Querencia Privacy Policy
Effective and last reviewed: 20 September 2026
Querencia is developed by Ariel Tyson. It helps you keep a personal record of symptoms, medication doses, and information for appointments. This policy describes the current development implementation. It does not announce App Store availability or certify the app’s security.
Your record stays in local storage
Querencia stores your record in a database inside the app’s sandbox on your device. It can include symptom values, medication names and schedules, dose history, baseline answers, diagnosis and appointment dates, laboratory values, and historical imported daily summaries. Dates and time zones keep entries associated with their original local day. Corrections retain earlier entries as part of your history.
The developer does not operate a server that receives your record. The current app has no account, advertising, analytics SDK, third-party tracking SDK, or developer-operated remote crash-reporting service. It does not sell your personal data, share it for advertising, or upload it for model training. Calculations happen on the device.
Apple Health and camera access
Health import is off in this version. Querencia does not request Health authorization, read new Health samples, or write to Apple Health. If an earlier development build stored daily sleep, heart-rate, or step summaries, they remain local until you remove them. In Privacy, use Remove imported Health summaries to erase those copies after device authentication. This also clears temporary exports that could contain them. Your other clinical records and original Apple Health data are unchanged. You can manage any earlier Health authorization in Apple’s Health or Settings interfaces.
The current navigation does not expose document-camera scanning and the app does not request camera permission. The dormant OCR component is not an available scanning feature. A future Health or camera feature requires a separate permission and policy review before release.
Notifications, Siri, and device authentication
If you allow notifications, Querencia schedules reminders locally through iOS. By default, their titles and bodies are generic and omit medication names and doses. Show medication details in notifications, in Privacy, is an explicit optional setting that requires device authentication to enable. With it enabled, medication names, doses, or dosing-window details can appear on your Lock Screen or paired devices. Changing the setting clears previous pending and delivered notifications and rebuilds reminders when permission is available. The app lock does not change iOS notification visibility. You can also disable notifications or adjust previews in iOS Settings. There is no developer push-notification server.
Siri and Shortcuts can record symptoms or doses and read out the next medication. All three actions require local-device authentication and check Querencia’s shared access policy before accessing the record. If the app lock is enabled and its unlocked session has expired, open Querencia and unlock it first. Spoken medication information can still be heard by people nearby. Apple handles Siri and Shortcuts under its own settings and policies; this is not a promise that Siri processing is offline.
The optional app lock uses Face ID, Touch ID, or your device passcode. It starts locked on a new launch and locks immediately when you leave by default; you can choose a one-minute or five-minute grace period in Privacy. Changing lock protection requires fresh device authentication. Security preferences are kept in a device-only Keychain item. Unavailable security preferences do not silently disable protection. Querencia receives an authentication result, not your passcode or biometric templates. An opaque cover hides app content, including presented sheets, while inactive; physical-device behavior remains part of release validation.
Storage protection and recovery
Querencia explicitly applies iOS Complete file protection to its clinical store, sidecar files, and app-created export files. Background record work is deferred while protected data is unavailable. The app lock is an additional access control, not a separate encryption system for all copies.
The clinical store is marked as excluded from device backups, and CloudKit synchronization is disabled. Keep an export if you need a copy before changing devices, deleting the app, or erasing your record. Querencia has no server copy it can restore. The complete JSON export is portable data; this version does not offer archive import. Ordinary app preferences may still be handled by device backups. Current exclusions do not remove backups made by earlier versions. Apple manages its backup services under its policies; see Apple’s iCloud Backup explanation.
Reports and exports
PDF and text appointment reports use the displayed inclusive date interval for symptoms, scheduled-day dose counts, confirmed labs, and derived observations. Medication summaries can include discontinued medications with recorded doses in that interval. These are records of saved entries, not a guarantee that every expected dose was logged. Review a report before sharing it.
Opening a report no longer creates a file. Choosing Export as PDF prepares a new temporary file and opens the system share sheet. Export complete record, in Privacy, requires device authentication and creates a versioned JSON file containing all stored clinical history, including corrections, medication definitions, dose relationships, unconfirmed labs, and historical imported summaries. It excludes device authentication secrets and app presentation settings.
Each file export uses a separate temporary location. The app removes it when sharing finishes or is cancelled. Interrupted exports are removed by a later launch once they are at least 24 hours old. You can use Clear temporary exports to retry cleanup; errors are surfaced rather than reported as successful removal. Files from the earlier report writer are removed on launch.
Exported PDF, text, and JSON content is readable by the destination you select. File protection in Querencia does not encrypt a recipient’s copy. Saving or sharing may transmit information to another app, person, or service under its policies. Querencia cannot recall those copies.
Retention and deletion
You can edit or delete individual symptom, dose, and lab entries from Timeline → Manage logs, and manage a medication’s dose history from its details. Edits are saved explicitly; cancelling leaves the stored entry unchanged. Symptom edits consolidate earlier corrections into the selected entry, and confirmed deletion removes that entry’s correction history so old values do not reappear. Individual deletion also clears app-managed temporary exports. These actions cannot change or remove copies already shared outside Querencia.
Medication settings let you adjust reminder times, interval dates and windows, or pause and resume reminders while retaining dose history. You can also delete a medication and all of its associated dose entries after confirmation. Other medications, symptoms and labs remain. Medication selection is optional, including during setup; you can use Querencia without adding any medicine. Changes refresh the app’s local record, reports and reminder schedule. They do not change a prescription or send information to a clinician.
Your local record remains until you remove it. Delete all local data, in Privacy, asks for confirmation and device authentication, then erases the clinical store, historical Health summaries, temporary exports, scheduled and delivered reminders, and record/privacy preferences. It returns the app to onboarding. A deletion that does not finish keeps the record closed and offers a retry. This action does not delete original Apple Health samples, previously made backups, or copies you already shared. The app’s alternate icon is a device presentation choice and can be changed separately.
Deleting the app removes its local app container. Offloading retains documents and data. Device-only Keychain items can outlive app deletion; the in-app delete action explicitly removes the lock preference. The developer cannot remotely retrieve or erase a local record it does not hold.
Websites and support
Opening a reference or policy link contacts that website, which may receive network information such as your IP address. Links do not attach your clinical record.
These policy websites use GitHub Pages without Querencia-added analytics scripts, advertising, embedded trackers, or third-party fonts. GitHub handles hosting and security information, including visitor IP addresses, under the GitHub General Privacy Statement.
If you submit a GitHub issue, your GitHub profile and report become public. GitHub and the developer receive the content you choose to submit to investigate and respond. Issue and commit history can remain available after resolution. Use synthetic examples; omit health records and identifying screenshots. Use the private security channel for sensitive reports.
Questions and changes
For non-sensitive discrepancies, open a privacy concern. For vulnerabilities, report privately. Ariel Tyson maintains these channels; GitHub requires an account to submit reports. Developer information is at arieljtyson.com.
Changes appear here with a revised review date and public version history. The data mapping explains the implementation boundaries. New services or data uses require review before release.