Overview
Blood Labs is built on a simple principle: your health data belongs to you. This policy explains what data the app handles, where it lives, and the choices you have. The short version — your lab results stay on your device, encrypted, and we never see them.
Data we collect
The app stores the lab results you import: marker names, values, units, reference ranges, test dates, and lab names. You can optionally add profile details such as a name, color, date of birth, and sex to improve reference-range accuracy. We do not collect your real identity, location, or contacts.
How your data is stored
All results are kept in encrypted local storage on your device. Encryption keys are protected by your device’s secure enclave. Nothing is uploaded to our servers — there is no Blood Labs cloud account, and the app works fully offline.
What we never do
- No AI models are trained on your health data.
- No data is sold, shared, or rented to third parties.
- No advertising and no cross-app tracking.
- No analytics tied to your lab values.
Cookies and website analytics
This website sets no cookies for browsing — the only exception is the blog comment system described below, which sets a cookie only if you choose to post a comment. We use a self-hosted, privacy-friendly analytics tool to count page views and see which pages people find useful. It stores nothing on your device and does not track you across other websites. It records only aggregate technical details such as the page visited, referring site, screen size, browser language, and country. This applies to the website only — the app itself sends us nothing, and your lab results are never involved.
Photos and lab reports
When you snap a photo of a lab report, recognition happens on your device. The original image and the extracted markers are stored locally and can be deleted at any time. Images are never transmitted to external services.
Family profiles
Profiles you create for family members live only on your device. Each profile’s results are stored separately and protected by the same encryption. You are responsible for obtaining consent from the people whose results you manage.
Blog comments
Comments on our blog run on Remark42, an open-source comment engine we host ourselves at comments.bloodlabs.app. There is no third-party comment service and no tracking scripts involved. Posting is anonymous: you choose a display name, and no account or email address is required.
When you post a comment, the comment server stores the text of your comment, the display name you chose, the page it belongs to, and a timestamp. Remark42 stores only a user ID, username, and avatar link, and hashes the identifier and name rather than exposing them. Like any web server, it also writes ordinary request logs.
Two cookies are set at that point, and only then: a signed login token (HttpOnly) that keeps you recognized as the author of your comment, and a token that protects the comment form against cross-site request forgery. Reading a post without commenting sets neither. There is no cross-site login, so your activity cannot be followed from here to any other site.
Remark42 can export everything it holds about you, and its “deleteme” request removes all information tied to your commenting activity. Both are available from the comment widget itself. Your lab results are never involved — the app and the comment system share no data whatsoever.
Your rights
Because your data never leaves your device, you are always in control. You can export your records, correct any value, or permanently erase all data by deleting a profile or uninstalling the app. There is no copy on our side to request or remove.
Contact
Questions about this policy or your data? privacy@bloodlabs.app