Privacy Policy
Privacy disclosures for personal information collected, used, shared, and retained by Suri.
Updated July 10, 2026
Privacy Policy
Effective date: July 10, 2026
Last updated: July 10, 2026
This Privacy Policy explains how LabLeoRex, Inc., doing business as Suri, collects, uses, discloses, retains, and protects personal information when you use the Suri mobile application, related websites, and services.
Suri is a United States service intended for adults. This Policy should be read together with the Terms and Conditions. A privacy policy is a notice of our practices and is not a request for consent where separate consent is required.
1. Privacy Summary
- We do not sell personal information or consumer health data.
- We do not use personal information or consumer health data for targeted or cross-context behavioral advertising.
- Most health-profile details you enter are maintained on your device rather than in Suri's central database.
- Some health-related identifiers, derived risk codes, product identifiers, symptom information, and request metadata are transmitted to our servers when you request interaction, personalization, scan, or symptom features.
- We use service providers to host the Service, store account and submission data, deliver email, distribute app updates, authenticate users, and verify app-store purchases.
- Suri is not a healthcare provider, health plan, or healthcare clearinghouse and does not represent that the Service is governed by HIPAA.
- You may delete your account in the app and may request access, correction, deletion, or other rights described below.
2. Scope
This Policy applies to personal information processed by Suri in connection with the Service. It does not govern an independent third party's service, such as Apple, Google, a device operating system, a government database, or an external website.
3. Information Stored on Your Device
If you choose to create a personal health profile, the app may maintain the following information on your device:
- Medication names, identifiers
- Supplement names and identifiers
- Food names and identifiers
The app attempts to use storage protections made available by the device operating system. Storage behavior may vary by device, operating-system version, device security settings, migration settings, and backup configuration. Suri does not guarantee that every form of local storage or device backup is encrypted or unavailable to a person who controls or compromises your device.
Suri does not maintain the complete local health profile in its central user database. However, local-only does not mean that no related information ever leaves the device. When you request certain features, the app transmits the limited information described in Section 4.
Deleting the app, clearing app data, changing devices, restoring a backup, or deleting a Suri account may affect local data differently. Use the in-app profile controls to remove local health information and the account-deletion control to request deletion of server-side information.
4. Health-Related and Product Request Data Transmitted to Suri
Depending on the feature you request, Suri may receive and process:
- Drug, supplement, food, product, ingredient, or barcode identifiers
- Active interaction trigger codes derived from medications you entered
- Counts of medications, supplements, or foods in a local profile
- Supplement and food database identifiers
- Products being compared against the local profile
- Technical request information such as account identifier, session information, and request time
This information may reveal or permit inferences about your medications, supplements, food products and is treated as sensitive health-related information.
We use the information to perform the lookup or interaction personalization; secure and troubleshoot the Service; enforce limits; and comply with law. We do not intentionally create a persistent server-side copy of your complete local health profile from these requests. Request contents may be processed in server memory, and limited request metadata may be retained in security or infrastructure logs as described in Section 10.
Do not enter names, contact information, medical-record numbers, insurance information, or other unnecessary identifiers in a symptom or support text field.
5. Other Information We Collect
Account and authentication information
We may collect:
- Email address
- Authentication provider and provider account identifier
- Authentication tokens, session tokens, and verification records
- Session IP address, user-agent information, creation time, and expiration time
- Account status, suspension information, and security events
Apple and Google may allow you to limit information shared during authentication. Their independent processing is governed by their policies.
Subscription and purchase information
For an Apple App Store or Google Play subscription, we may receive and store:
- Store provider and product identifier
- Subscription and billing period
- Purchase, transaction, or order identifier
- Purchase token or receipt-related payload
- Subscription status, renewal status, start date, and expiration date
- Refund or dispute information
This information is associated with your Suri account so we can verify and provide paid access. It is not anonymous. Apple or Google processes your payment credentials; Suri does not receive or store your full card number from an app-store purchase.
Suri does not currently offer direct card billing. If direct billing is introduced, this Policy and the purchase notice will be updated before collection begins.
Product reports, registrations, support, and feedback
If you contact us or submit a report, we may collect:
- Support category, subject, message, status, and resolution
- Product type, product identifier, product name, issue type, and correction details
- Optional contact email
- Barcode, product name, company name, and product-label image
- File content, file type, file metadata supplied with an upload, and review history
- Other information you choose to include
Product-label images are stored in cloud object storage. Do not include a face, prescription label, patient name, address, receipt, medical record, or other personal information in an image. If a product image is accepted into a public product record, a non-personal copy may remain as part of that record after the original submission is deleted.
Technical and network information
We and our infrastructure providers may process:
- IP address and approximate region inferred from IP
- Device type, operating system, app version, language, and user-agent information
- Request path, response status, request time, and performance information
- Authentication, security, fraud-prevention, and error information
- App update and delivery information
Suri does not currently use a third-party advertising SDK or cross-app behavioral advertising SDK.
Camera and photo access
Camera access is used to scan a barcode or capture a product image at your direction. Barcode image frames are processed on the device for scanning and are not intentionally uploaded as camera video. A product photograph is uploaded only when you choose to submit it through the product-registration flow.
Photo-library access is used only when you choose an image to submit. We do not request access to your contacts or precise GPS location for the current Service.
6. Sources of Information
We obtain information from:
- You, including information you enter, select, scan, photograph, or submit
- Your device and network when you use the Service
- Apple or Google when you authenticate or make an app-store purchase
- Service providers acting for Suri
- Public and third-party product, scientific, and government data sources
- Administrators and support personnel when they review a report, resolve a request, or protect the Service
7. How We Use Information
We use personal information for the following purposes:
- Create, authenticate, secure, and maintain accounts and sessions
- Provide product lookup, interaction, personalization, symptom, pet, subscription, and support features requested by you
- Verify subscription status and restore purchases
- Respond to support messages, correction requests, and product-registration submissions
- Operate, maintain, debug, protect, and improve the Service
- Detect fraud, abuse, unauthorized access, and security incidents
- Enforce the Terms and protect users, Suri, and others
- Send transactional, account, security, legal, and service communications
- Send marketing communications only if separately permitted, with an opt-out method
- Comply with law, legal process, tax, accounting, and regulatory obligations
- Create aggregated or de-identified information that cannot reasonably be linked to an individual
We will not use consumer health data for a materially different purpose without providing any notice and obtaining any consent required by law.
8. How We Disclose Information
We disclose information only as described below. We do not sell personal information or consumer health data. We do not disclose it for targeted or cross-context behavioral advertising.
Service providers
The providers used by the current Service include:
- Railway: application and API hosting; processes account, request, health-related request, and technical information as necessary to operate the Service
- Neon: hosted PostgreSQL database; stores account, authentication, subscription, support, report, product-registration, pet-setting, and administrative records
- Cloudflare R2: object storage for submitted product images and service content images
- Resend: delivery of transactional account and recovery email; processes recipient email address and email content
- Expo and EAS: app build, update, and delivery infrastructure; may process technical delivery information
- Apple: optional authentication, iOS app distribution, in-app purchase, subscription management, and device platform services
- Google: optional authentication, Android app distribution, in-app purchase, subscription management, and device platform services
Processors acting for Suri may use information only under instructions and contractual restrictions appropriate to the service they provide. Apple and Google may also act independently for their app-store, payment, device, or account services.
As of the effective date, Suri has no affiliate with which it shares consumer health data. If that changes, we will update this Policy before the new sharing begins and obtain consent where required.
Legal, safety, and security disclosures
We may disclose information when reasonably necessary to comply with law or valid legal process; investigate fraud, abuse, or security incidents; protect rights, safety, or property; or establish, exercise, or defend legal claims.
Business transactions
Information may be disclosed in connection with a proposed or completed financing, merger, acquisition, reorganization, bankruptcy, or sale of assets. A recipient must use protected information consistently with this Policy unless it provides legally required notice and obtains legally required consent.
At your direction
We may disclose information when you request or authorize the disclosure.
9. Consumer Health Data Privacy Notice
Suri maintains a separate Consumer Health Data Privacy Notice that explains the categories and sources of consumer health data, purposes of processing, service-provider recipients, consent and withdrawal, retention, deletion, and applicable consumer rights.
The current notice is available at:
https://checkable-production.up.railway.app/consumer-health-data-privacy
We do not sell consumer health data or use it for targeted or cross-context behavioral advertising. To exercise a consumer health data right, withdraw consent for future processing, request deletion, or appeal a decision, contact support@lableorexinc.com.
10. Retention
We retain personal information only for the period reasonably necessary for the disclosed purpose, security, legal compliance, or a documented legal claim. The current operational retention schedule is:
- Account profile and active authentication records: for the life of the account, then deleted or de-identified within 30 days after a verified deletion request, unless a limited exception applies
- Active sessions and verification records: until expiration, completion, sign-out, account deletion, or a shorter security cleanup period
- Health-related request contents: processed to return the requested result and not intentionally maintained as a persistent server-side health profile
- API security and infrastructure request metadata: up to 90 days
- App-store subscription and entitlement records: while needed to provide access and resolve billing, fraud, refund, or dispute issues; limited transaction records may be retained for up to seven years where required for tax or accounting
- Support tickets and correction reports: up to 3 years after closure
- Product-registration submissions and original submitted images: while pending and for up to 90 days after final resolution, unless needed for a legal claim; a non-personal image incorporated into a public product record may be retained as product data
- Consent and legal acceptance records: for the period required to demonstrate the consent or agreement, including any longer period required for automatic-renewal consent
- Backups: until overwritten under the applicable backup cycle; consumer health data deletion will comply with the maximum period required by applicable law
We may retain a minimal record of a deletion request, fraud event, legal hold, or transaction when necessary to document compliance, prevent abuse, comply with law, or resolve a dispute. We will not use such retained data for an unrelated purpose.
11. Security
We use administrative, technical, and organizational safeguards designed for the nature of the information processed. Measures include transport encryption, access restrictions, authentication controls, service-provider review, logging, and procedures for responding to security incidents.
No storage or transmission method is completely secure. We cannot guarantee that unauthorized access, loss, or misuse will never occur. You are responsible for securing your device, operating-system account, email account, and third-party sign-in account.
If a breach-notification law applies to an incident, including the FTC Health Breach Notification Rule where applicable, we will provide notices to affected individuals and regulators as required.
12. Your Choices and Privacy Rights
Depending on where you live and the law that applies, you may request access, confirmation, correction, deletion, portability, restriction, withdrawal of consent, or an appeal. You may also have a right to opt out of sale, targeted advertising, profiling, or certain disclosures.
Suri does not currently sell personal information, use it for targeted advertising, or use it for legally significant profiling. Therefore, an opt-out is not presently necessary for those activities. If those practices change, we will provide the required notice and controls before they begin.
You may:
- Update or remove local health-profile information in the app
- Change camera or photo permissions in device settings
- Cancel a subscription through Apple or Google subscription settings
- Unsubscribe from a marketing email using the link in that email
- Delete your Suri account in app settings
- Submit a privacy request through support@lableorexinc.com
We will not unlawfully discriminate against you for exercising a privacy right. We may need to verify your identity and authority. An authorized agent may submit a request where applicable, subject to verification.
13. California Notice at Collection and Privacy Rights
This Section applies to the extent California law applies. During the preceding 12 months, Suri may have collected the following California categories:
- Identifiers, including name, email, account identifier, IP address, provider account identifier, and session identifiers
- Customer records and commercial information, including subscription, product, transaction, and support records
- Internet or electronic activity, including request, device, app, and security information
- Audio, electronic, visual, or similar information, including a product image you choose to submit
- Inferences and sensitive personal information, including health-related queries, symptoms, medication-related trigger codes, and health information you choose to process through the Service
- Professional or employment information only if you voluntarily include it in a support communication, which we ask you not to do unless necessary
We collect these categories from the sources in Section 6 and use them for the purposes in Section 7. We disclose them for business purposes to the provider categories in Section 8. We do not sell these categories or share them for cross-context behavioral advertising. We do not offer a financial incentive in exchange for personal information.
Subject to applicable law, California residents may request to know, access, correct, delete, or obtain information about categories, sources, purposes, and recipients. They may also opt out of sale or sharing and limit certain uses of sensitive personal information. Because Suri does not presently sell or share personal information for cross-context behavioral advertising and uses sensitive information only for disclosed service purposes, those opt-outs do not presently change our processing.
If we later engage in a practice recognized by Global Privacy Control, we will process a valid signal as required. Browser Do Not Track signals are not currently used because the current mobile Service does not perform cross-site behavioral tracking.
14. Other United States State Rights
Residents of other states may have rights to access, correct, delete, obtain a copy of, or opt out of certain processing of personal information. Submit a request using the method in Section 12. We will apply the law that covers the request and provide an appeal process where required.
15. HIPAA
HIPAA generally applies to covered healthcare providers, health plans, healthcare clearinghouses, and their business associates. Suri is not currently acting as one of those entities when providing the consumer Service. Do not send protected health information to Suri on behalf of a HIPAA-covered entity unless we have entered into an appropriate written agreement and expressly authorized that use.
HIPAA status does not determine whether other privacy, consumer-protection, security, or breach-notification laws apply.
16. Children and Minors
Suri is intended only for adults who are at least 18. We do not knowingly allow a minor to create an account or knowingly collect personal information from a child under 13. If you believe a minor has provided information, contact support@lableorexinc.com so we can investigate and delete it as appropriate.
17. International Processing
Suri is operated from the United States, and information processed by our Service and providers may be stored in the United States. If we offer the Service in a country that requires a lawful international-transfer mechanism or additional notice, we will implement that mechanism and notice before relying on the transfer. Accessing the Service does not waive a non-waivable privacy right.
18. Device Backups and Third-Party Services
Your device manufacturer or operating-system provider may back up or retain app data according to your device and cloud-backup settings. Suri does not control a backup managed under your personal Apple, Google, or device account. Review those settings before entering sensitive information.
Third-party services have their own privacy policies. This Policy does not change their independent practices, but our processors remain subject to applicable contractual and legal obligations when processing information for Suri.
19. Changes to This Policy
We may update this Policy as the Service, data practices, providers, or law changes. We will update the effective date and provide additional notice before a material change takes effect. If a change requires consent, we will request consent rather than treating continued use alone as consent.
We will not begin collecting a new category of consumer health data or use existing consumer health data for a materially new purpose without the disclosure and affirmative consent required by law.
20. Contact and Requests
Data controller and service provider: LabLeoRex, Inc., doing business as Suri
Support email: support@lableorexinc.com
Account deletion instructions: https://checkable-production.up.railway.app/account-deletion
Consumer health data notice: https://checkable-production.up.railway.app/consumer-health-data-privacy