Effective on the day voXel is first released on the App Store.
voXel collects nothing about you and sends nothing anywhere. It has no account, no server, no analytics and no advertising. The medical images you open in it stay on your iPad.
That is the whole policy. The rest of this page explains it precisely, because "we care about your privacy" is what an app says when it is about to describe the data it takes.
Nothing.
There is no user account, so there is no name, email address or password. There is no analytics library, no crash reporting service, no advertising identifier, and no software from any other company inside the app. voXel contains no code that reports anything about you or your device to me or to anyone else.
The DICOM studies you import are copied into voXel's own storage on your iPad and stay there until you delete them. They are covered by the same iOS protections as the rest of your device's data, including its encryption at rest.
They are never uploaded. voXel has no cloud storage, no sync, no backup service and no sharing service, because it has no server of any kind. There is nowhere for an image to be sent to.
Two things move data at your explicit request, and only then:
The share sheet. When you export a slice as PNG, JPEG or PDF, a range as an animated GIF, or a surface as STL or OBJ, iOS asks where you want to send it. Whatever you choose is your choice, and once the file leaves through that sheet, voXel has no further control over it. Patient identifiers are not written into an exported picture or into its filename. An exported 3D surface carries no DICOM tags at all, which means it looks anonymous but is not necessarily so: a surface built at a skin threshold from a head scan reconstructs a recognisable face.
The local transfer server. If you switch it on, voXel listens for a connection from a computer on the same network so you can copy a folder of files across. It is off unless you turn it on, it is protected by a six digit pairing code that changes each time, it stops when you close it, and it never leaves your local network. It is plain HTTP and is not encrypted, so use it on a network you trust and not on a public one.
Apple requires apps to declare certain system APIs and the reason they are used. voXel declares two, and both are declared in the privacy manifest included in the app:
Preferences storage, to remember your own settings: your key shortcuts, the loupe magnification, and whether the performance readout is shown. These stay on your device.
Free disk space, so the Diagnostics screen can show you how much room is left before you import a large study. The number is displayed to you and is not recorded or sent anywhere.
voXel can write a report describing a problem, containing the app version, the device model, and which internal checks failed. It is written to a file on your device and shown to you. Nothing is sent automatically. If you decide to send it to me, you do that yourself through the share sheet, and you can read the whole file first.
Those reports are written so that they do not contain file paths, folder names or patient identifiers, because a DICOM export usually names its folders after the patient. An import error says "Entry 1 of 240 (.dcm)" rather than the name of the file it failed on.
If you send me a report, I use it to fix the problem described in it and for nothing else.
Apple runs the App Store, and this part is Apple's collection rather than voXel's.
If you have agreed in your iOS settings to share analytics and crash data with developers, Apple may show me anonymous aggregate figures: how many people downloaded the app, which countries, which iOS versions, and crash reports. None of it identifies you, and none of it contains your images, your file names or any patient information. You can turn it off in Settings, under Privacy and Security, then Analytics and Improvements.
Purchases are handled entirely by Apple. I never see your name, your address or your payment details, only the anonymous sales figures Apple reports.
voXel is rated for adults and is intended for clinicians, trainees and students. It is not directed at children, and since it collects nothing, it collects nothing from children either.
Most of the rights you have under Malaysia's Personal Data Protection Act, the EU and UK General Data Protection Regulation, and comparable laws elsewhere are rights to see, correct, export or delete the personal data a company holds about you. I hold none, so there is nothing for me to show you, correct, export or delete.
The images inside the app are in your hands. Deleting a study in voXel removes it from the app's storage. Deleting the app removes all of them.
This part is not about my collection of data. It is about yours.
Medical images are patient data. If you copy identifiable imaging from your hospital onto a personal iPad, the rules that apply to you are your employer's policies and your own jurisdiction's data protection law, and voXel cannot give you permission that your institution has not. voXel keeps those images private on your device; it cannot make it lawful for them to be there.
If you are showing a study to an audience, use the control that hides patient details before the screen is visible, not after.
If this policy changes, the new version appears at this address with a new effective date. Since the app collects nothing, any change here will be a clarification rather than a new permission. If voXel ever did start collecting something, it would be described here and in the app before it happened.
support@voxeldicom.com
Please do not attach medical images to a support email. I do not want them and I have no lawful basis to receive them. Describe the problem instead, or send the problem report the app generates, which is written to avoid containing them.