Omelette apps — Privacy Policy
Applies to PubMed Hub, PubMed Connect, Research Notes and Medics on Android (Google Play) and on iPhone, iPad and Mac (App Store) · Last updated: October 4, 2026
Omelette Inc., New York, USA, makes the PubMed Hub, PubMed Connect, Research Notes and Medics apps. This page explains what each app collects, who it goes to, and how to get rid of it. The separate policy for omeletteinc.com covers the website only.
The apps work differently, so each has its own part: PubMed Hub (optional account, library synced between devices) and PubMed Connect (no account; what you keep stays on your device and in its own backup) and Research Notes (no account; journal feeds read on your device) and Medics (no account; what you save stays on your device). Security, children, changes and contact apply to all of them.
PubMed Hub
You can search PubMed in the app without an account. An account is what makes your library sync between your devices, and it is optional.
What the app collects, and why
- Your account — the title, name and email address you enter when you register, and your password, which we store only as a cryptographic hash. Used to sign you in and to keep your library with your account.
- Signing in with Google — only if you choose Continue with Google. Google tells us your name, your email address and an identifier for your Google account, which we use to create your account or sign you in to it. We never see your Google password, and we ask Google for nothing else. If that email address already has a PubMed Hub account, signing in with Google opens it, switches its old password off and emails you to say so; you can set a new password at any time with Forgot password. You can disconnect Google in Your Profile > Connected accounts.
- Your library — the papers you save to My Articles and Favourites and your search history, so they are the same on every device you sign in on.
- Files you add — PDFs you download or add to PDF Box are stored with your account so they are available on your other devices.
- Messages you send us — the name, email address and message you enter on the Contact us screen, plus the app version, so we can reply and reproduce the problem.
- Crash reports — through Google Firebase Crashlytics: device model, operating system version, app version, the error itself, and an installation identifier. It is not linked to your name and we never attach your account to it.
- Advertising — free users see ads served by Google AdMob. The Google Mobile Ads SDK collects and shares with Google, for advertising, analytics and fraud prevention: your device's advertising ID and similar device identifiers, your IP address (which Google may use to estimate your general location), your interactions with the app and its ads, and diagnostics. Where the law requires it you are asked first, and you can change your answer at any time under Privacy choices in the app menu. PubMed Hub Pro subscribers see no ads.
What the app does not collect
- Voice search is handled by your device's own speech service. The app receives only the text.
- Read aloud runs on your device, using its text-to-speech voice. No audio is sent anywhere.
- Payments. Subscriptions are billed by Google Play. The app checks your purchase on the device against Google's signature; we never see your card details and your purchase history is not sent to our servers.
- We do not sell your data, and we do not use it to build advertising profiles of our own.
Services the app contacts
Some features send a request straight from your device to a service that is not ours. Those services receive the request and your IP address, and each has its own privacy policy. PubMed Hub is independent and is not affiliated with or endorsed by any of them.
| Service | What it is used for |
|---|---|
| NCBI E-utilities (U.S. National Library of Medicine) | Every PubMed search and every paper the app displays |
| NIH iCite | The citation count shown on a paper |
| Europe PMC | Downloading the free PDF of an open-access paper |
| Publisher websites, opened through doi.org | "Go to article", which opens the publisher's page in the app |
| Journal RSS feeds | The Research News screen |
| Google AdMob and Firebase Crashlytics | Ads for free users, and crash reports |
| Google Sign-In | "Continue with Google", only when you choose it |
Deleting your account and your data
You can delete your account at any time, either in the app under Your Profile > Delete account, or on the web at api-staging.omeletteinc.com/account/delete. Deletion is immediate and cannot be undone. If your account has no password (because you created it with Google), the app confirms the deletion with a code we email to you.
It removes your saved papers and favourites, your search history, the PDFs you uploaded and the files behind them, your sign-in sessions and any Google sign-in connected to the account. Your name, email address, phone number and password are erased from your account record. What stays is an anonymous marker that an account existed and when it was deleted, which carries nothing about you.
Messages you sent us through Contact us are kept separately until we have dealt with them, together with the address you sent them from, so an open support thread does not vanish mid-conversation. Ask us and we will delete those too.
Signing out removes your library and downloaded files from that device.
Your choices
- Search without an account. Nothing is stored with us until you create one.
- Change your advertising consent at any time under Privacy choices in the app menu, and reset your advertising ID in Android's settings.
- Delete your account in the app or on the web page above.
- Write to us and ask what we hold about you.
On iPhone, iPad and Mac
PubMed Hub from the App Store (version 26.09 and later) works as described above, with these differences.
- Sign in with Apple — if you choose it, Apple gives us an identifier for your Apple account, an email address (or an Apple private relay address if you choose Hide My Email), and your name the first time only, if you share it. Continue with Google uses the system's web sign-in sheet, not a Google SDK, and gives us the same as on Android. When an account that used Sign in with Apple is deleted, we also revoke the app's access with Apple.
- App Store billing — Apple takes payment; we never see your payment details, and the app checks your purchases on the device, so your purchase history is not sent to our servers. When you are signed in, your account's identifier is attached to a purchase as Apple's app account token, so the purchase can be matched to your account. Manage or cancel a subscription in your Apple Account's subscription settings; refunds are handled by Apple. Deleting your PubMed Hub account does not cancel an App Store subscription. Earlier no-ads purchases from version 7.2 keep working while they are valid.
- Ads on iPhone and iPad only — the same Google AdMob collection as above, through the Google Mobile Ads SDK and Google's consent SDK, with Google's consent or opt-out messages where the law requires them. Your advertising identifier is used only if you allow tracking when iOS asks; change that in Settings > Privacy & Security > Tracking, and your consent under Privacy choices in the app. Ads are limited to a general audience rating. There are no ads and no Google SDKs on the Mac.
- No crash-reporting or analytics SDK — the Apple app has no Crashlytics. If you choose to share analytics with app developers in your device's settings, Apple may pass us crash reports and usage statistics.
- Voice search — with your permission for the microphone and speech recognition, Apple's speech recognition turns your speech into a search, on the device where it can, otherwise on Apple's servers under Apple's privacy policy. We receive only the search text.
- On your device — your sign-in is kept in the Keychain on that device only. PDF Box files and NIH books are kept in the app's own storage and left out of iCloud backups. Read aloud uses your device's voices; no text leaves the device for it.
- Coming from version 7.2 — at first launch the app moves what 7.2 left on the device (saved papers, search words, downloaded PDFs and the email address to pre-fill sign-in) into the new version, and deletes 7.2's stored password without reading it. The PDFs are added to your account after you sign in; saved papers are added only if you agree.
- Contact us also sends the app version, the operating system version and the device type, to help us reproduce a problem.
- Services — the same as the table above, without Firebase Crashlytics and Google Sign-In's SDK, plus Apple's sign-in service when you choose Sign in with Apple.
- Deleting your account — in the app's profile screen on iPhone, iPad and Mac, or on the web page above, with the same effect as described above.
PubMed Connect
PubMed Connect has no accounts and no sign-in. What you keep in it stays on your phone and in your phone's own Android backup.
What stays on your phone
- Your reading — the topics you follow, the papers you save, your recent searches, and the free PDFs you download. They are stored in the app's private storage on your phone and are never sent to us.
- Android backup — if backup is turned on for your phone, Android includes your topics, saved papers and recent searches in your phone's own backup, which Google keeps in your Google account. We cannot see it. Downloaded PDFs are not part of that cloud backup; they are copied only when you move straight from one phone to another with Android's own transfer, and you can download a PDF again at any time.
What the app collects, and why
- Your searches — the words you search, your followed topics and the PubMed IDs of your saved papers go straight from your phone to NCBI's PubMed service so it can answer them. They are never sent to us.
- Messages you send us — the name, email address and message you enter on the Contact us screen, and which app it came from, are sent to Omelette Inc.'s server so we can reply.
- Advertising — the app is free and paid for by ads served by Google AdMob: a banner, and now and then a full-screen ad when you close the reader or a PDF. The Google Mobile Ads SDK collects and shares with Google, for advertising, analytics and fraud prevention: your device's advertising ID and similar device identifiers, your IP address (which Google may use to estimate your general location), your interactions with the app and its ads, and diagnostics. Where the law requires it, Google's consent message asks you first, and you can change your answer at any time under More > Privacy choices in the app.
What the app does not collect
- Listen reads a paper aloud with your phone's own text-to-speech voice. No audio is sent anywhere.
- Text you share into the app (or send with "Search PubMed Connect") is turned into a PubMed search on your phone. Only the search itself goes to PubMed.
- There is no crash reporting, no analytics of our own, and no payments or subscriptions.
- We do not sell your data, and we do not use it to build advertising profiles of our own.
Services the app contacts
Searches and papers go straight from your phone to the services below, not through us. Like any website you visit, they receive the request and your phone's IP address, and each has its own privacy policy. PubMed Connect is independent and is not affiliated with or endorsed by any of them.
| Service | What it is used for |
|---|---|
| NCBI E-utilities (U.S. National Library of Medicine) | Every PubMed search, every paper the app displays, the counts for the topics you follow, and a daily check of your saved papers for retractions |
| NIH iCite | The citation count shown on a paper, and its Cited by list |
| Europe PMC | Downloading the free PDF of an open-access paper |
| PubMed Central and publisher websites, opened through doi.org | Reading a paper in the app's reader, which checks each page with Google Safe Browsing |
| Google AdMob and Google's consent service | Ads, and asking for your advertising consent |
| Google Play services | Downloading the app's typefaces |
The app also asks Omelette Inc.'s own server for the day's announcement and the list of our other apps. Those requests carry nothing about you beyond what any web request does (your IP address).
Deleting your data
Everything the app keeps is on your phone. Remove a paper from Saved, delete a PDF in the PDF reader, or clear your recent searches in the app; uninstalling the app, or clearing its storage in Android's settings, removes all of it.
Messages you sent us through Contact us are kept until we have dealt with them, together with the address you sent them from, so an open support thread does not vanish mid-conversation. Ask us and we will delete those too.
Your choices
- Use every feature without giving us anything. Nothing reaches us unless you write to us.
- Change your advertising consent at any time under More > Privacy choices, and reset or delete your advertising ID in Android's settings.
- Write to us and ask what we hold about you.
On iPhone and iPad
PubMed Connect from the App Store (version 26.10 and later) works as described above, with these differences.
- Backup — your topics, saved papers and recent searches are part of your device's own iCloud or computer backup, if you use one. We cannot see it.
- Ads — the same Google AdMob collection as above. Your advertising identifier is used only if you allow tracking when iOS asks; change that in Settings > Privacy & Security > Tracking, and your advertising consent under More > Privacy choices.
- The reader opens PubMed Central and publisher pages in the app's web view; their own policies and cookies apply. The typefaces are part of the app, so nothing is downloaded for them.
- Deleting your data — deleting the app removes everything it kept on your device.
- If you choose to share analytics with app developers in your device's settings, Apple may pass us crash reports and usage statistics. The app itself has no crash-reporting or analytics SDK.
Research Notes
Research Notes has no accounts and no sign-in. It shows the latest articles from the journals you follow, read straight from each journal's own feed.
What stays on your device
- Your reading: the journals you follow, the articles you save, and which articles you have already seen. They are stored in the app on your device and are never sent to us.
- Android backup: if backup is turned on, Android includes these in your device's own backup, which Google keeps in your Google account. We cannot see it.
What the app collects, and why
- Messages you send us: the name, email address and message you enter on the Contact us screen, and which app it came from, so we can reply.
- Advertising: the app is free and shows ads from Google AdMob, a banner and now and then a full-screen ad when you close an article. The Google Mobile Ads SDK collects and shares with Google, for advertising, analytics and fraud prevention: your device's advertising ID and similar identifiers, your IP address (which Google may use to estimate your general location), your interactions with the app and its ads, and diagnostics. Where the law requires it you are asked first, and you can change your answer under More > Privacy choices.
Services the app contacts
To show new articles, your device asks each journal you follow for its feed, directly from the journal's publisher. The publisher receives that request and your IP address, as with any website. Opening an article shows the publisher's page, where the publisher's own policy and cookies apply. The list of journals comes from Omelette Inc.'s server and carries nothing about you. Listen reads an article aloud with your device's own voice; no audio is sent anywhere. There is no crash reporting, no analytics of our own, and no payments.
Deleting your data
Unfollow a journal or remove a saved article in the app; uninstalling the app removes everything it kept on your device. Messages you sent through Contact us are kept until we have dealt with them; ask us and we will delete those too.
Medics
Medics has no accounts and no sign-in. It is a reference for medicines, herbs and supplements, lab tests, medical terms and alternative medicine, written in simple words from public sources.
What stays on your device
- Your saved entries and recently viewed entries: stored in the app on your device and never sent to us. What you type in the search box stays on your device too; searching runs on the phone.
- Android backup: if backup is turned on, Android includes these in your device's own backup, which Google keeps in your Google account. We cannot see it.
What the app collects, and why
- Messages you send us: the name, email address and message you enter on the Contact us screen, and which app it came from, so we can reply.
- Advertising: the app is free and shows ads from Google AdMob, a banner and now and then a full-screen ad when you close an entry. The Google Mobile Ads SDK collects and shares with Google, for advertising, analytics and fraud prevention: your device's advertising ID and similar identifiers, your IP address (which Google may use to estimate your general location), your interactions with the app and its ads, and diagnostics. Where the law requires it you are asked first, and you can change your answer under More > Privacy choices.
Services the app contacts
The entries come from Omelette Inc.'s server, which carries nothing about you. The text is taken from public sources, among them FDA drug labels, the National Institutes of Health, MedlinePlus and the National Library of Medicine, the USDA, Wikipedia and the Government of India's Ayurvedic texts, and some of it is rewritten in simple words with the help of AI. Listen reads an entry aloud with your device's own voice; no audio is sent anywhere. There is no crash reporting, no analytics of our own, and no payments.
Deleting your data
Remove a saved entry in the app; uninstalling the app removes everything it kept on your device. Messages you sent through Contact us are kept until we have dealt with them; ask us and we will delete those too.
All apps
Security
Everything the apps send, to us or to the services above, travels over encrypted connections (HTTPS), except a few journal feeds that their publishers offer only over plain HTTP, and PubMed Hub stores passwords only as hashes.
Children
PubMed Hub, PubMed Connect, Research Notes and Medics are literature and reference tools for adults. They are not directed at children, and we do not knowingly collect personal information from anyone under 13.
Changes
If this policy changes, the new version is posted here with a new date.
Contact
To ask what we hold about you, to request deletion, or with any question about this policy, reach us through the contact form, or the Contact us screen in any of the apps.
PubMed Hub, PubMed Connect, Research Notes and Medics are independent apps from Omelette Inc. PubMed is a registered trademark of the U.S. Department of Health and Human Services. The apps are literature and reference tools and do not give medical advice. Medics is not a government app and is not affiliated with the FDA or any other agency.