Privacy
Privacy notice
Legible Blood Pressure stores personal records in the local profile on the device where they were entered.
What stays on this device
The app can store an optional local profile, cuff details, measurement sessions and raw readings, technique flags, context tags, notes, lifestyle markers, targets, reminders, imported contextual records, and model estimates. Sensitive payloads in a saved vault are encrypted on this device with a random data key protected by the user’s password.
What is transmitted
Personal records are not uploaded for storage or analysis. The host serves the application code, fonts, icons, manifest, service worker, and updates. The statistical model, file imports, reports, and encrypted backups run on the device. The app contains no advertising or behavioral analytics SDK. A hosting provider may receive ordinary web-request data, such as IP address, time, and requested public asset, under its own infrastructure policies; health values are not placed in those URLs.
Sharing, exports, and optional support
Nothing is shared unless the user creates an export or deliberately opens another service. PDF and CSV files are readable sharing formats. A password-protected .legiblebp file is the complete restore format. Once a file is shared, its protection depends on the chosen destination and recipient. The optional Venmo support link opens Venmo; no health record is sent with that link.
Retention, backup, and deletion
Records remain in this browser until the user deletes them, erases the app data, clears browser data, or the browser or operating system removes site storage. Uninstall behavior varies. The publisher cannot recover local records, a forgotten local password, or a forgotten backup password. Users should keep tested encrypted backups in a location they control. “Erase this device” removes the Legible databases, encrypted key material, drafts, and Legible caches for this origin.
Important limitations
At-rest encryption does not protect information while the unlocked app displays it, or from a compromised device, browser, extension, or malicious future same-origin update. Private browsing may be temporary. Local-only operation does not eliminate privacy, security, medical, or legal risk. No HIPAA-compliance claim is made.