Dr Atlas for iPhone
App Privacy Policy
Effective: 2026-09-10. This policy is provided in English and covers the Dr Atlas iPhone app, including answer logging introduced in version 1.2. The website has a separate privacy notice.
Dr Atlas is operated by an independent developer based in Türkiye. “Dr Atlas,” “we,” and “us” refer to the app's service provider, responsible for the processing described here. Contact contact@askdratlas.com for privacy questions or requests.
What to know before using the app
- No personal account registration, name, email address, or phone number is required. The app and its providers use technical identifiers to operate the service.
- Your questions, relevant conversation history, and attached images or PDFs are sent to Google's AI services to generate answers.
- After you accept the usage notice explaining answer storage, questions, answers, and submitted feedback are stored for quality review, with a 365-day expiry. Database deletion runs after expiry rather than at an exact instant.
- Deleting a chat or using “Delete All Data” clears local history. It does not delete copies already stored on our servers or by service providers.
Health information and intended users
Dr Atlas is for adults — healthcare professionals, students, researchers, and anyone seeking medical information. It is a literature and evidence tool, not medical advice. Do not use it for emergencies.
If you enter information about your own health, it is processed only as described here, with your consent. The usage notice you accept in the app is that consent, and you can decline it.
Do not enter information that identifies other people — a patient's name, date of birth, record number, or a face in a photo. Anonymise reports and images before attaching.
Questions, extracted text, and answers can still contain sensitive health information even without a name. You remain responsible for having an appropriate basis to submit another person's information and for any professional confidentiality duties that apply to you. Using the app does not create a clinician–patient relationship.
Questions, conversation context, and attachments
The app uses Google's Gemini models through Firebase AI Logic and Vertex AI, with Google Search grounding to find sources. Google receives the question and relevant conversation context. For an image or PDF, a model reads the file and extracts text and findings for the answer. The attachment itself may also be sent with the answering request. Questions and answer text may be processed again to generate suggested follow-up questions.
Attached files are saved in your local chat history. We do not include the original image or PDF files in our answer or feedback database. However, stored questions and answers may contain text or findings derived from an attachment.
Google's service-specific terms state: “Google will not use Customer Data to train or fine-tune any AI/ML models without Customer's prior permission or instruction.” This is a training restriction, not a promise that requests are never retained. Google's AI data-governance documentation describes retention for purposes including abuse monitoring and caching. Its current Search grounding terms allow derived search queries and contextual information to be retained for up to three days for debugging.
Answer logs and feedback
Starting in version 1.2, when logging is enabled and you have accepted the usage notice disclosing it, the app sends each completed question and answer to our Google Cloud Firestore database. Authorized people operating Dr Atlas may review these records to assess answer quality, citations, and service problems.
Answer records contain the question, answer, cited source URLs, model name, source count, app version, language/region, platform, message and chat identifiers, available token-usage counts, accepted notice version, and creation and expiry timestamps. They are associated with a random Firebase Authentication identifier. Feedback records include the related question and answer, rating, selected reasons, optional comment, and similar technical metadata.
We do not add a profile name, email, hardware identifier, advertising identifier, precise location, or IP-address field to these records. Information you type can nevertheless identify someone. A random identifier makes records pseudonymous; it does not guarantee anonymity.
Both answer logging and feedback storage require acceptance of a notice disclosing this storage. Existing users who previously accepted AI processing can select “Not now” on the updated logging notice and continue without this additional logging. This declines the new logging permission; it does not withdraw their previously given consent to AI processing. If you decline the initial usage notice, you cannot submit questions or attachments for AI processing.
Identifiers and local history
Firebase Authentication signs the app in anonymously and issues a random user identifier. There is no personal account sign-up, but a technical authentication record exists on Google's servers. It supports service access and associates logs from the same sign-in. Other providers use separate installation or purchase identifiers. Network requests expose an IP address and normal device or request information to the receiving service.
Chats, attachments, and extracted findings are saved in the app's local database for reopening and exporting answers. Preferences and consent records are stored on the device. Exported files, shared copies, and device backups are managed through the destination app or your backup settings.
Analytics, diagnostics, and app operation
- Google Analytics for Firebase: events include screens viewed, searches, message and answer lengths, source interactions, subscription status, errors, language changes, and token usage. Source events can include article titles and URLs. Version 1.2 records question length instead of question text; earlier versions could send the first 100 characters of a search question. Firebase also processes app-instance identifiers and technical usage information. The app uses the Analytics variant without advertising-identifier collection.
- Firebase Crashlytics: crash traces, installation identifiers, app version, device model, and operating-system information help diagnose failures. We do not intentionally add questions or attachments to crash reports.
- Firebase App Check: Apple device/app attestation and short-lived tokens help verify genuine app requests and prevent abuse.
- Firebase Remote Config: installation identifiers and app information support delivery of model settings, feature availability, maintenance notices, and policy links.
See Privacy and Security in Firebase for these services' data handling and retention practices.
Subscriptions and install attribution
Apple processes payments. RevenueCat receives its own app-user identifier, transaction and purchase information, and subscription status to verify purchases and unlock Pro. Dr Atlas does not receive payment-card details. See RevenueCat's privacy policy and Apple's privacy policy.
Apple's AdServices attribution through RevenueCat helps us understand whether an installation came from an Apple Search Ads campaign. This uses Apple's attribution token rather than the advertising identifier. The app can show Apple's tracking-permission prompt; AdServices attribution can operate with different information depending on that choice. Dr Atlas does not use the advertising identifier for tracking, display third-party advertising, or sell your questions for advertising.
A small device-keychain flag records whether the free question has been used. It can survive reinstalling and is not cleared by “Delete All Data.”
Notifications and literature sources
If you allow notifications, Firebase Cloud Messaging and Apple Push Notification service process messaging tokens and installation identifiers to deliver app announcements. You can disable notifications in iOS Settings. Disabling delivery does not necessarily erase identifiers already held by these providers.
For citations and figures, the app requests article information from NCBI/PubMed, PubMed Central, and Europe PMC using article identifiers. It also follows citation links and requests previews from publishers and image hosts. These requests concern cited sources rather than submitting your question as a literature-API query. Receiving sites see the requested URL, your IP address, and normal request information. Their policies also apply when you open a source in a browser.
Purposes, choices, and legal bases
We process information to provide requested answers, maintain service access, verify subscriptions, and respond to support requests. Processing information about your own health relies on the consent you give through the usage notice, as described above. Consent also applies to the question-and-answer logging disclosed in that notice. For other processing, where applicable law requires a legal basis, providing the requested service supports service access, purchases, and support; necessary security and diagnostics rely on our legitimate interest in operating a reliable service; and legally required records rely on the relevant legal obligation.
To withdraw consent, contact contact@askdratlas.com. Withdrawal does not affect processing that was lawful before withdrawal. Version 1.2 has no separate in-app switch to revoke accepted logging consent. To prevent further app requests while your request is handled, stop submitting questions or uninstall the app. This does not erase previously collected information.
If you email us, we receive your address, message, and any details you provide so we can respond. The app has no email registration or marketing mailing list. Do not send patient records or sensitive attachments in support emails.
Retention and deletion
- Answer logs and feedback: records expire 365 days after creation. Automatic deletion is enabled for both collections. Firestore deletes expired records asynchronously, typically within 24 hours after expiry, rather than at a guaranteed instant. See Google's expiry documentation.
- Local chats and attachments: kept until you delete the chat, use Settings → Delete All Data, or remove the app's local data. Exports and backups may remain separately.
- AI requests: subject to Google's processing and retention described above, separately from our answer logs.
- Analytics: retained according to the Google Analytics property's configured retention settings. Aggregated reports can have a different lifecycle from individual events.
- Crash reports: Google states that Crashlytics retains crash data and associated identifiers for 90 days before beginning removal from live and backup systems.
- Authentication, messaging, and configuration identifiers: retained under the relevant Firebase service's lifecycle and deletion procedures. Uninstalling or disabling notifications does not request deletion of all provider-side records.
- Purchases and support: kept as needed to administer purchases, resolve requests or disputes, and meet applicable legal recordkeeping requirements. Apple and RevenueCat also apply their own retention requirements.
“Delete All Data” clears local chats and the active conversation, then signs out of Firebase and attempts a new anonymous sign-in. It does not delete earlier server logs or the previous Firebase authentication record, revoke saved logging consent, or cancel an App Store subscription. Reinstalling does not reliably reset all identifiers. Changing an identifier does not make existing records unidentifiable.
For access, correction, deletion, or withdrawal requests, email contact@askdratlas.com. With no registered email linked to chats, we may need limited details to locate records and verify your request, such as an approximate date and a non-sensitive description of the question. Do not include information that identifies other people. We will explain if we cannot reliably identify the records or if a legal retention exception applies.
Storage, sharing, and security
Our answer and feedback database is in Frankfurt, Germany (Google Cloud region europe-west3). All processing does not stay in the EU: AI requests use Google's global service, the operator is based in Türkiye, and Google, Apple, RevenueCat, and literature providers may process information in other countries, including the United States.
Service providers process information for the purposes described here. Information may also be disclosed as necessary to comply with law, respond to valid legal requests, protect users, or investigate abuse. The Google Cloud data-processing terms and RevenueCat data-processing terms describe contractual protections and applicable transfer safeguards, including standard contractual clauses. Contact us for information about safeguards relevant to your data.
The app uses encrypted network connections and authenticated database access. App clients cannot read other users' answer or feedback records. Access for service operation and quality review is restricted to authorized personnel. No system can guarantee absolute security.
Your rights and policy changes
Depending on applicable law, you may have rights to access, correct, erase, restrict, object to processing, receive a portable copy of your data, and withdraw consent. You may also complain to your local data-protection authority. Contact contact@askdratlas.com to exercise your rights; we respond within the period required by applicable law.
We update this page and its effective date when our practices change. Where fresh consent is required, updating the page or continued app use does not replace that consent. See the Terms & Conditions for usage rules.