Privacy and security

How Ribbonside handles information.

A plain-language public overview of what stays on the device, what is used for account services, and how users stay in control.

Storage model Local-first health vault.

Core health records are stored on the person's phone rather than in a central Ribbonside health-record database.

On-device vault PIN lock Biometric unlock where supported No advertising trackers
Online records Limited account data.

Supabase-hosted account services store account, consent, support, subscription, AI usage-limit, and security records needed to run the service.

Supabase account services Row Level Security Service keys kept server-side

Privacy and security overview

Public website overview · Last updated 25 August 2026

Ribbonside is a private organiser and optional plain-English information tool. It is not a hospital system, electronic medical record, emergency service, diagnostic tool, or substitute for professional medical advice.

Short answer

Ribbonside is designed as a local-first private organiser for people managing the practical side of breast cancer care. The core health records a person enters into the app are stored on their own phone. The online backend is used for limited operational records such as sign-in, consent, support, subscriptions, AI usage limits, and security records.

Ribbonside does not sell health data, does not use advertising trackers, and does not give other people or Ribbonside support staff routine access to the user's private health vault.

Can staff see patient records?

Not from the on-phone vault. The person chooses what to show, export, or send.

Is it all cloud storage?

No. Core health records are stored locally on the device. Limited account and service records are online.

Is it medical advice?

No. Ribbonside is a personal organiser and general information tool.

What stays on the person's phone

These records are stored in the local Ribbonside vault on the device when the user chooses to add them.

Data typeStorage locationNotes
Diagnosis detailsPhone local vaultPatient-entered cancer type, stage, receptor details, hospital or clinician notes if entered.
Appointments and appointment notesPhone local vaultUsed for the user's own organisation and reminders.
Medications and reminder settingsPhone local vaultNotification popups are intentionally generic and do not show medication names.
Daily check-ins, symptom tags, exercise, and recovery entriesPhone local vaultPatient-entered or app-created private records.
Test result notesPhone local vaultPatient-entered values, not a clinician-authored report.
Care team contactsPhone local vaultDoctors, nurses, clinics, and support contacts added by the user.
Photos and documentsPhone app-private file vaultFiles selected by the user are saved in app-private storage.
Apple Health values on iPhoneOn-device display onlyIf the user grants permission on iPhone, Ribbonside reads selected activity values for display. Current verified app behaviour does not send HealthKit values to Ribbonside's backend or third parties.

What is stored online

Ribbonside still needs limited online records to operate accounts, consent, support, subscriptions, and optional AI features.

Data typeWhereWhy
Account sign-inSupabase AuthTo let the user sign in and maintain a secure session.
Profile basicsSupabase-hosted account serviceUser ID, name or email where supplied, plan, and terms acceptance.
Consent historySupabase-hosted account serviceAudit trail for privacy, health data, AI, subscriptions, and terms consent.
Support ticketsSupabase-hosted account serviceOnly when the user contacts support. May include health information if the user chooses to type it into the message.
Subscription entitlementApp store provider, RevenueCat, and Ribbonside account recordsTo confirm subscription status, purchases, renewals, and restore-purchase state.
AI usage limitsSupabase-hosted account serviceDaily and monthly counts and technical usage metadata. Ribbonside does not store the user's AI prompt text in Supabase.
Security and admin recordsSupabase-hosted account serviceAudit, rate-limit, service-integrity, and incident-response records.

Other providers

ProviderWhat may be sentWhen
Apple / Google platform servicesSign in with Apple on iPhone or Google sign-in on Android, app store account, subscriptions, refunds, OS notifications, and platform permission controls.Platform operation.
RevenueCatRibbonside user ID, subscription product, entitlement and purchase status.Subscriptions and restore-purchase checks.
Anthropic Claude APIText the user types into What does this mean?.Only after point-of-use consent. The app warns users not to enter names, dates of birth, Medicare numbers, medical record numbers, addresses, phone numbers, email addresses, or full clinical reports.
ResendTransactional support or service email delivery metadata and limited alert content.Support notification emails are designed not to include the private support message body.
Expo / EASBuild and app update infrastructure metadata.Build and distribution operations, not runtime storage of the user's health vault.
GitHub PagesPublic website request logs.Website hosting only, not app health vault processing.

Security scaffolding

Can someone else see patient records?

Not by default. Ribbonside support staff cannot log into Supabase and view the user's on-phone health vault. The person can choose to show the app on their phone, export a patient-entered records PDF or JSON file, or send selected details through support or What does this mean?.

For any care conversation, the safest workflow is simple: let the person open Ribbonside on their own phone, choose what to show, and treat any export as patient-entered information rather than a hospital record or clinician-authored summary.

If the phone is lost or replaced

Signing back into Ribbonside restores account and subscription access, but it does not currently restore health records stored in the local vault. Before changing, resetting or replacing a phone, use Export Data (JSON), which is available to every signed-in Ribbonside account. With an active Ribbonside subscription, you can also create a Share Records PDF. Save the files securely somewhere outside the phone.

Ribbonside does not currently provide automatic backup or restore. Current PDF and JSON exports cannot be imported back into Ribbonside.

How to keep a separate copy of records

In Ribbonside, open Account, then Privacy & Your Data. Export Data (JSON) is available to every signed-in Ribbonside account and includes raw records and available photo and document attachment data, subject to safety and size limits. Share Records PDF is a readable summary available with an active Ribbonside subscription. Photo and document files are listed but are not embedded in the PDF. Save the files somewhere outside the phone. Neither export can currently be imported back into Ribbonside.

Account deletion and vault erase

Some limited records may be retained only where needed for legal, security, billing, dispute, backup, audit, or service-integrity reasons.

Likely questions

Is patient health information stored in a cloud data centre?

Core health records are stored on the person's phone in the local vault. Supabase-hosted account services store limited online account, consent, support, subscription, security, and AI usage-limit records.

Is this an end-to-end encrypted clinical system?

No. Safer wording is that Ribbonside uses a local device vault for core health records and limited cloud/account services for app operation.

Can family or carers see records?

Not in the current local-first launch. Sharing is not active.

Does Ribbonside sell data or use ads?

No. Ribbonside says it does not sell health data, use advertising trackers, or share data with advertisers or data brokers.

Does What does this mean? send information overseas?

Yes, if the user chooses to use it. The text they type is sent to Anthropic's Claude API for processing after point-of-use consent.

Does Apple Health data leave the device?

Current verified app behaviour reads HealthKit values on-device on iPhone for display only and does not send them to Supabase, RevenueCat, Anthropic, support/admin tools, or analytics providers.

Is backup and restore planned?

Yes. Ribbonside is planning a user-controlled encrypted backup and restore feature. Until it is released and confirmed available in the app, users should continue exporting their records regularly.

What happens if there is a data breach?

Ribbonside maintains a data breach response plan and states that suspected eligible breaches will be assessed within 30 days, with notification to affected users and the OAIC where required.

Important limits