Medical disclaimer: Uralo is a personal tracking app for gout and uric acid. It is not a medical device, and it does not diagnose, treat, or provide medical advice. It never recommends or adjusts medication, and it never interprets a lab value as a diagnosis. Any pattern detection, correlation insight, urate-load score, or risk indication in the app is informational only, based on your own self-reported logs. Always consult a qualified clinician about your health, your medications, and your personal uric acid target.
Uralo is designed around a simple principle: your health data belongs on your device, not on our servers. Uralo has no user accounts and no server-side database of your health information. All lab results, flare episodes, meals and drinks, medication logs, and daily check-ins are stored locally on your device using Apple's SwiftData framework. We do not have a copy of this data, and we cannot see it unless you explicitly choose to share an anonymized snapshot with our AI features (see below).
Our backend is a stateless AI proxy. When you opt in to AI features, the specific data needed for that request is sent to our server, forwarded to our AI provider, and the response is returned to your device. Requests are held in an in-process cache for up to 24 hours purely to avoid duplicate AI calls, and that cache is wiped whenever the server restarts. We do not maintain a database of your requests or their contents.
The following categories of health data are collected and stored exclusively on your device, and are never transmitted to our servers unless you have opted in to AI features (in which case only the data needed for that specific request is sent, as described below):
Uralo includes several AI-assisted features: intake extraction from a photo or description, lab-report photo reading, narrative insights, the Weekly Digest, and the AI section of the Doctor Report. These features are off by default. The first time you use any of them, Uralo shows a plain-language consent prompt explaining exactly what will be sent. You must explicitly consent before any data leaves your device for AI processing, and you can revoke this consent at any time in Settings — doing so immediately stops all AI surfaces from making network calls, and each falls back to its offline behavior.
When AI consent is granted, only the following data is sent, and only for the specific feature you are using:
We never send your name or account identifiers (Uralo has no accounts), your free-text notes, or any photo besides the one you are actively logging. AI processing for these features is performed by OpenAI (model: gpt-4o-mini) via our backend proxy. Nothing you send is stored server-side beyond the short-lived, in-memory cache described above — there is no database of your AI requests.
With your permission, Uralo may read data such as weight and water intake from Apple HealthKit. This data is used only to pre-fill your daily check-ins inside the app. It is never transmitted to our servers.
Meal photos you capture or attach are stored on your device. A photo is only ever sent off-device if you have granted AI consent and you use the intake-extraction or lab-report-reading feature, in which case the photo is sent to our AI proxy as described above and not stored server-side.
Uralo uses Firebase Analytics and the Meta (Facebook) SDK to understand product usage, measure funnels, and (with your permission) attribute installs. This includes your device identifier (IDFA), and Uralo requests App Tracking Transparency (ATT) permission before this identifier is used for tracking. If you decline the ATT prompt, your device is not tracked for advertising purposes. Analytics data does not include your health data, photos, lab values, or any personally identifying information beyond the device identifier.
We may disclose information if required by law, court order, or government request, or to prevent fraud or protect the security of our service. Because we do not store your health data server-side, there is generally nothing for us to disclose beyond the limited analytics and transient AI-proxy data described above.
Because your health data lives entirely on your device and we keep no server-side copy, you already have full access to it inside the app, and you can correct or delete any entry directly in Uralo. Deleting the app removes all locally stored health data. If you have used an AI feature, that specific request may still exist in our transient cache for up to 24 hours before it is automatically discarded; you do not need to contact us for this to happen, but you may email us with questions at [email protected].
You can disable AI features at any time in Settings. This immediately stops Uralo from sending any data to our AI proxy.
You can decline the App Tracking Transparency prompt to prevent your device identifier from being used for tracking. iOS lets you change this decision later in Settings → Privacy & Security → Tracking.
Uralo is operated in the United States. Any data you send via an opted-in AI feature is processed in the US. If you are located outside the US, by using Uralo's AI features you consent to the transfer of that limited, anonymized data to the US for processing under US law.
We implement reasonable security measures, including encryption in transit (HTTPS), to protect any data that is sent to our AI proxy. However, no security measure is 100% guaranteed. If you have security concerns, please contact us at [email protected].
Uralo is a general-audience app and is not directed at children. We do not knowingly collect data from children. Uralo has no accounts, so there is no account-based data collection from any user, child or adult.
We may update this Privacy Policy at any time. We will notify you of material changes by updating the "Last updated" date above and, if required by law, via an in-app notification.
If you have questions about this Privacy Policy or our privacy practices, please contact us at:
Scriptstash
Email: [email protected]