Security & Privacy

Data Processing & Subprocessors

Effective date: 22 August 2026 · Last updated: 22 August 2026
Companion to the Privacy Policy

RRCH Labs is the Data Fiduciary for RxFolio. To operate the Service we rely on a small number of providers. This page describes the categories of provider, what each receives, and the safeguards that apply.

How we choose and control processors

Provider categories

Category Function Data received Health data involved
Cloud infrastructure and database hosting Run the RxFolio API and database All server-side account and clinical data, plus infrastructure logs Yes, as processor
Identity providers (Google, Microsoft) Authenticate you and issue identity tokens Your sign-in event, email, name, provider identifiers No
Your cloud storage (Google Drive, Microsoft OneDrive) Hold your medical documents in your own account The document files you choose to store, in their original format Yes, in your own account under your control
Summarization model (visit-preparation reports) Draft the wording of a visit-preparation report you ask us to generate Only the records you selected for that report Yes, for the duration of that request
App stores and payment processors Sell and verify subscriptions Purchase identifiers, order identifiers, subscription state No
Device-local notification scheduling Deliver medication reminders you configure on your device Reminder schedule and trigger metadata on the device only No — no third-party push transport in the current release
Error and crash monitoring Detect and diagnose defects, where enabled in a build Stack traces, device model, app version, coarse diagnostics No — health data is excluded from reports
Email delivery Respond to support and privacy requests Your email address and the content of your correspondence Only if you include it in your message
Backup and disaster recovery Protect against data loss, on infrastructure we control Our encrypted database backups — never written to your cloud account Yes, as processor
Indian drug reference registry (ABDM) Look up medicine names and strengths as you type The search term you type; no account or clinical record No

RxFolio uses no advertising networks, no data brokers, and no behavioural-analytics providers. There is no category of provider in the list above whose purpose is marketing or profiling.

Visit-preparation report generation

This is the only feature in RxFolio that sends your health content to a language model, and it runs only when you ask for a report. Generation happens on the RxFolio API rather than on your device, so model credentials stay server-side and we can apply rate limits and standard safety wording.

Only the records you selected for that report are included, together with the relevant hospital name when you chose one. The contents of your stored documents are never sent — at most the model is told that a document of a given type exists. Patient and clinician names are also excluded; the patient name is affixed to the report title on your device after generation.

In our current production deployment the model is self-hosted on infrastructure we operate, so the content is not passed to an outside model vendor, and the third-party providers the software can be configured to use are disabled. If that ever changes, the third-party provider would process the content under its own terms and retention policy, and we would update the Privacy Policy and name the provider before the change took effect. You can ask us at any time which model is in use. If generation is unavailable, RxFolio falls back to a plain structured summary assembled without a model.

The feature is optional. If you would rather no health content be processed this way, do not generate visit-preparation reports; everything else in RxFolio works without them.

Named providers

The table below names the material third-party and infrastructure providers we use today. If we add or replace a provider, we update this page and the Privacy Policy before the change takes effect.

Provider Purpose Data processed Processing location
RRCH Labs (self-hosted infrastructure) RxFolio API, database, encrypted backups, and self-hosted Ollama for visit-preparation reports Structured health data, subscriber records, transient visit-prep inputs India
Google LLC Sign-in, and Google Drive storage where you authorize it Identity claims; the document files you choose to store, in your own account Per Google’s policies
Microsoft Corporation Sign-in (Microsoft Entra ID), and OneDrive storage where you authorize it Identity claims; the document files you choose to store, in your own account Per Microsoft’s policies
Functional Software, Inc. (Sentry) Crash and error monitoring, where enabled in a given build Stack traces, device model, app version (health data excluded) United States (Sentry.io)
Google Play / Apple App Store Sell and verify subscriptions Purchase and order identifiers, subscription state Per store policies
Ayushman Bharat Digital Mission (ABDM) drug registry Medication name and strength lookup as you type The search term you type (proxied through our API) India

The summarization model used for visit-preparation reports is self-hosted by us and is therefore not a third-party processor in the current deployment; see the section above.

Change notice

To request the current list, or to be told about changes, write to privacy@rxfolio.org. Where a change materially affects how your personal data is processed, we update the Privacy Policy and, where required, seek renewed consent.

International processing

Our providers may process data in countries other than your own. Where required by applicable law we apply appropriate safeguards, and we do not transfer personal data to any territory restricted by the Government of India for such transfers. See Privacy Policy § 28.