Symptra — Privacy Policy

Last updated: 1 October 2026

Symptra is a health information app. This policy explains what information we collect, where it goes, how it is used, and what you can do about it.

There is no account or sign-in. We do not ask for your name, email address, phone number, or password.

1. Who We Are

Symptra is operated by the developer of the Google Play application app.symptra.health.

If you have questions about this Privacy Policy or want to make a request about your personal data, contact us at:

Email: info@cognify.ltd

We aim to respond to data requests within 30 days.

2. What the App Collects and What Happens to It

Your questions

This is what you type or dictate into a consultation.

Where it is kept: Your conversation is saved on your phone so that it is still there when you come back to it. The most recent 200 messages are kept and older ones are removed automatically. You can delete the whole conversation at any time using Clear conversation on the consultation screen.

Where it goes: Sent to our AI provider to generate an answer. The request passes through our own service, which holds the credentials needed to reach the AI provider, and is forwarded without being written down. We do not store your questions on our own servers.

Who receives it: Anthropic, our AI provider. The information is used to generate the response and is not used to train any model.

Lab reports you analyse

This is the photograph or PDF of a laboratory report you choose to have read, and the test results read from it.

Where it goes: The image or PDF is sent to our AI provider to be transcribed, and the test results read from it are then sent a second time so that an explanation can be written. Both requests pass through our own service in the same way a consultation does, and neither the image nor the results are stored on our own servers.

Where it is kept: The test results, the reference ranges, the explanation and the laboratory's name are saved on your phone so that you can read the report again without using another analysis. The photograph or PDF itself is not saved. You can delete any analysed report from the report analyzer screen.

Who receives it: Anthropic, our AI provider. The information is used to read the report and write the explanation, and is not used to train any model.

Your health profile

This may include your year of birth, sex, long-term conditions, medicines, and allergies that you enter during setup.

Where it is kept: On your phone. When you ask a question, relevant information from your profile is sent with the question so the answer can take it into account.

Who receives it: Anthropic, as part of the question sent to generate the answer.

Your food diary

This includes what you scanned, how much, and when.

Where it is kept: On your phone only.

Who receives it: Nobody. Your food diary does not leave your device.

Barcodes you scan

We use the barcode to look up product information.

Where it is kept: The barcode itself is not stored by us.

Who receives it: Open Food Facts, an open food database. The query contains the barcode and nothing else.

Account identifier

An anonymous identifier is created automatically when you first launch the app. No personal details are attached to it.

Where it is kept: Firebase Authentication and Cloud Firestore, both operated by Google, and on your phone.

Who receives it: Google, as the operator of these services.

The identifier allows us to count your daily free allowance. It does not identify you by name or email address. The allowance is also counted against a one-way hash of the identifier Android assigns to Symptra on your device, so reinstalling the app or clearing its data does not reset it. The original device identifier never leaves your phone, and the hash changes if the device is factory reset.

Crash reports

We use Firebase Crashlytics to collect technical information about the state of the app when it crashes.

Where it is kept: Firebase Crashlytics, operated by Google.

Who receives it: Google.

Crash reports do not contain anything you typed into the app and do not contain information from your health record. The app is designed so that this information is not included in crash reports.

Usage and analytics information

We collect information about how the app is used so that we can see where people get stuck and what to improve. This includes which screens you open, which features you use, whether a consultation succeeded or failed and how long it took, how far you got through setup, and standard technical details such as your app version, device model, country, and language.

This information does not include your questions, the answers you receive, your health profile, your food diary, or which emergency advisory you were shown. The app is designed so that this information cannot be included: usage events carry only counts, yes or no values, and fixed labels, never free text.

It is not linked to your name or any contact details.

Where it is kept: Google Analytics for Firebase, operated by Google.

Who receives it: Google.

Uninstalling the app stops this collection. We can also switch analytics collection off for the app without an update.

Technical request logs

When the app contacts our service, our hosting provider records the request. This includes your IP address, the time, which part of the service was contacted, the result, and how long it took.

These logs do not contain your questions, the answers you receive, or anything from your health profile.

We use them to keep the service running, to investigate faults, and to detect abuse of the service. We do not use them to build a profile of you.

Where it is kept: Google Cloud Logging, operated by Google.

Who receives it: Us, and Google as the operator of that service.

Device integrity checks

To stop our service being used by anything other than the real app, requests are accompanied by a check from Google Play Integrity, through Firebase App Check.

This confirms that the request comes from a genuine installation of Symptra. It does not tell us who you are and does not carry any health information.

Where it is kept: Firebase App Check and Google Play services, operated by Google.

Who receives it: Google, and a pass or fail result to us.

Notification token

If you allow notifications, the app may use a notification token to deliver notifications.

Where it is kept: Firebase Cloud Messaging, operated by Google.

Who receives it: Google.

Advertising identifiers

This version of Symptra does not show advertising and does not process advertising identifiers. If that changes, we will update this policy first. See Section 6, Advertising.

Reports about AI answers

If you use the Report this answer feature, we receive the report and the AI answer you reported.

Your original question is included only if you explicitly tick the option asking us to include it.

We keep the reported answer so that a person can read it and act on it. A report that cannot be read cannot be acted on.

Where it is kept: Google Cloud Firestore, operated by Google on our behalf.

Who receives it: Us, and Google as the operator of that service.

Microphone

The microphone is used only while you hold the dictate button.

Audio is converted into text by your phone. The audio itself is not sent to us or stored by us.

Camera

The camera is used only for reading barcodes.

The image is analysed on your device and is not stored or uploaded by Symptra.

3. Legal Basis for Processing

Health information can be considered a special category of personal data under the UK GDPR and EU GDPR.

Where these laws apply, we process health information on the basis of your explicit consent.

You provide consent when you enter health information and use the relevant health-information features of the app.

You can withdraw consent by deleting the app or clearing its app data. This removes information stored locally on your device.

For residents of Washington State, this Privacy Policy also serves as our Consumer Health Data Privacy Policy under the Washington My Health My Data Act.

We do not sell consumer health data and have never sold consumer health data.

4. How Long We Keep Information

Information stored on your phone

Information stored locally remains on your device until you delete it, clear the app's data, or uninstall the app.

Two kinds of information are also removed automatically as you keep using the app: your consultation keeps only its most recent 200 messages, and an analysed lab report is kept until you delete it.

Questions

We do not retain your questions on our own servers. Your conversation is kept on your phone, as described in section 2.

Our AI provider may retain information transiently to provide the service and for abuse monitoring, subject to its own applicable retention policies.

Consultation metering records

We keep records of how much of your daily free allowance has been used and when the current 24-hour window began.

When you use Delete my data, the record for the current 24-hour window is kept until that window ends, so that deleting your data cannot be used to renew the free allowance. It is then deleted.

Analysed lab reports

Analysed lab reports are kept on your phone until you delete them. We do not retain the image, the test results or the explanation on our own servers.

Crash reports

Crash reports are retained according to Google's standard Firebase Crashlytics retention period, currently 90 days.

Usage and analytics information

Usage and analytics information is retained according to Google's standard Google Analytics for Firebase retention periods.

Technical request logs

Technical request logs, including IP addresses, are retained for approximately 30 days and are then deleted automatically.

Content reports

Reports submitted through the Report this answer feature, including the reported answer, are deleted automatically 180 days after they are submitted, and in any event are retained for no longer than 24 months. This allows us to identify repeated problems and improve the service.

5. Your Rights and Choices

Depending on where you live, you may have rights to:

You can manage much of your information directly in the app.

Use Your details to change your health profile.

Use Delete my data in About & legal to delete your data immediately: it removes your reports about AI answers and your anonymous account from our servers, and then erases everything Symptra stored on your phone. See how to delete your data for more detail.

Uninstalling the app or clearing its data removes information stored locally on your device.

For information held on our servers, contact:

info@cognify.ltd

We will process valid requests in accordance with applicable law.

You also have the right to complain to your local data protection authority if you believe your privacy rights have been violated.

6. Advertising

This version of Symptra does not display advertising.

We do not send your health information, questions, or information from your health record to advertising networks.

7. Children

Symptra is not intended for children under 13.

We do not knowingly collect personal information from children under 13.

If you believe that a child under 13 has used Symptra and provided personal information, please contact us at:

info@cognify.ltd

We will take appropriate steps to delete the information where required by applicable law.

8. International Transfers

Our service providers, including Anthropic and Google, may process information in the United States and other countries.

Our own service runs on Google Cloud in the United States, so a request you make is processed there.

Where required, transfers of personal data from the UK or European Economic Area to countries that do not have an applicable adequacy decision are protected using appropriate safeguards, including Standard Contractual Clauses where applicable.

9. Changes to This Privacy Policy

We may update this Privacy Policy from time to time.

When we make changes, we will update the Last updated date at the top of this page.

If we make a material change that affects how we handle your health information, we will provide appropriate notice and, where required, ask for your consent again.

10. Symptra Is Not a Doctor

Symptra provides general health information.

Symptra is not a doctor, healthcare professional, or medical device.

The app does not diagnose, treat, cure, or prevent any illness or medical condition.

Information provided by Symptra should not be treated as a medical opinion or a substitute for professional medical advice.

Do not delay seeking medical care or stop, start, or change medication because of information provided by the app.

Always consult a qualified healthcare professional about a medical concern.

If you believe you are experiencing a medical emergency, contact your local emergency services immediately.

11. Contact Us

If you have questions about this Privacy Policy, want to exercise your privacy rights, or have a concern about how your information is handled, contact us:

Symptra

Email: info@cognify.ltd

Application: app.symptra.health

Last updated: 1 October 2026