Back to Home

CTGfai Privacy Policy

Last updated: 30 August 2026

This policy applies only to the CTGfai mobile app for iOS and Android, published by Tizfai Technologies AB. CTGfai is a decision-support tool for licensed midwives and physicians. It is not intended for patients and is not a substitute for clinical judgement.

1. Data We Process

  • Sign-in identity from Google or Apple: your name, your email address and the unique account identifier issued for CTGfai.
  • CTG images you capture or select for analysis, together with the clinical context you choose alongside them, such as gestational period and the assessment fields you fill in.
  • Assessment text generated from an analysis, including journal notes and any email address you enter to send a note to yourself.
  • Usage and entitlement data: how many assessments you have run, your chosen language, your professional type, and your subscription state.
  • Ratings and review comments you submit inside the app.
  • Technical identifiers attached by the authentication SDK, including an app installation identifier, the app identifier and basic device and OS information, plus the IP address the request arrives from.

2. What Is Not Stored

  • CTG images are not retained. An image is transmitted for analysis, the result is returned to your device, and the image is discarded. There is no image archive attached to your account.
  • CTGfai is designed so that no patient-identifying information needs to leave your device. The app provides a redaction tool so you can obscure names, personal identity numbers and any other identifying text visible on a trace before analysis. You remain responsible for using it.

3. Why We Process Data

  • To sign you in and keep your account and entitlements consistent across devices.
  • To produce the AI assessment and structured journal note you requested.
  • To count free, bonus and subscribed assessments and to apply your purchase.
  • To improve the quality of assessments using the feedback and ratings you give.
  • To detect abuse, investigate incidents and keep the service secure.

4. GDPR Legal Bases

  • Performance of a contract, for providing CTGfai and your subscription.
  • Legitimate interests, for securing the service, preventing misuse and maintaining service integrity.
  • Compliance with legal obligations, including accounting and security requirements.
  • Where a healthcare organization determines the purposes for which patient-related data is processed, that organization remains responsible for identifying the appropriate legal basis for it.

5. Third Parties Involved

CTGfai relies on a small number of named providers. They process data on our behalf under contractual confidentiality and data protection obligations. CTGfai does not sell personal data and does not use advertising or tracking SDKs.

  • OpenAI — CTG images and the clinical context you submit are sent to the OpenAI API to produce the assessment and the journal note. This is the only third party that receives image content.
  • Google Firebase Authentication — verifies your Google or Apple sign-in and issues the account identifier used by CTGfai.
  • Apple and Google — process your sign-in with Apple or Google and handle subscription purchases through their stores. We receive the resulting subscription state, not your payment details.
  • Hosting and infrastructure providers — operate the servers that run the CTGfai backend.

6. International Transfers

Analysis is performed by OpenAI, whose processing takes place partly outside the EEA, including in the United States. Where personal data is transferred outside the EEA or UK, we aim to rely on recognized transfer safeguards such as adequacy decisions or standard contractual clauses where required.

7. Security

  • All data in transit is protected with encrypted connections.
  • Every request that touches your account is bound to a verified sign-in token, so one account cannot act as another.
  • Access to backend data is restricted to authorized personnel.
  • The app is limited to verified licensed healthcare professionals.

8. Camera and Photo Permissions

  • Camera access is used to photograph a CTG trace.
  • Photo library access is used only when you choose an existing image.
  • Both can be withdrawn at any time from device settings.

9. Retention and Account Deletion

  • Account data is kept for as long as your account exists. CTG images are never retained, as described in section 2.
  • You can delete your account from inside the app at any time. It removes your name, email address, sign-in identity, assessment history, entitlements, ratings and activity log immediately, and the deletion cannot be reversed.
  • Full instructions, including what to do if you no longer have the app installed, are on the CTGfai account deletion page.
  • Deleting your account does not cancel a Google Play or App Store subscription. Cancel it in the store first, otherwise billing continues.

10. Your Rights Under GDPR

  • You may have rights of access, rectification, erasure, restriction, objection and data portability, subject to applicable law.
  • Where your healthcare organization controls the data, requests should normally be directed to that organization first.
  • We may need to verify identity and authority before acting on a request.

11. Complaints and Contact

For privacy requests, contact: kamal@tizfai.com

If you are in Sweden or the EEA, you may also have the right to lodge a complaint with your local supervisory authority. In Sweden, the supervisory authority is Integritetsskyddsmyndigheten (IMY).

12. Related Pages

  • CTGfai App Privacy
  • CTGfai EULA
  • CTGfai Account & Data Deletion