Privacy Policy
Doctor's Journal — Last updated: 10 October 2026
Doctor's Journal is committed to protecting your privacy and personal health information. This policy explains where your data lives, what leaves your device, and your rights over it. We comply with the New Zealand Privacy Act 2020 and follow best practices for health data handling.
Where Your Data Lives
Doctor's Journal is a local-first app. Your health records, medications, providers, documents, and all other personal data are stored in an encrypted database on your device only. We do not operate a central database of your health information. We cannot access, view, retrieve, or restore your data — not even if asked.
The following is stored on your device:
- Health records: recordings of medical appointments, transcriptions, and AI-generated summaries
- Symptoms diary, journal entries, and notes you create to remember for your doctor
- Medications: names, dosages, schedules, refill dates, and prescription details
- Documents: uploaded medical documents, test results, and associated metadata
- Healthcare providers: names, addresses, and contact details of your doctors, specialists, and pharmacies
- Calendar appointments and reminder schedules
- Optional health readings from Apple Health or Health Connect (heart rate, blood pressure, sleep, etc) if you choose to connect them
- Emergency information: emergency contacts and medical details you choose to store
Your Account and Subscription
To run your account, the app uses the following services. None of them receive your health records:
- Firebase (Google): Firebase Authentication stores your email address and sign-in credentials so the app can sign you in. Our Firebase backend (Cloud Functions, Firestore and Storage, on Google infrastructure) runs the AI features below and keeps a small record for your account: how many AI requests you have used and your subscription status. It does not store your health records.
- Account details we receive: when you create an account we receive your name, email address, sign-up date and sign-in method, so we can administer accounts and help you if you contact us. We do not receive your health records.
- Apple (App Store) / Google (Play Store): handle subscription payments. We do not receive or hold your payment details.
- RevenueCat: confirms whether your subscription is active. It receives your account identifier and your App Store or Play Store purchase record. It does not receive your health data.
Your health records, recordings, transcripts, medications, symptoms and other medical information stay on your device, apart from the AI processing described below.
What Leaves Your Device (AI Processing)
To provide AI-powered features, certain data is sent transiently to third-party services for processing. This data is not retained by us or by them for training:
- OpenAI (Whisper, GPT-4o-mini, text-to-speech): Audio recordings are sent to Whisper for transcription, transcripts are sent to GPT-4o-mini for summarisation and the Ask DJ voice-search feature, and summary text is sent to OpenAI's text-to-speech service for voice playback. All requests are routed through a secure Firebase Cloud Function (Google infrastructure) so the OpenAI API key is not exposed on the device. OpenAI does not retain your data for training when accessed via the API. Long recordings are uploaded temporarily to Firebase Storage for transcription; the audio file is deleted as soon as transcription finishes, whether it succeeds or fails.
- Google (Cloud Vision, Places): Used for document OCR and healthcare provider search. Google processes data per their Cloud Terms of Service and does not use it for advertising.
- Apple HealthKit / Google Health Connect: If you connect Apple Health (iOS) or Health Connect (Android), the app reads selected health readings (heart rate, blood pressure, sleep, etc) into your local journal. These readings stay on your device only and are never sent anywhere off your device.
All data transmitted to third parties is sent over TLS 1.3 encrypted connections. We never sell or share your data for advertising or marketing purposes.
Backups (You Control Them)
You can choose to enable encrypted backups. When you do:
- Your health data is encrypted with AES-256 on your device, before it leaves. The encryption key stays on your device only.
- The encrypted backup is uploaded to your own Google Drive or iCloud account — not ours. Only you have access to it.
- Google or Apple cannot read the contents of the backup — they only store an encrypted blob.
- If you delete the backup from your cloud storage, it is permanently gone. We cannot recover it.
If you disable backups, your data stays only on your device. If your device is lost or reset without a backup, your data cannot be recovered.
How the App Uses Your Data On Your Device
The app processes your data locally to:
- Show your medical history in a searchable timeline
- Manage medication schedules, refill dates, and reminders
- Schedule pre-appointment notifications (24 hours and 2 hours before)
- Read summaries back to you as audio in a voice you choose (text-to-speech)
- Answer your spoken questions from your own records (the "Ask DJ" feature)
- Filter out background chatter (e.g. children talking) so only medical conversation appears in summaries
- Extract text from scanned documents and prescriptions
AI Processing Consent
Before any AI processing occurs, the app will ask for your explicit consent. You may choose not to use AI features, in which case your audio recordings will be stored locally without transcription or summarisation. You can withdraw consent at any time in the app settings.
Your Rights
Under the New Zealand Privacy Act 2020, you have the right to:
- Export your data: You can export your complete medical history at any time in JSON format.
- Edit your information: All records in Doctor's Journal can be edited by you at any time.
- Delete your account: You can permanently delete your account and all associated data from within the app. This action is irreversible.
- Access your data: You can view all data that Doctor's Journal holds about you directly in the app.
- Correct your data: If any information is inaccurate, you can correct it yourself or contact us for assistance.
Data Retention
Doctor's Journal is designed as a permanent medical journal. Your data is retained on your device for as long as you choose to keep it. We do not automatically delete any of your health records.
If you delete your account, all data on your device will be permanently removed. Encrypted backups stored in your cloud account (Google Drive or iCloud) will need to be deleted separately by you, as we do not have access to your cloud storage.
App usage logs are retained on your device for up to 90 days for troubleshooting purposes. These logs never contain personally identifiable information or health data.
Data Security
We take the security of your health information very seriously and implement multiple layers of protection:
- Local encryption: Your data is stored in an encrypted database on your device.
- Backup encryption: All backups are encrypted with AES-256 encryption before leaving your device. Encryption keys are stored securely in your device's keychain (iOS) or keystore (Android).
- Transport encryption: All network communication uses TLS 1.3.
- Authentication: Your account is protected by Firebase Authentication with support for biometric login (Face ID / fingerprint).
- App lock: When enabled, the app requires biometric authentication each time you return to it.
- Session management: Automatic session timeout after 30 minutes of inactivity.
- Login protection: Account lockout after 5 failed login attempts for 15 minutes.
Children's Privacy
Doctor's Journal is not intended for use by children under the age of 16. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us so we can take appropriate action.
Changes to This Policy
We may update this privacy policy from time to time. When we make changes, we will update the "Last updated" date at the top of this policy and notify you within the app. We encourage you to review this policy periodically.
If we make material changes to how we handle your health data, we will provide prominent notice within the app and may require your renewed consent before continuing to process your data under the updated terms.
Contact
If you have any questions or concerns about this privacy policy or how your data is handled, please contact us at:
[email protected]