Apex Labs Privacy Policy
Effective 31 July 2026 ยท Last updated 3 August 2026
This policy explains how Apex Labs handles information.
1. Information handled
Apex Labs handles account details; laboratory-service credentials; patient, specimen, and laboratory information returned by authorised connected services; recently viewed patient history; watchlist entries; notification and appearance preferences; and limited technical information needed to operate the app.
2. Purposes
Information is used to authenticate you, retrieve and display authorised laboratory information, maintain your on-device history and watchlist, notify you that an update is available, remember settings, protect the app, and monitor service availability. Apex Labs does not use patient information for advertising or cross-app tracking.
3. On-device clinical storage
Laboratory credentials, patient history, and watchlist data are separated by Apex Labs account and stored in the iOS keychain without iCloud synchronisation. Laboratory results and PDFs may be cached in protected on-device storage, are excluded from backups, and expire after 48 hours without access. Apex Labs does not copy patient identities, searches, laboratory results, or PDFs into its Clerk identity service or Convex operational-status database.
4. Connected services
Clerk processes account, identity, device, and authentication information. Apple and Google process information when you select their sign-in service. NHLS LabTrak receives credentials, searches, and laboratory requests needed to return source records to the device. Convex uses the active account session to authorise limited aggregate success and failure reports used to display operational service status; its app records contain no patient, query, result, user, or device field. Connected providers may retain security, access, or service logs under their applicable legal and organisational requirements.
5. Notifications
If enabled, Apex Labs creates generic notifications stating that a laboratory update is available. Patient names, specimen references, and result values are not placed in notification text. Details are available only after opening and signing in to the app.
6. Sharing, advertising, and tracking
Apex Labs does not sell personal or patient information and does not use it for advertising or tracking. Information is transmitted only to provide requested connected services, comply with law, protect rights or security, or support the app through an authorised provider subject to appropriate safeguards.
7. Retention and deletion
Cached laboratory results and PDFs expire after 48 hours without access and can be cleared sooner. Other on-device clinical data remains until removed through Data Controls or account deletion. Deleting an Apex Labs account first removes its saved clinical data from that device and then requests deletion of its Clerk identity account. It does not alter source laboratory records or lawful provider security and access records. If the account uses Sign in with Apple, Apex Labs may direct you to Apple Account Settings to finish removing Apple sign-in access.
8. Security
Apex Labs uses HTTPS, device-bound keychain storage, protected files, account-scoped local storage, and authenticated access controls. No system is completely secure. Protect your device with a strong passcode and biometrics and report suspected unauthorised access promptly.
9. Your choices and rights
You can control notifications and camera access, remove stored LabTrak credentials, clear on-device clinical data, sign out, or delete your Apex Labs account in Settings. Additional access, correction, objection, or deletion rights may apply under local law and can be exercised through the responsible healthcare organisation or service provider.
10. Children and policy changes
Apex Labs is intended for authorised professional users and is not directed to children. Material policy changes will be reflected by an updated effective date and, where required, an in-app notice or renewed consent.
11. Contact
Contact dr.cdbredenkamp@gmail.com with privacy questions or suspected data incidents. Do not send patient information, laboratory results, credentials, or other sensitive information by email.