Privacy Policy

VaporChart Home

Last updated: July 15, 2026

Overview

VaporChart stores case records and clinical chart data in the app's local storage. The app has no account system, cloud chart sync, advertising, or analytics. An optional monitor-photo extraction feature can transmit a photo only when a deploying administrator has separately configured a cloud extractor and the user initiates extraction.

Data We Handle

Optional Cloud Photo Extraction

Cloud extraction is off and unavailable unless a deploying administrator explicitly enables it and supplies an endpoint and access credential. When configured, the app shows a disclosure and requires the user to initiate the request. The selected image is then sent over an encrypted network connection to that endpoint.

The reference extraction service uses Cloudflare infrastructure as a request proxy and OpenAI's API for image processing. A deploying organization may configure a different approved endpoint. Service-side retention, access, and processing terms depend on the actual deployment, service plan, and contracts. A request setting that disables API response storage is not by itself a guarantee of zero retention or regulatory compliance.

Camera and Photo Library

VaporChart requests camera or photo-library access only when you choose a related feature. Selecting or taking a photo does not add extracted values to a chart automatically; the user reviews, edits, verifies, and confirms them first.

Photo Retention

Monitor photos are not retained after review by default. A user may opt to keep them locally with charted readings. Queue-owned photos may remain locally while a user waits to retry an interrupted extraction. Cancelled, rejected, and discarded queue photos are deleted by the app, and retained monitor photos are excluded from app backup.

Data Security

Locally saved monitor-photo files use iOS file protection and are excluded from app backup. Other local app data relies on iOS and the device's security controls. Use a managed device, enable a strong device passcode, install security updates, and follow your organization's mobile-device policies.

Clinical and Regulatory Responsibility

VaporChart does not represent or certify that the app, an extraction deployment, or a user's workflow is HIPAA compliant. A healthcare organization must perform its own privacy and security review, determine whether required agreements are in place, configure eligible services, and establish appropriate access, retention, export, and incident-response policies before using VaporChart with protected health information.

Data Deletion

The app provides controls for deleting local case records and monitor photos, subject to any in-app trash or recovery period shown to the user. Uninstalling the app removes its active local container from the device, subject to Apple platform behavior and any device backups controlled by the user or organization. Contact your deploying organization about deletion from any separately configured external service.

Exports and Sharing

When a user exports or shares a chart, the recipient, destination app, and storage location are selected outside VaporChart's local chart store. Users are responsible for choosing an authorized destination and protecting the exported record.

Children's Privacy

VaporChart is intended for use by licensed healthcare providers and is not directed at children under 13.

Changes to This Policy

We may update this privacy policy from time to time. Changes will be posted on this page with an updated revision date.

Contact

If you have questions about this privacy policy, contact us at [email protected].