Log4Surg (UK Surgical Logbook)
Effective Date: September 27, 2026
Developer: M-PAX Group · App: Log4Surg (iOS, iPhone, iOS 17+, Bundle ID net.m-pax.Log4Surg)
Log4Surg is an offline-first operative logbook for UK surgical trainees: fast case entry with exact UK role terminology, ARCP-ready SAC and consolidation reports, validation tracking, and PDF/CSV export. It is designed so that we, the developer, do not operate a server, do not create accounts, and do not receive your logbook.
Short version:
We collect nothing automatically. Log4Surg contains no third-party analytics, crash-reporting SDKs, advertising SDKs, session replay, or fingerprinting. Crash diagnostics are Apple-only. We do not sell personal data and we do not share personal data with data brokers.
The only personal information we ever receive is what you choose to send us yourself, for example if you email [email protected] for support. We use such messages only to answer you, and we delete them on request. A “Copy diagnostics” button in the app’s About screen copies only app version, iOS version, dictionary version and case count — never case contents — for you to paste into a support email if you wish.
Anything you record (trainee name, grade, specialty, deanery, programme/NTN, GMC number, placements, hospitals, consultants/supervisors and their GMC numbers, procedures, roles, urgency flags, operation parts, hospital numbers, patient dates of birth, notes, validation status, settings) is stored in two places, both under your control:
NSFileProtectionComplete); sensitive fields (hospital number, patient date of birth, notes) are additionally encrypted with a key held in the Secure Enclave / keychain. Every feature works offline, including in airplane mode.Apple processes iCloud Drive data under your Apple services relationship — please see Apple’s Privacy Policy for Apple’s handling. There is no developer backend, and no cross-device sync beyond your own iCloud Drive backup/restore. Deleting the app deletes the on-device data; your iCloud Drive backup archives remain until you (the account holder) remove them.
Restore replaces current data from an iCloud Drive backup only after explicit confirmation, and only after a final local backup is taken.
| Category | Examples | Stored where |
|---|---|---|
| Logbook content you enter | Procedures, roles (O/A/S-TS/S-TU/P/T), urgency, hospitals, consultants, placements, hospital numbers, patient dates of birth, notes, validation status | Your device + your iCloud Drive backups. Never on a developer server. |
| Trainee details you enter | Name, grade, specialty, deanery, programme/NTN, GMC number, ARCP date | Your device (+ included in backups and report headers you export). Never on a developer server. |
| Device-private settings | Appearance, app lock & PIN settings, notification choices, indicative-number targets, favourites | Your device only (backed up as part of your archive). Never synced anywhere else. |
| Data the app refuses to store | Patient names, addresses, NHS numbers, photos | Nowhere — no such fields or columns exist. CSV import rejects identifier-like columns (e.g. “patient_name”) with an explanation instead of importing them. |
Log4Surg deliberately does not ask for precise location, contacts upload, HealthKit data, or photo-library access. Logbook content is exactly what you typed — there is no enrichment, matching, or profiling. Reports are computed live on-device from your cases by a single aggregation function; nothing is uploaded for computation.
Log4Surg has no accounts, no messaging and no server upload. Case data and reports leave the device only through your explicit actions: the iOS share sheet (PDF reports, grouped-summary CSV, raw-cases CSV, full backup files), Print, or Save to Files. Nothing is transmitted anywhere by the app except through those actions you initiate.
A warning is shown before exporting raw cases: “This file contains hospital numbers and patient dates of birth.” PDFs carry an anonymisation footer (“Contains hospital numbers and dates of birth only — no patient names”).
Request-validation messages (per case, per consultant, or bulk) are composed in-app listing unvalidated cases — the app does not email silently; you send the message yourself.
Import accepts the app’s own raw-cases CSV (round-trip) and an eLogbook-export mapping flow (pick file → map each column → preview 5 rows → import). Imports map only permitted columns; identifier-like columns are rejected with an explanation, future dates are rejected, and duplicates (same date + procedure + hospital number + date of birth) are offered as skip/review. Every imported case is tagged as a CSV import and starts unvalidated.
Log4Surg is an independent companion tool. It does not sync with elogbook.org (no public API exists), does not write to ISCP, and is not affiliated with or endorsed by elogbook.org, ISCP, JCST or the GMC. It does not record WBAs (CBD / CEX / DOPS / PBA / MSF — those live in ISCP) and never claims OPCS-4 compatibility.
The first release of Log4Surg contains no in-app purchase and no subscription: case entry, reports and export are fully available. If a future monetisation model is introduced, this policy and the App Privacy labels will be updated before release. Whatever model is chosen, records already logged will stay viewable and exportable.
Use of the app is governed by Apple’s Standard Licensed Application End User License Agreement: https://www.apple.com/legal/internet-services/itunes/dev/stdeula/.
App Privacy: Data Not Collected applies to the developer. User-entered logbook content is stored by the user on-device and in the user’s own iCloud Drive at the user’s direction and is not collected by the developer. The app declares no tracking and includes no third-party SDKs. The app’s privacy manifest reflects this.
Notes for review: the app stores medical training records (operative experience), not patient-care data, and contains no patient names by design. Any “sign-in” or “passcode” in the app is the local app lock (Face ID / Touch ID with PIN fallback), not an account. All features work fully offline; no demo account or test server is needed.
Because there is no developer account or database, privacy access/deletion requests are fulfilled by these in-app steps. If you need help, email us and we will walk you through them.
Records are protected by iOS complete file protection, with sensitive fields additionally encrypted via a Secure Enclave / keychain key. The app lock engages on backgrounding after a configurable interval (default 60 seconds). Temporary export files are deleted after sharing or on next launch. Report numbers are produced by one audited on-device computation — the generation timestamp, scope, filters, dictionary version and case count are printed on every report so any number can be traced back.
Log4Surg is intended for adult surgical trainees. We do not knowingly collect children’s data as a developer; any hospital numbers or dates of birth a trainee chooses to record are stored only on the trainee’s device / the trainee’s iCloud Drive as described above, and patient names cannot be recorded at all.
If privacy practices change (e.g. a future optional purchase or analytics feature), this page will be updated with a new effective date, and the app’s privacy manifest / App Privacy labels will be updated before release. Material changes will also be noted in release notes.
Developer: M-PAX Group.
Privacy / support: [email protected]
Support page: https://m-pax.net/log4surg.html
If you are in the UK/EU and have a data-protection question, include “Log4Surg privacy” in the subject line and we will respond. Since we hold no developer-side account data, most requests are resolved with the in-app export / delete steps in section 12. The trainee remains the data controller for their logbook.