OrthoLog
FeaturesAI disclosureLegalInstallOpen app
Privacy

Privacy notice

A full account of local storage, optional transmissions, purposes, roles, retention, security, transfers and individual rights.

Version 2.1 · Last reviewed 9 August 2026

Core design: RQAI does not operate a central OrthoLog patient database. A properly encrypted vault is user-controlled, while optional services receive data only when the user invokes them.

1. Scope and layered notice

This Privacy Notice covers the OrthoLog marketing website, PWA, native packages and support contact. It describes the current release as of the review date. Just-in-time notices in the app explain a transmission at the point of use; this full notice supplies the wider detail.

It does not replace a hospital, employer, training body, Google or AI provider privacy notice. Where you use OrthoLog in a professional setting, more than one notice may apply.

2. Who is responsible for personal data

RQAI is the independent project name used for the website and product. For limited data actually received through website hosting or support correspondence, the service operator determines the relevant purposes and can be contacted at hello@rqai.co.uk.

RQAI does not operate a central OrthoLog patient database and cannot read a properly encrypted user vault. For case content entered by a professional, the controller may be the user, employer, hospital or another organisation depending on who determines why and how it is processed. The relevant organisation must make and document that determination. An AI or cloud provider may act as processor, independent controller or both for different data under its contract. This notice cannot decide those roles for third parties.

3. Categories and sources of information

Information can come from the website visitor, app user, imported spreadsheet, selected image or PDF, connected Google account, chosen AI provider, hosting/security infrastructure or support correspondence.

  • Website technical data: IP address, request time, URL, response status, user agent, network and security events.
  • Acceptance data: legal version and acceptance timestamp stored on the device.
  • Profile and settings: optional display name, hospitals, consultants, favourites, privacy, lock, sync and AI settings.
  • Case data: operation details, optional identifiers, age/DOB, supervision, consultant and status.
  • Learning data: reflections, feedback, learning points, PBA-style entries, links and follow-up notes.
  • Files: source images, PDFs, spreadsheet rows and attachments.
  • Credentials: an AI API key encrypted in the local vault; temporary Google access tokens managed for the active session.
  • Support data: sender identity, contact details, message, technical context and attachments voluntarily supplied.

4. Data not requested

OrthoLog does not require a patient name and does not provide a patient-name field. The website does not require an OrthoLog account, payment card, advertising profile or marketing subscription. Do not place patient names, contact details, facial images, full clinical records, biometric identifiers, genetic information, payment data or passwords into free-text fields, attachments or support messages.

5. Website delivery and security logs

The site is delivered through hosting, content-delivery and security infrastructure. Those services necessarily process technical request data to route traffic, prevent abuse, diagnose faults and maintain security. RQAI does not intentionally use behavioural advertising, cross-site tracking or a marketing analytics profile in the current site.

The precise hosting-log retention and location are controlled by the hosting provider and operational settings. Technical logs should not contain vault contents, which remain client-side, but may reveal that a network address accessed OrthoLog at a particular time.

6. Local storage and the encrypted vault

The current web app stores the encrypted vault envelope in IndexedDB. Legal acceptance, last-sync information and limited app state may be stored in local storage. Native webview storage uses the platform’s local application storage. The vault can include case content, settings and attachments chosen by the user.

The vault is encrypted before storage. Data is temporarily decrypted in device memory while unlocked so the app can display and edit it. Operating-system paging, screenshots, accessibility services, clipboard tools, browser extensions or malware may access visible or in-memory data despite at-rest encryption.

7. Manual entry and local import

Manual entry and Excel/CSV parsing are performed on the device in the current release. These workflows do not require an AI provider. Selecting a local workflow does not by itself make the processing lawful; the responsible controller must still have authority, transparency and security arrangements.

8. Optional AI transmissions

When a user invokes AI extraction and confirms the disclosure, the selected image or PDF page, structured extraction instruction and API credential are sent directly to the chosen provider. Provider output returns directly to the app as draft structured text. OrthoLog does not intentionally proxy this content through an RQAI server.

An instruction to omit patient names cannot remove identifiers from the source image before transmission and cannot guarantee that output omits them. Users should crop or irreversibly redact before transmission where authorised, and should not transmit at all where approval is absent.

9. AI provider retention and account controls

Retention and training treatment depend on provider, endpoint, paid/free tier, organisation settings and feature. As of this review, OpenAI states API data is not used for training by default unless opted in, with endpoint-specific retention and approved zero-data-retention controls; Gemini documents different rules for paid services, abuse monitoring and optional zero-data-retention approval; Groq states normal inference is not retained by default except limited reliability/abuse cases and offers data controls. These rules may change.

The user must inspect current provider terms and data controls before each approved deployment. Enabling an OrthoLog adapter is not a data-processing agreement, transfer mechanism or confirmation that the account is suitable for health information.

10. Optional Google Drive processing

Google Identity Services is used for optional sign-in and authorisation. OrthoLog requests the drive.file scope, intended to limit access to files created or opened by the app. The app can create, find, read and update its managed encrypted vault file. It does not request the user’s Google password and does not intentionally store the Google email address in the vault.

The encrypted file can contain case data and attachments but excludes the configured AI API key. Google receives account, authorisation, IP, device and file-operation metadata under its own terms. Use only an account and storage service approved for the intended information.

11. Exports, downloads, clipboard and sharing

Exports occur at the user’s request. A structured case CSV may include optional MRN/local reference and DOB when entered. The learning portfolio omits MRN, DOB and images but may still contain indirectly identifying detail. The encrypted .ologbook backup contains the vault ciphertext but not the AI API key.

Downloaded, copied, printed, emailed or uploaded information is controlled by the destination and is no longer protected solely by the OrthoLog vault. The user must apply approved encryption, access control, retention and deletion.

12. Purposes of limited RQAI processing

Where RQAI actually receives personal data, the purposes are to deliver and secure the website; diagnose faults and abuse; provide requested support; maintain legal, security and dispute records; and improve the product using non-confidential feedback. RQAI does not intend to use vault contents for advertising, sell them, build a patient profile or train an RQAI model.

13. Lawful bases and special-category conditions

For necessary website delivery and security, the likely basis is legitimate interests in operating and protecting a free service, balanced against limited technical impact. Support processing may be necessary to respond to a request, take steps requested by the sender, pursue legitimate interests or comply with law depending on context. The exact basis can vary with the facts.

RQAI does not provide the Article 6 basis or Article 9 condition for patient information placed in a user-controlled vault or sent to a provider. The relevant controller must determine and document them. Consent to OrthoLog’s Terms is contractual acceptance and is not presented as a patient’s data-protection consent.

14. Data minimisation and pseudonymisation

Identifiers are optional. Users should record the minimum necessary for the documented purpose, prefer a local reference, avoid patient names and remove information when no longer needed. Pseudonymised information remains personal data where re-identification is reasonably possible or the key exists. Encryption and masking are safeguards, not anonymisation guarantees.

15. Recipients and categories of recipient

Depending on user choices, recipients may include the website hosting/security provider; the user’s email provider and RQAI’s email provider for support; Google for authentication and Drive; Gemini, Groq or OpenAI for AI requests; the operating-system or browser vendor; and any person or system to whom the user exports or shares data. RQAI does not broker or sell personal data.

16. International transfers

Hosting, support, Google and AI providers may process information outside the UK or EEA. A transfer can occur by sending data or making it accessible to an overseas organisation. Pseudonymised data may still be subject to transfer rules.

The controller initiating a restricted transfer must map the flow and use an applicable adequacy regulation, appropriate safeguard with the required transfer risk assessment, or a valid exception. Selecting a provider or ticking the app confirmation does not complete that work. If no valid transfer route exists, do not transmit the information.

17. Retention

  • Local vault: until the user deletes items, erases local data, clears storage or uninstalls; operating-system backups may persist separately.
  • Google Drive: until the user deletes the managed file or Google applies its account/retention process.
  • AI content: according to the provider, endpoint, account tier and configured controls at request time.
  • Acceptance record: until local storage is cleared or replaced by a later version.
  • Technical logs: according to proportionate operational, security and provider retention.
  • Support correspondence: for as long as reasonably needed to answer, secure, evidence or resolve the matter, then deleted or archived according to legal need.

The relevant controller must set and enforce a retention schedule for professional and patient-related content.

18. Security safeguards and residual risk

The current vault uses AES-256-GCM, PBKDF2-SHA-256 with 600,000 iterations, per-vault cryptographic values, auto-lock, optional masking and encrypted cloud/backup payloads. The API key is excluded from Drive and backup payloads. Site transport uses HTTPS in production.

No security control is absolute. Risk remains from weak or reused passphrases, compromised devices, malicious extensions, unlocked screens, screenshots, clipboard history, source photos, insecure exports, supply-chain compromise, provider processing, account takeover and user error.

19. Personal-data incidents

If a device, image, export, credential, vault or provider account is lost, accessed or disclosed without authority, stop further sync or transmission where safe, preserve necessary evidence, rotate credentials, notify the relevant organisation and follow its incident process immediately. The responsible controller must assess regulatory and individual notification duties within applicable deadlines.

Contact RQAI only for a suspected defect in OrthoLog, and do not include patient data in the report. RQAI cannot investigate content inside an encrypted vault.

20. Individual rights

Rights may include access, rectification, erasure, restriction, objection, portability and rights concerning automated decisions, subject to applicable conditions and exemptions. RQAI cannot search, retrieve, correct or export information held only inside a user-controlled encrypted vault. The app provides local view, edit, export and delete tools.

Requests concerning patient data used under an employer or hospital’s authority should go to that organisation. Requests about information actually held by RQAI may be sent to hello@rqai.co.uk; identity and scope may need to be verified. Never provide a vault passphrase to prove identity.

21. Automated decision-making and profiling

OrthoLog is not intended to make decisions based solely on automated processing that have legal or similarly significant effects. AI extracts draft text only. Descriptive statistics summarise user-entered cases. The app does not create a patient risk score, competence score, employment recommendation or clinical recommendation.

22. Cookies, local storage and tracking choices

The current site does not intentionally set advertising or behavioural analytics cookies. Essential browser storage supports the encrypted vault, legal acceptance, app operation and optional synchronisation. Blocking or clearing storage can prevent the app working or permanently remove local data. “Do Not Track” does not change the current behaviour because behavioural tracking is not intentionally used.

23. Children and vulnerable people

OrthoLog is not directed to children and must not be used by a child. A professional must not use the app to make decisions about a child or vulnerable person. A case involving such a person can be especially identifying; the same authority, minimisation and confidentiality rules apply, with any additional legal safeguards.

24. Changes to this notice

The notice will be reviewed when data flows, providers, purposes or law materially change. A new version or review date will be published and material changes may require renewed in-app acceptance. Historic text may be retained for accountability.

25. Questions and complaints

Privacy questions about RQAI-held information may be sent to hello@rqai.co.uk. Questions about professional case processing should normally go to the relevant organisation’s data protection officer or information-governance team. UK individuals may complain to the Information Commissioner’s Office; EU/EEA individuals may contact the competent supervisory authority. You do not have to contact RQAI before exercising a statutory right.

OrthoLog

A personal surgical logbook for recording operative experience, reflections and learning.

InformationLegal overviewPrivacy noticeTerms of useAI transparencyData and securityInstall and downloads
Contacthello@rqai.co.ukRQAI website
© 2026 RQAILast legal review: 9 August 2026