Cardiom is a wellness service, not a medical device. Health information can be sensitive, so our product is designed to collect only what supports the features you choose.
1. Information you provide
We process account details needed for sign-in, wellness readings you save, tags and notes you add, preferences, reminders and support messages you choose to send. Sign in with Apple may provide a private relay email instead of your personal email address.
2. Camera check-ins
Fingertip check-ins process a light waveform from the camera and do not store raw camera frames as a saved health record. Contactless face check-ins may create a temporary clip for secure processing. Cardiom is designed to remove that temporary media after the requested analysis completes and save only the selected results associated with your account.
3. Why information is processed
- To authenticate you and secure access to Cardiom.
- To save and synchronise your selected wellness records.
- To generate trends, reports and app features you request.
- To diagnose reliability, security and support issues.
- To meet legal obligations and prevent abuse.
4. Service providers
Cardiom uses carefully selected infrastructure providers for authentication, secure database storage, processing and service delivery. They process information under contractual and technical restrictions appropriate to their role. We do not sell personal health information.
5. Storage and retention
Saved readings remain available until you delete individual entries, reset your Cardiom data or request account deletion, subject to limited backups, fraud prevention and legal retention requirements. Temporary report files and processing media are designed for short-lived delivery rather than permanent storage.
6. Your choices
Cardiom provides controls for account access, synchronisation, Apple Health connection, notifications, data export and deletion. You may also contact us to request access, correction, portability or deletion where those rights apply.
7. Security
We use access controls, encrypted transport, row-level account separation and operational safeguards. No system can guarantee absolute security, so we also design visible sync and error states to help you understand what has and has not been saved.
8. Children
Cardiom is not directed to children under the minimum digital consent age applicable in their country. We do not knowingly create accounts for children where parental authorisation is required.
9. Updates
We may update this policy as Cardiom evolves. Material changes will be presented in the app or by another appropriate notice before they take effect.