DRAFT — this policy has not been reviewed by counsel. It is published because the App Store requires a stable, reachable privacy-policy URL; legal review is tracked separately.
UIOLI · Portobello
Privacy Policy
Last updated: not yet in effect — draft. This policy describes the UIOLI app (iOS), the UIOLI web properties at uioli.co and api.uioli.co, and the licensee console at uioli.co/clients, operated by Portobello ("UIOLI", "we").
The short version
- Receipts you scan can reveal what you or your household bought — including medical purchases. We treat that as sensitive, and we say below exactly when it touches our servers.
- Research donation is opt-in and revocable. A donated receipt crosses to the research lab as a PII-free projection: item descriptions and amounts only — never the receipt photo, never your name or account details.
- We do not sell personal information, and we do not run advertising trackers in the app.
What we collect
Account information
When you create a UIOLI account: your name, email address, and either a password (stored as a salted hash) or a passkey (WebAuthn credential, which never leaves your device's authenticator). When you link an employer benefit plan, the plan's administrator shares your enrollment and account-type information (FSA or HRA) with us.
Receipts and claims
The core record you create is a ProofPacket: a receipt photograph, the line items extracted from it, eligibility categorizations, your attestation, and optionally a Letter of Medical Necessity (LMN). Because receipts list purchased items, these records may indirectly indicate medical conditions (for example, a purchase of prescription medication). We store them encrypted at rest, served only through authenticated routes.
Camera capture works on-device (Apple Vision text recognition). The receipt does cross to our servers when you choose "send it to the service for a packet" — that upload is what creates the sealed evidence record. A purchase that never leaves your phone is never uploaded.
Usage and audit data
We log security and compliance events (sign-ins, attestations, packet access) as an append-only audit trail, because substantiation records must be reproducible for IRS review. On the marketing site, the "request a conversation" form collects your email, organization, and role solely to respond to the inquiry.
How we use it
- To build, seal, and — at your direction — deliver proof packets to your plan's TPA or employer administrator, who then adjudicate the claim. UIOLI does not adjudicate, pay, or hold your money.
- To operate the accounts, notifications, and support tied to your use of the app.
- For research, only under the separate consent described below.
Research contribution (separate, revocable consent)
You may enroll the app's "research contribution" setting. If you do, receipts you explicitly donate are sent to our research partner lab as a PII-free projection: item descriptions and amounts, and nothing else — never the receipt photograph, never your name, email, account identifiers, or plan details. Consent is versioned and timestamped; revoking stops all future donations immediately. Receipts already donated are handled lab-side under the projection agreement. Enrolling or revoking has no effect on your claims, reimbursements, or access to the app.
Who we share with
- Your TPA / plan administrator / employer — only the packets you submit to them, plus the minimum needed to verify your eligibility and balance.
- Research lab — only PII-free projections of receipts you donate under the consent above.
- Infrastructure vendors (Google Cloud / Firebase Hosting and Cloud Run) as data processors under confidentiality obligations.
- Business associates our plan-administration partners designate — our infrastructure is HIPAA-eligible, and a Business Associate Agreement applies where PHI flows under a plan administration engagement.
We do not sell personal information. We do not share it for advertising.
Retention
Substantiation records (packets, attestations, audit trail) are retained for a minimum of seven years, the IRS substantiation horizon for spending accounts, even if you close your account — the records that protected your claim are the records that must survive it. Account credentials, preferences, and anything not part of a substantiation record are deleted on account closure. Receipt photos are retained as part of the sealed evidence record; that is disclosed at capture.
Your choices
- Review and revoke research consent any time in Settings → Research contribution.
- Delete your account in Settings; substantiation retention above still applies.
- Decline uploads: advisory on-device checks never send your receipt anywhere.
- Questions, access, or correction requests: hello@uioli.app.
Children and scope
UIOLI is a benefit-administration tool for adults with employer or custodial spending accounts. It is not directed at children. This policy does not cover third-party sites we link to.
Changes
If this policy changes materially, we will update the date above and — for research consent specifically — re-ask rather than inherit your old yes.
Draft v0 · https://uioli.co/privacy
Also draft: Terms of Service · How to read a proof packet · UIOLI home