Privacy policy · Version 1.100.0

Private by default, with no developer cloud.

Prepared 8 September 2026 for version 1.100.0. This policy applies when you install that version. VisitRelay keeps the information you enter, import, or create inside the app’s local container unless you explicitly share or export it.

Which version are you using?

Version 1.100.0 is being prepared for App Review and is not yet publicly released. If you use the recording-capable version 1.23.0, read its existing privacy policy.

Information processed by VisitRelay

VisitRelay can process information you choose to provide, including:

  • care-profile labels and relationships;
  • exact medication items, medication-change notes, and the date you last changed or explicitly checked a list;
  • appointment details, questions, concerns, preparation items, and manual covered, ready, or clarification states;
  • short typed Visit Mode notes, personal “What I heard” notes, and reviewed source-linked drafts;
  • follow-up tasks and optional local reminder dates;
  • PDFs and images you import for a saved visit;
  • an optional minimal Apple Calendar event and the administrative fields you explicitly include; and
  • protected legacy audio and transcripts created by older versions, if they remain on the device. Version 1.100 cannot create either.

This content can contain sensitive health information.

No developer collection or tracking

Version 1.100.0 has no developer backend and does not automatically transmit visit content, identifiers, usage data, diagnostics, advertising data, or tracking data to the developer. If you choose to contact support or share a diagnostic, the recipient receives only what you deliberately send through your chosen service.

  • No account system
  • No advertising or cross-app tracking
  • No analytics or third-party SDK
  • No cloud sync or external artificial-intelligence provider

Typed-only Visit Mode and local organisation

Current Visit Mode is typed-only. VisitRelay does not request microphone or speech-recognition permission, record an appointment, run live transcription, or play audio. Standard keyboard dictation is controlled by iOS and the user’s keyboard settings.

Visit organisation defaults to deterministic on-device rules. You can instead choose manual organisation or, on supported devices, Apple’s local system language model. Selected source notes stay on the device. Generated wording is an untrusted draft linked to its source. The app checks source links, numbers, medication wording, negation, and other safety boundaries, but these checks are not clinical validation or a guarantee of accuracy. Compare every draft with your original notes. A fallback requires your choice.

Medication boundary

A medication list is your exact local reference. VisitRelay does not identify, normalize, verify, or change medicine names, strengths, instructions, interactions, allergies, or current status. A displayed date records only your edit or explicit recheck. It is not clinical verification.

Optional system features

App lock

You can require Face ID, Touch ID, or the device passcode. iOS performs authentication; VisitRelay receives only success or failure and never receives biometric data or your passcode. A privacy cover remains in place while the app is inactive.

Calendar

Calendar access is optional and requested only after you choose Add to Calendar. The event starts with a generic title, date, time, and duration. Clinician, clinic, appointment type, and location are each off until you include them. Questions, medications, symptoms, and visit notes are never eligible. Calendar providers may sync the event under their own settings and terms.

Notifications, widget, Siri, and Shortcuts

Reminders are optional local notifications; there is no push server. Follow-up wording is generic by default, and preparation reminders are always generic. The widget defaults to counts and timing, with wording separately opt-in and privacy-sensitive while locked. Prepare a Visit and Open Today carry only fixed destinations and open the app in the foreground after local device authentication.

Sharing and exports

Nothing is shared automatically. You inspect a complete preview and choose an Apple Share Sheet destination. Medication inclusion in a preparation handoff starts off. Original Visit Mode notes, retained legacy audio, and full legacy transcripts stay out of ordinary handoffs. Documents are private reference files and are never attached automatically.

Family updates are limited to one selected care profile and eligible confirmed or personally edited items. VisitRelay does not choose a recipient, send a message, track delivery, or verify that an update was read. A destination you select controls its copy under its own privacy terms.

Backup and local storage

App content is stored locally with iOS data protection. A backup is created only when you request it. The file uses authenticated AES-256-GCM encryption; a key derived from your password protects its random content key. Visit documents are included so restore cannot silently create an incomplete visit. Retained legacy audio is off unless you explicitly include it.

VisitRelay and the developer do not store or recover your backup password. Restore authenticates the file, shows content-free counts, and replaces current local data only after you confirm. Alerts are restored only after a separate opt-in.

Retention and deletion

You control retention. VisitRelay provides separate controls for documents, retained legacy audio, one visit, one care profile, the fictional example, and all local app data. Deleting a visit or profile also removes its owned local files and notification requests.

The private database, documents, retained legacy recordings, widget snapshot, and temporary exports are excluded from device backup. Temporary exports are removed after use or cleanup. An encrypted backup saved outside VisitRelay remains under your chosen destination and must be deleted there separately.

Security

VisitRelay applies complete file protection to its private database, documents, retained legacy recordings, recovery checkpoints, widget snapshot, and temporary exports. Imported files are restricted to supported PDF and image formats, copied under random internal names, and limited by count and size. No local storage can eliminate every risk; secure the device with a passcode and keep iOS updated.

Children and medical boundary

VisitRelay is intended for adults managing their own care or helping another person with permission. It is not directed to children. VisitRelay organises user-supplied information. It does not diagnose, treat, prescribe, interpret clinical results, recommend medical decisions, or replace a healthcare professional.

Policy changes

If VisitRelay’s data practices change, this policy and the App Store privacy answers will be updated before the changed version is released.

Contact

Questions about this policy can be sent to rhantho@gmail.com. Do not include health content, medication wording, clinician or patient identifiers, screenshots, documents, retained legacy audio or transcripts, encrypted backup files, or backup passwords.