MyBloodTest ("we", "our", "the app") is developed by Joelis labs, UAB. This Privacy Policy explains how we collect, use, store, and protect your information when you use MyBloodTest on iOS, Android, or the web.
Data Controller: Joelis labs, UAB, Girulių g. 10-201, LT-12112 Vilnius, Lithuania (Lithuanian Register of Legal Entities code: 307655634). Contact: info@mybloodtest.app
We take your privacy seriously. Your wellness data is sensitive, and we've designed MyBloodTest to keep you in control of it at all times.
1. Data We Collect
Wellness and test result data. Blood test results, body measurements, activity data, reproductive and menstrual-cycle data (such as menstrual flow, cervical mucus, and basal body temperature), and related notes that you enter manually, scan from lab reports, import from a file (your own MyBloodTest export, a CSV export from a third-party lab service, or a C-CDA / health-record XML file exported from a patient portal such as MyChart), or import from a connected wellness service (Apple Health, Google Health Connect, Fitbit, or Withings). This is your core data and the primary purpose of the app.
Account information. If you create an account with your email address and a password, we store your email address (and an optional display name you provide) and use it to identify your account and to send you account emails such as verification and password-reset messages. If you instead sign in with Google, Apple, or Facebook, we receive your name, email address, and profile photo from that provider. In all cases we use this solely to identify your account for cloud sync; we never receive or store your password (Firebase Authentication handles credentials).
App settings and preferences. Your chosen reference range sources, unit systems, display preferences, pinned biomarkers, and custom reference databases.
Child profile data. If you create child sub-profiles, we collect the child's name, date of birth, gender, height, and lab test results that you enter on their behalf. This data is stored under your account and subject to the same storage and sync policies as your own data. See Section 13 (Children's Privacy) for details.
Camera and photo library access. The app requests access to your device's camera and photo library so you can capture or select lab report images for the AI scan feature. We only access these when you explicitly initiate a scan; we do not access them in the background, and we do not access any photos other than the ones you select for scanning.
Scanned lab report documents. When you use the AI scan feature, your lab report files (images or PDFs) are sent to our Cloud Function server, which forwards them to an AI provider for text extraction and securely stores the original file under your account so you — and any doctor you choose to share it with — can view it later. Storing the original is a required part of the AI scan feature. The extracted text data (test names, values, units) is returned to your device. See Section 6 for details on processing, storage, sharing, and the optional use of your reports for product improvement.
Optional app analytics. If you are signed in and Analytics is enabled after you review the choice during onboarding or turn it on in Settings, the current scope collects pseudonymous product and reliability telemetry across iOS, Android, and the authenticated web app. A server relay independently rechecks the current account grant and sends only reviewed custom events. These cover aggregate feature and operation counts; counts and retention trends for consenting accounts; AI provider/model success, coarse error code, fallback, latency, and token counts; onboarding and subscription operations; connected-service connect, import-count, and disconnect operations; and coarse preferences such as metric/imperial or SI/conventional. They never include test values or interpretations, report text, notes, biomarker names or identifiers, exact result/biomarker units, date of birth, age, sex, profile/child identifiers, the raw account ID, raw searches, prompts, responses, AI error messages, page URL, referrer, or page title. When you affirmatively grant the current active-account Analytics scope, our server derives a stable Analytics-only pseudonym from the account ID using a secret-key one-way function. Google Analytics receives that pseudonym, but not the account ID or secret; we use it only to count consenting active accounts, deduplicate their use across signed-in platforms, and measure aggregate retention. Older grants remain limited to what their earlier disclosure covered and do not silently receive this pseudonym. The relay also uses a random runtime identifier on iOS/Android and a random browser-runtime identifier on authenticated web. The 1.2.4 native app does not include the Firebase Analytics SDK, and the web app loads no Analytics tag, so Product Analytics does not automatically collect screens, sessions, location, advertising identifiers, or app-store purchases. Public website pages are excluded. Analytics remains off in local-only use and while a child profile is active.
Ad attribution data. For signed-in mobile users, with your permission (the analytics consent, collected at onboarding and changeable at any time in Settings), we measure where new installs came from — which marketing campaign, ad network, or referrer — using Adjust. Adjust stays disabled while you use the app without an account. When enabled, Adjust receives a minimal set of non-advertising device-level signals (e.g. a pseudonymous device fingerprint and install-referrer data), install/open events, and a small number of post-install conversion events — a completed sign-up, onboarding completion (with your country), and subscription and free-trial events (with the plan, the purchase source, and the purchase amount and currency) — so we can measure which campaigns lead to sign-ups and subscriptions. We do not send advertising identifiers — the Android Advertising ID permission is stripped from the app and ad-ID/IDFA reading is disabled in the Adjust SDK. It does not receive your name, email address, Firebase account ID, wellness data, test results, or personal notes. Turning analytics off in Settings stops sending events to Adjust on this device.
Ads measurement (Google). Separately from mobile-app Analytics, a dedicated Ads Measurement choice controls whether generic conversion signals may be shared with Google to count campaign results. On iOS and Android this account setting is available to signed-in users, is collected during onboarding, remains changeable in Settings, and defaults off in the EEA, the UK, and Switzerland. It remains off in local-only mode. On the web, the browser-level Ads Measurement choice starts off everywhere and must be affirmatively enabled; a signed-in account's Ads Measurement setting must also be on. This is never used to personalize ads or build advertising profiles, and personalized-advertising signals are hard-disabled in code.
Crash reports. On iOS and Android, if you are signed in and enable Analytics in Settings, Firebase Crashlytics may collect technical crash reports containing device type, operating system version, and a stack trace. Crashlytics remains off while you use the app without an account. We do not attach your account identifier, wellness values, test results, or personal notes to those reports.
Rate-limit metadata. We track AI scan, AI Insight, and AI doctor-summary request counts per account to enforce the usage limits described in our Terms of Service, which vary by plan.
Subscription and purchase data. We use RevenueCat as our subscriptions partner to manage and validate premium entitlements. When you sign in, the RevenueCat SDK initializes and receives a pseudonymous app user ID (your account identifier) and device-level identifiers so it can recognize your subscription status across your devices — this happens for every signed-in user, including those on the free plan, so we can check whether you have an active subscription. If and when you purchase a premium subscription, RevenueCat additionally receives transaction data (the product purchased, purchase and renewal dates, and subscription status) from the Apple App Store, Google Play, or our web payment provider, which we use to unlock premium features and enforce plan-based limits. We never receive your full payment-card details — those are handled solely by the app store or payment provider.
Family plan members. If you create or join a Family plan, basic identity information — your display name, email address, and profile photo — is shared with the family owner and the other members of that plan so the group can be managed (the owner sees who is in their family; members can see who shares the plan). Your wellness data, test results, scanned documents, and personal notes are never shared between family accounts — each member's health data stays private to their own account. You can leave a family at any time, and the owner can remove a member at any time, which ends this sharing.
Web storage and cookies. On the web version, browser localStorage stores essential preferences (such as theme, language, and sign-in state) and your Ads Measurement choice. After a signed-in user grants the current cross-platform Analytics scope, localStorage also holds a random Product Analytics browser-runtime identifier. It may be replaced on reload and is deleted when consent is withdrawn or the account changes. The Product Analytics relay uses no Analytics cookie or browser Analytics tag and is controlled by the signed-in account setting, not the cookie banner. The banner is shown globally until you grant or reject the separate optional Ads Measurement purpose. Only after an affirmative browser choice — and, for a signed-in user, while the account Ads Measurement setting is also on — may Google's Ads tag (gtag.js) load on approved marketing and sign-up pages to count a store-button click or completed web sign-up. It receives no wellness data, test results, or personal notes; is never used for ad personalization or profiles; and is denied on health and account pages. No Google advertising request is made before your affirmative browser choice. You can change this browser choice at any time using the button below.
Switching waitlist. On our website, the "switching" landing page lets you optionally submit your email address — together with which tracking app you currently use and your browser's user-agent string — so we can let you know when the matching import feature becomes available. We store this solely to contact you about that feature; it is not added to a marketing list and is not shared. The legal basis is your consent, given when you submit the form, and you can withdraw it and ask us to delete the entry at any time using the contact email in Section 15.
2. Data We Do NOT Collect
We do not request or collect precise GPS location, contacts, call logs, or browsing history. The Product Analytics relay sends no user location, page URL, or referrer. We do not use advertising identifiers. We do not sell, rent, or trade your personal data to anyone.
3. How Your Data Is Stored
Local storage (default on iOS and Android). On the iOS and Android apps, all your wellness data is stored locally on your device using SQLite — the app works fully offline, and no account or internet connection is required to use the core features. This does not apply to the web version: the website has no local database, so your wellness data is stored in Google Firebase Firestore (cloud) and you must sign in to use it (see "Cloud sync" below and Section 7).
Cloud sync (optional). If you sign in and enable cloud sync, your manually entered and scanned results, imported clinical lab records (from a patient portal such as MyChart, or from Apple Health Records), settings, and custom reference databases are synced to Google Firebase Firestore. This data is stored in Firebase's secure infrastructure and is accessible only by your authenticated account. You can disable cloud sync at any time — your local data remains unaffected. (Fitness and wellness data from Apple Health, Google Health Connect, Fitbit, and Withings is treated separately and stays on-device — see "Wellness app imports" below.)
Original scanned documents (cloud). Separately from cloud sync, when you are signed in and use AI scanning, the original lab-report file is uploaded to and stored in Firebase Storage under your account. This is a required part of the AI scan feature and happens whether or not you have cloud sync enabled. See Section 6 for how it is stored, accessed, and shared, and Section 9 for deletion.
Doctor-share snapshots (cloud). When you create a share link to show your results to a doctor, MyBloodTest uploads a snapshot of the data you choose to share to Firebase Firestore so the doctor can open it — this happens whether or not you have cloud sync enabled. The snapshot contains the selected biomarker values with their dates, statuses, units, reference ranges and any notes you added; your latest AI Wellness Insight (if you have one); and basic profile identity (name, year of birth, gender, height). Your original scanned documents are included only if you explicitly opt in when creating the share. The share is protected by a link plus a PIN we generate and show you once to pass on to your doctor (we store only a hashed copy; the doctor re-enters it to view the share while it remains active), is time-limited, and can be revoked at any time (revoking or expiry removes access). Only the profile and categories you selected are included. For security and to detect abuse of share links (for example, repeated wrong-PIN attempts), each time a link is opened we record a one-way, irreversible hash of the viewer's IP address (from which the original address cannot be recovered) and their browser's user-agent string (which identifies the browser, operating system, and device type) in an access log attached to that share; we show the doctor a notice of this when they open the link. This access log is retained until up to 7 days after the share's scheduled expiry — stopping the share earlier does not shorten this window — and is then automatically deleted; deleting your account removes it immediately. See Section 6 for the AI summary generated for the doctor and Section 9 for deletion.
Wellness app imports (stored on-device). You can import wellness data from Apple Health and Google Health Connect (on-device platforms) and, if you connect them, from Fitbit and Withings (cloud services you authorize via secure OAuth — see Section 7). This paragraph covers fitness and wellness data (activity, body, nutrition, vitals, sleep) — not clinical lab records imported from a patient portal (MyChart) or Apple Health Records, which are treated like your scanned results and do sync when cloud sync is enabled (see "Cloud sync" above). Wellness-app imports (Apple Health, Health Connect, Fitbit, Withings) are available only in the iOS and Android apps — the web version does not offer them. Imported wellness data is stored only on the device where it was imported and is never part of our cross-device cloud sync — each device imports independently. The exception is features you explicitly trigger: generating an AI Wellness Insight or creating a doctor-share that includes wellness categories can transmit the specific values feeding that feature (which may include imported activity, body, nutrition, vitals, or reproductive and menstrual-cycle data) to our servers for that purpose, as described in Section 6 and the Doctor-share snapshots paragraph above.
4. How Your Data Is Used
Your data is used solely to provide and improve the app:
• Display your test results, trends, and status indicators
• Compute whether values are within reference ranges
• Sync data across your own devices (when enabled)
• Process lab report images for AI-powered text extraction
• Store your original scanned reports so you and any doctor you share with can view them
• Rate-limit AI scan, AI Insight, and AI doctor-summary requests (limits vary by plan, see Terms of Service)
• With your optional consent, measure aggregate signed-in app feature use and reliability
• With the same optional consent, collect native crash reports and install/campaign attribution to improve reliability and campaign performance
We do not use your wellness data for advertising, marketing, profiling, or research. Product Analytics excludes health values, health-record/report content, biomarker identity, and raw account identifiers and records only the reviewed pseudonymous fields described above.
5. Legal Basis for Processing
Under the EU General Data Protection Regulation (GDPR), we process your data on the following legal bases:
• Explicit consent (Art. 9(2)(a)). Your wellness and test result data is "special category" data under GDPR Article 9. We process it only with your explicit consent, which you provide when entering, scanning, or importing wellness data. You may withdraw consent at any time by deleting your data or account.
• Contract performance (Art. 6(1)(b)). Account authentication and cloud sync are processed as necessary to provide the service you requested.
• Consent (Art. 6(1)(a)). Optional signed-in Product Analytics, native Crashlytics, native install/campaign attribution, and Ads Measurement operate only under the choices shown during onboarding or in Settings. You may withdraw these choices at any time; future collection is then disabled.
6. AI Processing (Scanning, Wellness Insights & Doctor Summaries)
When you scan a lab report, the image is sent to a Firebase Cloud Function which forwards it to one of our AI providers — Anthropic Claude (served either directly via Anthropic's API or via Amazon Web Services' Bedrock platform), Google Gemini (served either directly via Google's Gemini API or via Google Cloud's Vertex AI platform), or OpenAI's ChatGPT (served either directly via OpenAI's API or via Microsoft's Azure OpenAI Service) — for text extraction. The provider and routing used for any given request are selected by us based on availability, model performance, and cost; you do not choose the provider. All providers' API terms prohibit using API inputs for their own model training by default. The extracted results are written to your Firestore document and then to your device.
AI Wellness Insights. When you generate an AI Wellness Insight, MyBloodTest sends a structured summary of your wellness data to the same AI providers and platforms described above for analysis. Unlike scanning, this is not an image — it is your actual data: biomarker names with their dated values, statuses and any notes you added — including reproductive and menstrual-cycle data (such as menstrual flow or cervical mucus) if you have imported it; aggregated trends (such as weekly, monthly, and quarterly averages); and basic profile attributes (your age or date of birth, gender, and height); and basic context such as your country and unit preferences, used to contextualize reference ranges and tailor advice to your locale. No original lab-report documents are sent. The data is transmitted to the provider via API solely to generate the insight. Under all providers' API terms it is not used to train their models; a provider may retain it only transiently (typically up to around 30 days) for its own abuse- and safety-monitoring before deleting it. This applies to both free and premium insight generations; the number of insights you can generate depends on your plan.
AI doctor summary. When you create a share link for a doctor, MyBloodTest generates a short AI summary of the shared results to help the doctor review them. As with AI Wellness Insights, a structured summary of your data (biomarker values, dates, statuses, reference ranges, basic profile attributes, and your latest AI Wellness Insight if you have one) — not original documents — is sent to the same AI providers and platforms described above. Your free-text notes are shown to the doctor in the shared snapshot but are not sent to the AI provider for this summary. It is transmitted via API solely to generate the summary; under all providers' API terms it is not used to train their models, and may be retained only transiently (typically up to around 30 days) for the provider's own abuse- and safety-monitoring before deletion.
Original document storage. So you can revisit your source reports and optionally show them to a doctor, MyBloodTest stores the original scanned file (image or PDF) in Firebase Storage under your account whenever you use AI scan. Storing the original is a required part of the AI scan feature. Each file is stored once and is accessible only through authenticated requests — by you, or by a doctor only when you explicitly choose to include original documents in a share link you create (the doctor can never reach a file from a profile or category you did not share). The AI provider receives the file only transiently for text extraction; under its API terms it does not train on the file, and may retain it only briefly (typically up to around 30 days) for its own abuse- and safety-monitoring before deleting it. Stored originals are permanently deleted when you delete your account (see Section 9).
Optional use for product improvement. Separately, if you enable "AI Training Data" in Settings (under Privacy → Help improve MyBloodTest), you allow us to use your stored lab reports and their extracted data to improve our own AI scanning models. This is optional and off by default. You can withdraw it at any time in Settings, which immediately makes your data ineligible for any future training. Withdrawing does not delete your stored originals — they remain available for you and any doctor you share them with; to remove the files themselves, delete your account. Child profiles are never eligible for training (see Section 13).
7. Third-Party Services
Firebase and Google Analytics, operated by Google Ireland Limited (EU users) / Google LLC (US). Firebase provides authentication, Firestore cloud storage, Cloud Functions, hosting, and native crash reporting. For Product Analytics, a Firebase Cloud Function verifies the current account grant and forwards only the reviewed event payload to Google Analytics on iOS, Android, and the authenticated web app. Google Analytics receives a random runtime identifier and, only for a current active-account Analytics grant, the stable Analytics-only pseudonym described in Section 1. MyBloodTest does not attach your raw Firebase Authentication account ID, Analytics user properties, URLs, health values, health-record/report content, or biomarker identity. Subject to Google's privacy policy.
Adjust (Adjust GmbH, Germany). Used to measure install attribution and post-install conversion events (sign-up, onboarding completion, and subscription/free-trial conversions, including plan, source, and purchase amount/currency) when you allow analytics. Adjust acts as a data processor for Joelis labs and receives device-level identifiers and these attribution/conversion events — never your wellness data, test results, or personal notes. When you allow Ads Measurement, Adjust also forwards Google's Consent Mode / DMA ad-measurement signal to Google Ads so ad conversions can be counted. Subject to Adjust's privacy policy at adjust.com/privacy-policy.
Google Ads direct website tag (web only). On the website, if you grant the Ads measurement cookie choice (and, when signed in, keep your account Ads Measurement setting on), we load Google's Ads tag (gtag.js) on our marketing and sign-up pages to count ad conversions — a store-button click, a completed web sign-up. This web-only statement describes the direct website tag; on iOS and Android, consented attribution may instead reach Google Ads through Adjust as described above. Under Google Consent Mode the website tag receives only these generic conversion signals, never your wellness data, test results, or personal notes; personalized-advertising signals are hard-disabled, so it can only count conversions, not build advertising profiles. Subject to Google's privacy policy.
AI providers — Anthropic (Claude), Google (Gemini), and OpenAI (ChatGPT). Used for AI-powered lab report text extraction and AI Wellness Insights. Claude is served either directly via Anthropic's API or via Amazon Web Services' Bedrock platform; ChatGPT is served either directly via OpenAI's API or via Microsoft's Azure OpenAI Service; Gemini is served either directly via Google's Gemini API or via Google Cloud's Vertex AI platform. Any given request may be routed to any of these providers and any of these underlying platforms based on availability, model performance, and cost. Images and prompts are processed via API; under each provider's API terms they are not used to train the provider's models, and may be retained only transiently (typically up to around 30 days) for the provider's own abuse- and safety-monitoring before deletion. Subject to each provider's and platform's respective API terms (Anthropic, AWS, Google, Google Cloud, OpenAI, Microsoft).
Apple Health / Google Health Connect. On-device wellness data APIs. We only read data — we never write to these platforms. Data access requires your explicit permission and can be revoked at any time in your device settings.
Fitbit (Fitbit LLC, a Google company, United States). Fitbit can be connected only in the iOS and Android apps (not on the web version). If you connect Fitbit, you authorize us via Fitbit's OAuth to read the activity and wellness data you approve from Fitbit's cloud API (servers in the United States). We use it only to import that data; our access is read-only (we never write back). Like all wellness-app imports, this data is stored on your device and is not part of our cross-device cloud sync. The data is also sent to our servers only for the specific values you choose to feed an AI Wellness Insight or doctor-share (see Sections 3 and 6). The app stores access/refresh state on your device. To make token rotation, disconnect, and account deletion recover safely after a crash or network failure, a server-only Firebase record also holds the refresh credential and revocation metadata; it contains no Fitbit wellness values and is used only to maintain or revoke the connection. Disconnecting or deleting your account requests provider revocation and erases the server record once acknowledged; if revocation is temporarily unavailable, the credential is retained only as retryable revocation debt until it succeeds. You can also revoke access from your Fitbit account. Subject to Fitbit's privacy policy.
Withings (Withings SA, France). Withings can be connected only in the iOS and Android apps (not on the web version). If you connect Withings, you authorize us via Withings' OAuth to read the measurements you approve from Withings' cloud API. We use it only to import that data; our access is read-only (we never write back). Like all wellness-app imports, this data is stored on your device and is not part of our cross-device cloud sync. The data is also sent to our servers only for the specific values you choose to feed an AI Wellness Insight or doctor-share (see Sections 3 and 6). The app stores access/refresh state on your device. To make token rotation, disconnect, and account deletion recover safely after a crash or network failure, a server-only Firebase record also holds the refresh credential and revocation metadata; it contains no Withings measurements and is used only to maintain or revoke the connection. Disconnecting or deleting your account requests provider revocation and erases the server record once acknowledged; if revocation is temporarily unavailable, the credential is retained only as retryable revocation debt until it succeeds. You can also revoke access from your Withings account. Subject to Withings' privacy policy.
Authentication (Firebase Authentication, plus Google, Apple, Facebook). Sign-in and account credentials are handled by Firebase Authentication. You can sign in with an email address and a password, or with Google, Apple, or Facebook. These providers supply basic profile information such as your name, email address, or profile photo; we do not access your contacts, posts, or other social content. In the iOS and Android apps, when Apple supplies MyBloodTest with a one-time authorization code, our backend exchanges it for a refresh credential used only to revoke MyBloodTest's Apple grant when you delete your account. On Android, Apple's browser response first passes through a server-only, verifier-protected handoff that becomes unusable after five minutes and is deleted after use or by scheduled cleanup; the reusable credentials are never put in the app callback URL. The refresh credential and its account binding and lifecycle metadata are kept in a server-only Firebase revocation record that app clients cannot read and that contains no wellness or test-result data. If Apple revocation is temporarily unavailable during deletion, this minimal record is retained as retryable revocation debt until Apple confirms success or that the grant is already invalid, and is then erased. The website's Firebase Apple sign-in popup does not expose that authorization code to MyBloodTest, so an account that used Apple only on the website may have no revocation credential on our server; in that case you can remove MyBloodTest under your Apple Account's Sign in with Apple settings. For email/password sign-in, your password is managed by Firebase Authentication and is never visible to us.
RevenueCat (RevenueCat, Inc., United States). Used to manage premium subscriptions and validate purchases across the Apple App Store, Google Play, and web. RevenueCat acts as a data processor for Joelis labs and receives a pseudonymous app user ID, device-level identifiers, and subscription/transaction data — never your wellness data, test results, or personal notes. Subject to RevenueCat's privacy policy at revenuecat.com/privacy.
Stripe (Stripe, Inc., United States). On the web version only, card payments are processed by Stripe (via RevenueCat). When you buy or manage a subscription on the website, Stripe receives the payment-card and billing details you enter at checkout and processes the charge; we never receive or store your full card number. On iOS and Android, payments are handled by the App Store / Google Play instead, not Stripe. Subject to Stripe's privacy policy at stripe.com/privacy.
8. International Data Transfers
Some of our third-party service providers (Firebase/Google, Anthropic, OpenAI, Amazon Web Services, Microsoft, RevenueCat, and — for subscriptions purchased on the web — our payment processor Stripe) are based in the United States. When you sign in (which initializes RevenueCat to validate your subscription status), use cloud sync, the AI scan feature, AI Wellness Insights, a doctor-share link (which uploads a snapshot and generates an AI summary), or a premium subscription, your data may be transferred to and processed in the US. These transfers are protected by the EU-US Data Privacy Framework and Standard Contractual Clauses (SCCs) as approved by the European Commission, ensuring your data receives an adequate level of protection as required by GDPR.
9. Data Retention and Deletion
Your local data persists until you uninstall the app or clear app data. Cloud-synced data persists in Firestore until you delete it. Google Analytics event- and user-level data is retained for up to 2 months, and exported Analytics event tables expire after 62 days. Firebase Crashlytics retains crash reports and associated identifiers for 90 days. Some aggregate Google Analytics report totals may remain without app-instance-level detail after the event-retention period.
How to delete your account and active app data
You have two options:
Option 1 — In-app deletion (recommended).
• Open MyBloodTest and sign in if you aren't already.
• Go to the Settings and open the Sync tab.
• Scroll to the bottom and tap Delete Account.
• Confirm by typing DELETE when prompted.
This permanently removes all your locally stored data, all cloud-synced data (Firestore documents under your user ID), your stored original lab-report documents (Firebase Storage), your AI-training consent (revoked immediately at deletion, with the consent record itself erased shortly afterward), child profile data, custom reference databases, any doctor-share links you created and their stored snapshots, AI scan, Insight, and doctor-summary rate-limit counters, and your authentication record (your Google, Apple, Facebook, or email/password sign-in identity). Wellness app imports are also cleared. If our server captured an Apple revocation credential from an iOS or Android sign-in, deletion immediately requests revocation of MyBloodTest's Apple ID grant. When Apple is temporarily unavailable, the server-only credential described in Section 7 remains only as retryable revocation debt until Apple acknowledges the revocation; the deleted account's ordinary data and sign-in record are not restored while that retry is pending. If you used Apple only through the website and our server has no revocation credential, deletion still removes your MyBloodTest data and authentication record, but you may also need to remove MyBloodTest manually under your Apple Account's Sign in with Apple settings. The action cannot be undone.
Provider records have separate retention. Purchase and transaction records held by the app stores (Apple, Google), by our payments partner RevenueCat, and — for subscriptions purchased on the web — by our payment processor Stripe — such as which product you bought and its purchase, renewal, and cancellation dates, linked to a pseudonymous account identifier — are retained by those providers as required for their own tax, accounting, refund, and fraud-prevention obligations. Withdrawing Analytics or deleting the account stops future optional collection and rotates/removes the local Analytics instance identifier, but pseudonymous Analytics and Crashlytics records already uploaded age out under the retention periods above rather than being erased immediately. These provider records are not used to restore the deleted account.
Option 2 — Email request (if you no longer have app access).
If you no longer have access to the app (e.g. uninstalled it, lost your device, or can't sign in), email us at info@mybloodtest.app from the email address tied to your account, with the subject "Account deletion request". We'll confirm and complete the deletion within 30 days.
Other deletion options
• Delete individual results. Long-press any result in Calendar or History and tap delete.
• Export your data first. Use Settings → Export and choose Backup to download a restorable copy of your profiles, results, portable display preferences, pins, custom references, insights, and stored original lab reports. You can choose whether to include imported wellness data. Account credentials, consent records, subscription records, and device connection state are intentionally excluded.
• Disconnect wellness imports. Wellness app imports are deleted from MyBloodTest when you disconnect the wellness platform in Settings. They can be re-imported at any time by reconnecting.
• Uninstall the app. Uninstalling removes the on-device data, but cloud-synced data remains until you delete it via the in-app option or email request above.
Disaster recovery snapshots. To protect against accidental data loss caused by software bugs or operational errors, our cloud database (Firebase Firestore) maintains automated point-in-time recovery snapshots for up to 7 days. When you delete your account, your data is removed immediately from active systems and purged automatically from these snapshots within 7 days as the recovery window rolls forward. Snapshots are encrypted at rest and accessible only by Joelis labs personnel for disaster recovery purposes — they are never read for any other reason and never shared with third parties.
10. Data Security
Data in transit is encrypted via TLS (HTTPS). Firebase Firestore data at rest is encrypted by Google. Local SQLite data is stored in the app's private sandbox, inaccessible to other apps. Authentication tokens are managed by Firebase Auth with industry-standard security. AI provider API keys (Anthropic, Google, OpenAI) are stored in Google Secret Manager and never exposed to clients.
11. Your Rights
Depending on your jurisdiction, you may have the right to:
• Access all personal data we hold about you
• Export your data (via the app's built-in Export feature)
• Delete your data (individual results or full account)
• Withdraw consent for cloud sync at any time
• Revoke wellness data access in your device settings
• Withdraw optional app analytics consent
For GDPR (EU/EEA), CCPA (California), or other data protection requests, contact us at the email below. If you are in the EU/EEA and believe your data protection rights have been violated, you have the right to lodge a complaint with your local supervisory authority. In Lithuania, this is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, VDAI) at vdai.lrv.lt.
12. Government and Law Enforcement Requests
If a government authority or law enforcement agency requests user data, Joelis labs, UAB reviews each request for legal validity and jurisdiction before responding. We challenge requests that appear unlawful, overbroad, or extrajudicial. Where disclosure is legally required, we disclose only the minimum information necessary and never bulk account contents. We document every request received, our response, and the legal basis. We will notify affected users of any request unless legally prohibited from doing so.
13. Children's Privacy
Child profiles managed by an account holder. Account holders may create child profiles within their own account to track wellness data for their minor children for whom they are the parent or legal guardian. Child profiles are not separate accounts — they are managed entirely by the adult account holder, who is responsible for all data entered. The child does not log in, sign up, or interact with the app directly. Wellness app integration, usage analytics, and AI training data collection are automatically disabled for child profiles.
Data collected for child profiles. We collect the child's name, date of birth, gender, height, and lab test results entered by the parent. This data is stored under the parent's account and subject to the same local storage and optional cloud sync policies described in this Privacy Policy.
Protections for child profiles. When a child profile is active: • Wellness app integration (Apple Health, Google Health Connect, Fitbit, Withings) is disabled — no automated data collection occurs for children. • Product Analytics and Crashlytics are disabled — no usage analytics or crash reports are collected. • AI training data consent is hidden and always off — a child's scanned reports are stored under your account so you can view and share them like your own results, but they are never used to train our AI models.
Legal basis. A child's wellness and test-result data is "special category" health data under GDPR Article 9, so we process it on the basis of the explicit consent of the parent or legal guardian (GDPR Article 9(2)(a)), given within the parent's own account — the child never logs in or provides consent themselves. We also comply with COPPA (US, children under 13) and Apple's guidelines for handling minors' data.
Parental rights. Parents can view, edit, export, and delete all data associated with a child profile at any time. Deleting a child profile permanently removes their results and profile data from both the device and the cloud (if sync is enabled). To request complete deletion of a child's data, parents may also contact us at the email below.
No direct child access. Children do not have independent accounts. The app requires the parent's authenticated session to access child data. If you believe a child has accessed the app without parental supervision, please contact us.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Continued use of the app after changes constitutes acceptance.
15. Contact
If you have questions about this Privacy Policy or want to exercise your data rights, contact us at: