LEGAL

Privacy Policy

Version 1.0 · Effective September 2, 2026

1. Data controller

Data controller: The developer of the ECG Brief application

2. Scope of the service

ECG Brief provides healthcare professionals with AI-assisted clinical decision support based on ECG images. A report is not a definitive result or diagnosis, does not replace physician review, and must not be the sole basis for an emergency decision.

The service is not intended for children or for direct patient use. Users are responsible for having authority to process uploaded data and for excluding unnecessary patient identifiers.

3. Data we process

  • Account: Supabase user ID and, depending on sign-in method, email address, Google or Apple identity and provider-supplied name.
  • Clinical content: the uploaded ECG image, information visible in the image, and the resulting structured AI report.
  • Consent: records of the AI-consent version, time, language, grant, and withdrawal.
  • Operations and security: request ID, model/prompt version, token usage, latency, failure category and limited technical diagnostics.
  • Subscriptions and credits: purchased product, plan, store, subscription status and periods, credit balance and movements, and non-reversible technical markers created to prevent repeated use.
  • Support: the email address and message supplied when contacting us.

Apple or Google processes payments. We do not receive full payment-card details, serve ads, create advertising profiles, or sell personal data.

4. Collection and legal bases

We collect data when a user enters the app, creates an account, uploads an ECG, gives consent, buys a subscription, or contacts support, and through technical processing required to operate the service safely and reliably. Processing relies, as applicable, on contract performance, legal obligations, legal claims, legitimate interests, and explicit consent. ECG images are sent to OpenAI for AI processing only after the user has separately given explicit consent in the app.

5. AI processing

After explicit consent, the ECG image is processed through the OpenAI API to generate a clinical decision-support report. OpenAI does not use API inputs or outputs to train its models by default. OpenAI's default abuse-monitoring logs may contain inputs and outputs and may be retained for up to 30 days, unless longer retention is legally required. The healthcare professional remains responsible for clinical review and action.

6. Service providers and international transfers

We use Supabase for authentication, database, private storage and server functions; OpenAI for AI report generation; RevenueCat for subscription verification; Apple and Google for sign-in, distribution and payments; Resend for verification emails; and Sentry for diagnostics configured to exclude personal and clinical content. These providers may process data outside Türkiye under applicable safeguards and transfer mechanisms.

7. Retention and deletion

  • Temporary ECG images and analysis records are retained for 7 days after completion.
  • Items explicitly saved by the user remain until deleted by the user or account deletion.
  • Account, consent, subscription and credit records remain until account deletion, subject to legal or dispute-related retention.
  • A non-reversible welcome-credit HMAC marker is retained for 3 years.
  • A non-reversible paid-period marker is retained for replay prevention while the service operates.
  • Support correspondence is retained for up to 3 years after resolution.

Deleting an ECG Brief account does not automatically cancel an App Store or Google Play subscription. It must be cancelled separately in the relevant store.

8. Security

We use encryption in transit, private storage, per-user access policies, server-side verification, least-privilege access and monitoring configured to exclude sensitive content. No system can guarantee absolute security.

9. Your rights

Subject to applicable law, you may request access, a copy, correction, deletion, restriction or objection, withdraw consent, and seek a remedy. In Settings, you can withdraw AI consent, delete analyses and permanently delete your account. If you cannot access the app, use our account deletion page or contact support.

Users in Türkiye may also contact the Personal Data Protection Authority.

10. Changes

We may update this policy when the service or law changes. Material changes will be communicated in the app or through another appropriate channel.