Addendum is a private, offline reflective journal for medical students. This policy explains what the app does and does not do with your information. In short: Addendum collects nothing, sends nothing, and stores everything encrypted on your device.
Nothing. Addendum has no analytics, no accounts, no advertising, and no third-party SDKs. Backshear LLC receives no data from your use of the app — we cannot see your journal, your usage, your device, or anything else.
Everything you write stays on your device only, inside an encrypted vault:
Backups and exports you create are written only where you choose (e.g., the Files app or a share-sheet destination you pick). Encrypted backups remain encrypted; de-identified text/PDF exports are produced locally.
If you choose to dictate a note, Addendum uses the microphone and Apple’s on-device speech recognition, which is forced to run entirely on your device. Audio is transcribed locally and is never sent to Apple or any server, and the audio itself is discarded — only the text you keep is saved, encrypted, in your journal. Permission is requested only the first time you tap to dictate.
If you turn on Settings → Reminders, Addendum schedules a small number of local notifications on your device — a nudge when your last backup is getting old, and a heads-up before a shelf exam you’ve dated in Pearls. These are scheduled entirely on this device (Apple’s local-notification system): there is no server, no push service, and nothing leaves your device. Notification text is deliberately generic — it never contains journal content, rotation names, or anything about a patient. The system permission prompt appears only when you turn the setting on, and turning it off (or erasing all data) removes every scheduled reminder. You can also verify the app’s build checksum and its live no-network policy at any time in Settings → Privacy you can verify (checksums are published on the Release checksums page).
None by default. Out of the box, Addendum makes zero network requests — enforced structurally
by a Content Security Policy (connect-src 'none') and a navigation guard in the app shell. You can
confirm it by turning on Airplane Mode; the app works fully.
Addendum offers an optional iCloud sync you can turn on in Settings → iCloud sync. When it’s on:
Addendum is designed to hold no patient identifiers. The data model never asks for names, dates of birth, record numbers, addresses, phone numbers, emails, photos, or provider names; ages are recorded only as broad bands, and encounters carry no calendar dates. A built-in check assists you in catching identifiers, but it is an assist, not a guarantee — you are responsible for keeping your entries de-identified and for following your school’s and hospital’s policies, which may be stricter than the law. Addendum is not a covered entity’s system and is not, by itself, “HIPAA compliant”; HIPAA compliance is a property of an organization’s program, not of an app.
Addendum is intended for adult medical students and is not directed to children.
You can erase all data at any time from Settings → Erase all data on this device. Because nothing is stored off-device, deleting the app (and any backups you made) removes your data entirely.
Addendum is a personal reflective journal — not an electronic health record, not clinical decision support, and not a substitute for any patient-encounter log your institution requires. It is provided “as is,” without warranty. To the fullest extent permitted by law, Backshear LLC is not liable for any loss or disclosure of information you choose to enter or export.
We may update this policy as the app evolves. Material changes will be reflected by an updated effective date.
Questions about this policy: open an issue · Backshear LLC.