Privacy Policy
Effective Date: October 3, 2026
NeuroLogicMD ("we," "our," or "the App") is committed to protecting your privacy. This Privacy Policy explains how we handle information in connection with your use of the NeuroLogicMD app for iPhone and iPad. What happens to data depends on the feature, so each feature has its own section below.
This policy replaces the January 15, 2026 version and covers every current version of the App. Features marked optional appear only in versions that offer them.
1. Clinical tools: data stays on your device
The clinical tools (calculators, scales, pathways, examination aids, results, and saved assessments) are local-first. We do not collect, store, or transmit clinical assessment data, personally identifiable information (PII), or protected health information (PHI) to our own servers or any third party. What you enter into a tool, its scores, and its results are never part of usage statistics. If you turn on the optional tool and section usage statistics (section 7), only which tab, section, or tool was opened is sent, with the technical details described there.
2. Local Data Storage & Encryption
All clinical assessment data, medical calculations, and notes you enter into the App are stored locally and exclusively on your device.
- Security: Data is encrypted using industry-standard AES-256-GCM encryption before being saved.
- Protection: Encryption keys are managed by the Apple Keychain and never leave your device.
- Control: You can delete your local assessment history at any time from within the App settings.
Learn progress (lessons, reviews, games, streaks, and settings) is also saved on your device.
From version 2.1, the App also counts how often you open each tool, on your device only, to show your most-used tools at the top of each section. These counts stay on your device; sharing which tools you open is a separate choice (section 7). You can turn this off or reset it in Settings → Personalization.
3. Hardware Permissions
The App asks for these only when you use a feature that needs them:
- Camera (optional): Used only when you turn on the eye-chart distance check in Visual Acuity or the live background in the visual aura simulator. Camera frames are processed on the device; no images or videos are saved or transmitted.
- Face data (TrueDepth camera, optional): In Visual Acuity, if you turn on "Check distance with camera" for the near (40 cm) test, the App uses Apple's ARKit face tracking with the front TrueDepth camera to estimate how far your eyes are from the screen, so the letters can be sized for that distance. The App reads only the position of your face and eyes that ARKit reports and calculates one number, the eye-to-screen distance. It does not use the face mesh, facial expressions, or camera images, and it does not identify or recognize anyone. Each camera frame is processed in the device's memory and is not kept; the latest distance estimate is held in memory only while the check is on and is cleared when you turn it off or leave Visual Acuity. Face data, camera images, and distance measurements are never saved on your device, sent to us, or shared with any third party (including the usage-statistics processor in sections 6 and 7), and are never used for advertising, marketing, or data mining. Because nothing is stored, there is nothing to retain or delete. The check is off by default; you can measure 40 cm manually instead.
- Face ID or Touch ID (optional): Used only if you turn on the app lock. Apple's system performs the check; the App never receives biometric data.
- Vibration and flashlight: The Toolbox uses the device's haptic engine and torch. Neither needs a permission, and the vibration is not a calibrated tuning fork.
- Notifications (optional): Used only if you turn on Learn's daily reminder or daily question. Reminders are scheduled on your device.
4. On-device intelligence and external services
- Apple Intelligence: Generated clinical summaries and Learn's chat cases use Apple's on-device model when it is available. The text stays on your device and is not sent to us or to any AI provider.
- External search (optional): If you choose OpenEvidence, UpToDate, or Google in search, the App asks first, then opens that service with your search text. That service's own privacy policy applies. Do not include patient identifiers.
- Public data pages and references: Some tools open public web pages (for example the New York State drug-checking dashboard or a guideline link). Those sites receive the standard information any web request carries.
5. HIPAA & Clinical Safety
While NeuroLogicMD is designed with privacy features intended to support HIPAA compliance (such as local encryption and no transmission of clinical data), the security of the information remains the responsibility of the user.
- Patient Identifiers: We strongly recommend that users do not enter specific patient identifiers (such as full names, birthdates, or Medical Record Numbers) into the App, including in any feedback note.
- Device Security: Users should protect their devices with strong passcodes and biometric locks (FaceID/TouchID), which can be integrated into the App via settings.
6. Learn usage statistics (optional)
- Availability: Offered only in versions of the App that show this choice. A version without a configured usage service collects and sends nothing, and its settings say so.
- Choice: Off unless you turn it on. Learn asks once, on its level screen, with equal "Yes" and "No" choices; you can change your answer at any time in Settings → Privacy or in Learn settings. Declining never changes access to Learn.
- What is collected: product interaction in Learn only, such as lessons, games, and screens opened; completion or abandonment; coarse ranges for time spent and accuracy; one-tap reactions; the reason code of a reported problem; and multiple-choice survey answers. Each event carries a random usage ID created for this installation (a pseudonymous device identifier), your Learn level (student or resident), and coarse ranges for how long you have used Learn and the time of day.
- Never collected: patient information, anything from the clinical tools, text you type, research participation or study codes, names, email addresses, advertising identifiers, or precise location. The App itself adds only the coarse time-of-day range above; TelemetryDeck records when each event arrives.
- Purpose: to understand which Learn content is used, where learners get stuck, and what needs correcting (analytics). It is not linked to your identity and is not used for tracking or advertising.
- Processor: TelemetryDeck (EU hosting), which processes the data on our behalf under a data processing agreement. The usage ID is hashed on your device before it is sent. With each event TelemetryDeck also receives technical details: app and iOS version, device model, screen size, language, region, time zone, accessibility settings (such as text size or reduced motion), and the date and time the event was sent.
- Sale: We do not sell or share this data for advertising.
- Retention: no longer than 25 months, after which it is deleted.
- Your controls: turning it off stops new events immediately and deletes the local usage ID. "Reset usage ID" starts a new random ID that cannot be linked to earlier data. Because the data is pseudonymous and not linked to you, we cannot identify an individual's past events.
7. Tool and section usage statistics (optional)
- Availability: Offered only in versions of the App that show this choice. A version without a configured usage service collects and sends nothing and does not show the choice.
- Choice: Off unless you turn it on in Settings → Privacy ("Share tool and section usage"). The App may also ask once, with equal "Yes" and "No" choices. Declining never changes access to any feature. This choice is separate from Learn usage statistics: agreeing to one does not turn on the other.
- What is collected: which tabs (Home, Learn, Toolbox, Settings), clinical sections (for example Stroke or Seizure), and tools (by their built-in tool name, for example "nihss") you open, at most once per day for each. Each event carries a random usage ID created for this installation (a pseudonymous device identifier) that is different from the Learn usage ID, so turning one off never affects the other.
- Never collected: anything you enter into a tool, scores, results, saved assessments, patient information, text you type, search terms, your Learn progress or level, research participation, names, email addresses, advertising identifiers, or precise location.
- Purpose: to see which parts of the App are used most and least, so we know what to improve, reorganize, or retire (analytics). It is not linked to your identity and is not used for tracking or advertising.
- Processor: TelemetryDeck (EU hosting), which processes the data on our behalf under a data processing agreement. The usage ID is hashed on your device before it is sent. With each event TelemetryDeck also receives technical details: app and iOS version, device model, screen size, language, region, time zone, accessibility settings (such as text size or reduced motion), and the date and time the event was sent.
- Sale: We do not sell or share this data for advertising.
- Retention: no longer than 25 months, after which it is deleted.
- Your controls: turning it off stops new events immediately and deletes the local usage ID; turning it on again starts a new ID that cannot be linked to earlier data. Because the data is pseudonymous and not linked to you, we cannot identify an individual's past events.
8. Feedback you choose to send (optional)
"Report a problem" and "Suggest a topic or feature" in Learn are sent only when you tap Send. The reason code goes with your usage statistics if they are on. A typed note (up to 500 characters for a problem report, 1,000 for a suggestion) is sent separately, without your usage ID, either to NeuroLogicMD's feedback inbox (a separate database that stores the category, the question code, the note, and the app version) or as a prefilled email you review in your mail app. Please do not include patient information. Feedback notes are kept only as long as needed to review and act on them, and no longer than 25 months.
9. Learn research (optional)
If a research study is offered in a future version, it has its own consent screen and study information, and nothing is collected unless you agree. Declining or stopping never affects Learn. Research data never shares an identifier with usage statistics or feedback. No version of the App released so far includes a study, so no research data is collected.
10. Apple App Analytics
We may receive anonymous, aggregated usage information (such as crash reports or installation totals) provided automatically by Apple App Analytics, provided you have opted in to share such data with developers in your iOS settings.
11. Children's Privacy
Our App is designed for healthcare professionals and students and is not intended for children under the age of 13.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the new version in the App and at www.neurologicmd.com/privacy, with its effective date.
13. Contact Us
If you have any questions or suggestions about our Privacy Policy, contact [email protected].