Privacy Policy
Effective April 27, 2026 · Last updated April 27, 2026
The short version: Your audio recordings never leave your iPhone. They are transcribed on your device. Only a scrubbed text transcript — with names, phone numbers, and identifiers removed — is sent to generate your summary. We have no ads and no way to see your health information. We collect anonymous usage analytics to improve the product, but never your medical data. Your data syncs securely through your iCloud account — we never store it on our servers.
What DayAfter does
DayAfter is an iOS application that helps caregivers understand and share medical visit information. You record a doctor's appointment or photograph handwritten notes, the app transcribes and extracts the medical content, then generates a structured plain-language summary you can share with family.
Data we collect inside the app
DayAfter does not require you to create an account or provide an email address. The app uses your Apple ID through iCloud to sync your data across devices — this is handled entirely by Apple's CloudKit infrastructure. We never see your Apple ID, password, or iCloud credentials. Here is exactly what is stored, and where:
| Data | Stored where | Sent off device? |
|---|---|---|
| Audio recordings (.m4a) | iPhone local storage only | No — never |
| Transcripts | iPhone + iCloud (encrypted) | Synced via iCloud Private Database. Only the scrubbed version is sent for summarization (see below) |
| Visit summaries | iPhone + iCloud (encrypted) | Synced via iCloud. Shared only when you choose to |
| Care subject profile (name, birth year, conditions) | iPhone + iCloud (encrypted) | Synced via iCloud. Never sent to AI services |
| Caregiver observations | iPhone + iCloud (encrypted) | Synced via iCloud only |
| Anonymous usage analytics | PostHog (EU-hosted) | Yes — feature usage events only, no medical data (see below) |
| Your API key (if using your own) | iPhone Keychain (encrypted) | Sent as an authentication header to Anthropic's API |
All persistent data uses Apple's SwiftData framework. Structured data (transcripts, summaries, profiles, tasks) syncs through Apple's CloudKit Private Database, which is encrypted and tied to your personal iCloud account. Audio recordings are stored locally on your device and are never uploaded. DayAfter does not operate its own backend database — your data lives in Apple's infrastructure under your Apple ID, not ours.
Audio recording and transcription
When you record a visit, DayAfter captures audio in AAC format (mono, 24 kHz) using Apple's AVAudioRecorder. The audio file is written to your device's local storage and stays there. It is never uploaded to any server.
Transcription is performed entirely on your device using WhisperKit, an open-source on-device speech recognition framework based on OpenAI's Whisper model. The model runs locally on your iPhone's Neural Engine and processor. No audio data is transmitted during transcription.
What is sent off your device
AI summarization. When you generate a summary, DayAfter sends a text-only request to Anthropic's Claude API. Before any text leaves your device, it passes through an automatic scrubbing step that removes or replaces: doctor names, phone numbers, email addresses, Social Security and government ID numbers, dates of birth, health card numbers (including OHIP, RAMQ, and BC PHN formats), driver's license numbers, insurance identifiers, and absolute dates (converted to relative references like "3 days ago"). You can review every redaction before the request is sent. The scrub review screen shows you exactly what will be removed and lets you adjust it. The request is sent over HTTPS to api.anthropic.com. DayAfter does not proxy, store, or log these requests. Anthropic's data handling is governed by their own privacy policy and API data usage policy.
iCloud sync. Structured data — transcripts, summaries, care subject profiles, tasks, and observations — syncs through Apple's CloudKit Private Database. This data is encrypted in transit and at rest by Apple and is accessible only through your iCloud account. Audio recordings are excluded from sync and remain on your device. For details on how Apple handles CloudKit data, see Apple's iCloud security overview.
Usage analytics. DayAfter collects anonymous product analytics through PostHog (EU-hosted) to understand which features are used, where people get stuck, and how to improve the app. Analytics events include things like "summary generated," "tab viewed," or "share initiated." They never include transcript content, medical terms, care subject names, or any health information. You can opt out of analytics in the app's settings. Analytics are not tied to your Apple ID or any personally identifiable information.
Sharing
When you share a visit summary, DayAfter uses iOS's built-in share sheet. The shared content is a plain-text version of the summary you see in the app — visit title, date, summary sections, medications, follow-ups, and a note that it was AI-generated. Sharing is always initiated by you; nothing is sent automatically.
Device permissions
DayAfter requests only the permissions it needs:
| Permission | Why |
|---|---|
| Microphone | To record doctor visits for transcription |
| Calendar | To add follow-up appointments mentioned during the visit |
| Reminders | To create reminders for follow-up tasks |
| Notifications | To send daily check-in reminders and follow-up nudges |
DayAfter does not request access to your camera, photos, location, contacts, or Apple Health data.
Third-party services
| Service | What it does | What data it receives |
|---|---|---|
| WhisperKit (on-device) | Speech-to-text transcription | Nothing leaves your device — runs entirely on your iPhone's Neural Engine |
| Anthropic Claude API | AI summarization and medical term extraction | Scrubbed transcript text only (identifiers removed) |
| Apple CloudKit | iCloud sync across your devices | Structured data (transcripts, summaries, profiles) — encrypted by Apple |
| PostHog (EU-hosted) | Anonymous product analytics | Feature usage events — no medical data, no personal identifiers |
There are no advertising frameworks, no data brokers, and no services that receive your medical content other than Anthropic's API (after scrubbing).
The website (dayafter.app)
The DayAfter website uses PostHog (EU-hosted) for visitor analytics. Website analytics are gated behind a cookie consent banner that defaults to opt-out, respects the Do Not Track browser signal, and fires zero events until you explicitly accept. If you join the waitlist, your email is stored by Buttondown, our email provider. Your email is used only to notify you about DayAfter availability and updates. Website analytics and app analytics are separate systems — no data is shared between them.
Children's privacy
DayAfter is not directed at children under 13 and does not knowingly collect information from children. If you believe a child has provided information through DayAfter, please contact us and we will delete it.
Data retention and deletion
Your data is stored on your device and in your iCloud Private Database. You can delete individual visit records within the app at any time — deletions sync across your devices through iCloud. Deleting the app removes all local data. To remove iCloud data, you can delete it from within the app before uninstalling, or manage it through your iCloud storage settings. DayAfter does not maintain a separate copy of your data — when it's gone from your iCloud account, it's gone.
Anonymous analytics data collected by PostHog is retained for product improvement and is not linked to your identity. It cannot be used to reconstruct your medical information because it never contained any.
Changes to this policy
If we make material changes to how DayAfter handles data, we will update this page and the effective date at the top. Because DayAfter does not collect email addresses inside the app, this page is the primary notice mechanism.
Contact
Questions about this policy or your data: hello@dayafter.app