DRAFT — this policy has not been reviewed by counsel. It is published because the App Store requires a stable, reachable privacy-policy URL; legal review is tracked separately.

UIOLI · Portobello

Privacy Policy

Last updated: not yet in effect — draft. This policy describes the UIOLI app (iOS), the UIOLI web properties at uioli.co and api.uioli.co, and the licensee console at uioli.co/clients, operated by Portobello ("UIOLI", "we").

The short version

What we collect

Account information

When you create a UIOLI account: your name, email address, and either a password (stored as a salted hash) or a passkey (WebAuthn credential, which never leaves your device's authenticator). When you link an employer benefit plan, the plan's administrator shares your enrollment and account-type information (FSA or HRA) with us.

Receipts and claims

The core record you create is a ProofPacket: a receipt photograph, the line items extracted from it, eligibility categorizations, your attestation, and optionally a Letter of Medical Necessity (LMN). Because receipts list purchased items, these records may indirectly indicate medical conditions (for example, a purchase of prescription medication). We store them encrypted at rest, served only through authenticated routes.

Camera capture works on-device (Apple Vision text recognition). The receipt does cross to our servers when you choose "send it to the service for a packet" — that upload is what creates the sealed evidence record. A purchase that never leaves your phone is never uploaded.

Usage and audit data

We log security and compliance events (sign-ins, attestations, packet access) as an append-only audit trail, because substantiation records must be reproducible for IRS review. On the marketing site, the "request a conversation" form collects your email, organization, and role solely to respond to the inquiry.

How we use it

Research contribution (separate, revocable consent)

You may enroll the app's "research contribution" setting. If you do, receipts you explicitly donate are sent to our research partner lab as a PII-free projection: item descriptions and amounts, and nothing else — never the receipt photograph, never your name, email, account identifiers, or plan details. Consent is versioned and timestamped; revoking stops all future donations immediately. Receipts already donated are handled lab-side under the projection agreement. Enrolling or revoking has no effect on your claims, reimbursements, or access to the app.

Who we share with

We do not sell personal information. We do not share it for advertising.

Retention

Substantiation records (packets, attestations, audit trail) are retained for a minimum of seven years, the IRS substantiation horizon for spending accounts, even if you close your account — the records that protected your claim are the records that must survive it. Account credentials, preferences, and anything not part of a substantiation record are deleted on account closure. Receipt photos are retained as part of the sealed evidence record; that is disclosed at capture.

Your choices

Children and scope

UIOLI is a benefit-administration tool for adults with employer or custodial spending accounts. It is not directed at children. This policy does not cover third-party sites we link to.

Changes

If this policy changes materially, we will update the date above and — for research consent specifically — re-ask rather than inherit your old yes.

Draft v0 · https://uioli.co/privacy

Also draft: Terms of Service · How to read a proof packet · UIOLI home