Security & Privacy

Health Data & Permissions

Effective date: 22 August 2026 · Last updated: 16 September 2026
Companion to the Privacy Policy

This page is the published data inventory for RxFolio. It lists every category of information the product processes, the purpose, where it is stored, and who else can receive it. It is the same source used for our app-store data-safety declarations.

Data inventory

Data Examples Where stored Purpose Shared with
Account identity Email address, display name, provider user id, profile photo URL Our database Authentication, subscriber record, plan entitlements Google or Microsoft as identity provider
Medications Name, strength, dose, route, frequency, schedule, intake logs, notes Our database Medication tracking and reminders Caregivers you invite
Medication label images Photo attached to a medication record (not read or analysed for text) Our database (size-limited image bytes) Help you identify a medication visually Caregivers you invite
Vitals and measurements Blood pressure, glucose, heart rate, weight, temperature, SpO₂ Our database Health tracking and trends Caregivers you invite
Clinical history Symptoms, moods, conditions, allergies, procedures, diagnoses, inventory Our database Personal health record Caregivers you invite
Care network Doctors, hospitals, hospital visits, hospital identifiers, insurance details Our database Organize care and visits Caregivers you invite
Medical documents Prescriptions, lab and imaging reports, discharge summaries, bills Files in your own Google Drive or OneDrive, in their original format Document storage and organization. RxFolio does not read the contents. Google or Microsoft (your own storage account)
Details you record against a document Medication names, dosages, dates, values you enter yourself Our database Make a document searchable and chartable None
Care grants Invitee email, profile, member kind, permissions, status Our database Let a caregiver or clinician access a profile you own The person you invite
Guest share sessions Clinic phone (encrypted), PIN hash, expiry, revoke state, profile, purpose Our database Time-boxed, read-only clinic view without a RxFolio account The guest who redeems the phone and PIN, until expiry or revoke
Care-access audit Actor id, owner id, profile id, timestamp (no clinical content) Our database Security, accountability, and abuse investigation None
Visit-preparation report content The records you selected for a report, plus the generated summary text Transient at our API while the report is generated Draft a summary you can review before a consultation Summarization model (self-hosted by default) — see Data Processing
Usage counters Feature request counts per period Our database Apply plan limits, prevent abuse None
Preferences Appearance, language, reminder and notification settings Our database and device storage Keep your configuration across devices None
Purchase identifiers Product id, order id, hashed purchase token, plan tier Our database Verify and renew entitlements Google Play or Apple; payment processor
Technical and security data IP address, device type, OS, app version, login timestamps, audit logs Server and infrastructure logs Security, abuse prevention, troubleshooting Cloud infrastructure provider
Crash diagnostics Stack traces, device model, app version Crash-reporting service, where enabled in a build Fix defects Crash-reporting vendor

Where the inventory says records are shared with caregivers, the same rows are also visible to a clinic guest while a Guest-access PIN window is live (read-only). See Privacy Policy — Guest access.

Health data is deliberately excluded from advertising systems, behavioural analytics, URLs and query strings, push-notification payloads, ordinary application logs, and crash reports.

Device permissions

RxFolio requests the minimum permissions needed, and requests them at the moment you activate the relevant feature rather than at startup. If you decline a permission, only the dependent feature is unavailable.

Permission Why it is requested When
Camera Photograph a prescription, report, bill, or medication label so the image can be stored. The capture is not read or analysed. Only when you take a photo
Photo library / file picker Attach an existing document or image to a record Only when you pick a file
Notifications Deliver medication reminders and alarms you configure When you first enable a reminder
Contacts Let you pick a person from the system contact picker when adding a profile member Only when you use the contact picker
Network state Detect whether the service is reachable, since clinical features require connectivity Continuous, no user data involved

RxFolio does not request location, microphone, Bluetooth, SMS, call logs, or Health Connect / HealthKit permissions in this release, and does not read health data from other apps on your device.

Cloud-storage scopes

Connecting Google Drive or Microsoft OneDrive is optional. RxFolio requests narrowly scoped access wherever the platform supports it.

Google Drive
RxFolio prefers the per-file scope (drive.file), which limits access to files RxFolio creates and files you explicitly select. RxFolio does not request permission to read your whole drive, and does not browse unrelated files.
Microsoft OneDrive
Sign-in uses User.Read only. If you choose to store documents in OneDrive, RxFolio then asks separately for Files.ReadWrite, which covers your own OneDrive files. RxFolio does not request Files.ReadWrite.All, so it has no access to your wider organization’s content. This scope is also what allows a caregiver you have invited to reach a profile folder you shared with them.

Microsoft’s narrower app-folder scope (Files.ReadWrite.AppFolder) is not used, because it cannot access folders shared between family members and is unavailable on work and school Microsoft accounts — it would break caregiver access.

What RxFolio writes, and in what form

Location in your account Contents Encrypted? Openable without RxFolio?
RxFolio/Profiles/<profile id>/Records/<category>/ Your medical documents, one folder per person you keep records for, in folders for Reports, Prescriptions, Discharge Notes, Bills, Insurance, Doctors, Hospitals, Hospital Visits, and Visit_Preps. Named <profile id>_<YYYYMMDD>_<original name>. The profile id is an opaque identifier, so neither your email address nor a patient name appears in the folder or file names. No RxFolio encryption layer — original PDFs and images Yes, in any Drive/OneDrive viewer, on any device

Your medical documents are the only thing RxFolio writes to your cloud account. Keeping them in their original format is deliberate: your records stay portable and remain accessible to you even after you delete your RxFolio account, since the files live in your account rather than ours. The trade-off is that, because RxFolio adds no encryption layer of its own, their protection rests on your cloud provider’s encryption and the security of your Google or Microsoft account — so secure that account and prefer two-step verification.

You can revoke RxFolio’s access at any time from your Google or Microsoft account settings; files already written stay where they are. See the Privacy Policy.

Third-party components

RxFolio contains no advertising SDKs and no behavioural-analytics SDKs. The third-party services it does rely on — identity, cloud storage, hosting, app-store billing, and optional crash reporting — are described at Data Processing & Subprocessors.

Keeping this page accurate

Whenever the data we collect, the data we share, a third-party component, a permission, a health feature, or a processing purpose changes, we review this page together with the Privacy Policy, our app-store data-safety declarations, our consent notice, and our retention schedule, so the published description matches the shipped product.