Privacy Policy
Last updated: August 10, 2026
My Chemo Diary (the “App”) helps patients and caregivers record symptoms, meals, medication, and schedules during cancer treatment. Essential Citronnier (“we”) respects your privacy. This policy explains what information we collect, and how we use and store it.
1. Information We Collect
- Account info: your email address and name (optional) when you sign in with Apple or Google, used to create and authenticate your account and to sync across devices. With Apple’s “Hide My Email,” we receive only an anonymized relay address.
- Health & diary records: symptoms, meals, medication, treatment schedules, sleep, mood, and medical documents you enter. These are stored on your device — on iOS they sync only to your private iCloud (CloudKit), and on Android they are kept locally on the device.
- Photos & documents: meal photos and medical test images you choose to scan are sent to our AI backend for food recognition, OCR, and NGS analysis.
- Apple Health data: with your permission, we read sleep data to display it in the app.
- Push token: your device push token is registered so we can deliver notifications.
- Newsletter: your email address if you subscribe on the website.
- Public shared content: diaries, support messages, and comments you explicitly choose to make public.
- Service logs: for security and error diagnosis, we keep API request logs (a pseudonymized IP hash, browser info, etc.) for up to 30 days. We do not store raw IP addresses.
- Product analytics: we retain feature-use events such as app launches, screen changes, and whether a record was saved, together with server-pseudonymized random installation and session identifiers, for up to 180 days. Health values, diary text, photos, and document contents are never included in analytics events.
2. How We Use Information
- Provide the service, authenticate your account, and sync across devices
- AI analysis of photos and documents (food recognition, medical OCR, NGS report parsing)
- Send notifications and the newsletter
- Improve the service and diagnose errors
- Measure feature usage and return trends while separating internal testing and app-review activity from general usage
3. Third-Party Processors
We use the following trusted processors only as needed to provide the service.
- Apple — Sign in with Apple, iCloud/CloudKit sync, APNs push, HealthKit
- Google — Google Sign-In, Android push notifications (Firebase Cloud Messaging)
- Anthropic (Claude) — AI analysis of medical documents, NGS, and meal photos
- Google Cloud — OCR fallback (Vision), backend hosting, and image storage
- Supabase — account, community, and pseudonymized product analytics database
- Google Analytics — website visits and page-usage statistics
- Resend — newsletter email delivery
- Vercel — website hosting
4. Retention & Deletion
- Records stored on your device and iCloud are removed when you delete the app or remove the data from iCloud.
- You can delete your server-side account at any time via Profile → Delete Account in the app; related server data is deleted with it.
- Product analytics events are automatically deleted after no more than 180 days. Account deletion also removes analytics data associated with that account and current installation.
- You may also request deletion by email.
5. Data Protection
- All data is transmitted encrypted over HTTPS.
- We never use health data for advertising and never sell it to third parties.
6. Your Rights
- You may request access to, correction of, or deletion of your information.
- You can delete your account and data directly in the app, or request it via the contact below.
7. Children’s Privacy
- The App is not directed to children under 14, and we do not knowingly collect their information.
8. Changes
- If this policy changes, we will post the updated version on this page with a new date.
9. Contact
- Privacy questions and deletion requests: lemonaatree@gmail.com