Privacy policy
Effective 15 August 2026
Arkalife keeps lab reports, readings and related records so you can review them over time. This policy explains what the product stores, what optional analytics can receive and the limits we place between clinical content and behavioural data.
Information stored by Arkalife
Arkalife stores account details, including your email address and a pseudonymous account identifier. A profile can include a name, date of birth, sex, height, diet, relationship and dated weight measurements.
When you upload a report, Arkalife stores the uploaded file and its report details, the extraction draft used by the review screen, and the results you confirm. Confirmed results can include the lab's printed test name, value, unit and reference range, canonical values, marker mapping and descriptive range flag. Arkalife also stores saved chat conversations and messages, and records needed for family profiles and invitations.
Optional product analytics
If you give analytics consent, Arkalife may send PostHog the following named product events and only their fixed properties:
- Signup started: which sign-in provider button was pressed.
- Signup completed: the number of onboarding steps completed.
- Report upload started: whether the report came from a camera or file.
- Extraction completed: duration and result and unmapped-result counts.
- Extraction failed: a fixed failure category.
- Review opened: result counts and a fixed patient-name match status.
- Review edited: the kind of field edited.
- Report confirmed: result, edited-result and unmapped-result counts.
- Marker viewed: the broad panel category, not the marker identity.
- Chat turn sent: the turn number, not the question or answer.
- Guide read: the published guide that was opened.
Analytics can also include fully-masked session replays and error reports. Session replays mask all text and all form inputs; they can show page layout and interactions such as clicks and scrolls. Arkalife removes query strings and fragments from its own URLs, and replaces marker, report, invitation, chat and guide identifiers in URL paths with route patterns before analytics properties are sent.
Sign-in counts, sent without consent
Arkalife counts three things about the sign-in screen itself. It does this before you have an account, and therefore before you have been asked for analytics consent:
- Sign-in screen shown: whether the screen was displaying an error.
- Sign-in button pressed: which provider button was pressed.
- Sign-in result: a fixed outcome — signed in, cancelled at the provider, or one of three failure categories.
These are counts and nothing else. They carry no account identifier, no email address, no name, no IP address, no location, and no identifier of any kind for you or your device — not even a temporary one, and no cookie is set. Each one is recorded against a single shared placeholder identifier, so they can be added up but cannot be grouped by person, linked to one another, or linked to you if you later sign in.
They exist because without them Arkalife cannot tell whether people who try to sign in are failing to. Nothing about your health records is involved.
Clinical content excluded from PostHog
PostHog does not receive lab values, reference ranges, patient names, marker identities, or the contents of chat questions or answers. It receives a pseudonymous account identifier for an account, never the account's email address or name. The sign-in counts described above carry no account identifier at all.
Your IP address is discarded on arrival and is never stored, so analytics carries no location derived from it. Arkalife does not record browser console output, does not automatically capture the text of elements you click, and does not collect heatmaps.
Processors and their different roles
Anthropic processes uploaded reports because extracting information from a report is a product function. The uploaded report therefore contains the clinical content needed for extraction.
PostHog, in its United States region, processes behavioural events only. PostHog receives no clinical content and no email address or name.
Meta receives conversion measurement for advertising, and only for visitors who reached Arkalife by clicking a Meta advertisement. If you arrived any other way, nothing about your visit is sent to Meta at any point. What is sent is the click identifier Meta itself added to the link you followed and, if you gave analytics consent, a one-way hash of your email address. A hash is not anonymous — Meta can match it to an account it already holds — which is why it is sent only with consent. Meta never receives a lab value, a reference range, a test or marker name, a report, a patient name, or anything else about your health records. There is no Meta tracking script anywhere on this site.
Consent and choice
Arkalife asks for analytics consent at signup and records the version of the policy you accepted. Consent to an older policy version does not count as consent to a materially changed policy. If you withhold analytics consent, the app works fully and no product analytics events are sent. The only exception is the sign-in counts described above, which carry no identifier of any kind and are not tied to you or your account.
Retention
Health records and reports are retained for as long as the account exists and are deleted within 30 days of account deletion. PostHog analytics events are retained for 12 months, and session replays for 30 days.
Medical disclaimer
Arkalife is a record-keeping tool, not a source of medical advice. Arkalife does not provide medical advice, diagnosis, or interpretation. Consult a physician about your health, results and care.