How to Delete Your Account and Data
To delete your EndoAI account and all associated data:
- Open the EndoAI app
- Go to Profile tab
- Scroll down and tap "Delete Account"
- Confirm deletion
This removes your account, symptom logs, reports, and personal data from active application systems. A minimal non-identifying operational record of the deletion event may be retained for security and compliance. It contains only event status and timestamps — not your email, account identifier, authentication data, or health data. Limited copies may remain temporarily in provider-managed backups under the providers' lifecycle controls.
Alternatively, email us at support@endoaiapp.co.uk with the subject "Delete My Account".
Data deleted: symptom logs, cycle data, AI reports, medical documents, profile information.
1. Who We Are
EndoAI ("we", "us", "our") is a wellness tracking application designed to help individuals with endometriosis log symptoms, identify patterns, and prepare evidence for healthcare appointments.
Data Controller: Mohamed Farhaan, EndoAI
Contact: support@endoaiapp.co.uk
2. Data We Collect
2.1 Health Data (Special Category Data)
Under UK GDPR, health data is classified as Special Category Data requiring explicit consent. We collect:
- Symptom logs: pain regions, intensity, type, and frequency
- Medication records: names, dosages, and frequency
- Menstrual cycle data: period dates, flow, colour, texture, cycle length
- Dietary information: inflammatory and anti-inflammatory food tracking
- Bowel symptoms and exercise activity
- Sleep hours, mood scores, and energy levels
- Medical documents: GP letters, scans, and prescriptions you upload
- Free-text notes you choose to provide
2.2 Account Information
- Email address
- Age
- Diagnosis status (suspected, confirmed, exploring, post-surgery)
- Password (hashed, never stored in plain text)
2.3 Device and Usage Information
When optional analytics or crash reporting is configured for the submitted app build, we may collect:
- Device type and operating system version
- App version
- Usage analytics (screens viewed, features used)
- Crash reports
3. Legal Basis for Processing
Health data: We process your health data based on your explicit consent (Article 9(2)(a) UK GDPR). You provide this consent during onboarding and may withdraw it at any time.
Account data: We process account data on the basis of contractual necessity (Article 6(1)(b) UK GDPR) to provide the service you have signed up for.
Analytics data: When optional analytics is enabled in the submitted app build, we process usage analytics based on legitimate interest (Article 6(1)(f) UK GDPR) to improve the app experience.
4. How We Use Your Data
- To display your symptom history and patterns within the app
- To generate AI-powered pattern reports and observations (not diagnoses)
- To create GP visit preparation summaries
- To provide cycle correlation insights
- To store medical documents you upload
- To send daily check-in reminders (if enabled)
- To improve the app based on optional usage analytics when enabled
5. AI Processing
When you generate AI reports or document summaries, your data is sent to our secure server-side Edge Functions. We use xAI's Grok API to process this data. The AI:
- Identifies patterns and correlations in your symptom data
- Generates structured observations informed by NICE guideline NG73 educational guidance
- Never provides diagnoses, medical advice, or treatment recommendations
6. Data Storage and Security
Your data is stored using Supabase services. All data is:
- Protected at rest by the storage provider
- Encrypted in transit using HTTPS/TLS
- Protected by Row-Level Security, which restricts normal authenticated account access to records associated with that account
- Accessible to authorised server-side functions only where needed to operate documented features such as export and account deletion
- Stored locally on your device first (offline-capable architecture)
7. Third-Party Services
We use the following third-party services to operate EndoAI:
- Supabase — Database, authentication, and file storage
- xAI — AI pattern analysis through the Grok API
- RevenueCat — Subscription management (processes app user identifier and subscription or purchase-status metadata)
- PostHog — Product analytics when configured for the submitted app build
- Sentry — Error tracking and crash reporting when configured for the submitted app build
We do not sell, rent, or share your personal or health data with any third party for marketing purposes. Ever.
8. Data Retention
We retain your account and health data while your account is active. If you delete your account:
- Your account and health data are removed from active application systems
- A minimal non-identifying deletion event record may be retained for security and compliance
- The retained event record contains no email, account identifier, authentication data, or health data
- Limited copies may remain temporarily in provider-managed backups under the providers' lifecycle controls
9. Your Rights
Under UK GDPR, you have the right to:
- Access — Request a copy of all data we hold about you
- Rectification — Correct inaccurate data
- Erasure — Request deletion of all your data
- Data portability — Export your data in a machine-readable format (JSON)
- Withdraw consent — Stop processing of your health data at any time
- Lodge a complaint — Contact the Information Commissioner's Office (ICO)
To exercise any of these rights, email privacy@endoaiapp.co.uk.
10. Children's Data
EndoAI is intended for adults aged 18 and over. We do not knowingly collect data from children or users under 18. If you believe a child has provided us with personal data, please contact us immediately.
11. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of significant changes via the app or email. Continued use of the app after changes constitutes acceptance of the updated policy.
12. Contact Us
For any privacy-related questions or requests:
Email: privacy@endoaiapp.co.uk
Data Protection Officer: dpo@endoaiapp.co.uk