Privacy Policy
Last updated 7 September 2026
Photographs of your eyes are personal. This page says plainly what we collect, why we need it, who else touches it, and how to delete it.
What we collect
Your account. An email address and a password, which is stored only as a bcrypt hash — we cannot read it and cannot tell you what it is. If you give a name, it is used to address you in the app and nowhere else.
Your photographs. The eye images you upload, and the annotated versions the analysis produces from them.
Your results. The findings of each scan: constitution, pupil measurements, markings, pigments and the notes explaining them.
Billing details. Handled entirely by Stripe. We store your Stripe customer identifier, your plan, and how many scans you have left. We never see or store your card number.
We do not collect location, contacts, advertising identifiers or browsing history, and there is no analytics or advertising SDK in the app.
Why we need it
- The photographs, to run the analysis you asked for.
- Your results, so your history is there when you come back.
- Your email, to sign you in and to contact you about your account.
- Your plan and credit balance, to know what you have paid for.
Where the law asks for a basis: performing our contract with you for everything above, and your consent for the health-related information a scan produces, which you give by choosing to run one.
Who else sees it
The analysis is not run on our own hardware. Your eye images are sent to OpenRouter, which routes them to the model that reads them. They are sent for the purpose of the analysis and are not used to train models.
Railway hosts the application, the database and the private object storage the images live in. Stripe processes payments. If you book a session with a practitioner, Calendly receives your name and email address to schedule it and send the calendar invitation.
Nobody else. We do not sell your data, do not share it with insurers or employers, and do not use it for advertising. Our revenue is subscriptions, which is exactly why it can stay that way.
Where it is kept, and for how long
Images are held in private object storage, not on a public URL. Everything else sits in a managed PostgreSQL database. Both are encrypted in transit and at rest, and every request is scoped to your account.
Your scans stay until you remove them. Removing one takes it out of your history. If you have bought a follow-up from that reading, the analysis behind it is kept so the comparison you paid for still works, and so we can tell that a follow-up photograph is the same eye — but the scan itself stops appearing anywhere you can see it. Deleting your account is the erasure: the scans, the images and the account itself go with it, immediately and not queued.
Your rights
- See what we hold — your full history is in the app.
- Remove a single scan from your history, or delete your whole account and everything in it, from Settings.
- Ask for a copy of your data, or correction of anything wrong.
- Object to how we use it, or withdraw consent, by writing to us.
If you are in the UK or EU you can also complain to your data protection authority. We would rather you told us first.
Children
Eyeagnosis is not for under-16s. If you believe a child has created an account, write to us and we will remove it.
This is not a medical service
Iridology is a wellness practice, not a diagnostic one. Eyeagnosis is not a medical device, the results are not a diagnosis, and they are not treated as clinical records. They are yours, and they say what was observed in a photograph.
Changes
If this policy changes in a way that affects you, we will say so in the app before it takes effect rather than quietly changing the date at the top.
Contact
support@eyeagnosis.app. We answer.