Epilog Privacy Policy

Last Updated: July 29, 2026

Health & Fitness App

🔒 Your privacy is our priority. Epilog stores health data locally on your device. Nothing is transmitted unless you use an optional feature described in this policy — such as Anonymous Research (weekly snapshots when enabled), optional AI Insights (free: weekly summary; Pro: daily), in-app promo tips from Firebase, seizure email alerts (Epilog Pro), or voluntary app feedback.

1. Introduction

Epilog ("we," "our," or "the App") is a seizure, medication, and diary tracking application designed to help individuals with epilepsy organise and record their health information. This Privacy Policy explains how Leandro Barreto / LND Tech ("the Developer") handles your information when you use the App.

By using Epilog, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the App.

2. Information We Collect

2.1 Data You Provide (Stored Locally)

When using Epilog, you may enter the following types of information, which is stored exclusively on your device using Apple's SwiftData framework:

2.2 Data We Do NOT Automatically Collect

Epilog does not automatically collect or transmit:

2.3 Anonymous App Account (Firebase)

On launch, Epilog may sign you in anonymously with Google Firebase Authentication. This creates a random user identifier (UID) that is not linked to your name, email, or phone number in the App. We use it only to:

This UID is stored in Firebase (users/{uid}) and is separate from your local health database.

2.4 Sign in with Apple & doctor sharing (optional, Epilog Pro)

If you choose the healthcare provider role or use Share with doctor, Epilog uses Sign in with Apple linked to Firebase Authentication so your device can connect securely with a doctor's device. Patients generate a time-limited QR code; doctors scan it to request access. The patient must confirm before any data is shared.

What is shared: read-only summaries only — seizure counts and trends, medication adherence percentages, active medication count, seizure type breakdown, and counts of items flagged for doctor discussion. Not shared: diary text, seizure notes, photos, videos, full names, dates of birth, emergency protocol details, or pharmacy information.

Summaries are stored in Firebase Firestore (connections, patient_summaries) while a link is active. Either party can revoke access at any time; revocation deletes the summary document for that connection. Pairing tokens expire after five minutes and are single-use.

3. Data Storage

📱 Your health records are stored on your device. They leave your device only when you use optional features — anonymised research (weekly when enabled), AI Insights (when you enable consent), promo message fetching (tips only; no health records), seizure email notifications (Pro), voluntary feedback — or when you explicitly export or share data yourself.

This means:

4. Anonymous Research Data Sharing

â„šī¸ When you first use Epilog, anonymous research sharing is enabled by default to help support the epilepsy community. You can turn it off before continuing or at any time under Settings → Research & Privacy. While enabled, Epilog sends an anonymised snapshot of your medication, seizure, mood, and age-band data at most once per week. If you opt out, no further research data is transmitted.

4.1 Purpose

When you enable this feature, Epilog sends anonymised snapshots of your medication, seizure, mood, and demographic data to a secure research database hosted on Google Firebase Firestore. Snapshots are sent at most once every seven days while the feature remains enabled. The data is aggregated for statistical and clinical research purposes only — not for advertising or marketing.

4.2 What Is Transmitted

When this feature is enabled, the App uploads a snapshot (schema version 2) containing only the following anonymised fields:

Demographics (per patient profile, no names or IDs):

Medications (per entry):

Seizures (per entry):

Mood / diary entries (per entry):

Snapshot metadata:

4.3 What Is NEVER Transmitted

The anonymous research upload explicitly excludes:

4.4 When Uploads Occur

While the feature is enabled, an anonymised upload is sent at most once per week (every seven days). The first upload happens when you continue past the welcome screen with sharing enabled, or when you turn the feature on in Settings → Research & Privacy; subsequent uploads occur when you open the App again after at least seven days have passed since the last successful upload. Disabling the toggle immediately stops any future uploads.

4.5 How Data Is Stored

Anonymous snapshots are stored in Google Firebase Firestore in a collection called anonymous_research_snapshots. Each upload receives a randomly generated document ID from Firebase that is not linked to your account or device in the App. Data is transmitted over HTTPS (encrypted in transit). Server-side rules restrict the App to creating new documents only — it cannot read, modify, or delete existing research records.

4.6 Legal Basis and Your Control

4.7 Data Recipients

Anonymous research data is processed and stored by Google Firebase (Firestore) on behalf of the Developer, in accordance with Google's Firebase Privacy Policy and Google Cloud Data Processing Terms. Aggregated datasets may be analysed by the Developer and shared with healthcare research partners in anonymised, non-identifiable form only.

4.8 Multi-Patient Profiles and Research

If you manage multiple patient profiles (Epilog Pro), anonymous research snapshots include data from all active profiles on the device in a single submission. Each profile's entries carry only a relationship category and age band — never a name or profile identifier. There is no cross-linking identifier between profiles within the snapshot or across submissions. An outside observer cannot determine how many profiles belong to the same device or user.

5. Seizure Email Notifications (Epilog Pro, Optional)

If you are an Epilog Pro subscriber and enable seizure email notifications, the App may send email alerts through the Developer's secure backend at lndtech.eu when a qualifying seizure is recorded. This feature is disabled by default and only runs when you configure it.

When you use this feature, the following data is transmitted to our email service:

This data is linked to the information you provide (names and emails) and is used solely to deliver the notification emails you requested. It is not used for advertising, sold to third parties, or added to anonymous research datasets. Emails are sent only when your configured notification rules are met.

5.2 Pharmacy Quick-Order Email (Optional)

Epilog lets you email a medication refill request directly to your pharmacy. This feature is disabled until you set it up and requires your explicit confirmation before the first email is sent.

When you use this feature:

Epilog does not store copies of sent emails, does not have access to your email account, and does not transmit pharmacy order data to any third party.

6. App Feedback (Optional)

If you choose to send feedback through Settings, the App transmits the following to Firebase Firestore (user_feedbacks):

Feedback is voluntary and is not linked to your account or device identifiers in the payload. Please do not include personal or medical identifying information in free-text suggestions.

7. Doctor Reports, Exports, and Daily Messages

7.1 Doctor Reports (Local Only)

Epilog Pro includes a Doctor Report feature that builds a clinical summary from your local data for neurologist visits. Report generation happens entirely on your device — no health data is sent to external AI services. You may export the report as PDF and share it yourself.

7.2 Exports

You can voluntarily export medication reports, emergency protocols, doctor reports, and diary entries (JSON/CSV) for backup or sharing with healthcare providers. These actions are entirely user-initiated.

7.3 Promo Messages (Firestore)

The App may display short educational or motivational tips on the Diary and Medications screens. Messages are fetched from Google Firebase Firestore (promo_messages) after anonymous sign-in. Only your App language is used to select content — no health records are sent in this request. Messages may include an optional "Learn more" link to pages on lndtech.eu.

7.4 AI Insights (Optional — Google Gemini via lndtech.eu)

If you enable AI Insights in the App (explicit consent required), Epilog sends a summary of your recent health data to our secure backend at lndtech.eu, which calls Google Gemini to generate supportive wellness text. This is not medical advice.

Data is sent only after you tap to enable AI Insights and accept the consent prompt. You can disable this at any time in the Insights screen. Epilog uses a paid Gemini API tier — your data is not used to train Google's models. Free-tier requests include a Firebase ID token for rate limiting; Pro requests include subscription verification via Apple. Raw GPS coordinates are never included in AI Insights payloads.

7.5 PDF and Data Export Details

When you export data from Epilog, the content depends on the export type. All exports are user-initiated and shared through iOS share sheets — Epilog does not upload them automatically.

No export file contains your device IDFV/IDFA, Firebase UID, or anonymous research data. You control who receives exported files.

8. Data Sharing Summary

We do not sell or rent your data. Data may leave your device only in these circumstances:

9. Advertising

Some versions of Epilog display advertisements served by Google AdMob. When ads are shown, Google AdMob may collect certain device information and use advertising identifiers in accordance with Google's Privacy Policy.

You can remove advertisements by subscribing to Epilog Pro through the App Store. The Developer does not receive your health data through AdMob.

10. Third-Party Services

Epilog integrates with the following third-party services:

Firebase and our hosting provider may process standard request metadata (such as IP address) as part of network infrastructure. The Developer does not integrate separate behavioural analytics or crash-reporting SDKs beyond those listed above.

11. Children's Privacy

Epilog can be used by individuals of all ages, including children under parental supervision. The multi-patient feature allows parents and caregivers to track seizure data for dependants.

12. Data Security

Your data is protected by:

12.1 Encrypted Backups (Coming Soon)

Epilog is developing an optional encrypted backup feature that is separate from standard iOS device backups. When available, it will work as follows:

This section will be updated with final details before the feature launches. The feature is currently disabled.

13. Your Rights

You have control over your data:

If you are located in the European Economic Area (EEA), you may have additional rights under GDPR, including the right to object to processing and the right to lodge a complaint with a supervisory authority. For anonymous research data, the right to erasure may be limited because submitted snapshots cannot be linked to your identity — contact us if you have concerns.

14. App Store Privacy Labels

Apple's App Privacy nutrition labels for Epilog reflect the data types collected when optional features apply — including Health data in anonymised research snapshots when sharing is enabled (not linked to you when no account or device identifiers are included), Contact Info and linked Health data when you use seizure email notifications, and Other User Content when you voluntarily submit feedback. Local health data that never leaves your device is not "collected" in the App Store sense. See Apple's App Privacy Details for definitions.

15. Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be reflected in the "Last Updated" date at the top of this page. Continued use of the App after changes constitutes acceptance of the revised policy where permitted by law.

16. Health Disclaimer

âš ī¸ Epilog is intended solely as a personal tracking and organisational tool. It is not a medical device and is not a substitute for professional medical advice, diagnosis, or treatment. The Developer makes no medical claims of any kind. Always consult with a qualified healthcare provider for any health-related decisions. In an emergency, contact your local emergency services immediately.

Contact Us

If you have any questions about this Privacy Policy, your data, or the App, please contact:

support@lndtech.eu

Leandro Barreto — LND Tech
lndtech.eu