Privacy Policy
Table of Contents
1. Overview & Core Philosophy
Welcome to MediSap, developed by Nirakar Labs. We believe your medical history and prescription details are deeply personal. Unlike traditional healthcare applications that require cloud accounts and transmit patient data across the internet, MediSap is engineered with a 100% On-Device, Local-First Architecture.
2. Information Handled by MediSap
All data processed by MediSap is created and stored exclusively on your physical device:
- Medical Images: Photos of prescription sheets, medicine bottles, cartons, or lab reports captured via camera or selected from your gallery.
- Audio Recordings: Voice notes recorded during doctor visits to document oral instructions and dosage schedules.
- Profiles: Profile names, avatars, dates of birth, and general notes created for you or your family members.
- Categories & Notes: Classification tags (Medicine, Prescription, Lab Report, Doctor Visit, Other) and dosage overlay text.
3. Device Permissions & Scopes
In accordance with Google Play Developer Policies, MediSap requests only the minimum runtime permissions necessary to deliver core features:
- Camera (
android.permission.CAMERA/NSCameraUsageDescription): Required to scan prescriptions and medicine packaging. Images are processed locally on device. - Microphone (
android.permission.RECORD_AUDIO/NSMicrophoneUsageDescription): Required only when you explicitly tap the record button to capture verbal consultation advice. - Media / Photos Storage: Required to allow users to import existing photos of prescriptions from their gallery or export saved records upon user request.
- Foreground Service (
android.permission.FOREGROUND_SERVICE_MEDIA_PLAYBACK): Used solely to provide reliable audio playback of recorded doctor instructions.
4. Doctor Voice Memo Consent Policy
MediSap includes audio recording capabilities to prevent patients from forgetting crucial oral instructions provided during consultations.
User Responsibility: Different jurisdictions have varying laws regarding audio recording (one-party vs. two-party consent). Users must always inform their healthcare provider and obtain explicit verbal consent prior to activating the audio recording feature.
5. Third-Party Services & Analytics
MediSap uses a minimal set of third-party infrastructure for application maintenance and reliability only:
- Google Firebase Realtime Database: Used exclusively to retrieve application version metadata (to alert users if an important update is available) and broadcast critical maintenance announcements. No medical records, names, images, or audio are ever transmitted to Firebase.
- Google Firebase Crashlytics & Analytics: Collects anonymized crash diagnostics and generic performance metrics (device model, OS version) to fix technical bugs. No health information or patient identifiable information is accessible or transmitted.
6. Data Retention & User Deletion Rights
Because your data is stored locally in an SQLite database on your device, you possess total control over data retention:
- Record Deletion: Deleting a medical record deletes the associated SQLite entry and permanently deletes the corresponding photo file, thumbnail, and audio file from storage.
- Profile Deletion (Cascading): Deleting a family member profile automatically cascades and deletes all associated records, photos, and voice notes permanently.
- App Uninstallation: Uninstalling MediSap automatically removes all local sandbox files and database entries created by the app.
7. Children's Privacy (COPPA Compliance)
While parents or guardians may create family profiles for their children to track their pediatric prescriptions, MediSap does not collect or transmit personal information from children to remote servers. The application is completely local and complies with the Children's Online Privacy Protection Act (COPPA).
8. Security Architecture
MediSap implements SQLite with Write-Ahead Logging (WAL) within the application's isolated sandbox directory. File writes are cryptographically verified before save completion. Because there is no centralized database, there is no single point of failure or remote honeypot susceptible to mass data breaches.
9. Contact & Inquiries
For any questions, clarifications, or feedback regarding this Privacy Policy or MediSap's data architecture, please contact Nirakar Labs:
Developer: Nirakar Labs
Email: nirakarlabs@gmail.com
Application: MediSap (com.nirakarlabs.medisap)