Privacy
BP Log holds health information, so it’s worth being exact about what that means. This page says what’s stored, who it reaches, and how to get rid of it.
Last updated 19 August 2026
What’s stored
Three things, and nothing else.
- Your account. An email address, and a name if one was supplied — either by the provider you signed in with, or typed into Settings. No profile picture: Google offers one and BP Log declines it, because the avatar you see is a drawn mark rather than a photo. Signing in with Apple may give a private relay address, or no address at all; both work.
- Your readings. Systolic and diastolic pressure, and optionally a pulse, a note, and which arm was used. Each one carries the time you say it was taken and the time it was recorded. The note is free text — whatever you put there is stored as you wrote it.
- How you sign in. For Google or Apple, the tokens that provider issues, which is what lets us confirm it’s you on your next visit and, for Apple, revoke our access when you delete your account. There are no passwords in BP Log, so there are none to store or lose.
What isn’t
No analytics, no advertising, no tracking pixels, no session recording, no third-party scripts, and no marketing email. The only message BP Log ever sends is a sign-in link you asked for.
Your readings are never sold or shared, and are not used to train machine-learning models — ours or anyone else’s.
Cookies and browser storage
The cookies BP Log sets are the ones that make signing in work: one that keeps you signed in, and two short-lived ones that protect the sign-in form against forgery. There are no advertising or analytics cookies, which is why you have never seen a cookie banner here.
Your browser also remembers three preferences locally, on your device only: your light or dark theme, whether the report hides your name, and how much history the report covers.
Who processes it
BP Log is run by Moonshot Labs LLC and relies on a small number of providers to operate. Each one sees only what it needs to:
- Vercel — hosting. Serves the app and processes requests.
- Neon — the database your account and readings are stored in.
- Resend — sends sign-in emails. Sees your email address, and nothing else.
- Google and Apple — only if you choose to sign in with them, and only to confirm who you are.
All of these are United States companies, and your data is processed in the United States.
Anything you export
The doctor’s report — as an image, a CSV, or a printout — is the one thing that leaves BP Log, and it leaves because you asked it to. Once it’s a file on your device, where it goes next is up to you, and this policy no longer reaches it.
Because that file is designed to be handed to someone, the Hide name switch on the report is on by default: an exported report carries your readings but not your name unless you turn it off.
Deleting everything
Settings → Delete account. It is immediate, permanent, and takes nothing on our side: your account, every reading attached to it, your sessions and your sign-in records are removed together, and any unused sign-in link that was still outstanding is invalidated. If you signed in with Apple, we revoke our access with Apple first.
There is no grace period and no archived copy — once it’s gone we cannot restore it, so export a CSV first if you want to keep your history.
Your rights over your data
- See it. The app shows everything it holds about you. The CSV export gives you a machine-readable copy.
- Correct it. Every reading can be edited or deleted, and your name changed, from inside the app.
- Delete it. As above, without asking anyone.
Depending on where you live you may have further rights — to object to processing, or to have your data sent elsewhere. Write to us and we’ll act on it.
Keeping it safe
Everything travels over HTTPS. Session cookies can’t be read by scripts in your browser. There are no passwords to be stolen, since BP Log has none. Readings are scoped to the account that created them at the database level, so one account cannot read another’s.
No service can promise perfect security, and this one doesn’t. What it can promise is a small amount of data in few places, which is the part that actually reduces the risk.
Children
BP Log isn’t directed at children under 13, and we don’t knowingly collect their information. If you believe a child has created an account, write to us and we’ll delete it.
Changes to this policy
If this policy changes in a way that affects what’s collected or who sees it, the date at the top will change and we’ll say so in the app before it takes effect.
Contact
Questions about any of this, or a request you’d rather make in writing: support@bplog.me.