Baseline — Privacy Policy
Last updated 2026-08-24
Baseline keeps your medical documents on your own device and in your own iCloud account. There is no Baseline account, no sign-up, and no server holding your records. When you add a document, its page is sent once to an AI model so it can be titled and dated accurately — and is not kept there.
Where your documents live
- On your device. Every page image and everything you can see in the app — titles, dates, summaries, the search index and your conversations — is stored in a database on the device.
- In your iCloud, if you are signed in. See below.
- Nowhere else. There is no Baseline server holding a copy of your archive.
iCloud sync
If you are signed in to iCloud, your documents sync through your own iCloud private database, so they appear on your other devices. That data belongs to your Apple Account and is governed by Apple's privacy policy. We have no access to it and no ability to read it. Signing out of iCloud is fully supported — the app works, without sync.
What is sent off the device, and when
Three things are sent to Baseline's gateway, which forwards them to an AI provider and keeps nothing:
- Adding a document. The page is read on your phone first, using Apple's Vision framework. Then the page image and that recognised text are both sent, once, so the document can be given a title, a date, a provider and a one-line summary. Sending the image is what makes the date and the clinic reliable — both are often printed in a letterhead that plain text recognition flattens away. At most the first six pages of a document are sent as images; the rest are sent as text.
- Indexing for search. The recognised text only is sent once, to produce the numeric vector that makes search work.
- Asking a question. Your question is sent as text only, plus only the documents the model explicitly asks to read while answering it.
Nothing else is sent. There is no background upload and no telemetry, and no page is ever sent a second time.
What the gateway keeps
Nothing. The gateway has no database. It receives the page, forwards it, returns the answer, and forgets it. It is operated on Cloudflare Workers, which processes the request and keeps short-lived operational logs (timing, status codes and errors) for reliability; those logs are not used to build any profile of you.
Who else processes the text
The gateway routes model requests through OpenRouter, which passes them to the model provider:
- Anthropic (Claude) — titling documents and answering questions.
- Google (Gemini embeddings) — producing the search index.
These providers process the page image and text to return a result. Baseline does not permit your content to be used to train models.
What we never collect
- No account, email address, password or phone number.
- No analytics, tracking, advertising identifiers or third-party SDKs of that kind.
- No name, date of birth or any patient identifier — the app never asks for one.
- No location.
Deleting your data
Open Settings → Delete everything in the app. That removes every document, page and conversation from the device and from your iCloud private database. Because the gateway stores nothing, there is nothing else to delete. Deleting the app removes the on-device copy; if you also want the iCloud copy gone, use Delete everything first.
Children
Baseline is not directed at children and does not knowingly collect information from them.
Not medical advice
Baseline is not a medical device and does not diagnose. It organises what your clinicians wrote and shows it back to you. What a result means for your health is a conversation for your doctor.
Changes
If this policy changes, the date at the top changes with it.