UroRef is an educational urology reference app built by Nity G (Urology SpR, North West Deanery). Its core reference content is bundled with the app and can be used offline. Optional online features include Ask Ariadne, live hospital-profile updates, hospital requests, externally hosted QR images and links to third-party websites. This notice explains what those features process and why.
Who we are
Data controller: Nity G, trading as UroRef. For privacy questions or a deletion request, email nity@uroref.com.
What this website collects
- No account, no login. The public website does not require an account.
- Private site search. Pagefind processes a downloaded static index in your browser. Search text is not added to result URLs or sent to an analytics service.
- Analytics are disabled by default. The site can be connected to an approved Umami installation for limited, aggregate measurement. It will not be enabled until its hosting, retention, consent position and event list are agreed. Search text, free text, patient details and session replay must not be collected.
- Feedback form — if you submit our Google feedback form, the data goes to Google Forms under their privacy policy. We use it only to improve UroRef.
Public showcase demonstration
The Ask Ariadne panel in the public showcase is fixed demonstration copy: it does not send the example question to a model or external service.
The interactive app preview at Try UroRef is different: it runs the production interface packaged with the Android app. Optional connected features in that preview, including Ask Ariadne and live hospital data, process information as described below. Preferences and recent activity may be stored in your browser rather than on an installed device.
Do not enter patient-identifiable or confidential information into site search, feedback forms or any demonstration.
Core app and on-device data
The app does not require an account. Core reference content works offline. Preferences, recent searches, pinned items, review-prompt state and your selected hospital are kept on your device. UroRef does not include advertising SDKs or third-party app-analytics SDKs, does not use cross-app tracking and does not sell personal data.
Ask Ariadne — optional online feature
Ariadne requires an internet connection. When you submit a question, the app sends the text you enter, up to six recent chat messages, a persistent random pseudonymous device identifier, a session identifier, your selected hospital (if any), and identifiers for hospital contacts already shown in that chat to a UroRef service hosted on Cloudflare. The device identifier is used for service security and rate limiting, not advertising.
Some common responses are produced within that service. Other requests are processed using Google Gemini. The prompt sent to Gemini may include your question, recent chat context, relevant guidance and selected-hospital operational context. Creating an SBAR also sends the question, answer, recent history and selected site to the UroRef service; the SBAR is generated there without a further Gemini request.
Never enter patient-identifiable or confidential information, including names, NHS or hospital numbers, exact dates of birth, addresses or contact details. The app displays this warning, but it does not automatically detect or remove identifiers. If you enter them, they may be transmitted to and processed by the services above.
Chat storage and service logs
- On your device: up to 30 chat messages and related session state are kept for eight hours so an accidentally closed chat can be resumed. ChooseNew patient to delete them sooner, or clear the app's data.
- Temporary service memory: the UroRef service keeps a shortened copy of recent session questions and answers in process memory for up to two hours. The current service does not use a persistent answer cache.
- Security counters and logs: hashed rate-limit counters are retained for up to one hour and one day. UroRef's custom service logs record metadata such as session and selected-site identifiers, response mode, errors, and hashes and lengths of questions and answers; they are designed not to place raw question or answer text in those logs.
Cloudflare and Google may process network, security, abuse-prevention and diagnostic data under their own terms and the service's account settings. Their infrastructure-level retention cannot be established from the app code alone. UroRef does not use Ariadne conversations for advertising. Do not assume the service has zero provider-side retention.
My Hospital and site-aware tools
Your selected hospital is stored on your device. The app may contact the UroRef Cloudflare service to obtain the current list of sites and operational profile; bundled fallback profiles may remain available offline. The selected site is also included in Ariadne requests so that relevant local operational context can be shown.
If you choose Request your site, the app sends the hospital name, optional trust name and your NHS email address to the UroRef service. These details are stored in Cloudflare KV for review and may be forwarded through Google Apps Script and Gmail to notify the UroRef administrator. The main request record currently has no automatic expiry. Email nity@uroref.com to request deletion.
Diagnostics and external services
UroRef does not include a dedicated crash-reporting SDK. Apple, Google, Cloudflare or Google Gemini may nevertheless process platform, network, diagnostic, security or abuse-prevention data under their own settings and privacy terms.
Tapping an external resource may open BAUS, MDCalc, BURST, Google Forms or an app store. Some QR images are generated by api.qrserver.com. These services receive ordinary network information such as an IP address and apply their own privacy policies.
Cookies
UroRef does not set advertising or cross-site tracking cookies. Analytics are disabled by default; if approved Umami measurement is enabled, it will use its cookieless mode and this notice will be updated. Embedded and external services you choose to open may process ordinary request information under their own terms.
Third-party services
- GitHub Pages — website hosting and ordinary web-request processing needed to serve the site.
- Cloudflare Workers and KV — Ariadne, live hospital data, rate limiting and site requests.
- Google Gemini — generation of some Ariadne responses.
- Google Apps Script, Gmail and Google Forms — site-request notification and feedback.
- Google Fonts — website typefaces; system fonts provide an offline fallback.
- api.qrserver.com and linked clinical websites — QR images and external resources.
- Apple and Google — for app distribution and any platform diagnostics you permit.
- Umami — optional aggregate site measurement, currently disabled unless explicitly configured.
Security
Connected-feature data is sent over HTTPS. No online service is risk-free, so never submit identifiable patient information or other confidential data to Ask Ariadne.
Your rights
Under UK GDPR you may have rights of access, rectification, erasure, restriction, portability and objection. To exercise a right, emailnity@uroref.com. We aim to respond within one month.
Changes
If this policy materially changes, the "last updated" date above will change and the change will be noted on the Updates page.
UroRef is a quick reference tool, not a substitute for clinical judgement. Always verify against your trust guidelines and seek senior advice where appropriate.