Privacy Policy
How Wellnetix Ltd handles the information you put into Lantern, the legal bases we rely on, and the rights you have under UK data-protection law.
The short version
- Your record stays with you. Lantern is offline-first. Wherever possible your notes and measurements are kept and processed on your device, encrypted at rest.
- Nothing is shared without your say-so. Lantern never sends your record anywhere on its own. You choose what to include in a clinician summary, and when.
- We do not sell your data, ever. We do not sell, rent, or trade your personal information, and we do not use it for advertising or marketing profiling.
- No scoring, no automated decisions. Lantern does not diagnose, score, rate, or make automated decisions about you.
- You can erase everything. Delete your data in the app, or send us a data-deletion request from the web — no app or account required.
Who we are
Lantern is a product of Wellnetix Ltd ("Wellnetix", "we", "us"), a company based in the United Kingdom. For the personal information you put into Lantern, Wellnetix Ltd is the data controller under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
- Privacy contact: nimind@wellnetixltd.com
- Data-protection queries and rights requests: nimind@wellnetixltd.com
- ICO registration: Wellnetix Ltd's Information Commissioner's Office (ICO) registration reference will be confirmed and published here before launch.
We have not appointed a statutory Data Protection Officer where one is not required; data-protection responsibility sits with a named accountable owner at Wellnetix Ltd, reachable at the address above.
What information Lantern handles
Lantern is designed to hold as little as possible, and to keep most of it on your device.
- The evidence you author. Notes, logged events, symptoms, questions, and other entries you write in your own words. Lantern keeps these verbatim.
- Digital check-in measures. When you choose to take an optional check-in task, Lantern records a neutral measurement — a value, its units, and the method used (for example a number of taps, or a sway path length). These are measurements only. Lantern does not attach a diagnosis, score, percentile, interpretation, or risk figure to them.
- On-device sensor capture. Some check-in tasks use your device's touchscreen, motion sensors, or microphone while the task runs. For voice tasks, the raw audio is processed on your device and discarded unless you explicitly choose to keep a recording — by default only the derived measurement frames are retained.
- Account information (optional). An account is optional. If you create one, we handle the sign-in identifier (such as an email address) needed to authenticate you and sync your record across your own devices. During the current development phase a simple developer sign-in may be used; a managed authentication provider is intended for launch (see Third parties).
- Sharing and consent records. When you generate a share-link for a clinician, Lantern keeps a consent ledger — a record of what you shared, with whom, when, and when you revoked it — so that sharing stays under your control.
- Basic technical data. Limited information needed to run the service securely and fix faults (for example app version, device type, and error diagnostics). We keep this to the minimum and do not use it to build advertising profiles.
We do not collect payment card details through the app, and we do not knowingly collect data about children (see Age).
Where your data lives
| Kind of data | Where it is held |
|---|---|
| Your notes, events, and questions | On your device, encrypted at rest; synced to our servers only if you use an account, so your own devices stay in step |
| Digital check-in measurements | On your device; included in a share or export only when you choose |
| Raw microphone audio | On your device during the task, then discarded (unless you choose to keep it) |
| Consent / share ledger | With your record, so you can see and revoke what you shared |
| Account sign-in identifier | With our authentication provider, to log you in |
Lantern is offline-first: it works without a connection, and syncing is there to keep your own devices consistent — not to route your record through us for any other purpose.
Why we use your data, and our legal bases
Under the UK GDPR we must have a lawful basis for each use of your personal data. Because much of what Lantern holds is health information — a "special category" of data — we also rely on a specific Article 9 condition, which for optional health features is your explicit consent.
| What we do | Article 6 basis | Article 9 basis (health data) |
|---|---|---|
| Provide the app and keep your record on your device | Performance of a contract with you / your consent to use the app | Explicit consent (Art. 9(2)(a)) |
| Run an optional check-in task using a sensor or microphone | Your consent (Art. 6(1)(a)) | Explicit consent (Art. 9(2)(a)) |
| Sync your record across your own devices (if you use an account) | Performance of a contract (Art. 6(1)(b)) | Explicit consent (Art. 9(2)(a)) |
| Generate and manage a share-link for a clinician | Your consent (Art. 6(1)(a)) | Explicit consent (Art. 9(2)(a)) |
| Keep the service secure and fix faults | Our legitimate interests in a safe, working service (Art. 6(1)(f)) | Not applicable — technical data only |
| Meet legal obligations (for example responding to a valid legal request) | Legal obligation (Art. 6(1)(c)) | As required by law |
Where we rely on consent, you can withdraw it at any time (see Your rights); withdrawing consent does not affect processing that already took place.
Special-category (health) data and explicit consent
Information about your neurological symptoms, and the measurements from check-in tasks, are treated as special-category health data. We only process it on the basis of your explicit consent, which Lantern asks for clearly and separately in the app before any sensor is used, and which you can decline or withdraw while still using the rest of Lantern. See the Consent page for how this works.
Sharing your record
- You decide what leaves your device. Lantern does not transmit your record on its own. When you want to share, you build a named summary and generate a time-limited, revocable share-link for your clinician.
- A consent ledger keeps you in control. Lantern records what you shared and when, and lets you revoke access.
- Portable, standards-based export. You can export your record — including in the healthcare-standard FHIR format — so it belongs to you and can be taken elsewhere.
- We do not share with advertisers or data brokers. We do not sell your data, and we do not disclose your record to third parties except the processors below, or where we are legally required to.
Third parties and processors
Lantern relies on a small number of service providers ("processors") who act only on our instructions and under a data-processing agreement. We name the categories here; the specific providers will be confirmed before launch.
- Cloud hosting and infrastructure. To run any server-side sync and store diagnostics securely.
- Authentication. To sign you in and secure your account, if you choose to create one. A managed authentication provider is intended for launch.
We do not use advertising networks, data brokers, or analytics that track you across other apps and websites for advertising.
International transfers
We aim to keep processing within the UK or the European Economic Area. Where a provider processes data outside the UK, we only allow it with the safeguards UK data-protection law requires — for example a UK adequacy decision, or the UK International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses. The specific locations and safeguards will be confirmed with the providers named before launch.
How we protect your data
- Encryption in transit. Data moving between the app and our servers is protected with transport encryption (TLS).
- Encryption at rest. Your record is stored encrypted at rest on your device.
- Data minimisation. We keep as little as possible, prefer on-device processing, and discard raw microphone audio by default.
- Access controls. Access to any server-side systems is restricted to those who need it.
No system is perfectly secure, but we take reasonable and appropriate technical and organisational measures to protect your information.
How long we keep your data
- While your account is active, we keep your record so the app works for you across your devices.
- On a verified deletion request, we erase your live data within 30 days.
- Backups containing your data are purged within 90 days.
- On-device data is under your control — deleting it in the app, or removing the app, erases the on-device copy.
Limited exceptions may apply where the law requires us to keep certain records (for example a minimal log that a deletion request was made and actioned). Full details, including the request form, are on the Data deletion & retention page. These periods are our intended policy and are subject to confirmation on final review before launch.
Your rights
Under UK data-protection law you have the right to:
- Be informed about how your data is used (this notice).
- Access a copy of your personal data.
- Rectify data that is inaccurate or incomplete.
- Erase your data ("right to be forgotten") — see Data deletion.
- Restrict processing in certain circumstances.
- Object to processing based on legitimate interests.
- Data portability — receive your data in a portable format (Lantern supports FHIR export).
- Withdraw consent at any time, where we rely on consent.
- Complain to the Information Commissioner's Office (ICO).
To exercise any right, contact nimind@wellnetixltd.com. We will respond within the statutory timeframe (normally one month). You will not be charged for making a request in the ordinary course.
Automated decision-making
Lantern does not carry out automated decision-making that produces legal or similarly significant effects about you, and it does not profile you. It does not detect, predict, forecast, score, or alert on anything. Interpretation of your record is for a qualified clinician, never the app.
Age
Lantern is intended for adults (18 and over). It is not designed for, or directed at, children, and we do not knowingly collect data from children. If you believe a child has used Lantern, contact us and we will erase the data.
Data breaches
If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ICO without undue delay and, where required, within 72 hours of becoming aware of it. Where a breach is likely to result in a high risk to you, we will inform you without undue delay.
Changes to this policy
We may update this policy as Lantern develops. We will change the "last updated" date at the top and, for significant changes, provide a more prominent notice. This is a draft that will be finalised before launch.
Contact and complaints
- Privacy team: nimind@wellnetixltd.com
- Complain to the regulator: You can contact the Information Commissioner's Office at ico.org.uk, by their helpline, or in writing. We would appreciate the chance to resolve your concern first.
Lantern is a product of Wellnetix Ltd, made in the UK. It is an evidence companion, not a medical device, and it does not diagnose or provide medical advice. In an emergency, contact your local emergency service — in the UK, call 999, or 111 for non-urgent NHS advice.
Delete your data at any time
You can erase everything from inside the app, or send us a data-deletion request from the web.