Health Data & Permissions
This page is the published data inventory for RxFolio. It lists every category of information the product processes, the purpose, where it is stored, and who else can receive it. It is the same source used for our app-store data-safety declarations.
Data inventory
| Data | Examples | Where stored | Purpose | Shared with |
|---|---|---|---|---|
| Account identity | Email address, display name, provider user id, profile photo URL | Our database | Authentication, subscriber record, plan entitlements | Google or Microsoft as identity provider |
| Medications | Name, strength, dose, route, frequency, schedule, intake logs, notes | Our database | Medication tracking and reminders | Caregivers you invite |
| Medication label images | Photo attached to a medication record (not read or analysed for text) | Our database (size-limited image bytes) | Help you identify a medication visually | Caregivers you invite |
| Vitals and measurements | Blood pressure, glucose, heart rate, weight, temperature, SpO₂ | Our database | Health tracking and trends | Caregivers you invite |
| Clinical history | Symptoms, moods, conditions, allergies, procedures, diagnoses, inventory | Our database | Personal health record | Caregivers you invite |
| Care network | Doctors, hospitals, hospital visits, hospital identifiers, insurance details | Our database | Organize care and visits | Caregivers you invite |
| Medical documents | Prescriptions, lab and imaging reports, discharge summaries, bills | Files in your own Google Drive or OneDrive, in their original format | Document storage and organization. RxFolio does not read the contents. | Google or Microsoft (your own storage account) |
| Details you record against a document | Medication names, dosages, dates, values you enter yourself | Our database | Make a document searchable and chartable | None |
| Care grants | Invitee email, profile, member kind, permissions, status | Our database | Let a caregiver or clinician access a profile you own | The person you invite |
| Guest share sessions | Clinic phone (encrypted), PIN hash, expiry, revoke state, profile, purpose | Our database | Time-boxed, read-only clinic view without a RxFolio account | The guest who redeems the phone and PIN, until expiry or revoke |
| Care-access audit | Actor id, owner id, profile id, timestamp (no clinical content) | Our database | Security, accountability, and abuse investigation | None |
| Visit-preparation report content | The records you selected for a report, plus the generated summary text | Transient at our API while the report is generated | Draft a summary you can review before a consultation | Summarization model (self-hosted by default) — see Data Processing |
| Usage counters | Feature request counts per period | Our database | Apply plan limits, prevent abuse | None |
| Preferences | Appearance, language, reminder and notification settings | Our database and device storage | Keep your configuration across devices | None |
| Purchase identifiers | Product id, order id, hashed purchase token, plan tier | Our database | Verify and renew entitlements | Google Play or Apple; payment processor |
| Technical and security data | IP address, device type, OS, app version, login timestamps, audit logs | Server and infrastructure logs | Security, abuse prevention, troubleshooting | Cloud infrastructure provider |
| Crash diagnostics | Stack traces, device model, app version | Crash-reporting service, where enabled in a build | Fix defects | Crash-reporting vendor |
Where the inventory says records are shared with caregivers, the same rows are also visible to a clinic guest while a Guest-access PIN window is live (read-only). See Privacy Policy — Guest access.
Health data is deliberately excluded from advertising systems, behavioural analytics, URLs and query strings, push-notification payloads, ordinary application logs, and crash reports.
Device permissions
RxFolio requests the minimum permissions needed, and requests them at the moment you activate the relevant feature rather than at startup. If you decline a permission, only the dependent feature is unavailable.
| Permission | Why it is requested | When |
|---|---|---|
| Camera | Photograph a prescription, report, bill, or medication label so the image can be stored. The capture is not read or analysed. | Only when you take a photo |
| Photo library / file picker | Attach an existing document or image to a record | Only when you pick a file |
| Notifications | Deliver medication reminders and alarms you configure | When you first enable a reminder |
| Contacts | Let you pick a person from the system contact picker when adding a profile member | Only when you use the contact picker |
| Network state | Detect whether the service is reachable, since clinical features require connectivity | Continuous, no user data involved |
RxFolio does not request location, microphone, Bluetooth, SMS, call logs, or Health Connect / HealthKit permissions in this release, and does not read health data from other apps on your device.
Cloud-storage scopes
Connecting Google Drive or Microsoft OneDrive is optional. RxFolio requests narrowly scoped access wherever the platform supports it.
- Google Drive
-
RxFolio prefers the per-file scope (
drive.file), which limits access to files RxFolio creates and files you explicitly select. RxFolio does not request permission to read your whole drive, and does not browse unrelated files. - Microsoft OneDrive
-
Sign-in uses
User.Readonly. If you choose to store documents in OneDrive, RxFolio then asks separately forFiles.ReadWrite, which covers your own OneDrive files. RxFolio does not requestFiles.ReadWrite.All, so it has no access to your wider organization’s content. This scope is also what allows a caregiver you have invited to reach a profile folder you shared with them.
Microsoft’s narrower app-folder scope (Files.ReadWrite.AppFolder) is not used,
because it cannot access folders shared between family members and is unavailable on work and
school Microsoft accounts — it would break caregiver access.
What RxFolio writes, and in what form
| Location in your account | Contents | Encrypted? | Openable without RxFolio? |
|---|---|---|---|
RxFolio/Profiles/<profile id>/Records/<category>/ |
Your medical documents, one folder per person you keep records for, in folders for
Reports, Prescriptions, Discharge Notes, Bills, Insurance, Doctors, Hospitals, Hospital
Visits, and Visit_Preps. Named
<profile id>_<YYYYMMDD>_<original name>. The profile id is
an opaque identifier, so neither your email address nor a patient name appears in the
folder or file names.
|
No RxFolio encryption layer — original PDFs and images | Yes, in any Drive/OneDrive viewer, on any device |
Your medical documents are the only thing RxFolio writes to your cloud account. Keeping them in their original format is deliberate: your records stay portable and remain accessible to you even after you delete your RxFolio account, since the files live in your account rather than ours. The trade-off is that, because RxFolio adds no encryption layer of its own, their protection rests on your cloud provider’s encryption and the security of your Google or Microsoft account — so secure that account and prefer two-step verification.
You can revoke RxFolio’s access at any time from your Google or Microsoft account settings; files already written stay where they are. See the Privacy Policy.
Third-party components
RxFolio contains no advertising SDKs and no behavioural-analytics SDKs. The third-party services it does rely on — identity, cloud storage, hosting, app-store billing, and optional crash reporting — are described at Data Processing & Subprocessors.
Keeping this page accurate
Whenever the data we collect, the data we share, a third-party component, a permission, a health feature, or a processing purpose changes, we review this page together with the Privacy Policy, our app-store data-safety declarations, our consent notice, and our retention schedule, so the published description matches the shipped product.