Privacy Policy
Last updated: 12 August 2026
MedFolio helps you organize medical documents into a private, on-device timeline. This policy explains what data the app handles, what stays on your device, and the limited cases where data is sent to a third party.
Plain-language summary: your medical documents, the text extracted from them, and all their details stay on your device. They are never uploaded to us — we do not run a server that receives your medical data. Data leaves your device only in the specific, mostly optional cases below.
1. Data stored on your device only
The following never leaves your device except through actions you take (e.g. exporting or backing up):
- Medical documents you add (photos, scans, PDFs) and their original files.
- Text produced by on-device OCR.
- Details — category, patient/profile name, hospital, doctor, visit date, summary.
- Family profiles (name, relationship, date of birth).
- Medicine schedules and dose history.
- App-lock PIN / biometric settings and your backup encryption key.
2. Data sent to third parties
2a. AI document analysis (optional) — Google Gemini
If you tap “Analyze with AI”, the app sends that document's image/file and the text on it to Google's Gemini API to extract details and a summary. It is optional, sent using either your own Gemini API key or a shared free-tier key (subject to a quota), and governed by Google's privacy policy once received by Google. It goes from your device directly to Google.
2b. Encrypted backup (optional) — your Google Drive
If you turn on backup, MedFolio encrypts a copy of your data on the device and uploads it to your own Google Drive. The encryption key stays on your phone and is never uploaded, so Drive only ever stores ciphertext — neither Google nor anyone you share the folder with can read the contents. Restoring needs that key; there is no recovery path if it is lost.
2c. Free-tier quota & anonymous telemetry — Firebase
- A scan counter keyed to a persistent device identifier, to enforce the shared-key limit. It is not linked to your name or medical data.
- Anonymous launch telemetry: app version, platform and OS version.
2d. Crash reporting — Firebase Crashlytics
Crash reports (stack trace, device model, OS version) help us fix bugs. They do not contain your documents or their contents.
3. Permissions we request and why
- Camera — to capture document photos (optional; you can import files instead).
- Notifications — to show medicine-dose reminders.
- Exact alarm / full-screen intent — so dose reminders fire at the exact time and can alert you over the lock screen.
- Biometric — optional app-lock unlock with fingerprint / face.
4. Children's privacy
The app is not directed at children under 13. You may store documents about family members, including children, but that data stays on your device as above.
5. Retention & deletion
On-device data persists until you delete a document/profile or uninstall the app. Free-tier quota records, telemetry and crash reports are retained by Firebase per Google's defaults. SeeData deletion or contact us to remove records tied to your device.
6. Your choices
- Don't run AI scans → no document data is sent to Google.
- Enter your own Gemini key → scans use your key, not the shared one.
- Leave backup off → nothing is uploaded to Drive.
7. Contact
Questions about this policy: quizuncle@gmail.com
Disclaimer: MedFolio is a document-organization tool, not a medical device, and does not provide medical advice, diagnosis or treatment. Always consult a qualified healthcare professional. AI-generated summaries and extracted details may be inaccurate — verify against the original document.