Privacy Policy
Effective date: 12 July 2026
This policy explains what personal data Aevo Health ("we", "us") collects when you use the Aevo Health mobile app, how we use and share that data, and the choices you have.
The data controller is The Royal London International Ltd. Contact us at support@hospitalnote.com for any privacy question.
1. What we collect
- Account identity — your name, email address and a unique user identifier, received from Apple or Google when you sign in with Sign in with Apple or Google Sign-In.
- Health information — the clinical data your clinic has recorded about you (biomarkers, blood results, care-plan items, risk assessments, patient documents). This data is created by your clinic and made visible to you through Aevo Health once you claim your record with a clinic-issued invite code.
- Sign-in and account-lifecycle events — an audit log of authentication events (sign-in, sign-out, patient claim, account deletion). We record the event, the actor and the time; no message content or health-data payloads are logged.
We do not collect location, contacts, photos, device identifiers for advertising, or any of the other categories in the Play Store Data safety form that aren't listed above.
2. How we use your data
- To operate the app: display your care plan and results, let you interact with the AI coach, and keep your session signed in on your device.
- To manage your account: identify you, link you to your patient record, and let you delete your account.
- For security and compliance: detect abuse, comply with our medical-records and security-audit obligations.
We do not use your data for advertising, we do not sell your data, and we do not use your data to train third-party machine-learning models.
3. Who we share data with
We share data only with the third-party service providers required to run Aevo Health:
- Apple and Google — for Sign in with Apple and Google Sign-In. We receive your name, email and a unique user identifier from them; we do not send them your health data.
- OpenRouter — the AI service that powers the Aevo Health "Ask Aevo" coach. When you send a message to the coach, we send OpenRouter a system prompt containing relevant clinical context (your care plan and current biomarker summary) along with your message so the coach can respond with medically appropriate advice. We do not send your name, email or account identifier to OpenRouter. Refer to OpenRouter's privacy policy for their retention practices.
- Firebase (Google) — configured in the app for future push-notification support. Firebase currently receives only the standard device registration information the platform SDKs send at startup; it does not receive your health data.
- Your clinic — clinicians at your clinic access your record through our clinical console for the purpose of care. They do this under their own duty of care and their own privacy notice, which sits alongside this one.
We do not share your data with advertisers, data brokers or analytics companies.
4. Where your data lives
Aevo Health is operated from the United Kingdom. Some of the third-party providers listed above (Apple, Google, OpenRouter) process data in the United States and other countries; when this happens they do so under standard contractual clauses or equivalent safeguards for international transfers.
5. How long we keep data
- Your account (name, email, identifier) — kept for as long as your account exists. Deleted when you delete your account (see below).
- Your clinical record — kept separately by your clinic in line with medical-records regulations. Deleting your app account does not delete your clinical record; it severs the link between your login and the record. Your clinic remains responsible for the record itself under its own retention policy.
- Audit log entries — retained for security and compliance purposes as required by law.
6. Your rights
You have the right to access, correct or delete the personal data we hold about you. You can:
- Delete your account — in the app (Profile → Delete account) or via our account deletion page.
- Request a copy of your data, or ask us to correct data that's wrong, by emailing support@hospitalnote.com.
If you are in the UK or EU, you also have the right to complain to a data protection authority (in the UK, the Information Commissioner's Office at ico.org.uk).
7. Security
All data transmitted between the app and our servers uses HTTPS. Session credentials on your device are stored in the platform keychain / keystore (iOS Keychain, Android Keystore) via Expo SecureStore. Server-side, patient documents are served only via short-lived signed URLs.
8. Who Aevo Health is for
Aevo Health is intended for adults (18 and over). We do not knowingly collect data from anyone under 18. If you believe a child has provided personal data through the app, please contact us and we will delete it.
9. Changes to this policy
If we make material changes to this policy we will update the effective date at the top and, where required, notify you through the app or by email before the change takes effect.
10. Contact
The Royal London International Ltd
support@hospitalnote.com