Not from the on-phone vault. The person chooses what to show, export, or send.
Core health records are stored on the person's phone rather than in a central Ribbonside health-record database.
Supabase-hosted account services store account, consent, support, subscription, AI usage-limit, and security records needed to run the service.
Privacy and security overview
Short answer
Ribbonside is designed as a local-first private organiser for people managing the practical side of breast cancer care. The core health records a person enters into the app are stored on their own phone. The online backend is used for limited operational records such as sign-in, consent, support, subscriptions, AI usage limits, and security records.
Ribbonside does not sell health data, does not use advertising trackers, and does not give other people or Ribbonside support staff routine access to the user's private health vault.
No. Core health records are stored locally on the device. Limited account and service records are online.
No. Ribbonside is a personal organiser and general information tool.
What stays on the person's phone
These records are stored in the local Ribbonside vault on the device when the user chooses to add them.
| Data type | Storage location | Notes |
|---|---|---|
| Diagnosis details | Phone local vault | Patient-entered cancer type, stage, receptor details, hospital or clinician notes if entered. |
| Appointments and appointment notes | Phone local vault | Used for the user's own organisation and reminders. |
| Medications and reminder settings | Phone local vault | Notification popups are intentionally generic and do not show medication names. |
| Daily check-ins, symptom tags, exercise, and recovery entries | Phone local vault | Patient-entered or app-created private records. |
| Test result notes | Phone local vault | Patient-entered values, not a clinician-authored report. |
| Care team contacts | Phone local vault | Doctors, nurses, clinics, and support contacts added by the user. |
| Photos and documents | Phone app-private file vault | Files selected by the user are saved in app-private storage. |
| Apple Health values on iPhone | On-device display only | If the user grants permission on iPhone, Ribbonside reads selected activity values for display. Current verified app behaviour does not send HealthKit values to Ribbonside's backend or third parties. |
What is stored online
Ribbonside still needs limited online records to operate accounts, consent, support, subscriptions, and optional AI features.
| Data type | Where | Why |
|---|---|---|
| Account sign-in | Supabase Auth | To let the user sign in and maintain a secure session. |
| Profile basics | Supabase-hosted account service | User ID, name or email where supplied, plan, and terms acceptance. |
| Consent history | Supabase-hosted account service | Audit trail for privacy, health data, AI, subscriptions, and terms consent. |
| Support tickets | Supabase-hosted account service | Only when the user contacts support. May include health information if the user chooses to type it into the message. |
| Subscription entitlement | App store provider, RevenueCat, and Ribbonside account records | To confirm subscription status, purchases, renewals, and restore-purchase state. |
| AI usage limits | Supabase-hosted account service | Daily and monthly counts and technical usage metadata. Ribbonside does not store the user's AI prompt text in Supabase. |
| Security and admin records | Supabase-hosted account service | Audit, rate-limit, service-integrity, and incident-response records. |
Other providers
| Provider | What may be sent | When |
|---|---|---|
| Apple / Google platform services | Sign in with Apple on iPhone or Google sign-in on Android, app store account, subscriptions, refunds, OS notifications, and platform permission controls. | Platform operation. |
| RevenueCat | Ribbonside user ID, subscription product, entitlement and purchase status. | Subscriptions and restore-purchase checks. |
| Anthropic Claude API | Text the user types into What does this mean?. | Only after point-of-use consent. The app warns users not to enter names, dates of birth, Medicare numbers, medical record numbers, addresses, phone numbers, email addresses, or full clinical reports. |
| Resend | Transactional support or service email delivery metadata and limited alert content. | Support notification emails are designed not to include the private support message body. |
| Expo / EAS | Build and app update infrastructure metadata. | Build and distribution operations, not runtime storage of the user's health vault. |
| GitHub Pages | Public website request logs. | Website hosting only, not app health vault processing. |
Security scaffolding
- Local-first design keeps core health records out of the central backend.
- The app requires sign-in before use.
- The app requires a PIN and can use biometric or device unlock where supported.
- The app locks when it backgrounds or the phone locks.
- Local records are scoped to the current signed-in user.
- Supabase tables use Row Level Security so normal users can access only their own permitted online records.
- Private runtime tables are not directly available to normal app users.
- Service-role access is kept inside Supabase Edge Functions, not inside the mobile app.
- Family, Circle, or carer sharing is not part of the current local-first launch.
- Ask AI goes through a Supabase Edge Function. The Anthropic API key is not in the app.
- AI requests are sign-in verified, size-limited, rate-limited, subscription-gated, and checked for obvious high-risk identifiers before sending.
- Support email alerts are minimal and do not include the private support ticket message body.
Can someone else see patient records?
Not by default. Ribbonside support staff cannot log into Supabase and view the user's on-phone health vault. The person can choose to show the app on their phone, export a patient-entered records PDF or JSON file, or send selected details through support or What does this mean?.
If the phone is lost or replaced
Signing back into Ribbonside restores account and subscription access, but it does not currently restore health records stored in the local vault. Before changing, resetting or replacing a phone, use Export Data (JSON), which is available to every signed-in Ribbonside account. With an active Ribbonside subscription, you can also create a Share Records PDF. Save the files securely somewhere outside the phone.
How to keep a separate copy of records
In Ribbonside, open Account, then Privacy & Your Data. Export Data (JSON) is available to every signed-in Ribbonside account and includes raw records and available photo and document attachment data, subject to safety and size limits. Share Records PDF is a readable summary available with an active Ribbonside subscription. Photo and document files are listed but are not embedded in the PDF. Save the files somewhere outside the phone. Neither export can currently be imported back into Ribbonside.
Account deletion and vault erase
- Erase Health Vault: deletes health records stored by Ribbonside on this phone only. It does not delete the online account, consent, support, billing, or subscription records.
- Delete Account: deletes the authenticated user where possible, removes or de-identifies Ribbonside-controlled online records where reasonably possible, cleans legacy storage paths, erases the local vault, and signs the user out.
Some limited records may be retained only where needed for legal, security, billing, dispute, backup, audit, or service-integrity reasons.
Likely questions
Core health records are stored on the person's phone in the local vault. Supabase-hosted account services store limited online account, consent, support, subscription, security, and AI usage-limit records.
No. Safer wording is that Ribbonside uses a local device vault for core health records and limited cloud/account services for app operation.
Not in the current local-first launch. Sharing is not active.
No. Ribbonside says it does not sell health data, use advertising trackers, or share data with advertisers or data brokers.
Yes, if the user chooses to use it. The text they type is sent to Anthropic's Claude API for processing after point-of-use consent.
Current verified app behaviour reads HealthKit values on-device on iPhone for display only and does not send them to Supabase, RevenueCat, Anthropic, support/admin tools, or analytics providers.
Yes. Ribbonside is planning a user-controlled encrypted backup and restore feature. Until it is released and confirmed available in the app, users should continue exporting their records regularly.
Ribbonside maintains a data breach response plan and states that suspected eligible breaches will be assessed within 30 days, with notification to affected users and the OAIC where required.
Important limits
- Ribbonside is not a medical service and does not replace a treating team.
- A user may still type sensitive information into support or What does this mean?, even though the app warns against it.
- A stolen, unlocked, rooted, jailbroken, or compromised device can still create risk.
- Local-first storage means signing in on another phone does not restore the local health vault. Current PDF and JSON exports are one-way files and cannot be imported back into Ribbonside.
- Independent mobile security review and Supabase access-control review remain sensible before any healthcare-partner rollout.