Anamnesix Română

Legal documents

Privacy Policy

Version 24 September 2026 · Controller: Lava Labs SRL

1. Who we are

Anamnesix is a personal patient-notes application for doctors, published by Lava Labs SRL, a company registered in Romania. It is used by one doctor on one phone to keep their own notes and history about the patients they treat, wherever they see them. It is not a clinic system, it has no sharing feature, and it does not replace the medical record kept by the clinic or hospital.

  • Registration number: [TODO: company registration number and fiscal code]
  • Registered office: [TODO: registered office address]
  • Contact for privacy matters: [TODO: privacy contact email]
  • Data protection officer: [TODO: state whether a DPO has been appointed and give the contact, or state that the decision was documented and no DPO is required]

This policy explains what personal data we process, why, where it is stored and what your rights are. It is written for doctors who use the app. Patients receive information from their doctor, who can use the patient notice template we provide.

2. Two roles: controller and processor

We act in two different roles depending on whose data is involved.

  • For your own data as a doctor (your account, subscription, usage and app diagnostics) we are the controller. We decide why and how that data is processed.
  • For the data of your patients, you are the controller and we are your processor. We only process patient data on your instructions, as described in the Data Processing Agreement you accept when you create an account. We never use patient data for our own purposes.

3. Data we process about you as a doctor

3.1 Data that stays on your phone

The following profile data is stored only in the app on your phone, inside the encrypted database, and is not sent to us: your name, practice name, licence (stamp) number, phone number, specialty, professional grade and your app preferences.

3.2 Account data

When you sign in, we process your email address and an account identifier. Sign-in uses a one-time code sent to your email; there is no password. The free tier of the app works without any account.

3.3 Subscription and usage data

For Premium we process your subscription state (trial, active, expired), the store product bought, and counters of your dictation minutes and cloud storage. Purchases are made through Apple App Store or Google Play; we receive the subscription state through our billing provider, keyed only by your account identifier. We never receive your payment card details.

3.4 Device and language

For cloud storage we record one device identifier per account and the language of your phone, so that only one phone uploads at a time and notices are sent in your language.

3.5 Audit events

We keep a short log of account-level events such as account creation, subscription changes, usage overruns and account deletion. These entries do not contain patient data.

3.6 Crash reports

If the app crashes or hits an unexpected error, a report is sent to our error-monitoring provider in the European Union. Before it leaves your phone, the report passes through a filter that removes emails, dates, sequences of digits, note contents, titles and screen navigation history. Screenshots are never attached and no user identity is attached. This helps us fix defects in the app.

3.7 Usage statistics (optional)

Only if you switch on "Share anonymous usage statistics" during setup or in Settings, the app sends anonymous events about which screens and features are used. No patient data, no names and no text you type are included, and no account identity is attached. You can switch this off at any time in Settings.

4. Patient data we process on your behalf

4.1 On your phone

All patient files are stored on your phone in an encrypted database and encrypted files, protected by your PIN and, optionally, your fingerprint or face. We have no access to this data.

4.2 Encrypted cloud backup (Premium)

With Premium, the app uploads copies of patient documents, thumbnails, voice memos and a backup of the whole database to our cloud storage in the European Union. Everything is encrypted on your phone before upload, with keys that exist only on your phone. We store only encrypted bytes and cannot read them.

The app also stores a copy of your encryption key that is itself locked with your 24-character recovery code. The recovery code is generated on your phone and is never sent to us, so we cannot open your backup and cannot recover it for you if the code is lost.

4.3 Dictation

When you record a voice memo and are signed in, the app decrypts the recording on your phone and sends it over an encrypted connection to our servers in the European Union, which pass it to our transcription provider, also in the European Union. The transcript is returned to your phone through our servers and stored encrypted on your phone. As soon as your phone confirms it has received the transcript, the audio and the transcript are deleted at the transcription provider. Our servers keep the audio only in memory while forwarding it and do not keep the transcript.

Voice memos may contain health information and, if you dictate them, patient names. You decide what to dictate. As the controller, you are responsible for informing your patients and, where their own voice is recorded, for obtaining their agreement.

  • Providing the account, sign-in codes, subscription and dictation minutes: performance of the contract with you (Article 6(1)(b) GDPR).
  • Storing encrypted backups and forwarding dictation: processing on your instructions as your processor under the Data Processing Agreement (Article 28 GDPR). Your own legal basis for patient data is the provision of health care by a professional bound by secrecy (Article 9(2)(h) GDPR).
  • Sending notices about your subscription lapsing and the deletion of cloud data: performance of the contract and our legitimate interest in warning you before data is removed (Article 6(1)(f) GDPR).
  • Crash reports, with the filter described above: our legitimate interest in keeping the app working correctly (Article 6(1)(f) GDPR).
  • Anonymous usage statistics: your consent (Article 6(1)(a) GDPR), which you can withdraw in Settings.
  • Rejecting disposable email domains and blocking accounts that repeatedly exceed their limits: our legitimate interest in preventing abuse (Article 6(1)(f) GDPR).
  • Keeping audit events: our legitimate interest in being able to demonstrate what happened to an account and to resolve disputes (Article 6(1)(f) GDPR).

6. Where data is stored and who receives it

Our servers, database, file storage and transcription provider are located in the European Union. A small number of providers outside the European Union receive limited data, never patient data:

  • Our billing provider receives your account identifier and subscription state.
  • Apple and Google process your purchase under their own terms.
  • Our error-monitoring and analytics providers are used through their European Union regions; their parent companies are in the United States.

The complete list of providers, the data each one receives, its location and the transfer mechanism (adequacy decision, EU-US Data Privacy Framework certification or standard contractual clauses) is in the Sub-processors document, available in the app under Settings and on our website. We give notice at least 30 days before adding a provider.

We do not sell data and we do not use data for advertising.

7. How long we keep data

  • Patient files on your phone: until you delete them. Deletion is immediate and permanent; there is no recycle bin.
  • Cloud backups: the newest seven database backups are kept; older ones are deleted. Encrypted documents and memos are kept until you delete them in the app.
  • After Premium ends: uploads stop, and you can still download or restore for 90 days. We send notices at day 0, day 60 and day 83. On day 90 everything stored in the cloud for your account is deleted.
  • Dictation audio and transcripts at the transcription provider: deleted as soon as your phone confirms delivery, and at the latest by our hourly clean-up job.
  • Dictation session records on our servers: the technical identifiers linking a session to a memo and to the provider are removed 30 days after the session ends; only the duration counters remain for billing.
  • Account data: until you delete your account.
  • Audit events: kept after account deletion with the account identifier removed, so they can no longer be linked to you.
  • Crash reports: kept by our error-monitoring provider for 90 days.
  • Usage statistics: kept by our analytics provider according to its retention settings, and can be deleted on request.

8. Your rights

You have the right to access your data, to have it corrected or deleted, to restrict or object to its processing, to receive it in a portable format and to withdraw consent where processing is based on consent.

  • Access, correction and deletion of your account: Settings, Account and Premium, Delete account. This deletes your email, subscription record and everything stored in the cloud. Patient files on your phone are not affected. A store subscription must be cancelled separately in the App Store or Google Play.
  • Withdrawing consent to usage statistics: Settings, switch off "Share anonymous usage statistics".
  • Any other request: write to [TODO: privacy contact email]. We answer within one month.

Requests from patients about their files must be addressed to their doctor, who is the controller. If a patient contacts us, we will forward the request to you where we can identify you, and otherwise explain that we cannot access patient files.

You can lodge a complaint with the Romanian supervisory authority: Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest, www.dataprotection.ro.

9. Security

The database on your phone is encrypted, each file is encrypted with its own key, and the master key is locked with a key derived from your PIN. Repeated wrong PINs trigger increasing waiting times. The app hides its content when you switch to another app and locks automatically. Cloud uploads are encrypted before they leave your phone and travel over encrypted connections. Our servers restrict every record to its owner and our staff do not have access to encryption keys. Details are in the Technical and Organisational Measures annex of the Data Processing Agreement.

10. Children

The app is intended for licensed medical professionals and is not directed at anyone under 18.

11. Changes to this policy

When we change this policy we update the version date at the top and publish the new text in the app and on our website. If a change affects the Data Processing Agreement or adds a provider, we notify you by email or in the app at least 30 days in advance. Continued use after that date means you accept the updated policy.