Data Retention & Deletion
This page states how long RxFolio keeps each category of data and precisely what happens when you delete your account. It is written so you can verify the outcome, not just trust it.
Retention schedule
| Category | Retention | Basis |
|---|---|---|
| Account and subscriber record | Life of the account; removed on deletion | Provide the Service |
| Clinical records (medications, vitals, symptoms, conditions, procedures, allergies, documents metadata) | Until you delete the record, or until account deletion | You asked us to store it |
| Document references held by us (type, title, and where the file is filed) | Until you delete the document, or until account deletion | Let you find and open your documents. The files themselves are in your own cloud account, not ours. |
| Care grants and invitations | Until revoked, declined, or account deletion | Enable care sharing you requested |
| Guest share sessions (clinic phone, PIN hash, expiry) | Until the window expires or is revoked, and removed on account deletion | Enable the guest PIN you created |
| Preferences and settings | Life of the account; removed on deletion | Provide the Service |
| Usage counters | Rolling periods used for plan limits; removed on deletion | Apply plan limits, prevent abuse |
| Care-access audit events | Retained at least twelve (12) months; identifiers anonymized rather than deleted where retention is legally required | Security obligation to detect and investigate unauthorized access |
| Server and security logs | A limited, defined period consistent with security obligations | Security and abuse investigation |
| Crash diagnostics | The vendor’s standard period, where enabled in a build | Fix defects |
| Billing and tax records | As required by applicable tax and accounting law | Legal obligation |
| Our encrypted database backups (on infrastructure we control, never in your cloud account) | Rotated on a defined cycle; deleted data disappears as backups age out | Disaster recovery |
| Session cache on your device | Cleared when you sign out, clear app data, or uninstall | Ephemeral working memory only |
| Documents in your own Drive or OneDrive | Indefinitely, until you delete them in that account | The files belong to your storage account, not to us |
What account deletion removes
When you delete your account — from the application or from this website — we run a single deletion workflow that removes the data associated with your identity from our systems:
- Your subscriber record, plan tier, and entitlement state;
- Structured clinical data across every record type: medications, schedules, schedule times, intake logs, medication images, vitals and health data, symptoms, moods, activities, allergies, conditions, procedures, reports, prescriptions, discharge notes, bills, insurance details, hospital records, doctors, and hospital visits;
- Clinical profiles and profile membership rows;
- Synchronization row versions, checkpoints, and stored sync blob files;
- Document reference records held by us;
- Care grants you own and care grants where you were the invitee;
- Your preferences and entity associations;
- Usage-tracking rows keyed to your account and email;
- Your authenticated session; tokens on the device used are cleared.
Deletion is executed immediately as a single database transaction plus file cleanup. It is not a "disable" or "freeze": the rows are removed, not flagged.
What deletion does not remove
-
Files in your own Google Drive or OneDrive. Everything under the
RxFolio/folder belongs to your storage account, so your documents stay readable and accessible to you after deletion — this is intentional, not an oversight. Delete the folder yourself if you want them gone. - Store subscriptions. Cancel a Google Play or Apple subscription in that store; deleting your RxFolio account does not cancel billing.
- Your Google or Microsoft account. RxFolio cannot and does not delete it. You may separately revoke RxFolio’s access in that provider’s settings.
- Copies you already shared. A report you sent to a doctor, caregiver, or family member stays with that recipient.
- Our encrypted backups already written. Data persists in the rotating disaster-recovery backups we hold on our own infrastructure for a limited period, until those backups age out and are overwritten.
- Records we must keep by law. Billing and tax records, and security or audit events required to detect and investigate unauthorized access, are retained for their statutory period. Where possible we anonymize the identifiers in those records rather than keeping them linked to you.
Deletion audit records we keep to prove that a deletion happened contain identifiers and timestamps only. We do not put health information into deletion audit records.
Export before you delete
Deletion cannot be undone and we cannot restore an individual account from backups. If you want to keep a copy, export your data first: in the application, use Account settings to download an account data export. The export includes your account metadata, preferences, care grants, clinical records, and document references. It intentionally excludes document file contents and medication image bytes, and does not include the contents of your Drive or OneDrive folders — those files are already yours and already openable without RxFolio.
Caregiver and shared-profile effects
If you delete your account while others have access to profiles you own, those grants are removed and the caregivers lose access. If you were a caregiver for someone else’s profile, your grant is removed but the profile owner’s data is untouched, because it belongs to their account.
How to delete
In the application
Settings → Account → Delete account & data, then confirm.
By email
Write to privacy@rxfolio.org. We may need to verify your identity. We respond within the period required by applicable law, and aim to acknowledge within 3 business days and resolve within 30 days.