Boom Consulting LLC  ›  SplintFab Scanner

Privacy Policy

How the SplintFab Scanner app handles camera, depth, and scan data.

Last updated: August 2026

Boom Consulting LLC ("we", "our", or "us") built the SplintFab Scanner app for professional orthotics and prosthetics clinicians. This policy explains what information the app handles and how.

1. Data We Collect

The app does not create accounts and does not require a login. It sends nothing to us while you scan. Two things leave the device. When you open the work-order form with an office code saved, the app sends that code to our server to look up your office record and fill in your office details. When you submit a work order, it uploads the scan and the order details. Those are the only requests the app makes; it sends no advertising identifier and nothing that identifies your individual iPhone. That path is described in Sections 4 and 6 below.

Categories of information: a submitted work order carries your name, email address, phone number, and office code; your clinic's name, shipping address, and country; the clinical details for that order — shoe size, which foot is being treated, requested modifications, quantity, and any notes you type; the finished 3D scan file and the name you gave it; a short calibration record naming the iPhone model that produced the scan and the scale factor applied to it; and the app version and iOS version the order was submitted on. The app collects no account credentials, no location, and no advertising identifier, and no record of your activity in the app is collected or transmitted.

2. Camera and Depth Sensor

The app uses your iPhone's front TrueDepth camera and depth sensor solely to capture 3D scans. Camera images and depth data are processed entirely on your device in real time. No camera image, depth frame, or video stream is ever uploaded, shared with us, or accessible to any third party. If you submit a work order, only the finished 3D scan — not the raw camera or depth frames — is uploaded; see Section 4.

Camera permission is required for the app to function. If permission is denied the scanning feature will not be available.

3. Face Data (TrueDepth Camera)

The app uses Apple's TrueDepth camera API as a 3D measurement sensor. During a scan it captures depth maps (per-pixel distance measurements) and colour camera images of whatever is in front of the camera — normally a patient's foot, ankle, or hand. If the camera is pointed at a face, the same depth maps and images may incidentally include face data. This data is collected for one purpose only: to reconstruct a three-dimensional model (a coloured point cloud) of the scanned body part for orthotic and prosthetic fabrication. There are no other uses, planned or otherwise.

To assemble the 3D scan as you move the device around the body part, the app aligns each new depth frame to the model built so far purely by matching their three-dimensional shape (geometric registration of the depth measurements). It does NOT use Apple's ARFaceTrackingConfiguration, any face-tracking API, or any other facial-analysis technology, and it does not use any motion or position sensor. The app performs no facial recognition, no face identification, and no facial analysis of any kind; it does not create faceprints or biometric templates; it does not use face data for authentication, advertising, or identifying any person; and it cannot identify any person from a scan. Like all other camera and depth data, the depth frames used for this alignment are processed on the device in real time and never uploaded or shared.

Storage and retention: in normal use, live depth frames and camera images are processed in memory on the device in real time and immediately discarded — they are not written to disk. Only the resulting 3D model is stored, and only when you explicitly tap Save; it remains in the app's private sandbox on your device until you delete it.

One optional exception: the app's Diagnostics screen includes a "Record scan data" setting that is off by default. If a clinician turns it on, the raw depth and camera frames from each scan are saved to the app's private sandbox on the device. This setting exists only to help improve scanning accuracy. While it is on, those raw frames — which, if the camera is pointed at a face, may incidentally include face data — are written to the device and remain there until you delete them; like all other data, they are never uploaded, transmitted, or shared. Leave this setting off unless you specifically intend to capture raw data.

We never receive or retain the raw camera images or depth frames captured during a scan. The only scan-derived data we ever receive is the finished 3D model, and only if you explicitly submit it to us as part of a work order — see Section 4.

Disclosure and sharing: face data — and all other camera and depth data — is never shared with us or with any third party, and is never uploaded to any server. The finished 3D scan leaves your device only if you explicitly export it using the Share function, or submit it to SplintFab as part of a work order (Section 4). The app contains no third-party SDKs that can access camera or depth data.

4. Scan and Work Order Data

All 3D scans captured with the app are stored locally in the app's private sandbox on your device.

Scans are shared or transmitted only when you take an explicit action: sharing a saved scan yourself using the app's Share function (for example, via AirDrop or email), or submitting a work order to SplintFab for fabrication.

If you submit a work order, the app uploads the scan, as a 3D model file, together with a short calibration record for the iPhone that captured it and the order details you enter — practitioner name, email, phone, office code, clinic name, shipping address, country, shoe size, which foot is being treated, requested modifications, quantity, and any notes — to SplintFab-owned servers hosted on Amazon Web Services (region us-east-1). The upload is encrypted in transit and at rest. Scan files and everything that identifies you or your patient — practitioner name, email, phone, clinic address, and your notes — are deleted automatically 180 days after you submit. What remains after that is a manufacturing record: the order number, the office it was made for, the date, and the device specification. It contains no patient information and no practitioner contact details, and we keep it because we manufacture the device and are required to keep a record of what we made. A work order is identified by its order number and by the name you give each scan — we do not ask for patient identity, and you should not put a patient's name in a scan name or in the notes.

Categories of recipients: two kinds of third party receive work-order information. Amazon Web Services hosts and stores it for us, under a business associate addendum with us. The fabricator assigned to your order reads the order details and downloads the scan files by signing in to our fabrication portal; the portal's download links expire after one hour. When you submit, the fabricator is sent a notification email, but that email contains only the order number and a link to the portal — none of the order details and none of the scan data travel by email. We do not sell work-order data and we do not give it to advertisers, analytics providers, or data brokers. Otherwise we would disclose it only to service providers acting for us, to comply with the law, or where you ask us to.

Reviewing and correcting your details: your name, email, phone, office code, clinic name, shipping address, and country are stored on your device and filled into each new work order, and you can read and edit them on the order form before you submit. Some of those fields come from the office record we hold for your office code, and the app refreshes them from that record when you open the form, so an edit you make on the device to one of those fields can be replaced the next time you open it. To change the office record itself, or to review or correct the details on an order you have already submitted, email sam@splintfab.com from the address on the order and tell us what to change.

When you share a scan yourself using the Share function, that transfer is entirely under your control; we have no involvement in or access to it.

Deleting a scan in the app permanently removes the file from your device. We do not retain copies of scans that were never submitted as a work order.

5. Analytics, Tracking, and Do Not Track

The app contains no analytics, telemetry, crash-reporting services, or advertising SDKs. No usage data of any kind is collected or transmitted.

The app does not track you or your patients, and it builds no profile of behavior over time, either inside the app or across other websites and services. Because nothing is tracked, a Do Not Track signal from your browser or device has nothing to switch off: there is no collection for it to stop and no setting it would change. The app behaves the same whether such a signal is present or not.

No other party collects personally identifiable information about your activities across different websites or services through this app. The app contains no third-party SDKs, no advertising libraries, no third-party analytics, and no embedded content from other companies. SplintFab adds no cookies, scripts, analytics, or trackers to the web page where this policy is posted.

6. Patient Data

When you scan a patient's foot or other body part, that scan constitutes sensitive health-related data. This data never leaves your device without your explicit action — sharing it yourself, or submitting it to SplintFab as part of a work order for fabrication (see Section 4). Responsibility for appropriate handling, retention, and sharing of patient data in accordance with applicable healthcare privacy regulations (such as HIPAA in the United States) rests with the clinician and their organization. If you submit patient data to SplintFab as part of a work order, you are representing that you have the right and any necessary authorization to do so.

7. Children's Privacy and Pediatric Patients

This app is a professional tool, intended for clinical use by adults. It is not directed to children, and children are not its users: the app has no accounts and no sign-in, and it is intended to be operated by the clinician. A scan may be of a patient of any age, including a minor — pediatric orthoses and prostheses are routine orthotic and prosthetic work — and we handle a scan and its work order identically whatever the patient's age. Obtaining any consent required before a scan is taken rests with the clinician and their organization, as described in Section 6.

8. Changes to This Policy

If we update this privacy policy we will revise the "Last updated" date above. The current version is always available at this URL and within the app under About → Privacy Policy.

9. Contact

For privacy questions or concerns please contact:

Boom Consulting LLC
SplintFab Scanner
sam@splintfab.com