Privacy Policy
Last updated 17 September 2026
In short: SurgiLog does not collect your data. Your cases are stored on your device. We operate no server and receive nothing from the app.
Who this covers
This policy applies to the SurgiLog mobile application for iOS and Android, and to this website. In it, “we” means the developer of SurgiLog and “you” means the person using the app.
What we collect
Nothing. The app has no account, no sign-in, and no analytics. It sends no data to us, because there is no server of ours for it to send data to.
The App Store and Google Play may give us anonymous, aggregated statistics such as download counts and crash reports. Those come from the store platforms, not from the app, and they do not identify you.
Where your cases are stored
In a database file inside the app’s private storage on your device. Other apps cannot read it. It is included in your device’s own backup (iCloud Backup or Google’s backup service) if you have that turned on, under your account and subject to Apple’s or Google’s terms rather than ours.
Deleting the app deletes the database and everything in it. We cannot recover it.
Patient identifiers
This is the part that matters most, so it is described exactly.
When you scan a wristband barcode or type a patient number, the app does the following on your device and nowhere else:
- It combines the number with a random secret key that is generated once on your device and held in the iOS Keychain or the Android Keystore.
- It produces a one-way code (an HMAC-SHA-256 hash). A one-way code cannot be turned back into the original number, and because it is keyed, it cannot be attacked by trying every possible number either.
- It stores that code and the last four characters of the number, so that you can still recognise a case in a list and be warned if you log the same patient twice on the same day.
- It discards the full number. The number is never written to the database, never written to a log, and never transmitted.
Exported PDF and CSV files contain the last four characters only. There is no full identifier in the app for an export to contain.
Camera and scanning
The app asks for camera access so it can read a barcode or printed label. Recognition runs entirely on the device using Google’s ML Kit, which is bundled into the app rather than called over the network. Camera images are not saved to your photo library and are not uploaded. An image captured for text recognition is written to the app’s temporary cache for the moment it is being read, and is not retained.
You can refuse camera access and type numbers by hand; the app works fully without it.
Third parties
One, and only for purchases. If you subscribe to SurgiLog Pro, the purchase is handled by Apple or Google and validated through RevenueCat, which tells the app whether your subscription is active. RevenueCat receives an anonymous identifier and your purchase status. It does not receive any case data, patient identifier, or anything else from the app, because the app does not send it any.
RevenueCat’s own policy is at revenuecat.com/privacy.
This website loads its typefaces from Google Fonts, which means your browser contacts Google to fetch them. It runs no analytics and sets no cookies.
Your responsibilities
SurgiLog is designed so that your logbook contains no directly identifying patient information. That design does not by itself satisfy every obligation you may have. You remain responsible for following your employer’s and your institution’s policies on record-keeping, and for any applicable law in your jurisdiction. If you type identifying information into a free-text field such as Notes, it is stored as you typed it — please do not.
Children
SurgiLog is a professional tool for clinicians and is not directed at children. We do not knowingly collect information from anyone, of any age.
Changes
If this policy changes, the date at the top changes with it, and material changes will be noted in the app’s release notes.
Contact
Questions about this policy: privacy@abdallah.ai.