Lably
English

Lably Privacy Policy

Effective date: October 1, 2026

Last updated: October 1, 2026


Summary

Details follow below. If you live in Washington, Nevada, or Connecticut (United States), please also read the Consumer Health Data Privacy Policy.


1. Who we are

The Lably app (МедКарта in the Russian version) (the “App”) is developed and provided by Viktar Muronchyk (Мурончик Виктор Олегович), an individual in the Republic of Belarus (“we,” “us,” the “developer”). The App has been released to test the idea; the developer is not registered as an individual entrepreneur (sole proprietor).

This Policy also applies to the lably-app.com website (the “Website”): what happens to data when you visit it is described in Section 2.7.

For the purposes of the GDPR, the UK GDPR, and the personal data laws of the CIS countries, we are the controller (“operator”) of the data processed on our server and by our service providers. We do not receive or see the data that is stored only on your device — you are in control of it.

Contact for data matters: [email protected]

Postal address: vul. Karla Marksa 29, OPS-25 (Post Office No. 25), 230025 Hrodna, Republic of Belarus (in Russian: 230025, Республика Беларусь, г. Гродно, ул. Карла Маркса, 29, ОПС-25)

2. What data we process

2.1. Data only on your device

Stored in the App’s storage on your device. We have no access to it:

Protection on the device: encryption provided by the operating system; service keys and settings are kept in the system’s secure storage (Keychain / Android Keystore). If you turn on unlocking with Face ID, Touch ID, or a fingerprint, the biometric check is performed by the operating system — the App receives only a “confirmed / not confirmed” answer and never receives the biometric data itself.

The App requests access to the camera, photos, and files only so that you can add a document. The files you select are processed on the device.

2.2. Data on our server

The server is needed for the trial, the subscription, and the recognition limit. It holds no health data.

Data Purpose Retention period
Device ID — a random code generated by the App itself. Not linked to a name, email, or phone number To determine which plan and limit apply to this device As long as the related records below are kept
Trial start date and platform (iOS / Android) To avoid granting the trial again 2 years from the start of the trial
Plan, subscription term, records of free periods granted To provide paid or complimentary access 1 year after the subscription ends
Number of recognitions per day (the day is counted in your time zone) Daily recognition limit 90 days

The device ID is kept in the device’s secure storage and may persist after the App is reinstalled (on iOS it usually does). This is intentional: otherwise the trial could be obtained over and over again. The device ID is shown on the “Data” screen so that you can refer to it in a request.

Each request to the server uses your IP address (only to limit excessive requests) and your time zone offset (so that the limit resets at your midnight). We do not store them. Our infrastructure provider (Cloudflare) may keep technical logs for a short time for security purposes — under its own rules, as our processor.

2.3. Document recognition

Happens only when you add a document yourself and confirm sending it on the redaction screen.

What is sent: images of the pages, with the areas you blacked out burned into the image itself (the original photo or file is not sent); the document type you selected; the App’s language; public reference lists — the list of test indicators and the list of laboratories for the selected country.

What is not sent: name, surname, email, phone number, device ID, Health Passport data, age, and sex. The instructions given to the recognition system prohibit it from extracting the patient’s full name, date of birth, address, phone number, document and insurance policy numbers, and the doctor’s name.

How it works: our server holds the copy in memory only for the duration of the request, passes it to OpenAI, and returns the result to the App; the copy is never written to the server’s disk. OpenAI processes the request as our processor: it does not use it to train its models and does not store it in its request history, but it may retain the request, including the images, for up to 30 days in logs used to detect abuse (requests flagged by its safety systems — longer, for the duration of the review), after which it deletes it.

Important: the recognition system sees everything you have not blacked out. Black out your full name, date of birth, address, insurance policy number, and other personal details. If the page contains information about another person, black that out too.

2.4. Usage statistics

We use Google Firebase Analytics to understand which features work and where users run into errors. The following is sent:

Not sent: the contents of documents, names and values of test indicators, diagnoses, Health Passport information, or any inferences about your health.

Consent and opting out. If your device’s region or the country selected in the App (the “Country” setting) is an EEA country, the United Kingdom, or Switzerland, or if your device’s region cannot be determined, statistics are off until you allow them: the App asks you once, and nothing is sent until you answer. In other countries statistics are on by default. You can turn them on or off at any time in “Profile → Settings → Usage statistics.” While statistics are off, no events are sent.

Statistics are retained for 2 months. “Delete all data” resets the installation ID and your choice: in countries where consent is required, the App will ask again; elsewhere, statistics are turned back on by default.

2.5. Purchases and subscriptions

We are not charging anything at this time. The App is in a testing phase: all plans are provided free of charge, and no payment details are requested or processed. The server stores only a record of the plan unlocked for free and its term (Section 2.2).

When real payments are introduced (we will announce this in the App in advance and update this Policy), subscriptions will be purchased through the App Store or Google Play. Payment details (card, address, Apple Account / Google Account) are processed by Apple or Google — we do not receive them. We receive purchase information from the store (transaction ID, plan, term, status, country) and link it to the device ID to unlock access.

2.6. Support requests

If you write to us, we receive your email address, the text of your message, and anything you attach to it. Please don’t send medical documents or results to support — we don’t need them to resolve your issue. Messages to [email protected] are received and forwarded to the developer by the Cloudflare Email Routing service; they are stored in the developer’s personal Gmail mailbox (Google LLC, United States) (Sections 5 and 6). We keep correspondence for 1 year after the request is closed, unless the law requires a longer period.

2.7. Visiting the Website

The Website consists of ready-made pages: it has no accounts, forms, ads, pixels, or embedded content from other services (videos, maps, social media buttons); fonts are loaded from the Website itself. The only third-party script on the Website is the Cloudflare Web Analytics statistics script (see below). The support link opens your email app — your message is sent as an ordinary support request (Section 2.6).

What the host sees. The Website is hosted on Cloudflare Pages (Cloudflare, Inc.). To deliver pages to you and to protect the Website from attacks and bots, Cloudflare processes technical data with each request: your IP address, information about your browser and device (user agent), the address of the requested page, and the date and time of the request. Cloudflare does this as our processor; in addition, under its own privacy policy, Cloudflare may use traffic information to detect and block malicious activity on its network. Cloudflare does not publicly state how long it keeps such logs. We do not keep or export visitor logs and do not try to find out who visited the Website. In the Cloudflare dashboard we can see aggregate traffic statistics and information about requests that Cloudflare’s protection blocked or challenged (including the IP address) — we look at it only to keep the Website running and secure.

Website statistics (Cloudflare Web Analytics). To understand how many people visit the Website, which pages they open, and how fast the pages load, we use Cloudflare Web Analytics. When you open a page, your browser loads a small Cloudflare script from static.cloudflareinsights.com and sends Cloudflare the page address, the address of the page you came from (referrer), and page load and performance metrics, together with — as with any request — your IP address and information about your browser and device (user agent). From this data, Cloudflare shows us aggregate statistics: the number of visits and page views, countries, device and browser types, referral sources, and load speed; we do not see information about individual visitors in them. The script does not use cookies and stores nothing in your browser; under its own rules, Cloudflare does not track visitors across different websites. Cloudflare processes this data as our processor; Cloudflare does not publicly state how long it keeps it.

Where statistics are not collected. The statistics script is not loaded if your request is served by a Cloudflare data center in an EEA country, the United Kingdom, or Switzerland. Which data center serves a request is chosen by Cloudflare’s network — usually the one nearest to you; your location is not determined. So if you are in one of these countries but use a VPN or proxy that exits in another country, statistics may be collected, and vice versa. You can opt out at any time by blocking static.cloudflareinsights.com in your browser (for example, with a content blocker) — the Website will work as usual.

Cookies and browser storage. The Website does not set cookies. If Cloudflare’s protection against bots and attacks is triggered (for example, if your browser needs to be checked), Cloudflare may set a strictly necessary security cookie; it is not used for advertising or tracking. If you choose a language yourself in the Website’s menu, your browser remembers that choice (the lably.locale entry in the browser’s local storage) so that the Website opens in that language next time. The entry contains only the language code, stays in your browser, and is never sent anywhere; you can delete it by clearing the site data in your browser settings.

3. Purposes and legal bases

Purpose Data Legal basis (GDPR / UK GDPR)
Storing and displaying your data on your device All data in Section 2.1 We do not process it — your device does
Recognizing a document Page images and parameters in Section 2.3 Performance of a contract (Art. 6(1)(b)) and your explicit consent to the processing of health data (Art. 9(2)(a)), which you give before each submission
Trial, subscription, daily limit Data in Section 2.2 Performance of a contract (Art. 6(1)(b))
Preventing repeat trials and server overload Device ID, trial record, IP address Legitimate interests (Art. 6(1)(f)) — protection against abuse
Statistics and fixing errors Data in Section 2.4 Consent (Art. 6(1)(a)) in the EEA / UK / Switzerland; legitimate interests (Art. 6(1)(f)) elsewhere, where the law permits
Responding to requests Data in Section 2.6 Legitimate interests (Art. 6(1)(f)) / performance of a contract
Displaying the Website and protecting it from attacks Technical data in Section 2.7 Legitimate interests (Art. 6(1)(f)) — operation and security of the Website
Website statistics Cloudflare Web Analytics data in Section 2.7 Legitimate interests (Art. 6(1)(f)) — understanding Website traffic and speed; no statistics are collected for requests served by data centers in the EEA, the United Kingdom, or Switzerland

For the purposes of the laws of Belarus, Russia, and Kazakhstan, the legal basis for processing health data and transferring it abroad is your consent, which you give by a separate action on the screen where you send the document, before each recognition; for all other data, it is the contract (the Terms of Use). Technical data about visits to the Website and its statistics data (Section 2.7) are processed to display the Website, protect it, and keep aggregate visit statistics.

You can withdraw your consent at any time: simply stop sending documents for recognition (each submission is a separate consent) and turn off statistics. Withdrawal does not affect the lawfulness of processing carried out before it.

4. Automated decision-making

We do not make decisions about you based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. Text recognition converts a document into digital form. Comparing a result with the reference range printed on your form happens on the device and is not a diagnosis.

5. Who else processes data

We do not sell or rent out your data and do not share it for advertising. Data is received only by the recipients listed in the table below: our processors — under a contract and on our instructions — and the app stores (Apple, Google) and the Gmail email service — under their own rules:

Recipient What it does What data Where Transfer mechanism from the EEA / UK
Cloudflare, Inc. Hosting of the server and database; hosting of the Website (Cloudflare Pages) and its statistics (Cloudflare Web Analytics); forwarding of support emails (Cloudflare Email Routing) Data in Sections 2.2 and 2.7; in transit — images in Section 2.3 and emails in Section 2.6 Global network of data centers, including the United States Data Privacy Framework (Cloudflare’s certification) and SCCs in Cloudflare’s DPA
OpenAI OpCo, LLC Text recognition Page images and parameters in Section 2.3 United States EU Standard Contractual Clauses (SCCs) and the UK Addendum to the SCCs in OpenAI’s DPA
Google LLC (Firebase) Usage statistics Data in Section 2.4 United States and other countries Data Privacy Framework (Google’s certification) and SCCs in the Google Ads Data Processing Terms
Google LLC (Gmail) Storing support emails in the developer’s mailbox Emails in Section 2.6 United States Data Privacy Framework (Google’s certification); Google processes emails under its own Gmail terms
Apple Inc. / Google LLC Selling subscriptions in the app stores Purchase data Store country Independent controllers under their own rules

We may disclose data where required by law, a court order, or a binding request from a public authority — only to the minimum extent necessary and after verifying that the request is lawful. If the business is sold or reorganized, the data will pass to the successor, who will be required to comply with this Policy; we will notify you in the App in advance.

6. International data transfers

Our processors and the other recipients in Section 5 are located in the United States and other countries, so your data may be processed outside the country where you live, including in countries where the level of personal data protection is lower than in yours.

7. How long we keep data

8. Deleting data

In the App: “Profile → Settings → Data → Delete all data.” This deletes all profiles, lab reports, results, the Health Passport, photos and PDFs of documents, temporary files, and settings on this device, and resets the statistics ID. Deletion cannot be undone. You can delete any individual document or family member’s profile at any time.

What the button in the App does not delete, and why:

Full deletion from the server: email [email protected] and include the device ID from the “Data” screen. We will delete the server records within 10 business days and ask our processors to delete their copies. Exception: the trial record is kept for up to 2 years from the start of the trial to prevent abuse; we will tell you about it in our reply.

9. Security

Data is transmitted only over an encrypted connection (TLS). A backup is encrypted on the device (AES-256) with a password that only you know: if you forget it, neither we nor anyone else can restore the backup. Access to the server infrastructure is restricted and protected; server logs contain no health data and no device IDs.

No system is entirely risk-free. Protect your device with a passcode and turn on the app lock. If we become aware of a breach affecting your data, we will notify you and the supervisory authorities within the time limits set by law (in the EU, 72 hours for notifying the supervisory authority; in the United States, under the FTC Health Breach Notification Rule).

10. Your rights

Wherever you live, you can: find out what data about you we process and get a copy of it; correct it; delete it; withdraw your consent; object to processing; and lodge a complaint with us and with a supervisory authority. You can do most of this yourself, directly in the App, because your health data is kept by you. For requests about server data, email [email protected] and include your device ID.

Response times. We respond within 10 business days — the shortest period under the applicable laws. If additional verification is needed, we will tell you so and why.

Identity verification. There are no accounts, so we verify a request using the device ID, which is visible only on your device. Do not share it publicly. We do not ask for any additional documents.

10.1. EEA, United Kingdom, Switzerland

In addition to the rights above: the right to restriction of processing, the right to data portability (export to a backup and to PDF is available in the App), and the right to object at any time to processing based on legitimate interests. You may lodge a complaint with the supervisory authority of the country where you live or work, or where you believe the infringement took place. In the United Kingdom, you have the right to complain to us first: we will acknowledge your complaint within 30 days and respond without undue delay; after that, you can contact the Information Commissioner’s Office (ICO).

10.2. United States

10.3. Belarus

Under Law No. 99-Z “On Personal Data Protection,” you may at any time, without giving reasons, withdraw your consent, obtain information about the processing of your data and about its transfer to third parties, and demand that your data be changed, that its processing be stopped, and that it be deleted. We consider such requests within 15 days (in practice, within 10 business days). You may lodge a complaint with the National Personal Data Protection Center of the Republic of Belarus.

10.4. Russia

Under Federal Law No. 152-FZ “On Personal Data,” you have the right to obtain information about the processing, to demand the rectification, blocking, or destruction of your data, and to withdraw your consent. We respond within 10 business days; after consent is withdrawn, we destroy the data within 30 days. You may lodge a complaint with Roskomnadzor or with a court.

10.5. Kazakhstan

Under the Law “On Personal Data and Their Protection,” you have the right to know about the processing of your data, to demand that it be changed, blocked, or destroyed, and to withdraw your consent. You may lodge a complaint with the authorized body for personal data protection.

10.6. Other countries

If you live in Brazil (LGPD), Canada, or another country with a data protection law, you have the rights that law gives you; we honor them in the same way and within the same time limits.

11. Children and family members’ profiles

The App is intended for adults (18 and over). We do not knowingly collect data from children.

On the Max plan, you can keep profiles for family members, including children. This data is stored only on your device; we do not receive it. By creating such a profile, you confirm that you are the parent or legal guardian of that person or have obtained that person’s consent. A family member’s documents are sent for recognition in the same way as yours (Section 2.3) — black out the personal details on them.

If you believe we have received a child’s data without parental consent, contact us and we will delete it.

12. Changes to this Policy

If the changes are material (new data, new recipients, new purposes), we will notify you in the App in advance and, where required, ask for your consent again. The date of the last update is shown at the top.

13. Contact us

Viktar Muronchyk (Мурончик Виктор Олегович), an individual, developer of the App

Postal address: vul. Karla Marksa 29, OPS-25 (Post Office No. 25), 230025 Hrodna, Republic of Belarus (in Russian: 230025, Республика Беларусь, г. Гродно, ул. Карла Маркса, 29, ОПС-25)

Email: [email protected]

This Policy is available in the App’s languages. If the law of your country requires the Policy to be in your language, the version in your language prevails.