Privacy Policy

Log4Surg (UK Surgical Logbook)

Log4Surg

Effective Date: September 27, 2026

Developer: M-PAX Group · App: Log4Surg (iOS, iPhone, iOS 17+, Bundle ID net.m-pax.Log4Surg)

Log4Surg is an offline-first operative logbook for UK surgical trainees: fast case entry with exact UK role terminology, ARCP-ready SAC and consolidation reports, validation tracking, and PDF/CSV export. It is designed so that we, the developer, do not operate a server, do not create accounts, and do not receive your logbook.

Short version:

1. Data we (the developer) collect

We collect nothing automatically. Log4Surg contains no third-party analytics, crash-reporting SDKs, advertising SDKs, session replay, or fingerprinting. Crash diagnostics are Apple-only. We do not sell personal data and we do not share personal data with data brokers.

The only personal information we ever receive is what you choose to send us yourself, for example if you email [email protected] for support. We use such messages only to answer you, and we delete them on request. A “Copy diagnostics” button in the app’s About screen copies only app version, iOS version, dictionary version and case count — never case contents — for you to paste into a support email if you wish.

2. Data you enter in the app — where it lives

Anything you record (trainee name, grade, specialty, deanery, programme/NTN, GMC number, placements, hospitals, consultants/supervisors and their GMC numbers, procedures, roles, urgency flags, operation parts, hospital numbers, patient dates of birth, notes, validation status, settings) is stored in two places, both under your control:

Apple processes iCloud Drive data under your Apple services relationship — please see Apple’s Privacy Policy for Apple’s handling. There is no developer backend, and no cross-device sync beyond your own iCloud Drive backup/restore. Deleting the app deletes the on-device data; your iCloud Drive backup archives remain until you (the account holder) remove them.

Restore replaces current data from an iCloud Drive backup only after explicit confirmation, and only after a final local backup is taken.

CategoryExamplesStored where
Logbook content you enterProcedures, roles (O/A/S-TS/S-TU/P/T), urgency, hospitals, consultants, placements, hospital numbers, patient dates of birth, notes, validation statusYour device + your iCloud Drive backups. Never on a developer server.
Trainee details you enterName, grade, specialty, deanery, programme/NTN, GMC number, ARCP dateYour device (+ included in backups and report headers you export). Never on a developer server.
Device-private settingsAppearance, app lock & PIN settings, notification choices, indicative-number targets, favouritesYour device only (backed up as part of your archive). Never synced anywhere else.
Data the app refuses to storePatient names, addresses, NHS numbers, photosNowhere — no such fields or columns exist. CSV import rejects identifier-like columns (e.g. “patient_name”) with an explanation instead of importing them.

3. Anonymisation guardrails (structural, not just policy)

4. Data minimisation

Log4Surg deliberately does not ask for precise location, contacts upload, HealthKit data, or photo-library access. Logbook content is exactly what you typed — there is no enrichment, matching, or profiling. Reports are computed live on-device from your cases by a single aggregation function; nothing is uploaded for computation.

5. Device permissions

6. Sharing and export (you send; the app never sends itself)

Log4Surg has no accounts, no messaging and no server upload. Case data and reports leave the device only through your explicit actions: the iOS share sheet (PDF reports, grouped-summary CSV, raw-cases CSV, full backup files), Print, or Save to Files. Nothing is transmitted anywhere by the app except through those actions you initiate.

A warning is shown before exporting raw cases: “This file contains hospital numbers and patient dates of birth.” PDFs carry an anonymisation footer (“Contains hospital numbers and dates of birth only — no patient names”).

Request-validation messages (per case, per consultant, or bulk) are composed in-app listing unvalidated cases — the app does not email silently; you send the message yourself.

7. CSV import

Import accepts the app’s own raw-cases CSV (round-trip) and an eLogbook-export mapping flow (pick file → map each column → preview 5 rows → import). Imports map only permitted columns; identifier-like columns are rejected with an explanation, future dates are rejected, and duplicates (same date + procedure + hospital number + date of birth) are offered as skip/review. Every imported case is tagged as a CSV import and starts unvalidated.

8. Relationship to elogbook.org, ISCP, JCST and GMC

Log4Surg is an independent companion tool. It does not sync with elogbook.org (no public API exists), does not write to ISCP, and is not affiliated with or endorsed by elogbook.org, ISCP, JCST or the GMC. It does not record WBAs (CBD / CEX / DOPS / PBA / MSF — those live in ISCP) and never claims OPCS-4 compatibility.

9. Purchases

The first release of Log4Surg contains no in-app purchase and no subscription: case entry, reports and export are fully available. If a future monetisation model is introduced, this policy and the App Privacy labels will be updated before release. Whatever model is chosen, records already logged will stay viewable and exportable.

Use of the app is governed by Apple’s Standard Licensed Application End User License Agreement: https://www.apple.com/legal/internet-services/itunes/dev/stdeula/.

10. What we do NOT do

11. Apple privacy labels & manifest (for App Store review)

App Privacy: Data Not Collected applies to the developer. User-entered logbook content is stored by the user on-device and in the user’s own iCloud Drive at the user’s direction and is not collected by the developer. The app declares no tracking and includes no third-party SDKs. The app’s privacy manifest reflects this.

Notes for review: the app stores medical training records (operative experience), not patient-care data, and contains no patient names by design. Any “sign-in” or “passcode” in the app is the local app lock (Face ID / Touch ID with PIN fallback), not an account. All features work fully offline; no demo account or test server is needed.

12. Retention, export & deletion (your control)

Because there is no developer account or database, privacy access/deletion requests are fulfilled by these in-app steps. If you need help, email us and we will walk you through them.

13. Security

Records are protected by iOS complete file protection, with sensitive fields additionally encrypted via a Secure Enclave / keychain key. The app lock engages on backgrounding after a configurable interval (default 60 seconds). Temporary export files are deleted after sharing or on next launch. Report numbers are produced by one audited on-device computation — the generation timestamp, scope, filters, dictionary version and case count are printed on every report so any number can be traced back.

14. Children

Log4Surg is intended for adult surgical trainees. We do not knowingly collect children’s data as a developer; any hospital numbers or dates of birth a trainee chooses to record are stored only on the trainee’s device / the trainee’s iCloud Drive as described above, and patient names cannot be recorded at all.

15. Changes to this policy

If privacy practices change (e.g. a future optional purchase or analytics feature), this page will be updated with a new effective date, and the app’s privacy manifest / App Privacy labels will be updated before release. Material changes will also be noted in release notes.

16. Contact

Developer: M-PAX Group.
Privacy / support: [email protected]
Support page: https://m-pax.net/log4surg.html

If you are in the UK/EU and have a data-protection question, include “Log4Surg privacy” in the subject line and we will respond. Since we hold no developer-side account data, most requests are resolved with the in-app export / delete steps in section 12. The trainee remains the data controller for their logbook.