Privacy Policy
SLE Handbook · Effective Date: August 24, 2026
SLE Handbook is a personal health record and preparation tool. It is not a medical device. It does not provide diagnosis, disease prediction, medication advice, or treatment recommendations.
1. About Us
SLE Handbook (the "App") is developed and operated by the Craft with love two-person team. The App is designed to help people with systemic lupus erythematosus (SLE) organize laboratory reports, clinic notes, medication records, symptom notes, and long-term lab trends.
This Privacy Policy explains what personal information we collect, why we collect it, how we process it, where it is stored, when it is shared, and how you can exercise your privacy rights.
2. What Data We Collect and Why
2.1 Data You Provide
Lab report, clinic note, and original medical-document archive images
Purpose: To extract lab item names, values, units, reference ranges, hospital names, and visit dates, or to retain the original text of medical materials such as CT, ultrasound, and pathology images with the date and hospital you enter.
Processing: The photo is uploaded to our server and, after your explicit third-party AI processing consent, sent to Volcengine for image recognition. Necessary recognized structured fields may be sent to DeepSeek for metric matching. The result is returned to the App and saved on-device after your confirmation.
Retention: For the Free plan, the temporary OCR copy is deleted after local archival. While the Support plan is active, lab-report images uploaded or stored on the device are silently retained as authenticated server copies. Membership expiry does not automatically delete them; they remain until the corresponding report or account is deleted. Full cloud backup for health records, medical-record images, and original medical-document archives remains separately opt-in. Up to three replaced backup versions are retained for no longer than 30 days for exceptional recovery and are removed when cloud backup or the account is deleted. Photos attached to daily records are not included in cloud backup.
Alternative: You may choose not to upload photos and manually enter lab values instead.
Daily check-ins, symptoms, and medication records
Purpose: To help you keep longitudinal personal health notes.
Processing: These records are stored on-device for display and export. When cloud backup is enabled, a copy is uploaded for new-device recovery. If you choose AI summary and explicitly agree to third-party AI summary processing, selected symptom records, medication records, lab values, and photo-tag text from the chosen time range are sent to DeepSeek to generate the recent-status summary and questions for the doctor. Original photos are not sent.
Retention: Until you delete the records in the App or delete your account.
System permissions and voice input
Camera / photo library: Used only when you choose to take or select lab-report, medical-record, or daily-record images.
Notifications: Used only when you enable follow-up or medication reminders.
Calendar: The current version does not write to the system calendar; follow-up reminders use local notifications only.
Microphone / Speech Recognition: Used only while you hold to speak on Today. iOS uses on-device recognition; Android uses the device's configured default speech-recognition service, which may process speech online according to device settings. The current version has no bundled offline speech model, saves only text and does not retain recordings or send audio to SLE Handbook if that service fails.
Lab values and observations
Purpose: To show lab trend charts, metric cards, and visit records inside the App.
Processing: After OCR extraction, observations confirmed by you are stored in the on-device database. A versioned copy is uploaded when cloud backup is enabled.
Retention: Until you delete the related report, delete a specific observation, or delete your account.
Historical lab-classification repair data
Purpose: After you start historical organization, the App uses OCR-structured results already saved on your device to recheck lab-item identities so older and newly added records use the same organization method.
Processing: Original lab-report images are not uploaded again and OCR is not rerun. The server checkpoints each report and performs bounded automatic retries. Trusted results are applied safely, while reports that cannot be confirmed remain unchanged. Organization changes only item identity; it never rewrites original results, units, dates, reference ranges, or report text.
Retention and deletion: Structured input and intermediate results are deleted under the task cleanup rules after closure. The server retains only technical records such as counts, safe report status, error category, provider calls, and token usage, without medical text or raw model output. Deleting the account removes the related tasks and data.
Medication list
Purpose: To support medication reminders and dosage records.
Processing: Medication records are saved to your account and used for in-app display and export.
Retention: Until you delete them manually or delete your account.
2.2 Account Data
Name and account identifier from current sign-in and legacy account compatibility
Purpose: To create your account, identify your login, and display the name you authorize the provider to supply.
Source: Current sign-in methods are Apple or email codes on iOS and email codes on Android. The current mobile app does not offer Google sign-in; the server retains its existing Google route only for legacy-client compatibility, and data for previously linked Google accounts remains protected under this policy.
Processing: Stored in our server database and linked to your health records for account functionality, security, and account deletion. We do not use this information for advertising or cross-app tracking.
Retention: While your account exists. After account deletion, raw Apple or legacy Google account identifiers and names are deleted. Only an irreversible hash identifier is retained to prevent repeated signup-credit claims.
Email address from Apple, email-code sign-in, or legacy Google sign-in
Purpose: Account identification and login across devices.
Source: Apple supplies it when you choose Apple sign-in, or you enter it for email-code sign-in. Existing accounts may also retain an email previously supplied through legacy Google sign-in. Apple may supply a private relay address.
Processing: Stored only in our server database. We do not provide it to advertisers or health-data processing providers.
Retention: While your account exists. You may delete your account at any time in "Me - Delete Account".
WeChat account identifier (deferred feature, currently unavailable)
Purpose: Account creation, login identification, and login across devices.
Source: The WeChat Open SDK remains bundled, but WeChat sign-in is disabled and the App does not initiate authorization. It may be enabled only after platform review, configuration, and verification on both platforms are complete.
Processing: If enabled, the App sends a one-time authorization code only after you tap WeChat sign-in and confirm authorization. The AppSecret, WeChat access token, and OpenID do not enter the mobile app. We do not request or retain your WeChat nickname, profile image, phone number, or email address, and we do not provide WeChat with lab reports, medical records, symptoms, medications, or other health records.
Retention: While your account exists. After account deletion, the raw OpenID is deleted; only an irreversible hash identifier is retained to prevent repeated signup-credit claims.
Quota counts and subscription state
Purpose: To enforce monthly usage limits for free users and subscription entitlements for subscribers.
Storage: Stored only on our server.
Retention: While your account exists. After account deletion, we retain only irreversible hash identifiers and necessary transaction audit records for abuse prevention, subscription restore, refund disputes, and compliance purposes.
Abuse prevention and payment audit identifiers
Purpose: To prevent repeated free or first-purchase offers after account deletion, prevent rebinding an Apple subscription to reset usage, keep Android codes single-use, and handle payment disputes.
Processing: We do not retain raw Apple / Google / WeChat / Afdian user identifiers, plaintext redemption codes, or unnecessary order content. The server stores HMAC-SHA256 identifiers, the last four code characters, and minimal order-audit fields.
Retention: These records may be retained after account deletion for the limited purposes described above. They are not used for advertising, profiling, or third-party tracking.
2.3 Automatically Collected Data
The App does not collect the following data:
- GPS or precise-location access, or location data used for advertising, profiling, or cross-app tracking
- Contacts
- Photo library content other than the photo you choose to upload
- Data for cross-app tracking
- Data for behavioral advertising or user profiling
- Data through third-party advertising SDKs
The App does collect the following minimal technical data:
- IP address: used only for API routing and rate-limiting abuse prevention. It is not long-term associated with your identity.
- Legacy Google sign-in IP address: Google may use it only when a legacy client starts Google sign-in to prevent fraud and estimate coarse location. The current mobile app does not start this flow.
- Device model and operating system version: used for troubleshooting. These may briefly appear in server logs, which are retained for 7 days.
3. Third-party Services and Data Sharing
We share data with third parties only in the limited situations described below.
Volcengine image recognition service
Provider: Beijing Volcengine Technology Co., Ltd., a ByteDance affiliate.
Shared data: The lab report or clinic note image you upload. We do not add extra personal information to the OCR request.
Purpose: OCR image recognition, converting lab report images into structured text.
Server location: Mainland China.
Retention and protection: We require Volcengine to process the data only to complete this recognition request and for necessary security or compliance purposes, not for advertising, behavioral profiling, or model training. The provider processes or caches data for the necessary period under its service terms, privacy policy, and security requirements, and should provide protection comparable to this policy.
Provider privacy policy: https://www.volcengine.com/docs/82379/1099475
Volcengine speech recognition service
Provider: Beijing Volcengine Technology Co., Ltd., a ByteDance affiliate.
Shared data: Only historical visit audio that a user of an older version actively chooses and confirms for processing. The current version has no new recording or processing entry point.
Purpose: To create a reviewable transcript for the legacy compatibility flow, which may also separate anonymous speaker segments.
Processing: Audio is relayed through the SLE Handbook server and converted in a temporary directory. Temporary files are deleted after processing; raw audio is not retained long term.
Server location: Mainland China.
Retention and protection: We require Volcengine to process the data only to complete this speech-recognition request and for necessary security or compliance purposes, not for advertising, behavioral profiling, or model training. The provider processes or caches data for the necessary period under its service terms, privacy policy, and security requirements, and should provide protection comparable to this policy.
Provider privacy policy: https://www.volcengine.com/docs/6256/64902?lang=zh
DeepSeek metric matching and AI summary service
Provider: DeepSeek.
Shared data: 1) Necessary test names, results, units, specimen hints, report type, and hospital name used to assist lab metric classification after recognition; 2) after you choose AI summary and agree, selected symptom records, medication records, lab values, and photo-tag text from the chosen time range.
Purpose: Assisting reviewable lab metric classification or generating the recent-status summary and questions for the doctor.
When used: Lab metric classification uses AI assistance only when needed. AI summary is used only when you choose it and agree.
Retention and protection: We require DeepSeek to process the data only to complete this metric-classification or summary request and for necessary security or compliance purposes, not for advertising, behavioral profiling, or model training. The provider processes or caches data for the necessary period under its service terms, privacy policy, and security requirements, and should provide protection comparable to this policy.
Sign in with Apple
Provider: Apple Inc.
Data flow: Apple provides your authorized email address to us. We do not provide health records or lab data to Apple for Sign in with Apple.
Purpose: Account login and identification.
Apple Privacy Policy: https://www.apple.com/legal/privacy/
Sign in with Google (legacy-client compatibility only)
Provider: Google LLC.
Processing: Google sign-in and its native SDK have been removed from the current mobile app. The server retains the existing route only for legacy-client compatibility and continues to protect data for previously linked Google accounts.
Purpose: Legacy-client account compatibility and management of existing linked accounts. We do not provide Google with lab reports, medical records, symptoms, medications, or other health records.
Google Privacy Policy: https://policies.google.com/privacy
WeChat sign-in / WeChat Open SDK
Provider: Shenzhen Tencent Computer Systems Company Limited.
When used: The SDK remains bundled, but WeChat sign-in is currently disabled and the App does not initiate authorization. It may be enabled only after platform review, configuration, and verification on both platforms. If enabled, authorization starts only after you tap "Sign in with WeChat." Android checks whether WeChat is installed. On iOS, the SDK may process the device model locally and use the system pasteboard for app-to-app communication required by sign-in.
Processing: WeChat completes OAuth authorization and supplies our server with a stable OpenID. Although the authorization scope supports nickname and profile image access, our server does not call the WeChat profile API or retain those fields. We do not provide any health records to WeChat.
WeChat Open SDK Personal Information Processing Rules: Tencent rules
App Store / Apple StoreKit
Provider: Apple Inc.
Shared data: Subscription receipt and transaction status needed to verify subscription entitlement on our server.
We do not receive: Your card number, payment credentials, or detailed payment information. Payments are processed by Apple.
Afdian (membership codes for the website Android APK)
Provider: Afdian, operated by Hainan Fengze Technology Co., Ltd.
When used: Only when a website Android user chooses to buy a non-renewing membership code on Afdian.
We retain: Order number, SKU, amount, status, and HMAC-SHA256 Afdian user identifiers for delivery verification, idempotency, and refund support.
Not provided: We do not send lab reports, medical records, symptoms, medications, or other health data to Afdian.
Operating-system speech recognition
Provider: Apple Inc. or the system speech-recognition provider configured on the Android device.
When used: For Today voice input. iOS uses on-device recognition. Android uses the device's configured default service.
Processing: The Android system service may process speech online according to device settings. The current version has no bundled offline speech model. The app saves text only and never sends voice audio to its own cloud-recognition endpoint when system recognition fails.
Not provided: Lab reports, medical records, symptoms, medications, and other health records are not provided as additional context to the system service.
Alibaba Cloud infrastructure
Provider: Alibaba Cloud Computing Co., Ltd.
Shared data: Our backend server, database, and file storage are hosted in Alibaba Cloud's Beijing region.
Role: Alibaba Cloud provides infrastructure hosting and does not independently read or process your health records for its own purposes.
We do not:
- Sell your health data to any third party
- Use your health data for advertising or behavioral profiling
- Use your health data to train any machine learning model, including our own models
- Share your data with organizations other than the providers listed above unless you explicitly consent or applicable law requires it
4. Storage and Security
4.1 Storage Location
- Account health records: lab values, symptoms, medication records, and observations are stored on-device by default. When cloud backup is enabled, a copy is stored in Alibaba Cloud's Beijing region for account recovery.
- Server data: account information and quota records are stored in a PostgreSQL database hosted in Alibaba Cloud's Beijing region.
- OCR images: Free-plan temporary copies are deleted after local archival. Support-plan lab-report image copies are stored in Alibaba Cloud's Beijing region until the corresponding report or account is deleted. Separately enabled full cloud-backup copies remain until the backup or account is deleted.
4.2 Security Measures
- Account authentication uses JWT and refresh-token rotation.
- Original images are never public. Retained member lab-report images and cloud-backup images are accessible only to the authenticated account owner.
- OCR provider calls are made only from our server. OCR API keys are never included in the mobile app.
- Server logs do not record raw lab report contents, patient names, lab values, or other sensitive medical content.
- All current TestFlight and production builds connect to our API through the filed HTTPS domain
api.craftwithlove.cloud.
4.3 Data Breach Notification
If a data security incident may affect your rights or interests, we will notify affected users within 72 hours by in-app notice or email and report to the relevant regulator where required by law.
5. Your Rights
Subject to the Personal Information Protection Law of the People's Republic of China (PIPL) and other applicable laws, you may have the following rights:
- Access and export: App data can be exported through the in-app export feature as a PDF or local JSON file.
- Correction: Data in the App can be edited or re-entered by you.
- Deletion: You can delete individual records in the App. You can delete your server account and server-side records through "Me - Delete Account". Account deletion takes effect immediately and cannot be restored.
- Withdraw sign-in authorization: You can revoke Sign in with Apple authorization in iOS Settings. If your account was linked through a legacy Google client or a previously enabled WeChat login, you may also revoke access in that provider's authorization settings.
- Restrict processing: If you do not use OCR uploads, our server will not receive your lab report photos.
- Complaint: If you have concerns about our data processing, you may contact us using the email below. You may also file a complaint with the competent regulator in your jurisdiction.
6. Children and Minors
The App is primarily intended for adult SLE patients. If a minor under 18 uses the App, the minor should do so under the guidance and consent of a parent or legal guardian. We do not intentionally collect data that specifically identifies a user as a minor.
7. Changes to This Privacy Policy
We may update this Privacy Policy when laws, regulations, or product features change. When we update this policy:
- The effective date at the top of this page will be updated.
- Material changes will be shown in the App and may require you to review the updated policy.
If you do not agree to the updated policy, you may stop using the App and delete your account.
8. Contact Us
If you have questions, complaints, or requests regarding this Privacy Policy or your personal information rights, please contact us:
We will respond within 1 business day after receiving your request.