Privacy Policy
Last updated: 27 May 2026
Portfol.io ("the App") is a medical ePortfolio dictation tool developed by Peter Woods. This policy explains what data we collect, how we use it, and your rights.
1. Data processed on your device
All speech recognition and anonymisation happens entirely on your device using Apple's on-device frameworks. Your audio is never transmitted to any server. The anonymisation process replaces identifiable information (names, dates, locations) locally before any text leaves your device.
2. Data we collect
- Account information — your name and email address (via Sign in with Apple) to identify your portfolio.
- Portfolio entries — the structured text of your ePortfolio entries, stored securely in Firebase Firestore under your user ID. Your original audio is never stored.
- Usage analytics — anonymised events (e.g. "entry created", "capture started") via Firebase Analytics to help improve the app. No personally identifiable information is included in analytics events.
- Crash reports — device model, OS version, and stack traces via Firebase Crashlytics to help us fix bugs. These are not linked to your identity.
- Purchase history — subscription status managed via RevenueCat to determine access to Pro features.
3. Data we do not collect
- Audio recordings — all speech recognition is on-device; no audio is ever uploaded.
- Patient data — the anonymisation step removes all identifiable patient information before any AI processing. You should not file entries that contain unanonymised patient identifiers.
- Location data.
- Contacts or calendar data.
4. How we use your data
Your portfolio entries are used solely to provide you with the App's core functionality — structuring, storing, and displaying your ePortfolio. We do not sell your data, share it with third parties for marketing, or use it to train AI models.
5. Third-party services
- Firebase (Google) — authentication, database, analytics, and crash reporting. Firebase Privacy Policy.
- Google Gemini — anonymised text is sent to Google's Gemini API for structuring into ePortfolio form fields. No patient-identifiable information is included. Gemini Terms.
- RevenueCat — subscription and purchase management. RevenueCat Privacy Policy.
- NICE (NHS England) — guideline reference lookups use the publicly available NICE API. No personal data is transmitted.
6. Data retention and deletion
Your portfolio data is retained for as long as you have an account. You can delete your account and all associated data at any time from the Profile screen in the App. Deletion is permanent and irreversible.
7. Data security
All data in transit is encrypted using TLS. Data at rest is stored in Firebase Firestore with security rules that restrict access to your user ID only.
8. Children
The App is not directed at children under 13. We do not knowingly collect data from children.
9. Your rights (UK GDPR)
Under UK GDPR you have the right to access, correct, or delete your personal data. To exercise these rights, contact us at the address below.
10. Contact
If you have questions about this policy, please contact: peter.woods@me.com
11. Changes to this policy
We may update this policy from time to time. The "last updated" date at the top will reflect any changes. Continued use of the App after changes constitutes acceptance of the updated policy.