Legal
Privacy Policy
Last updated: July 6, 2026
This Privacy Policy explains how Uncharted LLC (“Uncharted,” “we,” “us”) handles information in connection with the Uncharted mobile applications (iOS and Android), the Uncharted desktop application (macOS and Windows) (together, the “Apps”), and this website and licensing portal (the “Portal”).
The short version: the Apps are built so that patient data never leaves your device, and the Portal collects only the minimum needed to run accounts, licensing, and billing.
Patient data: we never have it
Everything you document in the Apps — patient identity, vitals, injuries, medications, labs, notes, photos, audio, video, location fixes, and the audit log — is stored only on the device where it was entered. There is no cloud sync, no server-side copy, and no analytics or telemetry that touches patient data. Specifically:
- All clinical records are stored in an encrypted database on the device (SQLCipher, AES-256), with the encryption key held in the device’s hardware-backed secure storage (iOS Keychain, Android Keystore, or the operating system’s secure storage on desktop).
- Photos and videos taken in the Apps are written only to the Apps’ private sandbox — never to the device camera roll — and EXIF metadata, including location, is stripped before saving.
- Exports (such as PDF handoff documents) are generated on-device and shared only where you direct them, using your device’s native sharing features. Once you share an export, its handling is governed by wherever you send it.
- You and your organization are the custodians of the records you create. Deleting the Apps or a record deletes the data; we have no copy and cannot recover it for you.
Because patient data never reaches us, please never include patient information — including screenshots of patient records — in support requests or other communications with us. If you contact support, describe the issue without patient details.
Information the Portal collects
The Portal exists to handle licensing and billing. If you are an organization administrator or an individual subscriber, we handle the following:
- Account information. For Portal admin accounts: name, email address, a securely hashed password, and your role and organization affiliation.
- Organization information. Organization name and billing email address.
- Billing information. Payments are processed by Stripe. We never see or store full payment card numbers; we retain only billing references such as customer and subscription identifiers and subscription status.
- Licensing and device activation data. License codes, license status, and — when a device is activated — a device fingerprint (a generated identifier used to bind a license to a device). This is licensing metadata only; it contains no patient data and no personal content from the Apps.
- Individual subscription data. Individual subscriptions purchased through the Apple App Store or Google Play are managed by the respective store and our subscription provider, RevenueCat. We receive subscription status events (such as purchase, renewal, or cancellation) tied to an anonymous app user identifier.
- Transactional email. We send account and licensing emails (verification, receipts, license codes) through our email provider, Resend.
- Correspondence. If you email us, we keep the correspondence so we can respond and improve support.
What we don't do
- We do not sell or rent any personal information.
- We do not run advertising, advertising trackers, or third-party analytics on the Apps.
- We do not collect usage analytics or telemetry from the Apps that involves patient data.
- We do not use patient data for any purpose — we never have it.
- We do not offer or require a Business Associate Agreement (BAA), because no protected health information ever reaches our systems (see Section 07).
Service providers
We use a small number of service providers to operate the Portal. Each receives only what it needs for its function:
- Stripe — payment processing for enterprise licensing (billing details are handled by Stripe directly).
- Keygen — license issuance, validation, and device activation (license codes and device fingerprints).
- RevenueCat — individual in-app subscription management (anonymous app user identifiers and subscription events).
- Apple App Store / Google Play — app distribution and individual subscription billing, under their own terms and privacy policies.
- Resend — transactional email delivery.
- Database and hosting infrastructure— the Portal’s account and licensing database is hosted with managed infrastructure providers in the United States, with encryption in transit.
None of these providers receives patient data, because patient data never leaves your device.
Cookies and local storage
The Portal uses only the cookies necessary to operate: a session cookie to keep Portal administrators signed in and related security (CSRF) cookies. The website stores your light/dark theme preference in your browser’s local storage. We do not use advertising or analytics cookies.
Security
- On-device clinical data is encrypted at rest (SQLCipher, AES-256) with hardware-backed keys, behind biometric or PIN app-lock.
- The Apps maintain a tamper-evident, hash-chained audit log — stored on-device inside the same encrypted database.
- Portal traffic is encrypted in transit (TLS). Passwords are stored only as salted hashes.
- Portal access is restricted to authenticated organization administrators, and each organization can access only its own licensing data.
No system is perfectly secure. If we learn of a security incident affecting Portal account data, we will notify affected users and, where required, regulators, consistent with applicable law — including, to the extent it applies, the FTC Health Breach Notification Rule.
HIPAA
Uncharted is a tool used by trained medical professionals and their organizations. We are not a HIPAA covered entity, and because no protected health information (PHI) is ever transmitted to or stored on our systems, we do not act as a business associate and do not offer a BAA. The Apps provide HIPAA-ready technical safeguards — encryption at rest, access controls, and audit logging — but compliance obligations for patient records rest with the professionals and organizations who create and hold them.
Data retention and deletion
- On-device clinical data is retained only on your device, under your control, until you delete it.
- Portal account and organization data is retained while your account or subscription is active, and for a reasonable period afterward as needed for legal, accounting, and dispute-resolution purposes.
- Billing records are retained as required by tax and accounting law.
- You may request access to, correction of, or deletion of your Portal account data by emailing contact@unchartedmed.com. We will respond consistent with applicable law.
Children
Uncharted is a professional tool intended for trained medical providers. It is not directed to children, and we do not knowingly collect personal information from anyone under 18.
Where data is processed
Uncharted is offered in the United States, and Portal data is processed and stored in the United States. If you access the Portal from elsewhere, you understand your account information will be transferred to and processed in the United States.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date above and, for material changes, provide additional notice (such as email to Portal account holders). Continued use of the Apps or Portal after a change takes effect constitutes acceptance of the updated policy.
Contact
Questions about this policy or our data practices: contact@unchartedmed.com. Please remember: never include patient information in any message to us. See also our Terms of Service.