Privacy policy
effective 21 august 2026
This is the public copy, the one both stores need a URL for. The identical text ships inside the app at Settings → Legal → Privacy policy, readable with the phone in aeroplane mode, because an app whose whole claim is that it never goes online should not make you go online to check.
The short version
Endonem keeps your health record on your phone, encrypted, and sends it nowhere. There is no account, no server, and no analytics. We cannot read your record, and neither can anyone else without your unlocked phone.
What is collected
Nothing is collected. Everything you enter — symptoms, pain scores, body map marks, cycle and bleeding, medication and how well it worked, appointments, your care team, letters and imaging you attach, and the reports built from all of it — is written to a database file on this device and stays there.
There is no sign-up, no email address, no phone number, no advertising identifier, and no usage analytics of any kind.
Crash reports
Endonem can write down what broke when something goes wrong. It is off until you turn it on, in Settings → Crash reports, and nothing is ever sent anywhere — the app has no way to send anything.
A report is four things: the date and time, which build you were running, the kind of error, and which lines of endonem's own code were running. Not the error's own message, and nothing from your record: no entry, no score, no symptom, no medication, no document, no name, and no identifier for you or this phone.
You can read every report in full on that screen, copy one, or delete them all. Turning the setting off deletes what was already written.
Backups
The record is kept out of your phone's backups, deliberately. On Android the app declines Auto Backup and device-to-device transfer; on iOS the database is excluded from iCloud and from encrypted local backups.
The reason is that the encryption key lives in the device keystore and is not backed up either, so a restored copy could not be opened by you or by anyone else — and a promise that nobody ever holds a copy should not have an exception in it.
The consequence is worth knowing before you need it: a new phone starts a new record. The only restorable copy is an encrypted vault you make yourself — Settings → Your data → Back up your record — opened by a passphrase you choose. Export everything produces a PDF you can read or hand over; it is not a backup you can restore.
How it is protected
The record is stored in a SQLCipher database, encrypted with a key held in the device keystore (Keychain on iOS, the Android Keystore on Android). The key never leaves the device and is not backed up anywhere by us. Attachments are stored inside that same encrypted file rather than on the filesystem.
You can additionally require your face, fingerprint or passcode before the app opens.
The consequence of holding no copy is worth saying plainly: if you lose the device and the key, we cannot recover your record. Nobody can.
What leaves the device
Only what you send, when you send it. Exporting or sharing a report hands a PDF to the share sheet you chose — mail, messages, print, a file. From that moment the copy is governed by whatever you sent it to, not by us.
Local-only mode, which is on by default, blocks the app from opening a network connection at all. On Android the app is built without the INTERNET permission, so the operating system enforces it too.
One address exists in the app: the App Store or Google Play page where a subscription is cancelled. It opens in your browser or store app, on your tap, and carries nothing about you beyond the fact that you tapped it.
Purchases
Subscriptions are handled entirely by the App Store or Google Play. They tell this app one thing — whether a subscription is active — and that answer is stored on the device alongside your settings. We never see your payment details, and the stores never see your health record.
Apple and Google process that purchase under their own privacy policies.
Notifications
Reminders are scheduled by the operating system on this phone. They never name a symptom or a condition — the most a reminder ever says is that you have a note for today.
Children
Endonem is not directed at children under 13 and should not be used by them. It is rated for teens and adults; anyone under the age of majority where they live should use it with a parent or guardian.
Your rights over your data
Because the record never leaves your phone, the usual requests resolve on the device and immediately.
- Access and portability — Settings → Your data → Back up your record writes an encrypted vault you can restore on a new phone. Export everything produces a PDF to read or hand over; it is not restorable.
- Erasure — Settings → Your data → Delete everything destroys the database file and the encryption key on this phone. Any vault or PDF you saved yourself is yours to delete. There is no copy on our side, no confirmation email, and no recovery window. Gone means gone.
- Rectification — every entry is editable in the app.
- Objection, restriction, portability under GDPR/UK GDPR, and the CCPA rights to know, delete and opt out of sale — all satisfied by the above, because we are not a processor of your health data at all. We never receive it. We do not sell or share personal information, and there is nothing to opt out of.
Deleting the app also removes the record, but Delete everything is the thorough version: it overwrites and removes the key as well.
Cancelling a subscription does none of this. Cancelling never touches your data.
Who we are
Endonem is published by Siddhant Singh, an individual, of House 208, Punjabi Colony, Pratapgarh, Uttar Pradesh 230001, India. There is no company behind it, and so no company number to give you.
That one person is the data controller for the purposes of the UK GDPR and the EU GDPR — although, as set out above, we never receive your health data, so there is nothing on our side for a controller to hold, lose or hand over.
Changes
If this policy ever changes in substance, the new version appears here and in the app, and the date above changes with it. Because there is no account, there is no mailing list to tell — reading it is the only way, so it is kept short enough to read.
Contact
sidd.develops@gmail.com — for questions about this policy. Please don't send us your health information; we have no way to keep it as safely as your phone does.
This is the whole policy. It is short because there is not much to say about data that never moves. The identical text ships inside the app at Settings → Legal → Privacy policy; if the two ever disagree, the copy on your device is the one that binds us.