Skip to content

Privacy Policy

Last updated August 3, 2026 · No servers of ours, no account

Lycana ("we," "our," or "the app") is a lupus health companion application built with a privacy-first architecture. All your health data is stored locally on your device — in the iOS Keychain, a local database the system protects, and, if you use a home-screen widget, a small store the widget reads — and never transmitted to our servers, because we don't have any.

1. Data We Collect

Information You Provide

  • Name, date of birth, biological sex, and ethnicity
  • Lupus diagnosis details (date, type, organ involvement, disease activity)
  • Medications and supplements (names, dosages, schedules)
  • Lab results (entered manually or scanned from documents)
  • Healthcare providers (names, specialties, contact info)
  • Symptom logs, severity ratings, and daily health entries
  • Lifestyle information (sleep quality, stress level, activity level, sun sensitivity)
  • Personal goals for health management

Health & Fitness Data (Apple HealthKit)

With your explicit permission, Lycana reads the following from Apple Health:

  • Heart rate, resting heart rate, and heart rate variability (HRV)
  • Step count
  • Blood oxygen saturation (SpO2)
  • Skin temperature
  • Sleep analysis (duration, stages)

Lycana only reads HealthKit data. It never writes data back to Apple Health.

Coarse Location

With your permission, Lycana accesses your approximate location (city-level, ~1 km accuracy) solely for weather and UV index lookups. Your precise location is never stored or transmitted. You can provide a manual location in Settings instead.

Camera & Photo Library

With your permission, Lycana uses the camera or photo library to scan lab documents. Images are processed on-device using Apple Vision OCR. The images are not stored — only the extracted text and values are retained locally.

Microphone & Speech

With your permission, Lycana uses the microphone and on-device speech recognition to enable voice dictation for symptom notes and health entries. This is an accessibility feature for users who find typing difficult during flares. Audio is processed locally and is never recorded or transmitted.

2. How Your Data Is Stored

On-Device Keychain Storage

Your health data never reaches us. All Protected Health Information (PHI) — medications, supplements, lab results, symptom logs, diagnosis details, healthcare providers, and ML model weights — is encrypted using the iOS Keychain with the strictest access level (whenUnlockedThisDeviceOnly). This means:

  • Data is encrypted by the device's Secure Enclave
  • Data is only accessible when your device is unlocked
  • Keychain entries are stored with ThisDeviceOnly protection, so they are not carried into iCloud or iTunes backups and cannot migrate to another device
  • Records held in the app's local database are a different case: they can be included in your device's own backup unless you exclude them from it. On iPhone that is a per-app switch in your iCloud settings; on Android the backup control is device-wide, so it is not something you can turn off for Lycana alone. Those backups are managed by Apple or Google, not by us, and we cannot read them.

    One case deserves naming, because it is the least protected: a backup made to a computer with Finder or Apple Devices is not encryptedunless you tick "Encrypt local backup". In an unencrypted backup the files are stored unencrypted whatever protection they had on the phone, so a copy of your record can sit in plain form on that computer. Ticking that box encrypts it; to remove copies already made, delete them from Finder under Manage Backups
Data CategoryStorageLeaves Device?
Medications, supplements, labsKeychainNever
Symptom logs, SLEDAI scoresKeychainNever
User profile, medical historyKeychainNever
ML model weights, predictionsKeychainNever
Scanned document imagesNot retainedNever
Widget content (Luna note, flare risk)Widget store, plain textDevice backup only
Location (for weather)Cached 10 minCoordinates only*

* Approximate coordinates are sent to Apple WeatherKit solely to retrieve weather and UV data. No health information is included in these requests.

3. On-Device AI & Machine Learning

All of Lycana's intelligence runs entirely on your device. No health data, model weights, or AI interactions ever leave your iPhone.

  • Luna AI Coach— powered by Apple Foundation Models running on the device's Neural Engine. Generates personalized greetings, pattern explanations, and encouragement. Falls back to built-in templates when the on-device model is unavailable.
  • Flare Risk Prediction — custom machine learning models (logistic regression and gradient-boosted trees) that train and predict locally using your symptom, wearable, and lab data. When you provide feedback on past predictions, that feedback is kept on your device and never sent to us.
  • Lab Document OCR — Apple Vision framework processes scanned documents on-device. No images are sent to external services.
  • Speech Recognition— Apple's on-device speech framework converts voice to text locally.

4. Third-Party Services

Lycana does not sell, share, or transmit your health data to any third party. The only network requests Lycana makes are:

ServiceData SentPurpose
Apple WeatherKitLatitude, longitudeWeather and UV index for sun safety alerts
ClinicalTrials.govCondition keywordsBrowsing public clinical trial listings

No health information, personal details, or identifiers are included in any of these requests. We do not use any analytics SDKs, advertising frameworks, or tracking technologies.

Subscription and payment data. Lycana is sold as a Lycana Pro subscription, managed entirely by the App Store. We do not see, collect, or store your payment method, billing address, or Apple ID. The app verifies your subscription status on-device using Apple's StoreKit 2 framework with cryptographic (JWS) verification — no receipts are sent to any Lycana server because Lycana has no server. Apple's handling of your payment information is governed by Apple's Privacy Policy.

5. Apple HealthKit Compliance

In accordance with Apple's HealthKit guidelines:

  • HealthKit data is never used for advertising or marketing purposes
  • HealthKit data is not sold to data brokers or information resellers
  • HealthKit data is not shared with third parties without your explicit consent
  • HealthKit data is used exclusively to provide health features within the app
  • HealthKit data is only read — Lycana never writes data to Apple Health

6. Device Permissions

Lycana requests only the permissions it needs, and each is optional. You can revoke any permission at any time in iOS Settings. The app continues to function with reduced features.

PermissionWhy
HealthKitRead wearable and health data for flare risk analysis
Location (When In Use)Fetch weather and UV index for sun safety alerts
CameraScan lab documents
Photo LibraryImport lab documents from saved photos
MicrophoneVoice dictation for symptom notes
Speech RecognitionOn-device speech-to-text
NotificationsMedication reminders, UV alerts, flare warnings

7. Security

Lycana's fully on-device architecture is its strongest security feature — your data cannot be breached remotely because we never receive it; there is no server of ours to breach. Additional security measures include:

  • iOS Keychain encryption with Secure Enclave for the copies held in the Keychain — symptoms, medicines, labs, profile and model weights. Records in the app's local database, and the few lines the widget reads, are covered by the device's own file encryption instead; they do not inherit the Keychain's this-device-only protection
  • On-device ML model weights encrypted alongside health data
  • No servers of ours, no cloud storage, and no network transmission of health data
  • No user accounts — no credentials to compromise
  • All AI processing runs locally on the device's Neural Engine
  • Optional biometric authentication (Face ID / Touch ID) for sensitive operations

8. Data Retention & Deletion

Your data is stored on your device for as long as you use the app. You are in full control:

  • Delete your account— available in Health → Privacy & export → Account → Delete Account. This erases everything Lycana holds on the phone (medications, supplements, labs, symptom logs, user profile, healthcare providers, ML model weights, and all other health data) and resets the app to its initial state. What it cannot reach is a copy your device's own backup has already captured — that one goes when you remove the backup.
  • Uninstall the app — this does not reliably erase your health data. iOS keeps Keychain entries after an app is removed, and Lycana deliberately offers to restore them if you reinstall. Use Delete Account above first if you want the data gone.

Because Lycana has no servers or cloud storage of its own, there is no data of ours to delete anywhere else, and deletion inside the app takes effect immediately. The one copy it cannot reach is your device's own backup, if one includes Lycana. An iCloud or Google backup clears when you remove it through your device settings. A backup made to a computer with Finder or Apple Devices has to be deleted there, under Manage Backups — and if it was made without "Encrypt local backup" ticked, the copy sitting on that computer is in plain form, which makes it the one most worth removing.

9. HIPAA Notice

Lycana is a personal health tracking tool and is not a "covered entity" or "business associate" under the Health Insurance Portability and Accountability Act (HIPAA). While we implement strong security measures to protect your data, the app is not intended to be used as part of a HIPAA-regulated workflow.

10. Children's Privacy

Lycana is not intended for use by children under the age of 17. We do not knowingly collect personal information from children. If you believe a child has provided information through the app, please contact us so we can delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes through an in-app notice and by updating the "Last updated" date above. Your continued use of Lycana after changes constitutes acceptance of the updated policy.

12. Contact Us

If you have questions about this Privacy Policy or your data, please contact us: