to data processed transiently by our recognition sub-processors (Section 2), or any other question about your rights, you may contact us using the details in Section 9.
  • We do not sell personal information and do not engage in behavioral advertising, so no "opt-out of sale/sharing" mechanism is required.
  • Billing and payment details for Anamnesis Plus are held by Apple, not by us. For billing questions, refund requests, or to exercise data-subject rights over your Apple ID payment data, please contact Apple Support (reportaproblem.apple.com) directly.

6. Children's Privacy

The App is intended for users who are at least 18 years old (see our Terms of Use). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can address it.

7. App Permissions

To provide its core functionality, the App will request the following permissions on your device:

  • Camera & Photo Library: used exclusively to scan or import physical and digital medical documents that you choose to add. We do not access your camera or photo library in the background or for any purpose other than the action you initiate.

8. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated Privacy Policy at this location and updating the "Effective Date" above. We encourage you to review this page periodically.

9. Contact Us

If you have any questions, requests, or concerns about this Privacy Policy or how your data is handled, please contact us at:

  • Data Controller: Brishtan Filipp
  • Email: anamnesis.health.app@gmail.com

Anamnesis

Your personal health records, organized and always with you.

anamnesis.health.app@gmail.com

  • 01 Privacy Policy How your documents and data are handled
  • 02 Terms of Use Subscriptions, disclaimers and your rights
  • 03 Support FAQ and a direct line to us

© 2026 Brishtan Filipp. Anamnesis is an organizational tool, not a medical device. It does not provide medical advice.

Apple and the Apple logo are trademarks of Apple Inc. App Store is a service mark of Apple Inc.