Privacy Policy
1. The one-paragraph version
Mediara Vault is a local-first medical record app. Your health records, profiles, documents and vitals are stored encrypted on your own device. Mediara has no server of its own: we never receive, store or can read your health data. The only data that leaves your device does so at your explicit request — an encrypted backup to your own Google Drive — or through features you turn on, such as importing from Health Connect, which stays on-device. There is no analytics and no tracking of any kind, and your health records are never used to target anything shown to you (see §6a).
2. Who the “controller” is
For the overwhelming majority of your data, you are. It lives on your device under keys only your device holds, and Mediara has no technical means to access it.
Mediara acts as a data controller only for the narrow items described in §5 — for example the fact that a backup file exists in your Drive. This local-first design is what keeps the controller’s footprint minimal.
3. What data the app handles, and where it lives
| Data | Examples | Where it is stored | Leaves the device? |
|---|---|---|---|
| Health records | Conditions, medications, allergies, vitals, documents and the text recognised in them, pregnancy and surgery data | Encrypted database (AES-256, whole-file) plus encrypted file vault, on-device only | Only inside an encrypted backup you create |
| Profiles | Names, dates of birth, relationships, including family members and children | The same encrypted on-device store | Only inside an encrypted backup |
| Photos and documents you add | Prescription photos, report scans, wound photos | Encrypted file vault, on-device | Only inside an encrypted backup, or when you share one deliberately |
| Health Connect imports | Steps, heart rate, glucose, blood pressure, weight and the other measurements you authorise | Read from Android Health Connect into the on-device store | No — stays on the device |
| Reminders and notifications | Medication schedules, appointment and measurement reminders | On-device alarms | No |
| Purchase status and monthly usage counts | Whether Mediara Plus is active; how many text extractions and PDF exports you have used this month | This device’s secure storage | No — never transmitted, and not part of your backups |
Special-category data. Almost everything above is health data — a special category under GDPR Article 9, and sensitive data under comparable laws elsewhere. The app’s design keeps it on your device precisely so that this sensitive data is never exposed to the developer or to any third party.
4. Permissions the app asks for, and why
| Permission | Why | Data sent anywhere? |
|---|---|---|
| Camera | Photographing prescriptions and reports to attach, plus wound and profile photos | No — images go straight into the encrypted vault |
| Microphone | Dictating notes instead of typing | No. Voice is handled by your device’s own speech recognition service, in its on-device mode only. The app requires on-device recognition; if your device cannot provide it, dictation is turned off and says so rather than sending audio to a network service. Mediara Vault never stores audio and operates no audio service |
| Notifications | Medication, appointment, vaccination and measurement reminders | No |
| Exact alarms and run-at-startup | Firing reminders on time, and re-arming them after a restart | No |
| Health Connect (read-only) | Importing vitals you already track | No — read locally. The app requests read access only and never write access |
| Internet | Google Sign-In and Google Drive backup and restore | Only those two destinations |
| Biometric | Unlocking the app, and disabling caregiver mode | No |
This version of the app requests no location, contacts, SMS, or advertising-ID permissions, does not request broad storage access, and does not request the ability to query all installed packages. Gallery selection goes through Android’s own photo picker, which returns only the single item you chose.
5. The only things that can leave your device
-
Encrypted backups to your own Google Drive. When you create a backup, an AES-256-encrypted archive is uploaded to your Google account, into a private per-app folder. Two backup types exist:
- Code-protected — end-to-end encrypted. Not even Google can decrypt it without your recovery code.
- Account-portable — a convenience option that escrows a key into your own Drive so a backup restores on any device you sign in to. The trade-off, shown in the app at the moment you choose it: anyone with full access to your Google account — including Google, someone who compromises the account, or a party with lawful process against Google — could unlock an account-portable backup. Code-protected backups are not exposed this way.
- Google Sign-In, used only to authorise Drive access. It is standard Google account authentication, and Mediara receives no health data through it.
- A small amount of backup metadata stored alongside each backup file in your Drive, so the restore screen can list backups before decrypting them: the date, the format version, and a count of profiles. The profile names themselves are encrypted.
- Mediara Plus purchases (optional). If you buy the optional Plus tier, the purchase is handled entirely by Google Play under Google’s terms. Mediara never receives your payment details; the app keeps only your Plus entitlement status, stored on the device. No health data is involved in, or linked to, a purchase.
- Anything you choose to share. A “Share with Doctor” PDF, an individual document, or a
.mediarabackup file goes wherever you send it through Android’s share sheet. This is always something you start, and once shared it is outside the app’s protection. - A crash report you choose to send. Only if you turned the optional Crash reports setting on and then decided to send a saved report yourself, through the share sheet, having read it first. The app never transmits one — see §6.
That is the complete list. There is no other network destination.
6. What the app does not do
- No analytics or telemetry. No analytics SDK is present in the build. The only network-touching components are Google Sign-In, Google Drive, Google Play Billing, and — on the device rather than over the network — ML Kit text recognition and Health Connect.
- No crash-reporting service. There is no crash SDK and no crash server. The optional Crash reports setting (Settings → Privacy, off unless you turn it on) saves a technical record of a crash on your device: the time, the app and Android versions, the error, and the stack trace. It contains no medical records, names, notes or file contents — the report has no field for them, and the error text is reduced before storage. Nothing is sent automatically; if you want to send one you do it yourself, after reading it. Turning the setting off deletes anything saved, and at most five are kept.
- No advertising identifiers, no cross-app tracking, and no profiling of you or of your health data. On advertising itself, see §6a.
- Purchases and usage counts stay on your device. The app keeps only your Plus status and a count of how many times you have used the monthly-limited features in the current month. Both are stored in this device’s secure storage, are never transmitted, contain no health data, and are not part of your backups.
- No selling or sharing of personal data with third parties.
- No developer-operated server that receives your health data.
- No use of Android’s own cloud backup or device-to-device transfer for this app’s data. Those channels are switched off, so your records cannot ride a copy path the app does not control.
6a. Advertising and other paid placements
The app you install today ships no advertising component of any kind. A future release may include advertising or other paid placements. This section states the limits that would apply in advance, so that introducing one could not quietly change how your data is handled:
- Your health records, profiles, documents and vitals are not used to select, target or measure anything shown to you. They stay on your device and Mediara has no copy to use. This is a property of the architecture, not a policy setting — there is no server and no route off the device for them to travel by.
- No advertising identifier is collected, and no personal data is sold or shared with an advertising network.
- Any change of this kind is a material change to this policy: it is shown in the app and your acceptance is requested again before it takes effect (see §12).
We word it this way deliberately. Asserting flatly that the app will never carry advertising would be a promise about every future build, and this policy would become inaccurate the moment the product changed. Binding the limits rather than the presence keeps the protection that actually matters — health data is never used for targeting — without making a promise we cannot underwrite.
7. The emergency card (opt-in)
If you turn on “show without biometric unlock” for the emergency card, a limited set of fields — for example blood group, allergies, key conditions and emergency contacts — can be read from Mediara Vault’s own lock screen without your fingerprint or face, so anyone who can already get into your phone can see them.
This does not place the card on your phone’s own lock screen: the phone must be unlocked first, and the app’s biometric unlock must be turned on for the option to have any effect at all. It is off by default, it exposes only the fields you choose, and nothing else in the app is reachable without your biometric.
8. Data retention and deletion
Because your data is on your device, you control retention. Delete records in the app, empty the Recycle Bin, delete a profile, or uninstall the app to remove all local data. Backups you created in your Google Drive are deleted from Drive by you.
Step-by-step instructions for every case are on the deleting your data page, and the full lifecycle is set out in the Data, Backup & Deletion Policy. There is no deletion request to make to us, because there is nothing on our side to delete.
Two technical retention notes, disclosed for completeness: deleted records rest in the Recycle Bin for 30 days before automatic purge, and the local audit log is bounded to 180 days or 50,000 entries. On a hard delete, the audit log’s related entries are crypto-shredded — their key material is destroyed.
9. Limitations we disclose honestly
- We cannot recover anything for you. Not your data after a lost phone with no backup, not a forgotten recovery code, and not a code-protected backup. This is the direct consequence of having no access, and it is a design decision rather than a gap to be closed later.
- Account-portable backups are not end-to-end encrypted. This is stated in the app at the moment you choose that option, and again in §5. If that trade-off matters to you, use a recovery code.
- A shared export leaves the app’s protection. A PDF summary is human-readable and unencrypted once it is out; where it goes next and how it is handled there is outside this policy.
- The audit log. A tamper-evident log records changes to your data. Historically it could retain encrypted traces of deleted records; this is now mitigated by crypto-shredding on hard delete, plus pruning by age and size.
10. Children’s data
The app is designed to let a parent or guardian keep records for family members, including children, entirely on their own device. That data is never transmitted to Mediara.
Where local law governs children’s data — GDPR Article 8, COPPA and comparable rules — note that the processing occurs on the guardian’s device under their control, and Mediara neither collects nor has access to it. The full statement is the Children’s Privacy Statement.
11. Your rights
Because your data is under your own control on your device, the rights that data-protection law grants you — access, rectification, erasure, portability — are exercised directly in the app: view it, edit it, delete it, and export or back it up. That is a more complete mechanism than any request to us could be, because we hold nothing to act on.
For the narrow controller-held items in §5, or to ask a question, contact support@mediara.care. You also have the right to lodge a complaint with your local data-protection authority.
11a. Users in specific jurisdictions
- United States (CCPA/CPRA and other state privacy laws). We do not sell personal information, do not share it for cross-context behavioural advertising (see §6a — this remains true whether or not the app carries advertising, because no personal data is disclosed to a third party for it), and do not use sensitive personal information for anything beyond the narrow, user-initiated purposes in §5. There is no “Do Not Sell or Share” mechanism because there is nothing to opt out of. Consumer health data, including pregnancy-related data, is covered by the same design: it stays on your device and we never receive it, so we cannot disclose it to anyone — including in response to legal process served on us.
- Canada (PIPEDA). The consent and openness principles are met through this policy and the in-app consent flow; the data-handling facts in §3–§6 apply unchanged.
- Australia (Privacy Act and the APPs). The disclosures in this policy serve as our APP-style privacy notice. Nothing in this policy excludes consumer guarantees under the Australian Consumer Law that cannot lawfully be excluded.
- India (DPDP Act 2023). Your records are processed on your own device under your control; the developer receives no personal data beyond the §5 items, which are handled on the basis of your explicit consent.
- European Union and United Kingdom (GDPR / UK GDPR). Health data is special-category data under Article 9 and is kept on-device by design. Mediara initiates no international transfers; a backup you create stays within your own Google account. For the narrow controller-touched items, the lawful basis is your consent.
- Everywhere. Whatever rights your local law grants you, the app itself is the mechanism — your data is in your hands in a way no request to us could improve on.
11b. This website
Everything above describes the Android app. The website you are reading now is a set of static pages with no accounts, no forms and no server-side processing.
- It sets no cookies and uses no local storage. There is nothing to consent to, which is why there is no cookie banner and no cookie policy.
- It runs no analytics, no tag manager, no advertising pixel and no third-party tracker.
- It loads nothing from a third party. Fonts, styles, scripts and images are all served from this domain, so visiting these pages does not disclose your visit to anyone else.
- Standard server logs kept by the hosting provider may record ordinary technical request data such as an IP address, as any web server does. Mediara does not use these to identify or profile you.
- Links to Google Play and Google Drive are ordinary outbound links; once you follow one, Google’s own policies apply.
12. Changes to this policy
Material changes are reflected here with an updated “last updated” date and are surfaced in the app: the legal set is versioned, and a material change re-arms the consent gate so your acceptance is requested again before continued use. Non-material corrections do not.
13. Contact
Mediara — support@mediara.care. This policy is governed by the laws of India, without displacing mandatory consumer-protection and data-protection rules of the country where you live.
Related: Data, Backup & Deletion Policy · Third-Party Services & Open-Source Notices · Children’s Privacy · Terms of Use · the plain-English security page.