Privacy Policy
Effective date: September 16, 2026
Narrativ stores your health data on your device and nowhere else. We don't have accounts, don't track you, and don't sell data.
What Narrativ Does
Narrativ is a personal health records app that helps you organize medical documents, track health events, and prepare for doctor visits. All of your data, meaning your documents, events, notes, and settings, is stored locally on your device using Apple's SwiftData framework.
Data We Don't Collect
Narrativ does not collect, transmit, or store:
- Personal identification (no accounts, no login, no email)
- Usage analytics or behavioral tracking
- Advertising identifiers
- Location data
- Contact or social information
Device Permissions
Narrativ may request the following permissions, each requiring your explicit consent:
- Camera, to photograph documents for import into your library.
- Apple Health (Clinical Records), to import clinical data such as conditions, medications, lab results, and immunizations from Apple Health. Narrativ reads this data but never writes to Apple Health.
You can revoke these permissions at any time in iOS Settings. The app remains fully functional without them.
Health System Connections
When you connect a health system, you sign in on that system's own website with your portal credentials. Narrativ never sees or stores your portal password. The health system issues Narrativ an access credential, stored in the iOS Keychain on your device, which Narrativ uses to fetch your records and to refresh them for the period you approved. The sign-in hands off to Narrativ through a web page that only forwards you back to the app and stores nothing. Records travel directly between the health system and your phone and are stored only on your device. You can disconnect at any time in Data Sources, which removes the credential and, if you choose, the records that came from it.
AI-Powered Features
Narrativ offers optional AI features for document text extraction, health event suggestions, and consultation assistance. These features use Anthropic's Claude API and require sending portions of your health data over the internet for processing.
Proxy Mode (Default During Beta)
If you have not provided your own API key, AI requests are routed through a forwarding service operated by Narrativ on Cloudflare Workers. This service:
- Forwards your request to Anthropic's API and returns the response
- Holds each response for up to one hour so a retried request is not charged twice, then deletes it
- Does not otherwise log, store, or index any health data
- Tracks an anonymized device identifier (a one-way hash) solely for daily usage limits. This identifier cannot be linked to your identity and expires after 24 hours
- Enforces per-device and monthly usage quotas
Direct Mode (Bring Your Own Key)
If you provide your own Anthropic API key in Settings, AI requests go directly from your device to Anthropic. No data passes through Narrativ's services. Your API key is stored in the iOS Keychain on your device.
What Gets Sent
When you use AI features, the following data may be included in API requests:
- Extracted text from documents (truncated to relevant portions)
- Document images (for vision-based extraction)
- Health event summaries (for suggestions and consultations)
AI results are stored only on your device. You can disable AI features entirely and use on-device text recognition instead.
Anthropic's Data Practices
When AI features are used, your data is processed by Anthropic in accordance with their privacy policy. Anthropic does not use API inputs to train their models.
Data Storage and Security
- All app data is stored locally on your device
- No Narrativ cloud, no server-side storage. Backups you export can be saved to iCloud Drive at your choice.
- Sensitive credentials (API keys) are stored in the iOS Keychain
- Deleting the app removes all Narrativ data from your device
Third-Party Services
Narrativ does not integrate with advertising networks, analytics platforms, or data brokers. The only external service used is Anthropic's Claude API for optional AI features, as described above.
Children's Privacy
Narrativ is not directed at children under 13 and does not knowingly collect information from children.
Changes to This Policy
If this policy changes, the updated version will be posted here with a new effective date. Significant changes will be communicated through the app.
Contact
Questions about this privacy policy can be directed to: contact@narrativ.health