Data you enter
The app only collects the data needed for the work journal: account email, clinics, work day entries, working time, private revenue fields, procedure and implant settings, portfolio case details, procedure notes, photos, and the notes you provide.
Notes and photos are selected and entered by you. Patient names and notes can sync with your account. Photo files stay in protected app storage on the iPhone where you selected them and are not uploaded to the Inciary cloud. If you enter identifying information, you must have the required consent or another legal basis.
Use and storage
This data is used so you can sign in, view your statistics, manage entries, and sync settings between devices.
Product account data is stored through Supabase infrastructure. Apple processes App Store purchases, and EVL Billing Core processes subscription status and store transaction records needed to provide access, restore purchases, prevent fraud, and meet billing or legal obligations. Hosting and authentication providers may process technical request data needed to operate and secure the service.
The app uses cookies and local storage for sign-in, language, theme, performance cache, drafts, and local preview mode. These are not used for advertising.
Privacy controls
The app may collect first-party product interaction analytics and privacy-bounded diagnostic events, such as route views, feature events, dashboard usage, settings changes, non-sensitive error categories, connectivity buckets, and optional country-level usage, linked to your account only to understand usage, reliability, and improve the product. The public Inciary website may separately count anonymous page, article, and App Store link events; the stored event does not contain a user ID, IP address, cookie ID, raw referrer, or full URL. Country-level usage stores only a two-letter country code from trusted platform request headers, not GPS, city, region, postal code, or precise location. These events do not include clinic names, patient names, notes, images, image file names, raw free text, raw error messages, exact revenue values, or email addresses. The app does not use advertising SDKs, third-party analytics SDKs, or cross-app tracking.
You can delete your account in the iPhone app on the `Profile` page. This removes linked product data and clears that account's local drafts, schedules, portfolio, and photos from that iPhone. Apple purchase, subscription, fraud-prevention, and audit records may be retained only where needed for billing, security, legal, or accounting obligations. If deletion is requested outside the app, delete the app from any offline devices to remove their protected local files.
For privacy questions or data requests, use the `Help` page inside the app. Authorized support administrators may access only privacy-safe account and aggregate usage statistics when needed to operate the service, provide support, handle user-requested data actions, deletion requests, security, abuse prevention, or legal compliance. Admin support views do not show clinic names, exact work-entry details, portfolio media, raw notes, procedure lists, implant settings, or exact revenue amounts. Support access is not used for advertising or cross-app tracking.

