Skip to content

Ally · Privacy

Your care information.
Your choices.

Ally keeps your saved care inbox on your iPhone. This policy also explains what happens when you share information, test a beta, contact us, or visit these pages.

Effective · Betz Software LLC

This policy covers the Ally iPhone app and the Ally pages at betzsoftware.com/ally, operated by Betz Software LLC (“we”). Ally is currently an invitation-only internal beta. It organizes care tasks and visit questions; it does not provide diagnosis, treatment, or emergency monitoring.

Ally has no app account, publisher cloud sync, cloud AI service, advertising, or app analytics SDK. It does not send your care inbox or Health records to a Betz Software server. Information you choose to share, support email, Apple TestFlight data, and website connection data are handled separately, as described below.

Care information and Health access

Ally processes the details you enter or choose to use: tasks, clinician or recipient names, drafts, visit questions, notes, check-in dates, and contact or outcome history. Saving a task from a record or visit note also saves its source information. A saved visit-note task includes the full reviewed note and, for an imported document, the original extracted text. Editing a title or draft does not erase its saved sources or earlier history.

Apple Health access is optional and read-only. With your permission, Ally can read available activity, sleep, resting heart rate, medication entries, and clinical records, including conditions, allergies, immunizations, laboratory results, medications, procedures, and vital signs. It uses these to show context, locate sources, and help prepare questions. Ally does not write to or delete your original Health records. The care inbox works without Health access.

When you choose a PDF, photo, or camera scan, text extraction takes place on your iPhone. You check the text before using it. Original document and image data are temporary in the import flow; the saved inbox retains text and source details, not the original file or scan. Ally does not add scans to Photos. Your Files or Photos provider may download an original stored in the cloud.

On-device processing and AI

Record lookup, task-based answers, and visit-question preparation use app logic and source text on your iPhone. Optional Apple Intelligence features also run on the device. Ally has no cloud inference fallback.

  • Administrative wording in chat: the model receives only an app-defined request category and tone. It selects from wording written into the app; Ally does not show free-form model prose. Raw messages, task details, conversation history, and Health content are not included in that model request. If selection is unavailable or fails, the app uses fixed wording.
  • Check recorded follow-ups:this separate feature, started by you, can give limited candidate instruction text, surrounding note context, record titles and dates, selected facts, and related-record context to Apple's on-device model. It classifies the supplied text. The questions shown use fixed wording and retain their sources for your review. This is not a complete chart review or confirmation that your care is up to date.

Storage, deletion, and your controls

Saved inbox files use iOS file protection and are excluded from device backups. Tasks, notes, drafts, histories, source excerpts, and dismissed suggestions remain until you delete them. There is no automatic sync or restore feature, including restoration from an Ally export. Deleting the app or losing your device can mean losing your inbox. We do not have a server copy to recover.

Live Health snapshots and chat are held in memory. Backgrounding clears the live Health feed; reopening can read data you still permit. Record excerpts already displayed in chat can remain until you clear the conversation or the app process ends. A source separately saved to a task remains with that task. Personal and fictional sample inboxes have separate storage.

  • In Ally:edit or delete individual tasks. Open You → Privacy & data to export or delete the current inbox. Whole-inbox deletion also clears the current conversation and removes that inbox's reminders. Delete each inbox separately if you want both cleared.
  • Conversation and record lookup: You lets you clear the conversation and change Use Health records for questions. Changing that setting clears the conversation. It does not change Health access for the rest of Ally.
  • System permissions:manage Ally's access in Apple Health and notification permission in iPhone Settings. Revoking Health access stops the affected future reads; it does not erase sources already saved to tasks.

Deleting an inbox leaves the other inbox, original Health records, system permissions, local preferences, and external copies unchanged. Local preferences include your selected inbox and getting-started settings. Deletion cannot be undone.

Sharing, export, and reminders

Ally does not automatically contact a clinician, pharmacy, or insurer. Approving a draft does not send it. If you choose to share or export, iOS passes a copy to the destination you select, which may be another app or cloud storage provider. That destination handles the copy under its own practices.

The JSON inbox export includes saved tasks, full notes, source excerpts, drafts, history, resolved tasks, and dismissed suggestion identifiers. It excludes the chat transcript and complete live Health library. Ally does not password-protect the export. Deleting data in Ally cannot remove copies you already shared or exported.

Reminders are local notifications you explicitly enable. Their generic wording and opaque identifiers contain no task title, medication, or clinical excerpt. iOS controls permission and delivery. Ally reconciles scheduled and delivered reminders when you turn them off or delete their tasks.

Support email and TestFlight

When you email us

Email to chris@betzsoftware.com is handled through Google Workspace. We receive your email address, message, mail metadata, and any attachments you send. We use them to answer your request, investigate a problem, and maintain support or privacy-request records. Please use fictional examples and do not send medical records, inbox exports, or screenshots with personal health details.

When you use the TestFlight beta

Apple automatically collects beta crash and usage information and shares it with us. This can include install and session activity, device and OS details, and your invitation name and email. TestFlight does not offer an opt-out from that collection while testing. Feedback you choose to submit can also include comments, screenshots, and diagnostic details. We use this information to investigate issues and improve Ally; we do not share TestFlight information with third parties. See Apple's TestFlight privacy notice.

We retain support correspondence and beta information we hold for as long as needed to handle requests, investigate and prevent recurring faults, maintain necessary records, and meet legal obligations. Retention depends on the issue, sensitivity, and any ongoing obligation; there is no single automatic deletion deadline. You can request deletion using the contact below. Apple and Google may retain service records or backups under their own applicable policies; deleting Ally does not delete those records. When information we hold is no longer needed for these purposes, we delete it, subject to applicable retention requirements and provider backup handling.

Website visitors and service providers

The Ally pages are hosted by Vercel. Delivering and protecting the website involves connection and request information such as your IP address, browser or device information, requested URL, timestamp, and diagnostic or security logs. Vercel processes this information to provide and secure its hosting service. Provider retention varies with the type of record and service settings. See Vercel's privacy notice.

We do not load website analytics or performance-tracking scripts on the Ally pages, and these pages have no contact or upload form. A theme preference may be stored in your browser. Other Betz Software pages may offer different forms or services; this policy describes Ally and its pages. Opening an Ally website link from the app does not add your care content to the URL.

Vercel supplies hosting, Google Workspace supplies support email, and Apple supplies Health, on-device AI, notifications, and TestFlight platform services. They handle the information needed for their respective services; they do not receive a copy of your local inbox merely because you use Ally. Providers may process information in countries other than where you live. Access to information we receive is for operating and supporting Ally, handling privacy requests, and meeting legal obligations. We do not sell or rent your care information or use it for targeted advertising.

Privacy requests and policy changes

Contact Betz Software LLC at chris@betzsoftware.com for a privacy question or to request access, correction, deletion, or a copy of information we hold about you. Depending on applicable law, you may also have rights to withdraw consent, object to or limit processing, or appeal a decision. You can send an appeal to the same address with “Privacy appeal” in the subject, or contact your relevant privacy regulator.

Describe the request without including health records. We may ask for information reasonably needed to verify and locate your request. We can help with data we hold, such as support correspondence; we cannot remotely access, erase, or restore the care inbox on your phone. Use the app controls above for local data and Apple's controls for information Apple holds.

We will update this page and its effective date when practices change. Material changes will also be explained through an appropriate app or beta notice. Where a change requires your consent, we will seek it before that processing begins.

Need help using the app? Visit Ally support.