Privacy Policy

Last updated: 2026-07-02

Who we are

NeuroLog is a personal health-record platform operated by its developer (contact: adelkazem.1991@gmail.com). It is currently a demonstration deployment: it is intended for evaluation with sample data, not for storing real medical records.

What we collect and why

  • Account data (name, email, hashed password, or your Google identity) — to operate your account.
  • Health records you upload (lab documents, MRI/CT imaging, symptom logs, appointment descriptions) — solely to show them back to you and to the doctors you choose.
  • Access audit trail — every time a doctor opens one of your records we log who, what, and when, and show it to you.
  • Device push tokens — only if you use the mobile app and enable notifications.

Legal bases: your consent (health data, Art. 9(2)(a) GDPR) and performance of the service you request (Art. 6(1)(b)).

Who can see your data

Nobody, by default. Doctors see a record only after you grant consent — per category or per individual file — and you can revoke that consent at any moment, effective immediately. Consents can carry an expiry date, after which access ends automatically.

AI features (optional, explicit)

If you choose to run an AI analysis on an imaging study, selected image slices are sent to an external AI provider (Google Gemini, or Anthropic/DeepSeek depending on configuration) to produce an informational reading. The same applies to the appointment intake assistant and the text you type there. This never happens automatically — each run is triggered by you and each AI output carries a disclaimer: it is not a diagnosis; a human doctor decides.

Processors we rely on

  • DigitalOcean (hosting)
  • Google (optional sign-in; Gemini for AI features you trigger)
  • DeepSeek / Anthropic (AI intake assistant, depending on configuration)
  • Google Firebase (push notifications, mobile app only)

Security

All traffic is encrypted (HTTPS/WSS). Files are stored privately and streamed only through access-controlled routes; the DICOM imaging server is not reachable without a logged-in session. Passwords are hashed; third-party tokens are encrypted at rest. Access to shared records is audit-logged.

Your rights

  • Access / portability: download a machine-readable export of everything we hold about you from your Profile page.
  • Rectification: edit your profile and records at any time.
  • Erasure: delete your account from the Profile page — this permanently removes your records, uploaded files, and imaging data.
  • Withdrawal of consent: revoke any doctor's access at any time.
  • Complaints: your local data-protection authority.

Cookies & retention

We use only strictly-necessary cookies (session, security). No advertising, no analytics trackers. Your data is kept until you delete it or your account.

← Back