Security & Privacy

Last updated: 16 September 2026 · Security contact: privacy@rxfolio.org

Your health data. Your control. RxFolio helps you organize health records while keeping control of where that information is stored: structured clinical data on our servers, and original documents in your own Google Drive or OneDrive when you connect them.

Prescriptions, diagnoses, and medication history are unusually sensitive if exposed. The policies and inventories below are the full public record; the rest of this page describes the controls we apply and the limits of what any system can promise.

Architecture

Where your data sits, and who decides access

The application talks to the RxFolio API over HTTPS. The API holds structured health data in a cloud-hosted database we operate and mediates every read and write, so authorization decisions happen on the server rather than being trusted from the client.

App or web client
    ↓ TLS
RxFolio API
    ↓
    Database — structured health data and metadata
    Google Drive / OneDrive — original documents (your account)

Identity supplied by Google or Microsoft. RxFolio does not hold copies of your document files on its servers.

Document files are handled separately: they are filed into your own Google Drive or OneDrive rather than a store we control. That is a security trade-off we made on purpose — see Documents in your own cloud below.

Controls

What protects your records

Encryption

HTTPS with modern TLS for all client-to-API traffic, and release builds require HTTPS. Database and storage encryption at rest is provided by our infrastructure, with application-level controls where appropriate.

Our database backups are held on infrastructure we control, not in your cloud account. OAuth access tokens are never used as data-encryption keys.

Authentication and authorization

Sign-in is delegated to Google or Microsoft, so RxFolio never receives or stores your password. The API validates identity tokens against the provider’s published signing keys, checks expiry, and enforces the expected audience in production.

Every request is authorized against the authenticated identity, so you can only reach your own records and profiles explicitly shared with you. Plan and entitlement state is owned by the server and cannot be raised by the client. Tokens on your device are held in platform secure storage.

Least privilege

Cloud-storage scopes are as narrow as the platform permits, so RxFolio cannot browse unrelated files. Device permissions are requested only when you use the dependent feature.

Administrative access to production is role-based and limited to those who need it. Database credentials and provider API keys are injected from the environment, never committed to source control.

Health data kept out of telemetry

Health information is deliberately excluded from application and server logs, URLs and query strings, push-notification payloads, analytics events, crash reports, and deletion audit records — which hold identifiers and timestamps only.

We use no advertising systems at all. Tokens and secrets are redacted wherever diagnostic output is produced.

Monitoring, backup, recovery

Security-relevant events are logged and retained for a defined period so unauthorized access can be detected and investigated. Care-access audit events are retained for at least twelve months.

Encrypted backups are taken and rotated on a defined cycle, and dependencies are monitored and updated for known vulnerabilities.

Incident response

We maintain a documented process: detection, classification, containment, investigation, impact assessment, notification, remediation, and post-incident review.

Where a personal-data breach occurs and the law requires it, we notify affected users and the competent authority within the applicable timeframe. See Privacy Policy § 32.

A deliberate trade-off

Documents in your own cloud

Your medical documents are filed into RxFolio/Profiles/<profile id>/Records/ in your own Google Drive or OneDrive, kept in their original PDF or image format so that you can open them independently of RxFolio. RxFolio does not apply an additional application-level encryption layer to these user-owned files. Protection of them is provided by your cloud-storage provider’s own encryption and by your account security. Your documents are the only thing RxFolio writes to your cloud account; our database backups stay on infrastructure we control.

Why we chose this

  • No vendor lock-in on documents you may urgently need
  • Openable from any device, with or without RxFolio installed
  • Your records survive account deletion, because they are in your account
  • No dependence on us keeping a key, or staying in business

What it means for you

  • Those files are only as protected as your Google or Microsoft account
  • Anyone with access to that account can read them
  • Enable two-step verification on it
  • Review third-party apps that can reach your drive

Full detail, including the folder layout and file-naming scheme, is on Features and Health Data & Permissions.

Coordinated disclosure

Reporting a vulnerability

If you believe you have found a security issue, email privacy@rxfolio.org with enough detail to reproduce it. We acknowledge reports and keep you informed as we investigate.

Please do

  • Give us a reasonable opportunity to remediate before public disclosure
  • Use only test accounts containing synthetic data
  • Include clear reproduction steps and the affected component

Please do not

  • Access, modify, or exfiltrate other people’s data
  • Run denial-of-service testing
  • Attempt social engineering against staff or users

Your side

What you can do

Honest limits

No internet-connected system can be guaranteed secure, and we do not claim otherwise. RxFolio is not end-to-end encrypted for structured clinical data: records are stored server-side so the service can sync, search, and share them, which means we hold them in a form our systems can process. Documents in your own cloud storage keep their original format without an RxFolio encryption layer, by design, as explained above. We also make no certification claims we have not earned. Where a specific control matters to your decision, ask us at privacy@rxfolio.org.