Privacy Policy
Last updated: June 21, 2026
This Privacy Policy explains how Prismo ("we", "us", "our") collects, uses, shares, and protects your information when you use the Prismo medical‑report analysis application and related services (the "App"). Please read it together with our Terms of Service and our Medical Disclaimer.
By using the App you agree to the practices described here. If you do not agree, please do not use the App.
1. Important Notice — The App Is Not a Medical Device
The App provides consumer health information for educational purposes only. It does not provide a medical diagnosis, does not offer assisted diagnosis, does not prescribe treatment, and is not a substitute for professional medical advice.
- All interpretations are generated by artificial intelligence (AI) and may be incomplete or incorrect. They are phrased as informational guidance (for example, "this may indicate…", "consider consulting a doctor"), never as a confirmed diagnosis.
- The App does not measure, infer, or claim to measure any vital sign (such as blood pressure, body temperature, blood glucose, or blood oxygen) using your device's sensors. It only helps you understand the text of medical reports that you upload.
- AI‑generated body diagrams are schematic illustrations for understanding only — they are not real medical images and are not a basis for diagnosis.
- Always check with a qualified healthcare professional before making any medical decision, and in addition to using the App. In an emergency, contact your local emergency services immediately (for example, 911 in the US, 112 in the EU).
2. Who We Are and Scope
Prismo is the data controller for the personal information processed through the App. The App is offered in the United States, the European Union, Canada, Japan, South Korea, Singapore, Australia, Israel, Saudi Arabia, the United Arab Emirates, and other regions. The App is not offered in mainland China.
If you have questions about this policy or your data, contact us at the address in Section 14 (Contact and Complaints).
3. The Health Data We Collect
Because health information is especially sensitive, we describe exactly what we collect.
3.1 Information you provide
- Medical reports you upload — PDF or image files of laboratory results, imaging reports (e.g. CT, MRI, ultrasound), examination summaries, and similar documents. These may contain special‑category health data and identifiers such as a patient name, institution, examination date, and medical record number.
- Profile information — for each person you add ("Profile": yourself, a family member, or a child you manage): display name, relationship, and optionally sex, date of birth, and an avatar.
- Your questions and conversations about a report (the follow‑up "Ask" and "Explain" features) and any annotations you create.
- Account details — email address (for email one‑time‑password login) and, if you sign in with Apple or Google, the identifier those providers return to us.
3.2 Information we derive from your reports
When you upload a report, our systems extract and store:
- the raw extracted text of the report;
- structured clinical data — report type, examination date, and laboratory items (name, value, unit, reference range, status);
- the AI interpretation, a structured summary, a glossary of terms, and any generated schematic body images.
3.3 Information collected automatically
- Device and installation data — device/app installation identifier, app version, platform, and a device fingerprint used only to prevent abuse of free usage allowances.
- Approximate location derived from IP address (country/region level, via MaxMind GeoLite2) for security, fraud prevention, and regional configuration. We do not collect precise GPS location.
- Log and diagnostic data — IP address, timestamps, and error/usage events needed to operate and secure the service.
- Purchase data — the subscription/purchase receipts that Apple or Google provide so we can verify entitlements. Payment card details are handled by Apple/Google, not by us.
We do not use Apple HealthKit, the Clinical Health Records API, or Motion & Fitness APIs, and we do not write data into HealthKit or any other health‑management app.
4. How We Use Your Information
We use your information only for the following purposes:
| Purpose | What it covers |
|---|---|
| Provide the core service | Parse, interpret, and visualize your reports; generate schematic images; answer follow‑up questions; manage your report library and health timeline. |
| AI processing | Send the de‑identified clinical content of your report to our AI processors to produce the interpretation (see Section 6). |
| Account and billing | Authenticate you, manage Profiles, verify in‑app purchases, and maintain your usage entitlements. |
| Security and abuse prevention | Protect accounts, enforce fair‑use limits, and prevent fraudulent claiming of free allowances. |
| Service improvement | Maintain reliability and quality of health interpretation. |
| Legal compliance | Meet our obligations under applicable law and respond to lawful requests. |
We do not use your health, fitness, or medical data for advertising, marketing, or use‑based data mining. We do not sell your data, and we do not share it with third parties for their own advertising or marketing. Health data is used only to provide and improve the health‑management features you request.
5. Legal Bases for Processing (EEA/UK and similar regimes)
Where the GDPR or a comparable law applies, we rely on:
- Explicit consent — for processing your special‑category health data and for AI processing. You give this consent on first use and can withdraw it at any time.
- Performance of a contract — to deliver the features you request.
- Legitimate interests — for security, abuse prevention, and service reliability, balanced against your rights.
- Legal obligation — where we must process data to comply with the law.
6. AI Processing and Third Parties
To interpret your reports we use the following processors, which act on our instructions under data‑processing agreements:
- Anthropic (Claude models) — text interpretation of report content.
- Google (Gemini models) — generation of schematic body illustrations.
- Cloud infrastructure (Amazon Web Services) — encrypted storage and hosting.
Privacy‑by‑design — de‑identification before AI processing. Before any content is sent to an AI processor, we remove identity PII such as patient name, institution, address, and medical record number. We retain only the clinical context needed for a correct interpretation (for example, sex, age, and the description of findings). Generated images never contain PII.
We may also disclose information:
- to Apple and Google, to verify in‑app purchases and subscription status;
- to service providers strictly for operating the App (e.g. transactional email delivery);
- where required by law, or to protect the rights, safety, and security of users and the public;
- in connection with a merger, acquisition, or asset sale, subject to this policy.
In every case, health data is never disclosed for advertising, marketing, or data‑mining purposes.
7. International Data Transfers and Data Residency
We host data in a single region in the United States (US West). If you are located in the EEA, the UK, or another region with cross‑border transfer rules, your data is transferred to the United States and protected by appropriate safeguards, including our certification under the EU‑US Data Privacy Framework (DPF) and/or Standard Contractual Clauses with a transfer impact assessment. Our AI and infrastructure processors are bound by equivalent safeguards.
8. Data Retention and Deletion
- We keep your reports and derived data for as long as your account is active or as needed to provide the service.
- Deleting a report removes its original file, extracted text, structured data, and generated images.
- Deleting your account (Settings → Account, with type‑to‑confirm) erases your personal data on a cascading basis, except where we must retain limited records to meet legal, accounting, or fraud‑prevention obligations.
- Backups are purged on a rolling schedule.
9. Your Privacy Rights
Subject to your local law (GDPR, CCPA/CPRA, PIPEDA, APPI, PIPA, PDPA, Australia Privacy Act, and others), you may have the right to:
- Access and export your data. Data export is free for all users and available in the App; we apply only a light anti‑abuse rate limit.
- Correct inaccurate data (for example, an examination date extracted from a report).
- Delete your data and account.
- Withdraw consent to data or AI processing at any time.
- Object to or restrict certain processing, and request data portability.
- Lodge a complaint with your data protection authority.
To exercise these rights, use the in‑App controls (Settings → Account and Settings → Consents) or contact us. We do not charge for exercising statutory rights, and we do not discriminate against you for doing so.
10. Consent Management
On first use you are asked to read and confirm the Medical Disclaimer and to consent to data processing and AI processing. You can review and update these choices at any time in Settings → Consents.
11. Children and Family Profiles
The App uses a parent‑managed model. The account holder must be an adult. An adult may add a Profile for a minor (for example, a child) and upload that child's reports, but:
- the child has no independent account or login — the child is only a Profile under the adult's account;
- creating a child Profile requires the account holder to confirm guardian consent that they are the parent or legal guardian, are of legal age, and consent to processing the minor's data;
- we do not direct any marketing or subscription prompts at minor Profiles.
We handle minors' data in line with the COPPA (US) and the GDPR rules on children's data (including member‑state age thresholds), and with Apple and Google children's policies.
12. Data Security
We protect your data with:
- Encryption in transit (TLS) for all network traffic.
- Encryption at rest — server‑side encryption of stored files in object storage and encryption of database volumes.
- De‑identification of report content before AI processing.
- Access controls and least‑privilege handling of sensitive data.
- An optional App Lock (Face ID / fingerprint / PIN) you can enable to protect access on your device.
We do not store your personal health information in iCloud; reports are stored in our own encrypted cloud storage. No method of transmission or storage is completely secure, but we work to protect your information using appropriate safeguards.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date and, where appropriate, notify you in the App and ask you to re‑confirm your consent. Continued use of the App after an update means you accept the revised policy.
14. Contact and Complaints
If you have questions, requests, or complaints about this policy or your data, contact our privacy team:
- Email: privacy@prismo.health
- Data Protection / EU‑US DPF inquiries: privacy@prismo.health
You also have the right to contact your local data protection authority.
