Privacy Policy
Effective 8 August 2026 · Version 2026-08-08
Avicrine handles health information, so we keep this policy specific and honest: it describes only what the application actually does today.
1. Who is responsible for your data
Avicrine is operated by Avicrine Enterprise, [REGISTERED ADDRESS — TO BE SUPPLIED BY OPERATOR]. Avicrine is supplied to you through a clinic. Your clinic decides which staff can see your records and is responsible for its own clinical record-keeping obligations. For privacy questions write to avicrine@gmail.com.
2. Information we collect
We collect only what the features you use require. There is no public self-registration: your clinic creates your account.
- Account information — username, password (stored only as a salted hash by our authentication provider), the clinic you belong to, and your role.
- Profile information — name, email if your clinic records one, phone, age or date of birth, gender (male or female), country, height, weight, emergency contact, and your diabetes type, diagnosis year and personal HbA1c or weight goals.
- Health tracking — glucose readings, weight, blood pressure, water, exercise and medication entries you record.
- Lab reports and documents — files you or your clinic upload, and the diabetes-related values extracted from them.
- Consultations and messages — consultation requests, scheduling details, clinician notes and message threads between you and your clinic.
- AI interactions — the questions you send to the AI companion and the replies it generates.
- Technical information — sign-in attempts, timestamps and administrative actions kept in security logs.
We do not operate advertising trackers, we do not run third-party analytics, we do not collect device contacts, precise location or your device's camera roll, and Avicrine does not currently process payments from patients, so we hold no card data.
3. Why we use it, and our reasoning
- Account and profile data — to identify you, connect you to the right clinic and keep your account secure.
- Health tracking, reports and analyses — to show your own trends and generate plain-language explanations for you and your care team.
- Consultations and messages — to run the request, scheduling and follow-up workflow with your clinic.
- AI interactions — to answer your questions and to let your doctor review and correct the guidance you were given.
- Security logs — to detect abuse, throttle repeated failed logins and investigate incidents.
We do not sell your data, we do not share it with advertisers, and we do not use your health information to train third-party AI models.
4. Who can see your information
- You — all of your own records.
- Your assigned doctor — the clinical records needed to care for you.
- Your clinic's admin staff — records belonging to that clinic only.
- Platform administrators — limited access for support, security and abuse investigation.
Access is enforced in the database itself, not only in the interface: every record is scoped to its owner and clinic, so one patient cannot reach another patient's data and one clinic cannot reach another clinic's data.
5. Service providers who process data for us
We do not sell your information, but trusted third-party service providers may process it on our behalf as necessary to operate and provide the service. We describe them by category rather than by vendor name:
| Provider | Purpose | Data involved |
|---|---|---|
| Cloud infrastructure and data storage providers | Store your account, profile, health tracking entries, consultations, messages and uploaded documents, and run the authentication system. | Account data, health data, uploaded files |
| Application hosting providers | Serve the application and route requests between the app and the services it depends on. | Technical request metadata |
| AI technology providers | Generate plain-language explanations, coaching replies and report summaries when you use an AI feature. | The text and report values included in that specific AI request |
| Security and operational monitoring providers | Help us keep the service available and detect abuse or technical faults. | Technical and security log data |
AI requests contain only the content needed for that request. AI technology providers process it to return a response; they are not given access to our database.
6. Where your data is stored and how it is protected
Data is stored with trusted cloud infrastructure and data storage providers, and is transmitted over HTTPS/TLS. Passwords are hashed. Uploaded files are held in a private bucket that is never publicly readable — downloads require an authenticated request and a short-lived signed link. Database access is restricted per user and per clinic.
We do not claim end-to-end encryption: our servers can process your data in order to provide these features. We also make no claim of HIPAA, GDPR or ISO certification; no independent audit has been performed.
7. How long we keep it
| Category | What | Retention | Who can access |
|---|---|---|---|
| Account & profile | Username, name, email (if provided), age, gender, country, contact details | While the account is active. Removal is requested through your clinic administrator; see the account management section. | You, your clinic's admin staff, your assigned doctor |
| Health tracking | Glucose, weight, blood pressure, water, exercise, medication logs | While the account is active. Removal is requested through your clinic administrator; see the account management section. | You, your assigned doctor, your clinic's admin staff |
| Lab reports & AI analyses | Uploaded report files and the extracted values plus AI explanation | While the account is active. Removal is requested through your clinic administrator; see the account management section. | You, your assigned doctor, your clinic's admin staff |
| Consultations & clinical messages | Requests, reasons, scheduling, clinician notes, message threads | While the account is active. Your clinic may be independently required to keep clinical records for a longer statutory period — ask your clinic. | You, your assigned doctor, your clinic's admin staff |
| AI conversations | Your messages to the AI companion and its replies | While the account is active. Removal is requested through your clinic administrator; see the account management section. | You, your assigned doctor |
| Security & audit logs | Sign-in attempts, administrative actions, timestamps | Up to 12 months, then deleted. Not deleted on account deletion. | Platform administrators only |
8. Account management and deletion
Accounts on Avicrine are created and managed by your authorized clinic administrator. The application does not currently provide a self-service “delete account” option, so patients and other users cannot delete their own account directly from the website or app.
If you want your account or the information associated with it removed, contact your authorized clinic administrator, who handles account management for your clinic. You can also write to avicrine@gmail.com and we will pass the request to the responsible clinic or action it where we are able to.
We cannot promise immediate or complete deletion in every case: some information may need to be retained for legitimate security, clinical record-keeping or legal reasons. In particular, security and audit log entries are kept for up to 12 months for abuse investigation, and your clinic may hold its own copies of clinical records under record-keeping rules that apply to the clinic rather than to Avicrine.
9. Your choices
- You can view and correct your profile information at any time.
- You choose what you log — tracking entries are optional.
- You can decline AI features by not using them; the rest of the app still works.
- You can ask your clinic administrator, or contact us, about access to or removal of your information.
10. Children
Avicrine is intended for adults managing diabetes. Accounts for minors should only be created by a clinic with the consent of a parent or guardian, in line with the clinic's own rules.
11. Changes and contact
If this policy changes materially, we update the version above and ask you to review it again inside the app. Questions, access requests and complaints: avicrine@gmail.com.