OrthoLog — Privacy Policy
Last updated: 8 September 2026
OrthoLog is a personal surgical logbook for orthopedic surgery residents. This policy explains, in plain language, what the app does and does not do with information.
The short version
OrthoLog has no accounts, no sign-up, no company servers, no advertising, and no tracking. Your logbook lives on your phone, syncing privately through your own Apple iCloud account so it is backed up and follows you to a new phone. The app works fully offline, with or without iCloud.
Three things, and only these three, are sent to the developer of OrthoLog:
- Anonymous usage counts — numbers describing how the app's features get used (for example, how many cases were logged, and how many were started by voice rather than by tapping). See "Anonymous usage counts" below for the complete list.
- Two pieces of text from your logbook — procedure names you type in yourself when the built-in catalog doesn't have the operation, and whatever you write in a case's "Note" box, labelled with the operation it was written about. The first is used to add missing operations to the catalog; the second, to improve the app around how residents actually work. The separate "Private note" box is never sent. See "The two note boxes" below.
- Feedback you write yourself, if and when you choose to tap "Send feedback".
All three travel through the developer's own Apple iCloud (CloudKit) container — not a company server and not any third party. None of them includes anything a patient could be identified from, and none includes your name or your training year.
Photos you attach to a case are not on that list and never will be. They stay on your own devices — see "Photos you attach" below.
Voice recordings and voice transcripts are not on that list either. Audio is processed in memory using Apple's on-device speech recognition, never stored or uploaded, and a pending text draft stays only on the phone until you save or discard it.
What OrthoLog stores
Everything you put into OrthoLog — your surgical cases, the surgeons you work with, the hospitals you rotate through, your name and training year, any private notes, and any photos you attach to a case — is saved on your device using your iPhone's built-in on-device storage, protected by the iPhone's own encryption whenever your phone is locked. If you are signed into iCloud, this same information also syncs to your own private iCloud account (Apple's iCloud service, tied to your Apple ID) so it is backed up and follows you to a new iPhone. This uses only your personal iCloud — never our servers and never any other account — and you can turn it off simply by turning off iCloud; the app keeps working fully offline either way.
What OrthoLog does NOT do
- It does not create an account or ask you to log in.
- It does not send your case list anywhere. Apart from the two pieces of text described above, nothing about a case is transmitted — not its date, not the surgeon, the hospital, the rotation, or your level of involvement. (If you use iCloud, all of that syncs only to your own private iCloud account — Apple's service under your Apple ID.) An operation's name is sent only when you typed it in yourself, or as the label on a note you wrote.
- It does not send your "Private note" anywhere, ever. That box exists so that anything you want kept to yourself has a place to go.
- It does not use advertising, or tracking of any kind. Nothing it collects is combined with data from other companies, or shared with or sold to anybody.
- It does not upload or retain voice audio, and it does not send voice transcripts to the developer, analytics, feedback, or any third party.
- It does not read your photo library, your location, your contacts, or any device identifiers — no advertising identifier, no phone or hardware ID, no Apple ID, no email address unless you type one into feedback yourself. The only images it ever holds are the ones you deliberately attach to a case, and it never sends those anywhere (see "Photos you attach" below).
- It has no field for a patient identifier — there is nowhere in the app to record a patient's name, a medical record or chart number, or a full date of birth. It isn't that the app promises not to keep them; there is simply nowhere to put them.
One honest caveat about being anonymous: the usage counts and any feedback you send both carry the same random installation identifier described below. That means if you choose to type your email address into feedback, that email can be connected to that installation's counts and text. If you leave the email blank, nothing sent from the app carries anything that identifies you.
The two note boxes
Every case has two note boxes, and which one you type into decides where the words can go:
| Stays on your phone | In a spreadsheet you export | Sent to the developer | |
|---|---|---|---|
| Note | yes | yes | yes |
| Private note | yes | only if you tick the box | never |
Anything you would rather nobody else read belongs in Private note. It is never uploaded, and it is left out of any spreadsheet you export unless you deliberately turn on "Include my private notes" — a switch that starts off every single time.
The Note box is sent to the developer along with the usage counts below, labelled with the operation it was written about — a note reading "cemented, tricky exposure" is of no use without knowing it was a hip replacement. Nothing else about the case goes with it: not the date, not the surgeon, not the hospital, not the rotation, not your level of involvement. As with feedback, please don't write patient details in it.
Photos you attach
You can attach pre-op, intra-op and post-op images to a case, each with its own note.
A photo never leaves your own devices. It is never sent to the developer — not the image, not a count of how many you have, not even whether a case has any. There is no exception to this and no switch that changes it. The only three places a photo can travel are ones you control yourself:
- your own private iCloud, if you have iCloud switched on, so your images survive a new phone;
- your own backup file, if you save one (there's a switch for whether photos are included, since they make the file much larger);
- an export you deliberately choose — the "Case book" option, which is meant for you rather than for a supervisor. The spreadsheet export never contains images.
Two things worth knowing. When you add an image, the app shrinks it and strips the hidden data that photos carry — the time it was taken, the device, sometimes the place. And the app does not look at what is in your images: it cannot read them, scan them, or check them, which also means it cannot warn you if one contains something it shouldn't. Crop out anything identifying before you attach it. A screenshot of a hospital record usually has the patient's name and number along the top, and an X-ray photographed off a screen often has an identifying strip burned into the image itself.
Anonymous usage counts
So that OrthoLog can be improved around how residents actually use it, the app keeps a small set of counters on your phone and sends them, at most once a day, to a shared area inside the developer's own Apple iCloud (CloudKit) container. This is the complete list of what is sent:
- Counts of: cases saved; how many were started from a blank form, the body map, procedure search, voice, "repeat last case", or a spreadsheet import; how many were flagged as EPA candidates or as robot-assisted; and how many times History, Insights, Settings, procedure search, export, backup, restore and the feedback screen were opened.
- Two dates: when you first opened the app, and when you last opened it.
- A count of how many separate days you have opened the app.
- The app version you are running.
- A random identifier for this installation of the app — a random number generated on your phone, used only to tell one installation's counts apart from another's. It is not derived from your phone, your Apple ID, or anything else, it exists nowhere but this app, and deleting the app forgets it permanently.
- Procedure names you typed in yourself — only ones that aren't in the app's built-in catalog, because those are the operations it is missing. A procedure you picked from the catalog is never included.
- The text of your "Note" boxes — the shared one only, each labelled with the operation it was written about, as described above.
What is never included: your "Private note", any case date, any surgeon or hospital name, any rotation, your involvement level, your name, your training year, your email, or anything a patient could be identified from. If you are not signed into iCloud or have no connection, nothing is sent and the app carries on working exactly the same.
You can turn this off. It is on when you install the app. To stop it, go to Settings → About and turn off "Share anonymous usage data". Turning it off does three things: the app stops counting, everything it has already counted is deleted from your phone, and what was already sent is deleted as well. (That last step needs a connection — if you are offline when you switch it off, the already-sent copy is removed the next time the app can reach iCloud.) Nothing else about the app changes, and you can turn it back on at any time.
About the "shared area" this goes to. Apple gives every app developer two kinds of storage: a private one, where each person's own data is visible only to them, and a shared one belonging to the app itself. Your cases sync through the private one. The usage counts and feedback described here go to the shared one, which is how they reach the developer without any company server existing. It is not on the public internet and it is not searchable, but it is not the same thing as your own private storage either, and this policy previously described it incorrectly as private.
Data you choose to share
OrthoLog can create files at your request — a spreadsheet export of your cases, or a full backup of your logbook. These files are created only when you tap the button to make them, and they go only where you choose to send them (for example, saving to your Files app, or emailing them to yourself or a supervisor). OrthoLog never sends these anywhere on its own. Your private notes are left out of the spreadsheet export unless you turn on "Include my private notes" before creating it; they are always included in your own personal backup file, which is meant for you.
Feedback you send
OrthoLog has a "Send feedback" screen in Settings. If you write something there and tap Send, that message is delivered to the developer through the same shared area of his own Apple iCloud (CloudKit) container — no company server, no third party. It carries the text you wrote, the app version, your iOS version, the random installation identifier described above, and an email address only if you choose to type one in so you can get a reply. Leave the email blank and the message is anonymous.
Please do not include any patient details in it. Nothing is sent unless you tap Send. If you are offline, the message waits on your phone until you next open the app.
Voice logging (optional)
You can start voice logging from Home or say “Hey Siri, log a case in OrthoLog.” Both routes open the same recorder inside OrthoLog; there is no shared Shortcut to install. Siri handles only the launch command. The case itself is transcribed with Apple's Speech framework using an on-device recognizer required by the app. If on-device recognition is unavailable for the device or locale, OrthoLog stops and offers typed entry rather than sending the recording to a network recognizer.
OrthoLog uses microphone audio only in memory for the current attempt. It never writes that audio to a file, stores it, uploads it, or includes it in analytics or feedback. The resulting transcript is shown as an editable draft and used to suggest fields on the new-case form. To prevent an unfinished dictation from disappearing during navigation, up to five pending text drafts may stay locally on the phone for up to 24 hours; they are removed after the case is successfully saved or you explicitly discard the draft. Transcripts are never sent to the developer.
Nothing is logged automatically. You see the transcript, every field OrthoLog matched, and any ambiguity notices before choosing whether to save. Voice logging is optional, requires microphone and Speech Recognition permission, and the rest of the app works without it.
Reminders
If you flag a case as an EPA (Entrustable Professional Activity) candidate, OrthoLog can remind you later to follow up on it. This uses your iPhone's own built-in local notifications — scheduled and delivered entirely on your device, with no server involved and no internet connection needed. This is on by default but can be turned off at any time in Settings.
iCloud sync (optional)
If you are signed into iCloud, OrthoLog syncs your logbook through your own personal iCloud account so it is backed up automatically and follows you if you change iPhones. This uses only Apple's iCloud service tied to your own Apple ID — never a separate account, never our servers, and only while you leave iCloud turned on. Your data in iCloud is handled by Apple under Apple's own privacy terms, the same as your other iCloud content. The app always works fully with iCloud off; syncing is a convenience, never a requirement.
Children
OrthoLog is a professional tool intended for medical residents. It is not directed at children.
Contact
Questions about this policy can be sent to privacy@ortholog.ca.
Email privacy@ortholog.ca.