Privacy Policy for ScopeXR
Effective Date: 6/14/26
ScopeXR Inc. (“ScopeXR,” “we,” “us,” or “our”) operates the ScopeXR application (the “App”) for visionOS and the scopexr.com website (the “Website”). This Privacy Policy describes how information is handled when you use the App or visit the Website.
1. Scope and Audience
ScopeXR is intended exclusively for licensed healthcare professionals, including practicing physicians. The App is not designed for children and is not directed toward individuals under the age of 13.
2. Data We Do Not Collect
ScopeXR is architected to operate entirely without collecting, storing, or transmitting personal data or patient data.
Specifically:
- No user accounts or authentication
- No names, email addresses, or personal identifiers
- No patient information
- No backend databases or cloud storage
- No data synchronization across devices
- No HealthKit or health data collection
To the maximum extent possible, the App functions locally on the device.
3. On-Device Access and Processing
The App may access certain device resources only at the user’s explicit initiation and control, and only for real-time functionality:
- Files: Local or cloud-connected files may be accessed for in-app use. File contents do not leave the device.
- Video & Network Sources: Local or network video sources, including NDI streams and HDMI/USB capture devices. All processing is local.
- FaceTime: The App can initiate FaceTime calls using Apple’s infrastructure. Calls may include the user’s Persona and voice audio. ScopeXR does not receive or store FaceTime content.
The App does not access photos, location data, or HealthKit.
4. Analytics and Diagnostics (De-Identified)
ScopeXR uses limited third-party services for analytics and diagnostics in a de-identified and anonymized manner.
TelemetryDeck (Analytics)
- Used for aggregated App usage, Website page-view, and performance metrics
- Configured in anonymous mode
- No user accounts or persistent identifiers
- No user-entered content collected
- Technical metadata such as filenames and USB device identifiers may be logged for diagnostics only
On the Website, TelemetryDeck may process the page URL, referring URL, campaign parameters, approximate country or region, browser type, operating system, device category, and related technical metadata. TelemetryDeck does not use cookies or fingerprinting. It derives a privacy-preserving identifier from the IP address, user agent, App ID, and a daily changing salt; the resulting identifier cannot recognize a visitor across different days.
Sentry (Error and Event Logging)
- Used for crash reporting and performance monitoring
- May collect stack traces, breadcrumbs, and device/OS information
- No personal identifiers or patient data collected
IP Addresses
TelemetryDeck and Sentry may process IP addresses as part of standard network operations. ScopeXR does not intentionally collect, store, or associate IP addresses with individual users.
5. Third-Party Libraries
The App includes the NDI library for video streaming. NDI data is processed locally or within the user’s network and is not transmitted to ScopeXR servers.
6. Monetization and Advertising
- No advertising
- No in-app purchases or subscriptions
7. Regulatory Considerations
Because ScopeXR does not collect personal data:
- GDPR: No processing of personal data as defined by GDPR
- CCPA/CPRA: No collection, sale, or sharing of personal information
- HIPAA: No creation, receipt, maintenance, or transmission of PHI
8. Data Retention and Deletion
ScopeXR does not store personal data. De-identified diagnostic data retention is governed by third-party providers’ policies.
9. Security
ScopeXR follows industry best practices emphasizing local-only processing and minimal data exposure.
10. Changes to This Policy
This Privacy Policy may be updated periodically. Updates will be reflected by a revised effective date.
11. Contact Information
ScopeXR Inc.
Email: support@scopexr.com