LogEM privacy policy
Who we are
LogEM is a procedures logbook app for emergency medicine clinicians. It is operated by Dr Thomas Porter, a sole trader registered with the UK Information Commissioner's Office (ICO) under reference ZC140250. In this policy, "we", "us" and "our" mean Dr Thomas Porter, who is the data controller for LogEM.
The data controller is Dr Thomas Porter as an individual, not a company. If LogEM's operation moves to a company in future, we will update this policy and tell you before there is any change to who controls your data.
For any question about this policy, or to exercise your rights, contact us at privacy@logem.co.uk.
Our approach: privacy by design
LogEM is built so that your clinical records stay private, on your own device.
- Your logbook stays on your device, and we never see it. The procedures, scans, notes, and any images you record are stored only in a database on your phone. They are not uploaded to us, we keep no copy of them on any server, and we have no way to access them. This is a deliberate design choice: the safest place for your clinical records is your own device, not ours.
- No patient-identifiable information by design. LogEM is a record of the procedures and scans you perform. It has no fields for patient names, dates of birth, or hospital or NHS numbers, and we ask you never to enter such details.
- We do not hold your password. You sign in with Apple or Google, so we never see or store a password.
- No advertising, no tracking, no selling, no AI training. We do not use advertising cookies or third-party trackers, we do not sell your data, and we do not use your data to train artificial-intelligence models.
- No automated decisions. We do not make decisions about you by solely automated means, and we do not carry out profiling that produces legal or similarly significant effects.
What we hold, and what we do not
We hold a small amount of data. This section sets out exactly what that is, and what it is not.
What we hold:
1. Your sign-in identity. When you sign in with Apple or Google, we receive a unique identifier and an email address. If you use Apple's Hide My Email, that address is a private relay address, and that is all we ever see. We use this to create and secure your account and to sign you in. An account is needed to use LogEM. Lawful basis: Article 6(1)(b) UK GDPR (performance of our contract with you).
2. Your marketing preference. Whether you have chosen to receive emails from us about new features and our other products. This is off unless you turn it on. If you do turn it on, we also store the first name you entered, so we can address our emails to you; if you turn marketing off again, we delete it. Lawful basis: Article 6(1)(a) UK GDPR (consent), which you can withdraw at any time.
What we do not hold:
- Your logbook. Your posts, entries, procedures, scans, supervision details, notes, and any images stay on your device. We never receive them and cannot see them.
- A password. Sign-in is handled by Apple or Google.
- No cloud backup of your logbook, no sync to our servers, and no pooled or shared data of any kind.
Your logbook stays on your device
Because your logbook is stored only on your phone, keeping it safe is in your hands. Two things protect it, and using both is best:
- Your phone's own backup. Your device can include LogEM in its encrypted backup (Apple's iCloud Backup, or Android's Backup by Google One). If you get a new phone of the same kind and restore it from that backup, your logbook comes back with it. Make sure that backup is switched on and has enough storage; it can quietly be off or out of quota. The in-app "Backups" page (Account → Backups) explains how to check.
- Manual export. From Reports you can export your logbook as a PDF, CSV, or JSON file at any time. We recommend doing this regularly and saving a copy somewhere safe. It is the surest safety net, and the only way to move your logbook between an iPhone and an Android phone.
An iCloud backup will not restore onto an Android phone, and vice versa. If a backup is off, out of storage, or has not run, there may be nothing to restore, which is why a recent export matters.
Patient information, free text, and special category data
LogEM is designed so that you never need to enter special category data or any information that identifies a patient, and our Terms require you not to. The age and sex you record are coarse clinical context and are not linked to anything that could identify a patient.
The notes, supervisor, and findings fields are free text. You must not enter anything that could identify a patient, directly or in combination (for example a rare presentation tied to a place or date), and you should not enter a colleague's details beyond what you genuinely need. Anything you type into a free-text field stays on your device under your control; it is your professional responsibility under your confidentiality and data-protection duties. If you choose to enter special category data about yourself, it too remains on your device, and you can remove it by deleting the entry. The same care applies to anything you choose to send us as feedback by email: do not include information that could identify a patient.
Who we share your data with
Authentication processor. Supabase provides our sign-in (authentication). The minimal account record described above (your identifier, your email or Apple relay address, your marketing preference, and, if you opt into marketing, your first name) is held on Supabase servers in the United Kingdom (London region) under a data-processing agreement. Supabase is a US-headquartered company whose staff may access data from outside the UK/EEA for support and maintenance; where that happens it is covered by appropriate safeguards (the UK International Data Transfer Addendum or EU Standard Contractual Clauses) in our agreement with them. Supabase does not hold your logbook; your logbook never leaves your device.
Independent providers. When you sign in with Apple or Google, those companies act as independent data controllers under their own privacy policies. They verify your identity and we receive only a unique identifier and an email (or Apple relay) address. We do not control how Apple or Google process the data they hold about you; please see their own privacy policies.
We do not share your logbook with anyone: not your deanery, the Royal College of Emergency Medicine, the GMC, the NHS, or any ePortfolio provider. We could not, because we do not have it.
Feedback
If you send us feedback from within the app, it opens your own email app with your message and some basic, non-identifying diagnostics (your app version, platform, and device type). It reaches us as an ordinary email; we do not collect it through any in-app server, and there is no screenshot upload. Please keep your message free of patient-identifiable information.
Marketing
If you opt in, we may email you about new features and other apps or products we release. It is off by default. You can unsubscribe at any time using the link in any email or by turning the option off in Settings. We will not send you marketing without your consent.
How long we keep your data
- Your sign-in identity: for as long as your account exists. If your account is inactive for 24 months, we will contact you and, if you do not respond, delete it. This removes only the small account record we hold (your identifier, email or relay address, marketing preference, and, if set, your first name). It does not touch your logbook, which lives on your device, not with us, and is never deleted by us.
- Your logbook: it is on your device, not with us, so we keep nothing. It stays on your device until you delete entries, clear the app's data, or uninstall the app.
- After account deletion: when you delete your account in the app, we delete the account record from our systems within 30 days. Short-term backups are rotated and overwritten within their cycle. Your on-device logbook is yours and is not removed by deleting your account; you can export it first, or use "Clear all data" to remove it from the device.
- Marketing records: kept as long as needed to demonstrate compliance.
Your rights
Under UK data protection law you have the right to:
- Access the data we hold about you. Your logbook is on your device and visible in the app; you can export it from Reports at any time. The only data we hold is your sign-in identity, your marketing preference, and, if you opt into marketing, your first name.
- Rectify inaccurate data. You can edit your logbook and your name in the app.
- Erase your data. You can delete your account in the app, which removes the account record we hold. Your on-device logbook is under your control: delete entries or use "Clear all data".
- Portability of your data. You can export your logbook as JSON, CSV, or PDF.
- Restrict processing in certain circumstances.
- Object to processing based on our legitimate interests, and to direct marketing at any time.
- Withdraw consent at any time for marketing.
- Complain to the ICO, the UK supervisory authority, at any time (ico.org.uk / 0303 123 1113). We would welcome the chance to put things right first, but you do not have to contact us before going to the ICO.
To exercise any right, email privacy@logem.co.uk. We will respond within one month.
Security
The most important thing we do for your security is hold as little as possible: your clinical logbook never leaves your device, so it cannot be exposed by a breach of our systems. The minimal account record we do hold is protected with encryption in transit (TLS), encryption at rest, and database-level access controls (row-level security) so that each account can only ever access its own record. No system is perfectly secure, but we use appropriate technical and organisational measures.
If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the ICO within 72 hours (Article 33 UK GDPR), and we will notify you without undue delay where the breach is likely to result in a high risk to you.
Storage on your device
As a mobile app, LogEM stores your logbook in a database on your device, with small settings and your sign-in session held in the device's secure storage. This is strictly necessary to provide the logbook you have asked for, so under the Privacy and Electronic Communications Regulations no consent is required for it. LogEM uses no advertising cookies, analytics SDKs, or third-party trackers, so no consent banner is needed.
Children
LogEM is intended for qualified clinicians and clinicians in training. It is not directed at, or intended for use by, anyone under 18, and we do not knowingly collect data from anyone under 18. If you believe someone under 18 has an account, contact privacy@logem.co.uk and we will delete it.
Changes to this policy
We may update this policy as LogEM develops. In particular, we plan to add optional paid ("Pro") features in future, which would introduce subscription and payment information handled through the Apple App Store or Google Play and our payments provider. That would change what we process, and we would update this policy and tell you in the app and by email before any such change takes effect. The version and date at the top show when it was last updated.
Contact
Dr Thomas Porter, data controller for LogEM. ICO registration: ZC140250. Email: privacy@logem.co.uk. For questions about the Terms of Service, email support@logem.co.uk.