Privacy Notice
Last updated: 20 August 2026.
MySymplyApp is operated by BranchX Limited, a company registered in Ireland. This notice explains what information MySymplyApp collects when you use the app, how we use it, how long we keep it, and the rights you have.
1. Who we are
BranchX Limited is the data controller for information you enter into MySymplyApp. You can contact us at info@branchx.ie.
2. Information we collect
- Account: email address, display name, preferred name, timezone, country, language, and accessibility settings.
- Health diary: voice recordings, transcripts you review, mood tags, symptom notes, medications and their schedules, medication events, videos and photos you upload as evidence, and documents such as letters and prescriptions.
- Care circle: invitations you send, permissions you grant to family, carers, or clinicians, and notes carers add to your diary.
- Reports and shares: structured reports you generate for appointments and the recipient-facing share links you create.
- Operational logs: audit events (who did what, when), signed-in device metadata, and error reports.
3. Why we use it (lawful bases)
- Consent for processing health data — you can withdraw this at any time from Account & Privacy.
- Contract for providing the app and its features to you.
- Legitimate interests for security monitoring and abuse prevention (e.g. rate limits, audit trails).
- Legal obligation where we must retain records to comply with applicable law.
4. Automated processing (transcription and document analysis)
Voice transcription runs on your own device. A speech model runs inside your browser and produces the text locally; the recording is not sent to OpenAI, the Lovable AI Gateway or any other outside speech-to-text service to create the transcript. Only the resulting text is saved back to your account, where you can review and correct it. The original automatic transcript is kept separately from your corrections, and unreviewed automatic text is never included in approved or shared reports. If your device cannot complete the transcription, the recording stays saved and you can retry or type the text yourself — there is no cloud fallback. See the transcription notice for details.
Document analysis (MySymplyApp Scan) is separate and optional. If you turn it on and choose a document to be read, that document is sent to an AI provider listed on the sub-processors page. Nothing is filed into your record until you confirm it.
5. Sharing
We do not sell your data. We share information only in these cases:
- With people you explicitly add to your care circle, limited to the permissions you grant them.
- With recipients of share links you create — access is time-limited, revocable, and audited.
- With our infrastructure and AI sub-processors, listed on the Sub-processors page.
- Where legally required (court order, lawful request).
6. International transfers
MySymplyApp is hosted in the European Union. Voice transcription does not involve a transfer, because it happens on your device. Some sub-processors — for example the document-analysis provider, or support access by our infrastructure providers — may process data in the United States under Standard Contractual Clauses and, where available, the EU–US Data Privacy Framework.
7. Retention
You control retention for voice audio (keep, auto-delete after 7 days, or auto-delete after 30 days). Transcripts remain until you delete them. Structured data (medications, appointments, notes) is kept for as long as your account is active. When you delete your account, all personal and health data is erased after a 30-day cancellation window; audit logs referencing you are anonymised.
8. Your rights
- Access — export a full copy of your data from Account & Privacy.
- Rectification — edit medications, transcripts, notes, and profile fields.
- Erasure — request account deletion; grace period of 30 days.
- Restriction and objection — withdraw consent for health processing.
- Portability — the export bundle is machine-readable JSON plus your files.
- Complaint — you may lodge a complaint with your data protection authority (in Ireland: the Data Protection Commission).
9. Security
Access is enforced by row-level security. All connections use TLS. Passwords are checked against the HaveIBeenPwned breach list. Share links use hashed tokens and rate limits. See the Security page.
10. Contact and changes
For privacy questions or to exercise a right, contact us. We will keep this notice up to date and highlight material changes in the app.