Privacy Notice & Medical Disclaimer

Last Updated: 12th August 2026

1. Introduction

Acumi Ltd ("we", "us", or "our") is committed to protecting your privacy. We operate the Acumi mobile application (the "App").

Who is responsible for your information depends on how you use Acumi.

  • If you have only ever used Acumi on your own: we are the Data Controller for everything in your account.
  • If you are, or have ever been, under the care of a clinic through Acumi: that clinic is the Data Controller for the records created during that care, and we hold those records on the clinic's behalf as its Data Processor.

Section 7 explains what this means for how long records are kept, and section 8 for your rights.

This Notice explains how we collect, use, and store your data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Important: Medical Disclaimer & Liability

The App is a passive data recording tool only.

  • No Medical Advice: We do not provide medical diagnosis, treatment, or advice. The App does not interpret your data, flag health risks, or provide "red alerts."
  • No Monitoring: We do not monitor your data in real-time. If you enter data indicating a health crisis (e.g., severe side effects or dangerous vital signs), we will not be alerted and cannot intervene.
  • Emergency: In a medical emergency, you must contact 999 or your GP immediately. Do not rely on this App for safety.
  • User Responsibility: You are solely responsible for the accuracy of the data you enter and for any decision to share this data with healthcare professionals.

3. Data We Collect

We classify your data into two legal categories as required by UK law:

A. Personal Data (General)

  • Identity: Name, Date of Birth (to verify age).
  • Contact: Email address (for account security).
  • Address & GP Details: Home address and GP practice details (if provided, to support shared care with your clinician).
  • Appointments: Scheduled appointment dates and times with your healthcare provider.
  • Technical: IP address, device model, and operating system (collected automatically to fix bugs and maintain security).
  • Biometric Authentication: The App may use your device's biometric capabilities (Face ID, Touch ID, or fingerprint) to unlock the App. Biometric data never leaves your device and is not accessible to us.

B. Special Category Data (Health)

  • Vital Signs: Weight, Heart Rate, Blood Pressure, Heart Rate Variability (HRV), Step Count, and Exercise Minutes.
  • Medication Records: Drug names, dosages, schedules, and adherence logs (taken, skipped, or snoozed).
  • Health Journal: Symptom and side effect logs (appetite, fatigue, anxiety), mood and energy scores, sleep quality and duration, and daily notes.
  • Behaviour Tracking: Self-reported scores for impulsivity, irritability, risk-taking, emotional blunting, restlessness, and addictive behaviours.
  • Clinical Questionnaires: Responses to standardised mental health assessments (e.g., PHQ-9, GAD-7, BCQ) assigned by your clinician, including scores and interpretation results.
  • Audio Notes: Voice memos regarding your symptoms (if you choose to record them).

C. Wearable & Device Health Data

If you choose to enable wearable integration, the App can read health data from your device. On iOS this uses Apple HealthKit; on Android this uses Health Connect. The App does not write any data back to these platforms.

Data types we may read:

  • Body Measurements: Weight (Body Mass).
  • Heart: Resting Heart Rate, Blood Pressure (Systolic and Diastolic), Heart Rate Variability (HRV SDNN).
  • Activity: Step Count, Exercise Minutes.
  • Sleep: Sleep Analysis (duration and sleep stages).
  • State of Mind (iOS only): Daily Mood (valence classification and emotion labels). Requires iOS 18 or later; opt-in only.

How Wearable Data Is Used:

  • Wearable data is used solely to auto-populate your health tracking fields within the App, reducing the need for manual data entry.
  • If you have manually entered data for a given day, your manual entry always takes precedence over wearable data.
  • Wearable-sourced data is clearly marked in the App so you can distinguish it from your manual entries.

What We Do NOT Do with Wearable Data:

  • We do not use HealthKit or Health Connect data for advertising, marketing, or data mining purposes.
  • We do not sell, share, or disclose wearable data to third parties, including advertising networks, data brokers, or information resellers.
  • Wearable data is not stored in any third-party analytics or tracking systems.

Your Control:

  • Wearable integration is entirely opt-in. You must explicitly enable it in the App settings.
  • iOS: You can disable HealthKit sync at any time via the App settings or by revoking permissions in your device's Settings > Privacy & Security > Health > Acumi.
  • Android: You can disable Health Connect sync at any time via the App settings or by revoking permissions in your device's Settings > Apps > Health Connect > App permissions > Acumi.
  • You can choose which individual data types to sync (e.g., enable sleep sync but disable weight sync).

4. Our Lawful Basis for Processing

Under the UK GDPR, we must have a lawful basis for processing your data. We rely on the following:

Data Type Lawful Basis Explanation
Account & Identity Contract (Art. 6(1)(b)) Necessary to provide the App service you signed up for.
Health Data Provision of Health Care (Art. 9(2)(h)) Necessary for the management of your own health records via our platform.
App Analytics Legitimate Interests (Art. 6(1)(f)) Necessary to improve App stability, fix crashes, and ensure security.
Clinical Integration Explicit Consent (Art. 9(2)(a)) You actively choose to link your account to your clinician.

5. Where We Store Your Data

We are a UK-based company. Your personal health data is encrypted and stored securely on servers located physically within the United Kingdom (AWS London Region, managed by Supabase).

We do not transfer your health data outside the UK or EEA. If our infrastructure providers change, we will ensure strictly equivalent legal safeguards are in place (e.g., UK International Data Transfer Agreements).

6. Who We Share Your Data With

We strictly do not sell your personal or health data. We share data only in the following specific circumstances:

A. Healthcare Integration (API)

If you explicitly choose to link your App account with your registered clinic or hospital system (via our secure API), we will transmit your health logs to them.

  • Legal Basis: Performance of Contract and Explicit Consent.
  • Security: Data is transferred via encrypted HTTPS/TLS 1.2+ channels.

B. At Your Direction (User-Generated Reports)

If you use the App to generate a report (e.g., PDF export) and choose to share it via email, messaging, or other apps:

  • Transfer of Control: You acknowledge that once the file is generated, the data leaves our secure systems.
  • Your Responsibility: You are solely responsible for securing that file and ensuring it is sent to the correct recipient. We are not liable for data breaches caused by user error (e.g., sending a report to the wrong email address).

C. Service Providers

We use trusted third-party companies to provide our infrastructure. They act as Data Processors and process data only on our strict instructions:

  • Database & Authentication: Supabase (UK Region): stores your account, health data, and handles sign-in.
  • Report Generation: Google Cloud Platform (europe-west2, London): generates PDF reports from your health data on demand. Data is processed transiently and not stored.
  • Acumi Portal Hosting: Google Firebase Hosting: serves the clinician portal (no patient health data is stored on Firebase).

D. Legal Authorities

We may disclose your data if required to do so by UK law (e.g., in response to a court order).

7. How Long We Keep Your Data

While your account is open, we keep your health records so that your history is there for you. What happens when you close your account depends on whether you have used Acumi with a clinic, because that changes who the records belong to.

A. If you have only ever used Acumi on your own

We are the Data Controller for everything in your account, and no one else has a duty to keep it. You can delete your account yourself in the App, under Settings, then Account, then Delete account.

  • Your check-ins, medicines, notes, settings and personal details are removed from our live systems straight away.
  • They are removed from our backups within 30 days.
  • We keep one dated record that an account was deleted. It holds an internal reference only, with no name, email address or health information in it.
  • This cannot be undone, and we cannot recover your history afterwards.

B. If you are, or have ever been, under the care of a clinic through Acumi

Your clinic is the Data Controller for the records created during that care, and it is required by law to keep them. We hold those records on your clinic's behalf as its Data Processor, so we cannot delete them at your request. Only your clinic can decide what may be removed, and when.

  • Why the clinic must keep them: health and care providers have to retain patient records to meet their legal obligations. Under the NHS Records Management Code of Practice an adult's health record is normally kept for at least eight years, and CQC Regulation 17 requires providers to keep accurate and complete records of the care they give.
  • What you can do: you can delete your Acumi account from the same screen in the App. That deletes your login, your personal details and everything you recorded on your own straight away, and clears them from our backups within 30 days. The records from your care are kept for your clinic, with your name and contact details taken off, for as long as your clinic has to keep them, and then deleted. We tell your clinic, by name, that you have closed your account.
  • This cannot be undone. Once your account is deleted you cannot sign in to it again, and we cannot recover what you recorded on your own.
  • This still applies after you are discharged. Once a clinic has held records from your care, they remain the clinic's to keep, even once you are no longer their patient.

If you sign up on your own and later join a clinic through Acumi, part B applies to you from that point onwards.

8. Your Rights

Under the UK GDPR, you have the following rights:

  • Right of Access: You can request a copy of all personal data we hold about you.
  • Right to Rectification: You can correct wrong information (e.g., a wrong medication dosage) directly in the App.
  • Right to Erasure ("Right to be Forgotten"): What this means for you depends on whether you have used Acumi with a clinic. Both routes start in the same place: Settings, then Account, then Delete account.
    • If you have only ever used Acumi on your own: you can delete your entire account and history at any time. It takes effect straight away and is irreversible.
    • If you are, or have ever been, with a clinic: you can delete your account from the same screen. We delete your login, your personal details and everything you recorded on your own. The records from your care are not deleted then, because your clinic is the Data Controller for them and has to keep them: we keep them for your clinic, with your name and contact details taken off, until its retention period ends. See section 7 for what is kept and why.
  • Right to Portability: You can request a copy of your raw data in a machine-readable format by contacting us at the address below.
  • Right to Restrict Processing: You can ask us to pause processing your data if you believe it is inaccurate.

The right to erasure is not absolute. Article 17(3) of the UK GDPR disapplies it where an organisation has to keep records to meet a legal obligation, which is the position health and care providers are in. This is why the answer differs depending on whether a clinic holds records from your care.

To exercise any of these rights, please contact us using the details below. Where your clinic is the Data Controller for the records, you can also raise these rights with the clinic directly, and we will help you reach the right person there.

9. Complaints

If you have concerns about how we handle your data, please contact our Data Protection Lead first.

Email: support@acumi.app

If you remain unhappy, you have the right to lodge a complaint with the UK regulator:

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any significant changes via the App or email.

Back to Home