Privacy Policy

Last updated: July 2026

Summary

By default, FieldMedic transmits nothing. All information you enter stays on your device, and FieldMedic does not collect, transmit, or store any personal data.

If you choose to enable the optional FieldMedic Beacon cloud features (cloud backup, team sync, the records portal), your records are transmitted and stored end-to-end encrypted — encrypted on your device with a key that never reaches us, so neither FieldMedic nor its hosting provider can ever read them. Details in the Beacon section below.


Data Storage

All data entered into FieldMedic — including patient records, vital signs readings, team member details, and kit lists — is stored locally on your device using your device's native storage.

Unless you enable the optional Beacon cloud features (below), this data is not sent to any server, shared with any third party, or accessed by the developer.

On iOS, locally stored data benefits from Apple's hardware-level encryption when your device is locked.

Cloud Sync & Backup — FieldMedic Beacon (optional)

Beacon is an optional subscription that keeps an encrypted copy of your records in the cloud: automatic backup, sync across your team's devices, and access from a computer via the Records Portal. Nothing is uploaded unless you turn these features on, and you can turn them off at any time (your on-device records are unaffected).

End-to-end encryption. Before any data leaves your device it is encrypted (AES-256) with a key derived from a code — your personal recovery code or your team's join code — that is exchanged directly between your devices and never sent to our servers. As a result, neither FieldMedic nor its hosting provider can read your synced data: the cloud stores only unreadable ciphertext, plus limited non-clinical routing labels (a team identifier, a device identifier, timestamps) and the names/roles users declare in team access logs.

Where it is stored. Encrypted data is hosted in the United Kingdom/European Union on managed infrastructure provided by Supabase, acting as a sub-processor under a signed data processing agreement.

Roles under UK GDPR. When you enable Beacon, you remain the data controller for any patient data you record; FieldMedic acts as your data processor, processing only encrypted data on your instructions. You are responsible for having a lawful basis (and, for health data, an Article 9 condition) to record and share that data, and for sharing join codes and recovery codes only with authorised members of your team. A Data Processing Agreement is available on request from hello@fieldmedic.app.

Recovery codes. For your privacy, we cannot recover lost codes. If your whole team loses its codes, the encrypted cloud copy is permanently unrecoverable — your on-device data and exported backup files are unaffected.

Stopping and deletion. Turning off backup or leaving a team stops syncing immediately. To have stored encrypted data deleted, contact hello@fieldmedic.app.

Analytics and Tracking

FieldMedic does not use any analytics, advertising, crash reporting, or user tracking of any kind. No data about your usage of the app is collected or transmitted.

In-App Purchases

FieldMedic Pro is available as a one-time in-app purchase. All payment transactions are processed entirely by Apple through the App Store. FieldMedic does not receive, store, or process any payment or financial information.

Purchase status is verified through RevenueCat, a third-party service. RevenueCat may store an anonymous device identifier solely to verify your purchase entitlement. This identifier is not linked to any personally identifiable information and does not constitute personal data under UK GDPR or EU GDPR. You can view RevenueCat's privacy policy at revenuecat.com/privacy.

Clinical Data and GDPR

Patient records and medical information entered into the app are stored on your device, and are transmitted only if you enable the Beacon cloud features — in which case they are end-to-end encrypted before leaving your device, as described above.

You are the data controller for any patient information you record, and are responsible for ensuring its appropriate handling in accordance with UK GDPR, EU GDPR, or any other applicable data protection laws in your jurisdiction. When Beacon is enabled, FieldMedic acts as your data processor for the encrypted data it stores on your behalf; when Beacon is not enabled, FieldMedic processes no personal data at all.

FieldMedic is registered with the UK Information Commissioner's Office.

Export and Backup

The app provides an optional data export feature that saves a backup file to your device. This file is created locally and is only shared if you choose to share it yourself. You are responsible for the handling and security of any exported files containing personal data.

Children

FieldMedic is intended for use by trained medical professionals and is not directed at children under the age of 13.

Changes to This Policy

Any updates to this privacy policy will be reflected on this page with an updated date.

Contact

If you have any questions about this privacy policy, please contact: hello@fieldmedic.app


FieldMedic is a clinical decision-support tool for trained expedition medics. It does not replace professional medical judgement.