Controller: Adrian Kereky, a natural person, Romania (until the company that will take over the service is incorporated; the change will be announced here). Data protection contact: privacy@anpheros.com.
This policy covers the Anpheros Daily app (iPhone, Android, Mac, web at app.anpheros.com), the anpheros.com website and Anpheros Platform insofar as it processes your data.
1. What Anpheros is
Anpheros Daily keeps your medical record: symptoms, measurements, weight, sleep, activity, medications, lab results, documents, vaccines, conditions, appointments, pregnancy, the emergency card, the profiles of your family members. An assistant based on artificial intelligence answers questions about the record. This is health data, a special category under Article 9 of Regulation (EU) 2016/679 (GDPR). We process it only with your explicit consent (Article 9(2)(a)) and for the purposes below.
2. What data we process
2.1 Account data
Email address, name, profile photo (optional), authentication identifier, chosen language and country, subscription plan, devices linked to the account.
2.2 Health data you enter
Symptoms (with intensity, body location, photos), measurements (blood pressure, pulse, oxygen, temperature, glucose), weight, sleep, activity, mood, meals and water, medications and doses, conditions, allergies, vaccines, lab results (including scanned reports), medical documents (photos, PDF), appointments, pregnancy data, blood group, emergency contacts, voice notes, conversations with the assistant.
Lab reports, medicine boxes and documents you photograph are read by the AI assistant to extract values; the image and the extracted values are kept in your record. The vision test uses the camera and microphone only during the test; only the result is kept.
2.3 Data about other people
You can create profiles for family members (children, parents) and record data about them. You are responsible for the data you enter about others and for their agreement where required. A profile can later be transferred to the person's own account.
2.4 Health data read from your phone and watch
Only if you turn the connection on in Settings › Devices and health data, and only for the categories you choose: Apple Health (iPhone, Apple Watch), Health Connect and Samsung Health (Android, Galaxy Watch), the Anpheros apps for Apple Watch and Wear OS.
| Category | What we read | How it is kept |
|---|---|---|
| Heart | heart rate, resting heart rate, heart rate variability, rhythm alerts, ECG classification (not the ECG trace) | heart rate as 4-hour summaries (min, average, max, count); the rest per day or as records |
| Breathing | blood oxygen, respiratory rate | 4-hour summaries / records |
| Blood pressure, glucose, temperature | each measurement from connected devices | each measurement |
| Body | weight, height, body composition | each measurement |
| Sleep | sleep sessions and their stages | each session |
| Activity | steps, distance, calories, workouts | per day; workouts as records |
| Nutrition, cycle, other | water, meals, menstrual flow, headaches, mindfulness | records |
| Profile | sex, date of birth, blood group | only if missing from your profile |
The app only reads. It writes nothing back to Apple Health, Health Connect or Samsung Health. On first connection it reads the last 30 days, then only what is new, when you open the app or tap "Sync now". We do not read in the background. This data is not used for advertising, not sold and not sent to third parties for marketing, in line with Apple's and Google's rules for health data.
2.5 Technical data
Server logs (IP address, time, request path, response code, internal identifiers), with no medical content. The anpheros.com website uses no tracking cookies and no third-party analytics; it only remembers your chosen language, in your browser. The contact form uses Cloudflare Turnstile against bots.
3. Why we process data
| Purpose | Legal basis |
|---|---|
| To keep your and your family's medical record and show it to you in the app | explicit consent (Article 9(2)(a)); performance of the contract for account data (Article 6(1)(b)) |
| To answer your questions through the AI assistant and extract values from scanned documents | explicit consent |
| To point out correlations and observations (Plus and Max plans) | explicit consent |
| To share the record with the people or doctors you choose | explicit consent, given in the app at each share |
| To send account emails (confirmation, password reset, important changes) | performance of the contract |
| To keep the service running and secure (technical logs, rate limiting, access log) | legitimate interest (Article 6(1)(f)) |
We do not use your data for advertising, do not sell it and do not build marketing profiles. We make no automated decisions with legal effects on you.
You can withdraw consent at any time, in the app (disconnecting the phone, deleting data, revoking a share or deleting the account) or by writing to us. Withdrawal does not affect processing done before.
4. Who we share data with, at your choice
- Family: another person sees a profile from your account only after scanning a QR code you generate. The data stays in your account; you can revoke access at any time.
- Doctors: you can generate a time-limited link (between 1 and 90 days) to a person's record summary. The link can be revoked at any time; every opening is recorded in the access log you see in the app.
- Third-party apps through Anpheros Platform: another app, or a doctor with platform access, can read or write your record only after you accept, on a consent screen, which data, in which direction and for how long. Each app sees you under a different identifier, so apps cannot combine data about you without your consent. You see in the app who has access and when they last read, and you can withdraw it.
Outside these cases we give your data to no one, except the processors below and where required by law.
5. Where data is kept and who processes it
- Hosting: Google Cloud, region europe-west4 (Netherlands): servers, database (Cloud SQL) and files (Cloud Storage), encrypted at rest and in transit.
- AI assistant: Google Cloud Vertex AI (Gemini models). We use the service's global endpoint, which means a request to the assistant may be processed by Google in data centres outside the European Union, under the European Commission's standard contractual clauses included in our contract with Google. Google does not use data sent through Vertex AI to train its models. Your record stays stored in the EU; only the context needed for the answer is sent to the model.
- Authentication: Firebase Authentication (Google), a global service, with the same contractual safeguards.
- Email and forms: Google Workspace; Cloudflare for DNS and contact-form protection.
- Payments: we currently process no payments and store no card data. When we introduce paid subscriptions through the App Store or Google Play, payment will be processed by Apple or Google and we will receive only the subscription status; we will update this page.
All processors are bound by data processing agreements under Article 28 GDPR.
6. How long we keep data
- For as long as you have an account. What you delete in the app is marked deleted immediately and no longer appears anywhere, including for the assistant and for people with access.
- When you delete the account (Settings › Profile › Delete account): your identity (name, email, date of birth, link to authentication) is anonymised immediately; all health data is marked deleted and disappears from the app; files are deleted from storage; the assistant's data (conversations, index) is physically removed; the authentication account is deleted. The operation is irreversible.
- The access log (who opened what, when) is kept after deletion, without personal data, with internal identifiers only, as an obligation to be able to demonstrate earlier accesses (Article 17(3)(b)).
- Database backups expire after 7 days; files deleted from storage can be technically recovered for at most 7 days. Technical logs are kept for 30 days.
- Data imported from your phone can be deleted separately, from Settings › Devices and health data › Disconnect › Delete imported data.
7. Your rights
Access, rectification, erasure, restriction, portability (PDF export or HL7 FHIR format from the app), objection, withdrawal of consent and a complaint to the Romanian supervisory authority (www.dataprotection.ro) or the authority in your country. Write to privacy@anpheros.com; we answer within 30 days, usually much sooner.
8. Children
Anpheros is not aimed at people under 16 as account holders. Child profiles in an account are created and managed by the parent or guardian, who is responsible for the data entered.
9. Security
Access only through an authenticated account; every request is checked on the server against your account and profile; data encrypted in transit and at rest; logs contain no medical data; the team's access to production is restricted and recorded; the internal security audit of October 2026 left no critical or high issues open. If you find a vulnerability, write to security@anpheros.com.
10. Changes
If we change this policy, we announce it in the app and on this page, with the date. For changes that affect health data we ask for consent again.