Privacy policy
The short version
BiomedPortal keeps your equipment inventory on your device and nowhere else. There is no account to create, no server holding your records, and no analytics or tracking of any kind. Exactly one piece of information is ever sent anywhere: the device identifier printed on a piece of equipment, sent to a public U.S. government database to ask what that product is.
We do not collect your personal information. Not your name, not your email, not your location, not a device identifier belonging to you, and not the contents of your inventory. There is no mechanism in the app by which we could — the app has no account system and sends nothing to any server we operate. We do not operate a server.
Who this policy is from
BiomedPortal (“BiomedPortal”, “we”, “us”) publishes the BiomedPortal app for iPhone and iPad. Questions about this policy, or about privacy generally, go to privacy@biomedportal.com.
Information stored on your device
When you use BiomedPortal, the following is written to your device's own storage, inside the app's private container:
- Equipment records — the identifier you scanned or typed, its issuing agency, the product details returned by the FDA database, any make, model, serial number, unit label and location you entered yourself, and the date you added it.
- Photographs you take in the app — of equipment labels, units and accessories. Photos are resized and re-encoded when saved, which removes the camera metadata, including any location data, that the original capture carried.
- PDF manuals you import, and the maintenance facts extracted from their text.
- Small app preferences, such as whether you have loaded or removed the sample inventory.
All of this is protected by iOS file protection, meaning it is readable only while your device is unlocked. It is included in your device's own iPhone or iCloud backup if you have one — that backup is Apple's, made under Apple's terms and your settings, and we have no access to it or visibility into it.
None of this is transmitted to us. We have no way to read it, recover it, or delete it for you.
What leaves your device, and when
1. Device identifier lookups (AccessGUDID)
When you scan a barcode or type an identifier, the app sends that identifier over HTTPS to AccessGUDID, the public Global Unique Device Identification Database operated by the U.S. National Library of Medicine (NLM), part of the National Institutes of Health, on behalf of the U.S. Food and Drug Administration.
What is sent is the identifier of a manufactured product — the number printed on an autoclave or a box of burs. It describes the equipment, not you. Nothing is attached to it: no account, no name, no practice, no device identifier belonging to your phone, no location, and nothing else from your inventory.
As with any request to any website, the NLM's servers can see the originating IP address and the fact that a request was made. That is inherent to using the internet and is outside our control; the NLM's handling of it is governed by its own privacy policy, at nlm.nih.gov/privacy.html. We never see these requests, because they do not pass through any system of ours.
If you would rather make no network requests at all, use Enter identifier by hand and simply do not run the lookup, or turn off the app's network access in iOS Settings. Everything else in the app keeps working.
2. Backup files you create
Creating a backup produces a single encrypted file. The file is encrypted on your device with AES-256-GCM, using a key derived from the passphrase you choose via PBKDF2-HMAC-SHA256 with 210,000 iterations and a fresh random salt for every file. The passphrase is never stored, never transmitted, and cannot be recovered — by you or by us. If it is lost, the file cannot be opened.
Where the file goes is entirely your decision, made through the iOS share sheet: Files, a practice drive, AirDrop, email, or a cloud service you already use. Once it leaves the app it is subject to whatever terms govern the place you put it. We never receive it.
3. Nothing else
There is no other outbound network activity. No crash reporting, no telemetry, no advertising, no attribution, no remote configuration, and no third-party SDKs of any description linked into the app.
Camera
BiomedPortal asks for camera access for two purposes: reading barcodes on equipment labels, and photographing equipment. Camera frames are processed live on your device to detect barcodes and are not recorded unless you deliberately take a photo. Photos you take are saved only inside the app.
The app does not request access to your photo library, and cannot read photos you took elsewhere. If you decline camera access, everything else in the app still works — you can enter identifiers by hand.
Tracking and advertising
BiomedPortal does not track you, in the ordinary sense or in Apple's specific sense. It does not use the Advertising Identifier, does not link your activity to data from other companies' apps or websites, does not share anything with data brokers, and does not show advertising. Because of this it never presents an App Tracking Transparency prompt. Its App Store privacy label reads Data Not Collected.
Health and patient information
BiomedPortal is an equipment inventory tool. It is not a medical device, it performs no clinical function, and it is not designed to hold information about patients. It has no free-text notes field, deliberately, so there is no obvious place for such information to be typed.
Because nothing you enter is transmitted to or stored by us, we do not receive protected health information and do not act as a HIPAA business associate. If you photograph equipment in a clinical area, take the ordinary care you would with any camera: what ends up in the frame stays on your device and remains your responsibility under your own policies.
Children
BiomedPortal is a tool for managing equipment and is not directed at children. We do not knowingly collect information from anyone, including children — we do not collect information at all.
Retention and deletion
We hold nothing, so there is nothing for us to retain or delete. On your side:
- Delete an individual device, photo or manual from within the app at any time.
- About & privacy → Delete all equipment data removes every record, photo, manual and extracted fact from the device immediately and irreversibly.
- Deleting the app removes its entire container, including everything above.
None of these touch a backup file you have already saved somewhere else. Delete that yourself if you want it gone.
Your rights (GDPR, UK GDPR, CCPA/CPRA and similar laws)
These laws give you rights over personal data a company holds about you — access, correction, deletion, portability, objection, and the right not to be discriminated against for exercising them. We hold no personal data about you, so in practice:
- Access and portability — everything is already on your device and in your hands. The backup file contains a plain-JSON inventory readable in any text editor once decrypted, so your data is portable by construction.
- Deletion and correction — done in the app, instantly, without asking us.
- Sale or sharing of personal information — we do not sell or share personal information, and never have. There is nothing to opt out of.
Where any processing does occur — the AccessGUDID lookup — the lawful basis under the GDPR is legitimate interest in providing the feature you asked for by tapping Look up, and the data involved is a product identifier rather than personal data. You can send a request to privacy@biomedportal.com at any time; the honest answer will usually be that we hold no record of you to act on.
Apple's role
The app is distributed through the App Store. Apple collects information about App Store downloads, purchases and, if you have opted in, aggregated usage analytics — under Apple's privacy policy, not this one. We may see anonymous, aggregated App Store statistics from Apple; they identify nobody.
This website
biomedportal.com is a set of static pages. It sets no cookies, runs no analytics, embeds no third-party scripts, fonts or trackers, and has no forms. Your browser's request to fetch a page is handled by the hosting provider, whose server logs are the only record it produces.
Changes to this policy
If this policy changes, the new version appears here with a new “last updated” date. A change that materially reduces your privacy — for example, adding analytics or any server component — would be announced in the app's release notes as well, because it would also require changing the App Store privacy label.
Contact
Privacy questions: privacy@biomedportal.com
Everything else: support@biomedportal.com, or the
support page.