Privacy Policy

SLE Handbook · Effective Date: August 24, 2026
SLE Handbook is a personal health record and preparation tool. It is not a medical device. It does not provide diagnosis, disease prediction, medication advice, or treatment recommendations.

1. About Us

SLE Handbook (the "App") is developed and operated by the Craft with love two-person team. The App is designed to help people with systemic lupus erythematosus (SLE) organize laboratory reports, clinic notes, medication records, symptom notes, and long-term lab trends.

This Privacy Policy explains what personal information we collect, why we collect it, how we process it, where it is stored, when it is shared, and how you can exercise your privacy rights.

2. What Data We Collect and Why

2.1 Data You Provide

Lab report, clinic note, and original medical-document archive images
Purpose: To extract lab item names, values, units, reference ranges, hospital names, and visit dates, or to retain the original text of medical materials such as CT, ultrasound, and pathology images with the date and hospital you enter.
Processing: The photo is uploaded to our server and, after your explicit third-party AI processing consent, sent to Volcengine for image recognition. Necessary recognized structured fields may be sent to DeepSeek for metric matching. The result is returned to the App and saved on-device after your confirmation.
Retention: For the Free plan, the temporary OCR copy is deleted after local archival. While the Support plan is active, lab-report images uploaded or stored on the device are silently retained as authenticated server copies. Membership expiry does not automatically delete them; they remain until the corresponding report or account is deleted. Full cloud backup for health records, medical-record images, and original medical-document archives remains separately opt-in. Up to three replaced backup versions are retained for no longer than 30 days for exceptional recovery and are removed when cloud backup or the account is deleted. Photos attached to daily records are not included in cloud backup.
Alternative: You may choose not to upload photos and manually enter lab values instead.
Daily check-ins, symptoms, and medication records
Purpose: To help you keep longitudinal personal health notes.
Processing: These records are stored on-device for display and export. When cloud backup is enabled, a copy is uploaded for new-device recovery. If you choose AI summary and explicitly agree to third-party AI summary processing, selected symptom records, medication records, lab values, and photo-tag text from the chosen time range are sent to DeepSeek to generate the recent-status summary and questions for the doctor. Original photos are not sent.
Retention: Until you delete the records in the App or delete your account.
System permissions and voice input
Camera / photo library: Used only when you choose to take or select lab-report, medical-record, or daily-record images.
Notifications: Used only when you enable follow-up or medication reminders.
Calendar: The current version does not write to the system calendar; follow-up reminders use local notifications only.
Microphone / Speech Recognition: Used only while you hold to speak on Today. iOS uses on-device recognition; Android uses the device's configured default speech-recognition service, which may process speech online according to device settings. The current version has no bundled offline speech model, saves only text and does not retain recordings or send audio to SLE Handbook if that service fails.
Lab values and observations
Purpose: To show lab trend charts, metric cards, and visit records inside the App.
Processing: After OCR extraction, observations confirmed by you are stored in the on-device database. A versioned copy is uploaded when cloud backup is enabled.
Retention: Until you delete the related report, delete a specific observation, or delete your account.
Historical lab-classification repair data
Purpose: After you start historical organization, the App uses OCR-structured results already saved on your device to recheck lab-item identities so older and newly added records use the same organization method.
Processing: Original lab-report images are not uploaded again and OCR is not rerun. The server checkpoints each report and performs bounded automatic retries. Trusted results are applied safely, while reports that cannot be confirmed remain unchanged. Organization changes only item identity; it never rewrites original results, units, dates, reference ranges, or report text.
Retention and deletion: Structured input and intermediate results are deleted under the task cleanup rules after closure. The server retains only technical records such as counts, safe report status, error category, provider calls, and token usage, without medical text or raw model output. Deleting the account removes the related tasks and data.
Medication list
Purpose: To support medication reminders and dosage records.
Processing: Medication records are saved to your account and used for in-app display and export.
Retention: Until you delete them manually or delete your account.

2.2 Account Data

Name and account identifier from current sign-in and legacy account compatibility
Purpose: To create your account, identify your login, and display the name you authorize the provider to supply.
Source: Current sign-in methods are Apple or email codes on iOS and email codes on Android. The current mobile app does not offer Google sign-in; the server retains its existing Google route only for legacy-client compatibility, and data for previously linked Google accounts remains protected under this policy.
Processing: Stored in our server database and linked to your health records for account functionality, security, and account deletion. We do not use this information for advertising or cross-app tracking.
Retention: While your account exists. After account deletion, raw Apple or legacy Google account identifiers and names are deleted. Only an irreversible hash identifier is retained to prevent repeated signup-credit claims.
Email address from Apple, email-code sign-in, or legacy Google sign-in
Purpose: Account identification and login across devices.
Source: Apple supplies it when you choose Apple sign-in, or you enter it for email-code sign-in. Existing accounts may also retain an email previously supplied through legacy Google sign-in. Apple may supply a private relay address.
Processing: Stored only in our server database. We do not provide it to advertisers or health-data processing providers.
Retention: While your account exists. You may delete your account at any time in "Me - Delete Account".
WeChat account identifier (deferred feature, currently unavailable)
Purpose: Account creation, login identification, and login across devices.
Source: The WeChat Open SDK remains bundled, but WeChat sign-in is disabled and the App does not initiate authorization. It may be enabled only after platform review, configuration, and verification on both platforms are complete.
Processing: If enabled, the App sends a one-time authorization code only after you tap WeChat sign-in and confirm authorization. The AppSecret, WeChat access token, and OpenID do not enter the mobile app. We do not request or retain your WeChat nickname, profile image, phone number, or email address, and we do not provide WeChat with lab reports, medical records, symptoms, medications, or other health records.
Retention: While your account exists. After account deletion, the raw OpenID is deleted; only an irreversible hash identifier is retained to prevent repeated signup-credit claims.
Quota counts and subscription state
Purpose: To enforce monthly usage limits for free users and subscription entitlements for subscribers.
Storage: Stored only on our server.
Retention: While your account exists. After account deletion, we retain only irreversible hash identifiers and necessary transaction audit records for abuse prevention, subscription restore, refund disputes, and compliance purposes.
Abuse prevention and payment audit identifiers
Purpose: To prevent repeated free or first-purchase offers after account deletion, prevent rebinding an Apple subscription to reset usage, keep Android codes single-use, and handle payment disputes.
Processing: We do not retain raw Apple / Google / WeChat / Afdian user identifiers, plaintext redemption codes, or unnecessary order content. The server stores HMAC-SHA256 identifiers, the last four code characters, and minimal order-audit fields.
Retention: These records may be retained after account deletion for the limited purposes described above. They are not used for advertising, profiling, or third-party tracking.

2.3 Automatically Collected Data

The App does not collect the following data:

The App does collect the following minimal technical data:

3. Third-party Services and Data Sharing

We share data with third parties only in the limited situations described below.

Volcengine image recognition service
Provider: Beijing Volcengine Technology Co., Ltd., a ByteDance affiliate.
Shared data: The lab report or clinic note image you upload. We do not add extra personal information to the OCR request.
Purpose: OCR image recognition, converting lab report images into structured text.
Server location: Mainland China.
Retention and protection: We require Volcengine to process the data only to complete this recognition request and for necessary security or compliance purposes, not for advertising, behavioral profiling, or model training. The provider processes or caches data for the necessary period under its service terms, privacy policy, and security requirements, and should provide protection comparable to this policy.
Provider privacy policy: https://www.volcengine.com/docs/82379/1099475
Volcengine speech recognition service
Provider: Beijing Volcengine Technology Co., Ltd., a ByteDance affiliate.
Shared data: Only historical visit audio that a user of an older version actively chooses and confirms for processing. The current version has no new recording or processing entry point.
Purpose: To create a reviewable transcript for the legacy compatibility flow, which may also separate anonymous speaker segments.
Processing: Audio is relayed through the SLE Handbook server and converted in a temporary directory. Temporary files are deleted after processing; raw audio is not retained long term.
Server location: Mainland China.
Retention and protection: We require Volcengine to process the data only to complete this speech-recognition request and for necessary security or compliance purposes, not for advertising, behavioral profiling, or model training. The provider processes or caches data for the necessary period under its service terms, privacy policy, and security requirements, and should provide protection comparable to this policy.
Provider privacy policy: https://www.volcengine.com/docs/6256/64902?lang=zh
DeepSeek metric matching and AI summary service
Provider: DeepSeek.
Shared data: 1) Necessary test names, results, units, specimen hints, report type, and hospital name used to assist lab metric classification after recognition; 2) after you choose AI summary and agree, selected symptom records, medication records, lab values, and photo-tag text from the chosen time range.
Purpose: Assisting reviewable lab metric classification or generating the recent-status summary and questions for the doctor.
When used: Lab metric classification uses AI assistance only when needed. AI summary is used only when you choose it and agree.
Retention and protection: We require DeepSeek to process the data only to complete this metric-classification or summary request and for necessary security or compliance purposes, not for advertising, behavioral profiling, or model training. The provider processes or caches data for the necessary period under its service terms, privacy policy, and security requirements, and should provide protection comparable to this policy.
Sign in with Apple
Provider: Apple Inc.
Data flow: Apple provides your authorized email address to us. We do not provide health records or lab data to Apple for Sign in with Apple.
Purpose: Account login and identification.
Apple Privacy Policy: https://www.apple.com/legal/privacy/
Sign in with Google (legacy-client compatibility only)
Provider: Google LLC.
Processing: Google sign-in and its native SDK have been removed from the current mobile app. The server retains the existing route only for legacy-client compatibility and continues to protect data for previously linked Google accounts.
Purpose: Legacy-client account compatibility and management of existing linked accounts. We do not provide Google with lab reports, medical records, symptoms, medications, or other health records.
Google Privacy Policy: https://policies.google.com/privacy
WeChat sign-in / WeChat Open SDK
Provider: Shenzhen Tencent Computer Systems Company Limited.
When used: The SDK remains bundled, but WeChat sign-in is currently disabled and the App does not initiate authorization. It may be enabled only after platform review, configuration, and verification on both platforms. If enabled, authorization starts only after you tap "Sign in with WeChat." Android checks whether WeChat is installed. On iOS, the SDK may process the device model locally and use the system pasteboard for app-to-app communication required by sign-in.
Processing: WeChat completes OAuth authorization and supplies our server with a stable OpenID. Although the authorization scope supports nickname and profile image access, our server does not call the WeChat profile API or retain those fields. We do not provide any health records to WeChat.
WeChat Open SDK Personal Information Processing Rules: Tencent rules
App Store / Apple StoreKit
Provider: Apple Inc.
Shared data: Subscription receipt and transaction status needed to verify subscription entitlement on our server.
We do not receive: Your card number, payment credentials, or detailed payment information. Payments are processed by Apple.
Afdian (membership codes for the website Android APK)
Provider: Afdian, operated by Hainan Fengze Technology Co., Ltd.
When used: Only when a website Android user chooses to buy a non-renewing membership code on Afdian.
We retain: Order number, SKU, amount, status, and HMAC-SHA256 Afdian user identifiers for delivery verification, idempotency, and refund support.
Not provided: We do not send lab reports, medical records, symptoms, medications, or other health data to Afdian.
Operating-system speech recognition
Provider: Apple Inc. or the system speech-recognition provider configured on the Android device.
When used: For Today voice input. iOS uses on-device recognition. Android uses the device's configured default service.
Processing: The Android system service may process speech online according to device settings. The current version has no bundled offline speech model. The app saves text only and never sends voice audio to its own cloud-recognition endpoint when system recognition fails.
Not provided: Lab reports, medical records, symptoms, medications, and other health records are not provided as additional context to the system service.
Alibaba Cloud infrastructure
Provider: Alibaba Cloud Computing Co., Ltd.
Shared data: Our backend server, database, and file storage are hosted in Alibaba Cloud's Beijing region.
Role: Alibaba Cloud provides infrastructure hosting and does not independently read or process your health records for its own purposes.

We do not:

4. Storage and Security

4.1 Storage Location

4.2 Security Measures

4.3 Data Breach Notification

If a data security incident may affect your rights or interests, we will notify affected users within 72 hours by in-app notice or email and report to the relevant regulator where required by law.

5. Your Rights

Subject to the Personal Information Protection Law of the People's Republic of China (PIPL) and other applicable laws, you may have the following rights:

6. Children and Minors

The App is primarily intended for adult SLE patients. If a minor under 18 uses the App, the minor should do so under the guidance and consent of a parent or legal guardian. We do not intentionally collect data that specifically identifies a user as a minor.

7. Changes to This Privacy Policy

We may update this Privacy Policy when laws, regulations, or product features change. When we update this policy:

If you do not agree to the updated policy, you may stop using the App and delete your account.

8. Contact Us

If you have questions, complaints, or requests regarding this Privacy Policy or your personal information rights, please contact us:

We will respond within 1 business day after receiving your request.