endonem

Privacy policy

effective 21 august 2026

This is the public copy, the one both stores need a URL for. The identical text ships inside the app at Settings → Legal → Privacy policy, readable with the phone in aeroplane mode, because an app whose whole claim is that it never goes online should not make you go online to check.

The short version

Endonem keeps your health record on your phone, encrypted, and sends it nowhere. There is no account, no server, and no analytics. We cannot read your record, and neither can anyone else without your unlocked phone.

What is collected

Nothing is collected. Everything you enter — symptoms, pain scores, body map marks, cycle and bleeding, medication and how well it worked, appointments, your care team, letters and imaging you attach, and the reports built from all of it — is written to a database file on this device and stays there.

There is no sign-up, no email address, no phone number, no advertising identifier, and no usage analytics of any kind.

Crash reports

Endonem can write down what broke when something goes wrong. It is off until you turn it on, in Settings → Crash reports, and nothing is ever sent anywhere — the app has no way to send anything.

A report is four things: the date and time, which build you were running, the kind of error, and which lines of endonem's own code were running. Not the error's own message, and nothing from your record: no entry, no score, no symptom, no medication, no document, no name, and no identifier for you or this phone.

You can read every report in full on that screen, copy one, or delete them all. Turning the setting off deletes what was already written.

Backups

The record is kept out of your phone's backups, deliberately. On Android the app declines Auto Backup and device-to-device transfer; on iOS the database is excluded from iCloud and from encrypted local backups.

The reason is that the encryption key lives in the device keystore and is not backed up either, so a restored copy could not be opened by you or by anyone else — and a promise that nobody ever holds a copy should not have an exception in it.

The consequence is worth knowing before you need it: a new phone starts a new record. The only restorable copy is an encrypted vault you make yourself — Settings → Your data → Back up your record — opened by a passphrase you choose. Export everything produces a PDF you can read or hand over; it is not a backup you can restore.

How it is protected

The record is stored in a SQLCipher database, encrypted with a key held in the device keystore (Keychain on iOS, the Android Keystore on Android). The key never leaves the device and is not backed up anywhere by us. Attachments are stored inside that same encrypted file rather than on the filesystem.

You can additionally require your face, fingerprint or passcode before the app opens.

The consequence of holding no copy is worth saying plainly: if you lose the device and the key, we cannot recover your record. Nobody can.

What leaves the device

Only what you send, when you send it. Exporting or sharing a report hands a PDF to the share sheet you chose — mail, messages, print, a file. From that moment the copy is governed by whatever you sent it to, not by us.

Local-only mode, which is on by default, blocks the app from opening a network connection at all. On Android the app is built without the INTERNET permission, so the operating system enforces it too.

One address exists in the app: the App Store or Google Play page where a subscription is cancelled. It opens in your browser or store app, on your tap, and carries nothing about you beyond the fact that you tapped it.

Purchases

Subscriptions are handled entirely by the App Store or Google Play. They tell this app one thing — whether a subscription is active — and that answer is stored on the device alongside your settings. We never see your payment details, and the stores never see your health record.

Apple and Google process that purchase under their own privacy policies.

Notifications

Reminders are scheduled by the operating system on this phone. They never name a symptom or a condition — the most a reminder ever says is that you have a note for today.

Children

Endonem is not directed at children under 13 and should not be used by them. It is rated for teens and adults; anyone under the age of majority where they live should use it with a parent or guardian.

Your rights over your data

Because the record never leaves your phone, the usual requests resolve on the device and immediately.

Deleting the app also removes the record, but Delete everything is the thorough version: it overwrites and removes the key as well.

Cancelling a subscription does none of this. Cancelling never touches your data.

Who we are

Endonem is published by Siddhant Singh, an individual, of House 208, Punjabi Colony, Pratapgarh, Uttar Pradesh 230001, India. There is no company behind it, and so no company number to give you.

That one person is the data controller for the purposes of the UK GDPR and the EU GDPR — although, as set out above, we never receive your health data, so there is nothing on our side for a controller to hold, lose or hand over.

Changes

If this policy ever changes in substance, the new version appears here and in the app, and the date above changes with it. Because there is no account, there is no mailing list to tell — reading it is the only way, so it is kept short enough to read.

Contact

sidd.develops@gmail.com — for questions about this policy. Please don't send us your health information; we have no way to keep it as safely as your phone does.

This is the whole policy. It is short because there is not much to say about data that never moves. The identical text ships inside the app at Settings → Legal → Privacy policy; if the two ever disagree, the copy on your device is the one that binds us.